Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5Apache

High [CVE-2026-67588] Apache Qpid ProtonJ2: pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.

CVE-2026-67588
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-67465] Apache Qpid Proton-Dotnet: pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.

CVE-2026-67465
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-68074] Apache Qpid Broker-J: pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.

CVE-2026-68074
Unclassified
Aug 5, 2026
High7.5Red Hat

High [CVE-2026-66257] Denial of Service via unbounded symbol value caching

Denial of Service via unbounded symbol value caching. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-66257
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-66257] Apache Qpid Proton-J: pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.

CVE-2026-66257
Unclassified
Aug 5, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64572] free fib_alias with kfree_rcu on insert error path

free fib_alias with kfree_rcu() on insert error path. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-64572
Unclassified
Aug 5, 2026
High7.5Red Hat

High [CVE-2026-67863] Denial of Service via use-after-free vulnerability

Denial of Service via use-after-free vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825.

CVE-2026-67863
Unclassified
Aug 5, 2026
High7.5Red Hat

High [CVE-2026-67870] Denial of Service via incomplete validation in AddReferences

Denial of Service via incomplete validation in AddReferences. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476.

CVE-2026-67870
Unclassified
Aug 5, 2026
High7.5Red Hat

High [CVE-2026-67869] Denial of Service via buffer overflow in Service_Call

Denial of Service via buffer overflow in Service_Call. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125.

CVE-2026-67869
Unclassified
Aug 5, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64577] check skb_pull_data return in gtp1u_send_echo_resp

check skb_pull_data() return in gtp1u_send_echo_resp(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-124.

CVE-2026-64577
Unclassified
Aug 5, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64573] fix NVM tag length underflow in TLV parser

fix NVM tag length underflow in TLV parser. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.

CVE-2026-64573
Unclassified
Aug 5, 2026
High7.0Red Hat

High [CVE-2026-64582] Fix a use-after-free problem in rxe_mmap

Fix a use-after-free problem in rxe_mmap. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-64582
Unclassified
Aug 5, 2026
High7.5Red Hat

High [CVE-2026-67864] Denial of Service via NodeManagement type-instantiation logic

Denial of Service via NodeManagement type-instantiation logic. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1287.

CVE-2026-67864
Unclassified
Aug 5, 2026
High7.5Red Hat

High [CVE-2026-56848] Heap-use-after-free in HTTP/2 handling can lead to denial of service

Heap-use-after-free in HTTP/2 handling can lead to denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-56848
Unclassified
Aug 4, 2026
High8.8Red Hat

High [CVE-2026-15307] Remote code execution via GeoDjango spatial lookups

Remote code execution via GeoDjango spatial lookups. Red Hat rates this important (CVSS 8.8). Weakness: CWE-434. Red Hat lists fixing advisory RHSA-2026:59153 with package ansible-automation-platform-25/hub-rhel8:1787101922, ansible-automation-platform-26/lightspeed-rhel9:1787244079, python3.12-django-0:5.2.17-1.el8ap, ansible-automation-platform-25/lightspeed-rhel8:1787229385. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Discovery 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 5 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0; Red Hat Satellite 6; Red Hat Update Infrastructure 4 for Cloud Providers; Red Hat Update Infrastructure 5; and 1 more.

CVE-2026-15307
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-68494] Denial of Service via incomplete fix in async JSON parser

Denial of Service via incomplete fix in async JSON parser. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:53643 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, jackson-core. Affected products named by the advisory: Cryostat 4; OpenShift Developer Tools and Services; OpenShift Serverless; Red Hat AI Inference Server; and 28 more. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat AMQ Clients; Red Hat Ansible Automation Platform 2; Red Hat build of Apache Camel 4 for Quarkus 3; and 24 more.

CVE-2026-68494
Unclassified
Aug 4, 2026
High7.3Vendor: MediumRed Hat

High [CVE-2026-42169] GIMP APNG loader heap-buffer-overflow when fcTL width exceeds IHDR width (file-png.c)

GIMP APNG loader heap-buffer-overflow when fcTL width exceeds IHDR width (file-png.c). Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-131. Red Hat lists fixing advisory RHSA-2026:50817 with package gimp-2:3.0.4-4.el9_8.9. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-42169
Unclassified
Aug 4, 2026
High7.2Zyxel

High [CVE-2026-14818] path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN series firmware versions from V4.16 through V5.42 Patch 1 could allow an authenticated attacker with administrator privileges to execute a crafted malicious configuration file on an affected device

A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN series firmware versions from V4.16 through V5.42 Patch 1 could allow an authenticated attacker with administrator privileges to execute a crafted malicious configuration file on an affected device.

CVE-2026-14818
Firewalls (USG FLEX/ATP)
Aug 4, 2026
High7.2Zyxel

High [CVE-2026-6837] post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

CVE-2026-6837
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-56846] Remote memory exhaustion via HTTP/2 retained header blocks

Remote memory exhaustion via HTTP/2 retained header blocks. Red Hat rates this important (CVSS 7.5). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:48305 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.

CVE-2026-56846
Unclassified
Aug 4, 2026