Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-71267] Stack buffer overflow via overly long filenames
Stack buffer overflow via overly long filenames. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120.
High [CVE-2026-71235] Arbitrary Code Execution via Unrestricted Script Execution
Arbitrary Code Execution via Unrestricted Script Execution. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:59467 with package oadp/oadp-velero-rhel9:1786944540. Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; Builds for Red Hat OpenShift; cert-manager Operator for Red Hat OpenShift; Compliance Operator; and 35 more. Affected products named by the advisory: Confidential Compute Attestation; Cryostat 4; Deployment Validation Operator; External Secrets Operator for Red Hat OpenShift; and 31 more.
High [CVE-2026-59679] Font Server Client encoding Out-Of-Bounds Read/Write
Font Server Client encoding[] Out-Of-Bounds Read/Write. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:55447 with package libXfont2-0:2.0.3-12.el9_8.3, libXfont2-0:2.0.3-12.el9_4.3, libXfont2-0:2.0.6-5.el10_2.3, libXfont2-0:2.0.3-12.el9_2.3. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.
High [CVE-2026-44950] Privilege Escalation via Heap Buffer Overflow in Font Server Client
Privilege Escalation via Heap Buffer Overflow in Font Server Client. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:55447 with package libXfont2-0:2.0.3-12.el9_8.3, libXfont2-0:2.0.3-12.el9_4.3, libXfont2-0:2.0.6-5.el10_2.3, libXfont2-0:2.0.3-12.el9_2.3. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.
High [CVE-2026-71202] Denial of Service via integer underflow in image cropping function
Denial of Service via integer underflow in image cropping function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-61485] ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy
- * UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
High [CVE-2026-61483] ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy
- * UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
High [CVE-2026-67592] Apache Qpid ProtonJ2: It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue
High [CVE-2026-67590] Apache Qpid ProtonJ2: pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.
High [CVE-2026-67552] Apache Qpid Proton-Dotnet: pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue
High [CVE-2026-68073] Apache Qpid Broker-J: pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
High [CVE-2026-66274] Denial of Service via unbounded type nesting
Denial of Service via unbounded type nesting. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat AMQ Clients; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 2 more. Affected products named by the advisory: Red Hat build of Quarkus; Red Hat JBoss Enterprise Application Platform Expansion Pack.
High [CVE-2026-66274] Apache Qpid Proton-J: pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
High [CVE-2026-67589] Denial of Service via excessive memory allocation
Denial of Service via excessive memory allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat AMQ Clients.
High [CVE-2026-67589] Apache Qpid ProtonJ2: pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.
High [CVE-2026-67551] Apache Qpid Proton-Dotnet: pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service
pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
High [CVE-2026-68060] Apache Qpid Broker-J: pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
High [CVE-2026-66273] Denial of Service due to excessive allocation
Denial of Service due to excessive allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-66273] Apache Qpid Proton-J: pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
High [CVE-2026-67588] Denial of Service via unbounded symbol value caching
Denial of Service via unbounded symbol value caching. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat AMQ Clients.