Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

3333 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.0Vendor: MediumRed Hat

High [CVE-2026-64208] crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks

crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks. Red Hat rates this moderate (CVSS 7). Weakness: CWE-120.

CVE-2026-64208
Unclassified
Jul 24, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64216] netfs Use-After-Free vulnerability allows local denial of service and memory corruption

netfs Use-After-Free vulnerability allows local denial of service and memory corruption. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.

CVE-2026-64216
Unclassified
Jul 24, 2026
High8.2Red Hat

High [CVE-2026-16804] Sandbox escape via crafted HTML page

Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) This can be achieved by enticing a user to visit a specially crafted HTML page. Successful exploitation could allow the attacker to perform a sandbox escape, potentially gaining elevated privileges or further access to the underlying system. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-787.

CVE-2026-16804
Unclassified
Jul 23, 2026
High8.8Red Hat

High [CVE-2026-16805] Use after free in Blink

Use after free in Blink. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.

CVE-2026-16805
Unclassified
Jul 23, 2026
High8.8Red Hat

High [CVE-2026-16806] Arbitrary code execution via use after free vulnerability in WebMCP

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) This can occur when a user visits a specially crafted HTML page, potentially leading to unauthorized control over the affected system. This vulnerability is rated Important as it allows a remote attacker to achieve arbitrary code execution within the Chromium browser's sandbox. The flaw, a use-after-free in the WebMCP component, is triggered when a user navigates to a specially crafted HTML page, posing a significant risk of unauthorized system control. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

CVE-2026-16806
Unclassified
Jul 23, 2026
High8.8Red Hat

High [CVE-2026-16807] Sandbox escape via crafted HTML page

Sandbox escape via crafted HTML page. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-16807
Unclassified
Jul 23, 2026
High7.8Red Hat

High [CVE-2026-60122] Arbitrary OS command execution via code injection in gpsprof utility

Arbitrary OS command execution via code injection in gpsprof utility. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: gpsd-minimal.

CVE-2026-60122
Red Hat Enterprise Linux
Jul 23, 2026
High7.5Red Hat

High [CVE-2026-14257] Denial of Service via memory exhaustion in expand function

Denial of Service via memory exhaustion in expand() function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:45381 with package nodejs26-main-26.5.0-1.4.hum1, grafana12-4-main-12.4.6-0.4.hum1, nodejs22-main-22.23.1-2.3.hum1, nodejs24-main-24.18.0-0.5.hum1.

CVE-2026-14257
Unclassified
Jul 23, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-64611] cpu exhaustion via infinite loop in cfieee1284normalizemakemodel

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service. A Moderate denial-of-service vulnerability in libcupsfilters allows network attackers to exhaust CPU resources by sending malformed IEEE-1284 device IDs. Red Hat rates this as Moderate because the vulnerable component, cups-browsed, is disabled by default in RHEL. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat fixing advisory: RHSA-2026:56965. Affected products named by the advisory: Red Hat package: libcupsfilters.

CVE-2026-64611
Red Hat Enterprise Linux
Jul 23, 2026
High8.8Red Hat

High [CVE-2026-16745] backend port 8080 trusts x-forwarded-access-token without origin validation

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure. Important: This flaw allows for privilege escalation within the cluster by bypassing authentication. It is due to the odh-dashboard backend binding to 0.0.0.0:8080 and trusting the x-forwarded-access-token header without origin validation. This enables any pod in the cluster to impersonate users by supplying an arbitrary token, circumventing the intended kube-rbac-proxy authentication. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-346. Affected Red Hat products: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4. Red Hat fixing advisory: RHSA-2026:53261, RHSA-2026:53263, RHSA-2026:53262, RHSA-2026:60520.

CVE-2026-16745
Unclassified
Jul 23, 2026
High8.8Red Hat

High [CVE-2026-19496] SQL injection (CWE-89) in query parameter filtering — unsanitised user input interpolated into WHERE clause

SQL injection (CWE-89) in query parameter filtering — unsanitised user input interpolated into WHERE clause. Red Hat rates this important (CVSS 8.8). Weakness: CWE-89.

CVE-2026-19496
Unclassified
Jul 23, 2026
High8.8Red Hat

High [CVE-2026-64835] Arbitrary code execution, information disclosure, or denial of service via crafted ADX/AAX audio files

Arbitrary code execution, information disclosure, or denial of service via crafted ADX/AAX audio files. Red Hat rates this important (CVSS 8.8). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:51180 with package ffmpeg-0:6.1.6-3.el9ai. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-64835
Unclassified
Jul 22, 2026
High7.5Red Hat

High [CVE-2026-64834] Denial of Service via crafted RTP/ASF stream

Denial of Service via crafted RTP/ASF stream. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835.

CVE-2026-64834
Unclassified
Jul 22, 2026
High8.8Red Hat

High [CVE-2026-64831] Arbitrary code execution via crafted HEVC/H.265 bitstream

FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution. A flaw was found in FFmpeg. A remote attacker can exploit a stack buffer overflow vulnerability in the Vulkan HEVC (High Efficiency Video Coding) hardware decoder by providing a specially crafted HEVC/H.265 bitstream. This can lead to overwriting memory on the stack, potentially allowing the attacker to execute arbitrary code on the affected system. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-120. Red Hat lists Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI) as not affected.

CVE-2026-64831
Unclassified
Jul 22, 2026
High7.8Red Hat

High [CVE-2026-44191] Visual Studio Code Ansible Lightspeed extension: Remote Code Execution via command injection in configuration settings

A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker to inject shell separators. This can be triggered automatically during Language Server initialization or manually when executing a playbook. Successful exploitation leads to remote code execution (RCE) on the victim's machine with the privileges of the Visual Studio Code user, potentially resulting in a complete system compromise. This can occur when opening a malicious workspace or manually executing a playbook, leading to a complete compromise of the user's system. Note the VS Code extension is distributed via VS Code Marketplace, not shipped in AAP RPMs or containers. The vulnerable code does not exist in any AAP-shipped artifact. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-78. Red Hat lists Red Hat Ansible Automation Platform 2 as not affected.

CVE-2026-44191
Unclassified
Jul 22, 2026
High7.8Red Hat

High [CVE-2026-44190] Ansible Lightspeed Visual Studio Code extension: Arbitrary code execution via command injection in activation script setting

A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the `ansible.python.activationScript` setting, intended for a virtual environment activation script, does not properly validate user input as a file path. If a user opens or executes a specially crafted project, an attacker could exploit this to gain complete control over the user's system with the privileges of the Visual Studio Code application. It enables arbitrary code execution on a user's system with VS Code process privileges if a malicious project's `.vscode/settings.json` is opened or a playbook executed without prior validation. This could lead to a complete system compromise. Note the VS Code extension is distributed via VS Code Marketplace, not shipped in AAP RPMs or containers. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-78. Red Hat lists Red Hat Ansible Automation Platform 2 as not affected.

CVE-2026-44190
Unclassified
Jul 22, 2026
High7.8Red Hat

High [CVE-2026-44189] Visual Studio Code Ansible Lightspeed Extension: Arbitrary Code Execution via Malicious Playbook Filename

A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters are not properly sanitized, leading to the execution of arbitrary code with the privileges of the user running VS Code. This could result in a full system compromise, including the exfiltration of sensitive data, modification of project files, and permanent data loss. This could result in significant impact to confidentiality, integrity, and availability of user data and the system. Note the VS Code extension is distributed via VS Code Marketplace, not shipped in AAP RPMs or containers. The vulnerable code does not exist in any AAP-shipped artifact. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-88. Red Hat lists Red Hat Ansible Automation Platform 2 as not affected.

CVE-2026-44189
Unclassified
Jul 22, 2026
High7.5Red Hat

High [CVE-2026-40691] Denial of Service via crafted DNSCrypt query

In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. The size clamp that protects the UDP path is not applied on the TCP path, so a reply larger than 65504 bytes is shifted forward by 48 bytes inside a buffer of capacity equal to 'msg-buffer-size', writing past the end of the heap allocation. A single malicious encrypted query crashes the resolver and lead to denial of service. This vulnerability needs Unbound to be compiled with DNSCrypt support ('--enable-dnscrypt') and the 'dnscrypt:' clause to be configured and enabled for the listening interfaces. A flaw was found in Unbound, a domain name system (DNS) resolver. When Unbound is configured with DNSCrypt support, a remote attacker could send a specially crafted DNSCrypt query over TCP. This malicious query could cause a memory error, leading to a server crash and a Denial of Service (DoS). This means legitimate users would be unable to access services relying on the Unbound server. This is an Important denial of service vulnerability affecting Unbound when built with DNSCrypt support. This vulnerability doesn't impact any supported the versions of unbound as shipped with Red Hat Enterprise Linux as it is not compiled with DNSCrypt support.

CVE-2026-40691
Unclassified
Jul 22, 2026
High7.5Red Hat

High [CVE-2026-11331] Potential wildcard CNAME RPZ policy bypass

An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1. A flaw was found in BIND 9, a widely used Domain Name System (DNS) software. A remote attacker could exploit this by sending specially crafted, excessively long DNS queries. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-20. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected. Red Hat fixing advisory: RHSA-2026:55437, RHSA-2026:54509, RHSA-2026:54510, RHSA-2026:55442, RHSA-2026:57189, RHSA-2026:55441, RHSA-2026:54071.

CVE-2026-11331
Red Hat Enterprise Linux
Jul 22, 2026
High8.6Red Hat

High [CVE-2026-13321] DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1. An attacker controlling any DNSSEC-signed zone can craft NSEC records that span into victim zones, enabling cross-zone cache poisoning with authenticated denial-of-service responses (AD=1). Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N). Weakness: CWE-345. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat OpenShift Container Platform 4.22; Red Hat Hardened Images; Red Hat Enterprise Linux 6. Red Hat lists Red Hat Enterprise Linux 9 as not affected. Red Hat fixing advisory: RHSA-2026:55437, RHSA-2026:60383, RHSA-2026:54509, RHSA-2026:54654, RHSA-2026:54510, RHSA-2026:55442, RHSA-2026:57189, RHSA-2026:55441, RHSA-2026:57362, RHSA-2026:54071. Affected products named by the advisory: Red Hat package: bind9.16; Red Hat package: bind9.18.

CVE-2026-13321
Red Hat Enterprise Linux
Jul 22, 2026