Complete feed
Security advisories & CVEs
3333 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-11605] Unnecessary validation of DNSSEC signed records
The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste disproportionate CPU time. This issue affects BIND 9 versions 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-400. Affected Red Hat products: Red Hat Hardened Images. Under investigation: Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:42853.
High [CVE-2026-11622] Potential memory usage beyond configured limits
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1. This Important flaw in BIND's DNSSEC-validating resolver can lead to a denial of service. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-400. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat OpenShift Container Platform 4.22; Red Hat Hardened Images; Red Hat Enterprise Linux 6. Red Hat lists Red Hat Enterprise Linux 9 as not affected. Red Hat fixing advisory: RHSA-2026:55437, RHSA-2026:60383, RHSA-2026:54509, RHSA-2026:54654, RHSA-2026:54510, RHSA-2026:55442, RHSA-2026:57189, RHSA-2026:55441, RHSA-2026:57362, RHSA-2026:54071.
High [CVE-2026-11721] Cache poisoning via label count discrepancy, RRSIG, wildcards
It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-345. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat OpenShift Container Platform 4.22; Red Hat Hardened Images; Red Hat Enterprise Linux 6. Red Hat lists Red Hat Enterprise Linux 9 as not affected. Red Hat fixing advisory: RHSA-2026:55437, RHSA-2026:60383, RHSA-2026:54509, RHSA-2026:54654, RHSA-2026:54510, RHSA-2026:55442, RHSA-2026:57189, RHSA-2026:55441, RHSA-2026:57362, RHSA-2026:54071.
High [CVE-2026-12617] Record ordering based unexpected exit with CNAME or DNAME
The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds positively to the A query but delays the DNAME response and later responds negatively, `named` may quit unexpectedly. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1. This Important flaw in BIND can lead to a denial of service in Red Hat products. The `named` daemon may terminate unexpectedly when processing specific CNAME/DNAME and A record query orderings, coupled with precisely timed authoritative server responses. Exploitation requires an attacker to manipulate DNS responses from an authoritative server to a vulnerable resolver. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-617. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4 as not affected. Red Hat fixing advisory: RHSA-2026:54071.
High [CVE-2026-13204] Unexpected exit with NSEC and NSEC3 both present
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-617. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat OpenShift Container Platform 4.22; Red Hat Hardened Images; Red Hat Enterprise Linux 6. Red Hat lists Red Hat Enterprise Linux 9 as not affected. Red Hat fixing advisory: RHSA-2026:55437, RHSA-2026:60383, RHSA-2026:54509, RHSA-2026:54654, RHSA-2026:54510, RHSA-2026:55442, RHSA-2026:57189, RHSA-2026:55441, RHSA-2026:57362, RHSA-2026:54071. Affected products named by the advisory: Red Hat package: bind9.16; Red Hat package: bind9.18.
High [CVE-2026-32665] Denial of Service via improper validation of DNS-over-QUIC client length
Denial of Service via improper validation of DNS-over-QUIC client length. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
High [CVE-2026-44690] Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes
Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes. Red Hat rates this important (CVSS 8.6). Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
High [CVE-2026-55973] Denial of Service via malformed EDNS Report-Channel option
Denial of Service via malformed EDNS Report-Channel option. Red Hat rates this important (CVSS 7.5). Weakness: CWE-805. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
High [CVE-2025-50327] Privilege escalation and arbitrary code execution via Mark-of-the-Web bypass
Privilege escalation and arbitrary code execution via Mark-of-the-Web bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1289.
High [CVE-2026-73144] Unbounded memory growth via unvalidated list count in FRN module
Unbounded memory growth via unvalidated list count in FRN module. Red Hat rates this important. Weakness: CWE-770.
High [CVE-2026-56820] Certificate revocation bypass via OCSP response replay attack
Certificate revocation bypass via OCSP response replay attack. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295.
High [CVE-2026-56819] Denial of Service via HTTP/2 DATA frame memory leak
Denial of Service via HTTP/2 DATA frame memory leak. Red Hat rates this important (CVSS 7.5). Weakness: CWE-911. Red Hat lists fixing advisory RHSA-2026:47172 with package netty-codec-http2.
High [CVE-2026-56817] Information disclosure via XML External Entity (XXE) vulnerability
Information disclosure via XML External Entity (XXE) vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-611.
High [CVE-2026-56746] Security control bypass allows unauthorized requests via null origin header
Security control bypass allows unauthorized requests via null origin header. Red Hat rates this important (CVSS 7.5). Weakness: CWE-807. Red Hat lists fixing advisory RHSA-2026:47172 with package netty-codec-http.
High [CVE-2026-56745] Denial of Service via memory exhaustion in SPDY-to-HTTP codec
Denial of Service via memory exhaustion in SPDY-to-HTTP codec. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Red Hat lists fixing advisory RHSA-2026:47172 with package netty-codec-http.
High [CVE-2026-55851] Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message
Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:47172 with package netty-codec-haproxy.
High [CVE-2026-47063] Enhance Jar handling (Oracle CPU 2026-07)
Enhance Jar handling (Oracle CPU 2026-07). Red Hat rates this important (CVSS 7.5). Weakness: CWE-347. Red Hat lists fixing advisory RHSA-2026:50281 with package java-21-openjdk-1:21.0.12.0.8-1.1.el8, java-25-openjdk-main-25.0.4.0.7-1.1.1.hum1, java-21-openjdk-1:21.0.12.0.8-1.1.el9, java-25-openjdk-windows. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7.
High [CVE-2026-47057] Improve Nashorn index handling (Oracle CPU 2026-07)
Improve Nashorn index handling (Oracle CPU 2026-07). Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:42882 with package java-1.8.0-openjdk-1:1.8.0.502.b07-1.1.el7_9, java-1.8.0-ibm-1:1.8.0.8.70-1.el8_10, java-1.8.0-openjdk-1:1.8.0.502.b07-1.2.el9, java-1.8.0-openjdk-windows. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-47058] Enhance Dataview Implementation (Oracle CPU 2026-07)
Enhance Dataview Implementation (Oracle CPU 2026-07). Red Hat rates this important (CVSS 7.4). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:42882 with package java-1.8.0-openjdk-1:1.8.0.502.b07-1.1.el7_9, java-1.8.0-ibm-1:1.8.0.8.70-1.el8_10, java-1.8.0-openjdk-1:1.8.0.502.b07-1.2.el9, java-1.8.0-openjdk-windows. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-56852] Denial of Service via invalid UTF-8 input
Denial of Service via invalid UTF-8 input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:49360 with package prometheus3-5-main-3.5.5-0.3.hum1, buildah-main-1.45.0-2.hum1, opentofu1-10-main-1.10.10-0.3.hum1, podman-main-6.0.2-2.1.hum1.