Complete feed
Security advisories & CVEs
432 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Critical [CVE-2026-17655] Insufficient validation of untrusted input in ANGLE
Insufficient validation of untrusted input in ANGLE. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-1286.
Critical [CVE-2026-17653] Use after free in Skia
Use after free in Skia. Red Hat rates this critical (CVSS 9). Weakness: CWE-825.
Critical [CVE-2026-17651] Insufficient validation of untrusted input in Dawn
Insufficient validation of untrusted input in Dawn. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-79.
Critical [CVE-2026-17650] Use after free in Compositing
Use after free in Compositing. Red Hat rates this important (CVSS 9.9). Weakness: CWE-825.
Critical [CVE-2026-17652] Use after free in Views
Use after free in Views. Red Hat rates this critical (CVSS 9). Weakness: CWE-825.
Critical [CVE-2026-51992] Arbitrary code execution via SQL Injection in create dictionaries function
Arbitrary code execution via SQL Injection in create dictionaries function. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-89.
Critical [CVE-2026-44210] Privilege escalation and information disclosure via command-line argument injection
Privilege escalation and information disclosure via command-line argument injection. Red Hat rates this important (CVSS 9.9). Weakness: CWE-88.
Critical [CVE-2026-65601] Privilege Escalation via Kubernetes Gateway API Namespace Confusion
Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, Traefik used the backend Service namespace instead of the HTTPRoute namespace. A low-privileged route author holding a ReferenceGrant for a cross-namespace Service could therefore bind a Traefik Middleware from the backend namespace without a separate grant for that middleware, potentially injecting trusted reverse-proxy identity headers into downstream requests. The issue is fixed in version 3.7.7. A flaw was found in Traefik, a cloud-native edge router. This flaw allows an attacker to bypass security controls by incorrectly binding a Traefik Middleware from a different namespace, potentially leading to the injection of trusted identity headers into network requests. This could result in unauthorized access or privilege escalation within the Kubernetes cluster. This is an Important flaw in Traefik's Kubernetes Gateway API provider, affecting Red Hat OpenShift Dev Spaces. A low-privileged user in a Kubernetes environment can exploit a namespace confusion vulnerability to bypass security controls. Red Hat severity: Important — CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N). Weakness: CWE-348. Affected Red Hat products: Red Hat OpenShift Dev Spaces.
Critical [CVE-2026-65600] Authentication bypass via path traversal in ReplacePathRegex middleware
Traefik versions = v3.6.0 = v3.7.0 <= v3.7.6 contain an authentication bypass via path traversal in the ReplacePathRegex middleware. When ReplacePathRegex is configured with a regex that captures user-controlled path segments without a mandatory path separator (e.g. regex "^/api(.*)", replacement "/$1"), the middleware forwards the replaced path to the backend without validating that it matches its normalized form. An unauthenticated remote attacker can send a crafted request (e.g. GET /api../admin) that produces an un-normalized path such as /../admin, which a backend that normalizes paths resolves to a protected route, bypassing authentication middleware. Fixed in v2.11.52, v3.6.23, and v3.7.7. A flaw was found in Traefik. When this middleware is misconfigured, it forwards un-normalized paths, allowing a backend to resolve them to protected routes and grant unauthorized access. This bypass enables access to sensitive administrative interfaces. This Critical flaw in Traefik's `ReplacePathRegex` middleware allows an unauthenticated remote attacker to bypass authentication. The impact to OpenShift Dev Spaces is rated as low, because the affected `ReplacePathRegex` middleware is not configured in the shipped Traefik gateway. Red Hat severity: Critical — CVSS 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N). Weakness: CWE-22.
Critical [CVE-2026-64193] Net::DNS: Net::DNS: Arbitrary code execution via EDNS EXTENDED ERROR handling
Net::DNS: Net::DNS: Arbitrary code execution via EDNS EXTENDED ERROR handling. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-78.
Critical [CVE-2026-12701] relative_path_validator bypass via directory traversal in FilesystemExport
A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../" anywhere in the path. An authenticated administrator can craft a relative_path containing embedded traversal sequences (e.g., "looking/normal/../../../../etc/shadow") that escapes the intended export directory during FilesystemExport operations. Because the file content is also user-controlled (uploaded artifact), this allows arbitrary file write to any location writable by the Pulp service user, potentially leading to service compromise or further system exploitation. This vulnerability is rated as Important severity because an authenticated administrator can achieve arbitrary file write outside the intended export directory with fully attacker-controlled content. The FilesystemExport API is restricted to admin-level users (in Satellite, authenticated via SSL certificate; in standalone RBAC deployments, admin role only). The Pulp process runs as the "pulp" system user (not root), and file permission bits cannot be controlled by the attacker.
Critical [CVE-2026-16242] Konnectivity proxy-server accepts agent connections without validating client certificates
Konnectivity proxy-server accepts agent connections without validating client certificates. Red Hat rates this critical (CVSS 9.4). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:48284 with package multicluster-engine/hypershift-rhel9-operator:1784856942, multicluster-engine/hypershift-rhel9-operator:1784905769, openshift4/ose-hypershift-rhel9:1785192936, multicluster-engine/hypershift-rhel9-operator:1784905804.
Critical [CVE-2026-15773] Use after free in Core
Use after free in Core. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825.
Critical [CVE-2026-15775] Insufficient policy enforcement in V8
Insufficient policy enforcement in V8. Red Hat rates this important (CVSS 9.3). Weakness: CWE-346.
Critical [CVE-2026-15774] Use after free in Skia
Use after free in Skia. Red Hat rates this important (CVSS 9). Weakness: CWE-825.
Critical [CVE-2026-54058] Memory disclosure or denial of service via crafted McIdas AREA image
Memory disclosure or denial of service via crafted McIdas AREA image. Red Hat rates this important (CVSS 9.1). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:48021 with package quay/quay-rhel8:1785261506, python-pillow-0:5.1.1-23.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.
Critical [CVE-2026-57211] Information disclosure via path validation bypass in management plugin
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extension plugins are enabled, causing outbound DNS and SMB requests to attacker-controlled UNC paths. This issue is fixed in versions 4.1.11 and 4.2.6. A flaw was found in RabbitMQ. This can lead to outbound DNS and Server Message Block (SMB) requests to attacker-controlled network paths, potentially disclosing sensitive information. Red Hat severity: Critical — CVSS 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-76. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0 as not affected. Red Hat fixing advisory: RHSA-2026:35939, RHSA-2026:35940.
Critical [CVE-2026-15143] SSRF and local file read via user-supplied XML Schema (xml-with-schema:)
SSRF and local file read via user-supplied XML Schema (xml-with-schema:). Red Hat rates this important (CVSS 9.3). Weakness: CWE-918.
Critical [CVE-2026-15131] Insufficient data validation in Navigation
Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) An insufficient data validation flaw was found in the Navigation component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N). Weakness: CWE-653.
Critical [CVE-2026-15121] Use after free in WebRTC
Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) An use after free flaw was found in the WebRTC component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.