Complete feed
Security advisories & CVEs
302 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Low [CVE-2026-64647] Information disclosure via server-side request caching
Information disclosure via server-side request caching. Red Hat rates this low (CVSS 3.7). Weakness: CWE-524.
Low [CVE-2026-17513] Denial of Service via ftype argument manipulation
Denial of Service via ftype argument manipulation. Red Hat rates this low (CVSS 3.3). Weakness: CWE-617.
Low [CVE-2026-17512] Information disclosure via out-of-bounds read
Information disclosure via out-of-bounds read. Red Hat rates this low (CVSS 3.3). Weakness: CWE-125.
Low [CVE-2026-66011] ImageMagick before 7.1.2-27 Memory Leak via Invalid CLI Options
ImageMagick before 7.1.2-27 Memory Leak via Invalid CLI Options. Red Hat rates this low (CVSS 3.3). Weakness: CWE-772.
Low [CVE-2026-64317] bound Rock Ridge symlink components to the SL record
bound Rock Ridge symlink components to the SL record. Red Hat rates this low (CVSS 3.9). Weakness: CWE-125.
Low [CVE-2026-17039] CA renewal request processing omits realm authorization check performed by enrollment path
A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization. Red Hat Product Security assessed this issue as having Low impact. However, exploitation additionally requires a non-default, though supported, deployment configuration: a realm-mapped authorization manager configured for multi-tenant or delegated sub-CA (MSP-style) use. Deployments that do not configure this feature are not exposed to this issue. Direct testing was performed to determine the practical consequences of the confirmed bypass rather than relying on the authorization gap alone to drive severity. That testing found no confidentiality impact, since the resulting certificate's content is already retrievable by any user through the product's own standard, intended certificate-lookup functionality, independent of this issue. No private key material is exposed at any point, so the issue cannot be used for impersonation. The victim's original certificate and their own ability to renew it are both unaffected, and revocation requires a separate, unrelated authentication mechanism this issue does not touch, so there is no denial-of-service capability.
Low [CVE-2026-52686] DNSSEC validation bypass due to unsigned wildcard expansion proofs
DNSSEC validation bypass due to unsigned wildcard expansion proofs. Red Hat rates this low (CVSS 3.7). Weakness: CWE-347.
Low [CVE-2026-56444] Denial of Service due to incorrect client reply accounting with specific serve-expired configuration
Denial of Service due to incorrect client reply accounting with specific serve-expired configuration. Red Hat rates this low (CVSS 3.7). Weakness: CWE-772. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
Low [CVE-2026-54478] DNS Cookie security bypass via incorrect server cookie calculation
DNS Cookie security bypass via incorrect server cookie calculation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-303. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
Low [CVE-2026-50046] Denial of Service due to freed pointer dereference in DNS-over-TLS handling
Denial of Service due to freed pointer dereference in DNS-over-TLS handling. Red Hat rates this low (CVSS 3.7). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
Low [CVE-2026-46582] Information disclosure via DNSSEC wildcard replay
Information disclosure via DNSSEC wildcard replay. Red Hat rates this low (CVSS 3.7). Weakness: CWE-358. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
Low [CVE-2026-42955] DNS cache integrity issue
DNS cache integrity issue. Red Hat rates this low (CVSS 3.7). Weakness: CWE-354. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
Low [CVE-2026-41637] Denial of Service via terminated DNS-over-QUIC queries
Denial of Service via terminated DNS-over-QUIC queries. Red Hat rates this low (CVSS 3.7). Weakness: CWE-911. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
Low [CVE-2026-44187] Ansible Lightspeed extension for Visual Studio Code: Information disclosure of Google Gemini API key
A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. The extension insecurely stores the API key in plain text within the user's configuration file and writes it to output log files. This information disclosure can lead to the attacker obtaining the API credential and potentially consuming the user's API quota. Note the VS Code extension is distributed via VS Code Marketplace, not shipped in AAP RPMs or containers. Red Hat severity: Low — CVSS 3.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-256. Red Hat lists Red Hat Ansible Automation Platform 2 as not affected.
Low [CVE-2026-16517] Signed Integer Overflow in archive_write_zip_header
A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption. Red Hat Product Security rates this issue as Low severity. The vulnerability is in the ZIP write path only and requires both ZIP encryption to be enabled and a file size near INT64_MAX, making real-world exploitation highly unlikely. The resulting undefined behavior could theoretically cause incorrect Zip64 extension decisions or a crash, but the conditions are too contrived for practical exploitation. Weakness: CWE-190. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 9 as not affected. Red Hat fixing advisory: RHSA-2026:43818. Affected products named by the advisory: Red Hat package: libarchive.
Low [CVE-2026-47010] Enhance JPEG handling (Oracle CPU 2026-07)
Enhance JPEG handling (Oracle CPU 2026-07). Red Hat rates this low (CVSS 3.7). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:50281 with package java-21-openjdk-1:21.0.12.0.8-1.1.el8, java-25-openjdk-main-25.0.4.0.7-1.1.1.hum1, java-21-openjdk-1:21.0.12.0.8-1.1.el9, java-25-openjdk-windows. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7.
Low [CVE-2026-47059] Enhance AWT ImagingLib (Oracle CPU 2026-07)
Enhance AWT ImagingLib (Oracle CPU 2026-07). Red Hat rates this low (CVSS 3.7). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:50281 with package java-21-openjdk-1:21.0.12.0.8-1.1.el8, java-25-openjdk-main-25.0.4.0.7-1.1.1.hum1, java-21-openjdk-1:21.0.12.0.8-1.1.el9, java-25-openjdk-windows. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7.
Low [CVE-2026-12547] information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch
SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials. This vulnerability is deemed LOW because it requires the user changing the desktop proxy settings from an authenticated proxy to the attacker's proxy. Red Hat severity: Low — CVSS 3.4 (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N). Weakness: CWE-201. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3.
Low [CVE-2026-59849] denial of service via automatic certificate authentication loop
A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service. Red Hat severity: Low — CVSS 3.1 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-835. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Hardened Images. Red Hat lists Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected. Red Hat fixing advisory: RHSA-2026:55855, RHSA-2026:42922. Affected products named by the advisory: Red Hat package: libssh.
Low [CVE-2026-59846] information disclosure via ProxyCommand %r username expansion
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior. Red Hat severity: Low — CVSS 3.9 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N). Weakness: CWE-78. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Hardened Images; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:55855, RHSA-2026:42922. Affected products named by the advisory: Red Hat package: libssh.