Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

1779 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium4.8Red Hat

Medium [CVE-2026-74241] LDAP referral filter injection in Quay external LDAP authentication

LDAP referral filter injection in Quay external LDAP authentication. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-90. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.

CVE-2026-74241
Unclassified
Aug 14, 2026
Medium5.4Red Hat

Medium [CVE-2026-74240] JWT claim validation bypasses in Quay federated robot and SSO authentication

JWT claim validation bypasses in Quay federated robot and SSO authentication. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-287. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.

CVE-2026-74240
Unclassified
Aug 14, 2026
Medium6.8Red Hat Updated

Medium [CVE-2026-49263] Denial of Service and parser desynchronization via WebAssembly `br_table` instruction-size truncation

Denial of Service and parser desynchronization via WebAssembly `br_table` instruction-size truncation. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: capstone.

CVE-2026-49263
Red Hat Enterprise Linux
Aug 14, 2026
Medium6.2Red Hat Updated

Medium [CVE-2026-49282] Denial of service via out-of-bounds read in M68K and RISCV backends

Denial of service via out-of-bounds read in M68K and RISCV backends. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: capstone.

CVE-2026-49282
Red Hat Enterprise Linux
Aug 14, 2026
Medium6.7Red Hat Updated

Medium [CVE-2026-46380] Server-Side Request Forgery via unvalidated URL in remote fetching subsystem

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without validation. This allows an attacker to perform Server-Side Request Forgery, targeting internal services or cloud metadata endpoints. Red Hat severity: Moderate — CVSS 6.7 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N). Weakness: CWE-918. Affected Red Hat products: File Integrity Operator. Red Hat lists Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-46380
Unclassified
Aug 14, 2026
Medium4.4Vendor: LowRed Hat

Medium [CVE-2026-13002] Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing

A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients. Redhat confirms that the dnsmasq component is required for installations where DNNSEC service is in use. Red Hat severity: Low — CVSS 4.4 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7 as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: dnsmasq.

CVE-2026-13002
Red Hat Enterprise Linux
Aug 14, 2026
Medium5.3Red Hat

Medium [CVE-2026-19879] HTTP response header integrity issue due to character truncation

HTTP response header integrity issue due to character truncation. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-681. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 6 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7; and 2 more.

CVE-2026-19879
Red Hat Enterprise Linux
Aug 14, 2026
Medium5.3Red Hat Updated

Medium [CVE-2026-73051] HTTP Request Smuggling via malformed HTTP/1.1 headers

actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated remote attackers can exploit this through a front-end intermediary to desynchronize backend requests and smuggle malicious HTTP requests to the Actix service. This vulnerability allows unauthenticated remote attackers to perform HTTP request smuggling. By sending specially crafted HTTP/1.1 requests that include both Content-Length and Transfer-Encoding: chunked headers, an attacker can desynchronize backend requests through a front-end intermediary. This desynchronization enables the attacker to smuggle malicious HTTP requests to the Actix service, potentially leading to unauthorized actions or data manipulation. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). Weakness: CWE-444. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Update Service. Red Hat lists Confidential Compute Attestation; Red Hat Connectivity Link 1; Red Hat Hardened Images; Red Hat Trusted Profile Analyzer as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: keylime-agent-rust; Red Hat package: trustee.

CVE-2026-73051
Red Hat Enterprise Linux
Aug 14, 2026
Medium6.5Red Hat

Medium [CVE-2026-72816] IP Spoofing via RealIP Middleware allows bypassing access controls

IP Spoofing via RealIP Middleware allows bypassing access controls. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-346. Red Hat lists fixing advisory RHSA-2026:49718 with package cosign-main-3.1.3-0.1.hum1, spire1-14-main-1.14.7-0.4.hum1, spire1-15-main-1.15.2-0.4.hum1. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Gatekeeper 3; Logging Subsystem for Red Hat OpenShift; and 18 more. Affected products named by the advisory: Migration Toolkit for Applications 8; Multicluster Engine for Kubernetes; OpenShift Pipelines; OpenShift Serverless; and 14 more.

CVE-2026-72816
Red Hat Enterprise Linux
Aug 14, 2026
Medium6.5Red Hat

Medium [CVE-2026-72817] IP spoofing via X-Forwarded-For header manipulation

IP spoofing via X-Forwarded-For header manipulation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-501. Red Hat lists fixing advisory RHSA-2026:49718 with package cosign-main-3.1.3-0.1.hum1, spire1-14-main-1.14.7-0.4.hum1, spire1-15-main-1.15.2-0.4.hum1. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Gatekeeper 3; Logging Subsystem for Red Hat OpenShift; and 19 more. Affected products named by the advisory: Migration Toolkit for Applications 8; Multicluster Engine for Kubernetes; OpenShift Pipelines; OpenShift Serverless; and 15 more.

CVE-2026-72817
Red Hat Enterprise Linux
Aug 14, 2026
Medium6.5Red Hat

Medium [CVE-2026-72815] go-chi chi: IP spoofing via X-Forwarded-For header allows bypass of access controls

go-chi chi: IP spoofing via X-Forwarded-For header allows bypass of access controls. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-940. Red Hat lists fixing advisory RHSA-2026:49718 with package prometheus3-13-main-3.13.2-0.2.hum1, cosign-main-3.1.3-0.1.hum1, spire1-14-main-1.14.7-0.4.hum1, spire1-15-main-1.15.2-0.4.hum1. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Gatekeeper 3; Migration Toolkit for Applications 8; and 12 more. Affected products named by the advisory: OpenShift Pipelines; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Advanced Cluster Security 4; Red Hat Edge Manager 1; and 8 more.

CVE-2026-72815
Unclassified
Aug 14, 2026
Medium5.3Red Hat Updated

Medium [CVE-2026-72814] Information Disclosure via relative path traversal

The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the serve_from argument to Files::new(), the mount path defaults to an empty path; the service then joins the request path with this empty path and canonicalizes it, causing Rust to resolve it as a relative path. As a result, an attacker can request paths that resolve relative to the application's working directory and access unintended files. This allows an attacker to access unintended files, leading to information disclosure. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-22. Affected Red Hat products: Red Hat OpenShift Update Service. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-72814
Unclassified
Aug 14, 2026
Medium5.5Red Hat

Medium [CVE-2026-19617] Denial of Service via uncontrolled recursion in config parser

Denial of Service via uncontrolled recursion in config parser. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.

CVE-2026-19617
Unclassified
Aug 14, 2026
Medium5.3NetApp

Medium [CVE-2026-45205] IBM Db2 Vulnerability in NetApp Products

IBM Db2 Server versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 on Linux and Unix are susceptible to a vulnerability in commons-configuration2-2.10.1. Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-45205
Unclassified
Aug 14, 2026
Medium5.5NetApp

Medium [CVE-2026-18097] IBM Db2 Vulnerability in NetApp Products

IBM Db2 Server versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 on all platforms are susceptible to a vulnerability which could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-18097
Unclassified
Aug 14, 2026
Medium4.3NetApp

Medium [CVE-2026-16480] IBM Db2 Vulnerability in NetApp Products

IBM Db2 Server versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 on all platforms are susceptible to a vulnerability which could allow a non-privileged user to bypass authority checks and modify database catalog data. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-16480
Unclassified
Aug 14, 2026
Medium5.5NetApp

Medium [CVE-2026-58084] FreeBSD Vulnerability in NetApp Products

FreeBSD versions 15.1 and 15.0 are susceptible to a vulnerability which when successfully exploited could allow an unprivileged local user who can obtain uninitialized kernel stack memory by creating a POSIX timer with CLOCK_TAI and calling timer_settime(2) disclose sensitive kernel data. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-58084
Unclassified
Aug 14, 2026
Medium6.3Red Hat

Medium [CVE-2026-73416] Extension blocklist bypass via weak package-name canonicalization

Extension blocklist bypass via weak package-name canonicalization. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-1289.

CVE-2026-73416
Unclassified
Aug 13, 2026
Medium4.6Red Hat

Medium [CVE-2026-73428] Stored Cross-Site Scripting via HTML paste allows arbitrary code execution.

Stored Cross-Site Scripting via HTML paste allows arbitrary code execution. Red Hat rates this moderate (CVSS 4.6). Weakness: CWE-79.

CVE-2026-73428
Unclassified
Aug 13, 2026
Medium5.0Red Hat Updated

Medium [CVE-2026-73479] Terminal escape sequence injection via unfiltered marked file paths

Terminal escape sequence injection via unfiltered marked file paths. Red Hat rates this moderate (CVSS 5). Weakness: CWE-117.

CVE-2026-73479
Unclassified
Aug 13, 2026