Complete feed
Security advisories & CVEs
3496 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-78684] Denial of Service via DeepStream backend resource control bypass.
Denial of Service via DeepStream backend resource control bypass. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-79652] JWT Bearer authorization grant does not enforce consentRequired
JWT Bearer authorization grant does not enforce consentRequired. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-862. Affected product named by the advisory: Red Hat Build of Keycloak.
Medium [CVE-2026-77117] Non-progress DoS in SHIFT_JISX0213 ->
Non-progress DoS in SHIFT_JISX0213 ->. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Hardened Images; Red Hat package: glibc.
Medium [CVE-2026-11610 +1] incomplete fix may introduce a connection-stall DoS
CVE-2026-11610 incomplete fix may introduce a connection-stall DoS. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Directory Server 11; Red Hat Directory Server 12; Red Hat Directory Server 13; Red Hat Enterprise Linux 10; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.
Medium [CVE-2026-19499] Buffer Overflow in strfmon right-justification padding
Buffer Overflow in strfmon right-justification padding. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Hardened Images; Red Hat package: glibc.
Medium [CVE-2026-78322] stack buffer overflow in parse_progress_line for 7z and RAR handlers
stack buffer overflow in parse_progress_line for 7z and RAR handlers. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat package: file-roller.
Medium [CVE-2026-19542] Fix out-of-bounds array write in tdelete
Fix out-of-bounds array write in tdelete. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:59721 with package glibc-main-2.43-8.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: glibc.
Medium [CVE-2026-59183] Integer Overflow Vulnerability Leading to Application Crash
Integer Overflow Vulnerability Leading to Application Crash. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: openexr.
Medium [CVE-2026-55373] Denial of Service via infinite loop in sample count processing.
Denial of Service via infinite loop in sample count processing. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: openexr.
Medium [CVE-2026-55371] Denial of Service via NULL pointer dereference in exr_attr_set_bytes
Denial of Service via NULL pointer dereference in exr_attr_set_bytes(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-55059] Heap out-of-bounds write leads to denial of service
Heap out-of-bounds write leads to denial of service. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-124. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: openexr.
Medium [CVE-2026-54920] Denial of Service via crafted HTJ2K-compressed EXR file
Denial of Service via crafted HTJ2K-compressed EXR file. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-617.
Medium [CVE-2026-63073] untrusted sender DN used as format string in CMP response validation
untrusted sender DN used as format string in CMP response validation. Red Hat rates this low (CVSS 5.9). Weakness: CWE-134. Red Hat lists fixing advisory RHSA-2026:59641 with package openssl3-main-3.5.8-0.1.hum1, openssl-main-3.5.8-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 6 more. Affected products named by the advisory: Red Hat JBoss Core Services; Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7; Red Hat OpenShift Container Platform 4; and 2 more.
Medium [CVE-2026-68516] Denial of service via crafted HTJ2K-compressed EXR with invalid image-offset
Denial of service via crafted HTJ2K-compressed EXR with invalid image-offset. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-787.
Medium [CVE-2026-17113] unvalidated image env var causes daemon crash
unvalidated image env var causes daemon crash. Red Hat rates this moderate (CVSS 6). Weakness: CWE-1287. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-75509] Issuer-validation bypass via array-valued claims
Issuer-validation bypass via array-valued claims. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-480. Affected products named by the advisory: Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux command line assistant; Red Hat OpenShift Virtualization 4; Red Hat Satellite 6.
Medium [CVE-2026-78475] Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader
A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file. To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted PIX image with GIMP, reducing the likelihood of exploitation. Due to this reason, this flaw has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gimp.
Medium [CVE-2026-76845] Arbitrary File Overwrite via Symlink Following
Arbitrary File Overwrite via Symlink Following. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-59. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 8; and 7 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; and 3 more.
Medium [CVE-2026-78323] JSSTrustManager does not verify NSS trust flags on CA certificates
JSSTrustManager does not verify NSS trust flags on CA certificates. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-295. Affected products named by the advisory: Red Hat Certificate System 10; Red Hat Certificate System 11; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: jss.
Medium [CVE-2026-59295] Micrometer Instrumentation for Apache HttpAsyncClient: Denial of Service via asynchronous request failures
Micrometer Instrumentation for Apache HttpAsyncClient: Denial of Service via asynchronous request failures. Red Hat rates this moderate. Weakness: CWE-772. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat build of Quarkus.