Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5Red Hat

High [CVE-2026-67214] Denial of Service via negative size input in non-secure module functions

Denial of Service via negative size input in non-secure module functions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-839. Red Hat lists fixing advisory RHSA-2026:48241 with package grafana13-1-main-13.1.1-0.3.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-67214
Unclassified
Jul 29, 2026
High7.5Red Hat

High [CVE-2026-67213] Denial of Service via infinite loop in random ID generation

Denial of Service via infinite loop in random ID generation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:47619 with package jaeger-main-2.20.0-0.6.hum1, grafana13-1-main-13.1.1-0.3.hum1, grafana12-4-main-12.4.6-0.2.hum1.

CVE-2026-67213
Unclassified
Jul 29, 2026
High7.5Red Hat

High [CVE-2026-16308] io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service

io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:54435 with package rhbk/keycloak-rhel9:26.6-11, rhbk/keycloak-operator-bundle:26.4.14-1, rhbk-keycloak-rhel9/rhbk-keycloak-rhel9, rhbk-openshift-rhel9/rhbk-openshift-rhel9.

CVE-2026-16308
Unclassified
Jul 29, 2026
High7.8Red Hat

High [CVE-2026-44944] Authentication bypass in iscsiuio control socket

Authentication bypass in iscsiuio control socket. Red Hat rates this important (CVSS 7.8). Weakness: CWE-1220. Red Hat lists fixing advisory RHSA-2026:53844 with package iscsi-initiator-utils-0:6.2.1.11-1.git4b3e853.el10_2.2, iscsi-initiator-utils-0:6.2.1.11-1.git4b3e853.el9_8.2. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-44944
Unclassified
Jul 29, 2026
High8.6Red Hat

High [CVE-2026-44943] Privilege Escalation via Path Traversal

Privilege Escalation via Path Traversal. Red Hat rates this important (CVSS 8.6). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:53844 with package iscsi-initiator-utils-0:6.2.1.11-1.git4b3e853.el10_2.2, iscsi-initiator-utils-0:6.2.1.11-1.git4b3e853.el9_8.2. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-44943
Unclassified
Jul 29, 2026
High7.8Red Hat

High [CVE-2026-18220] Out-of-bounds write in BFD DLX ELF backend relocation processing

Out-of-bounds write in BFD DLX ELF backend relocation processing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787.

CVE-2026-18220
Unclassified
Jul 29, 2026
High8.8Apache

High [CVE-2026-50622] Description: Missing Authorization in Apache Atlas

Missing Authorization in Apache Atlas. Affect Version: This issue affects Apache Atlas: from 0.8 through 2.5.0.

CVE-2026-50622
Unclassified
Jul 29, 2026
High7.3Apache

High [CVE-2026-23904] Apache Kyuubi: Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination

Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, resulting in SSRF or open-proxy behavior. This issue affects Apache Kyuubi: from 1.8.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which disables the proxy by default. To restore proxied Engine UI, set kyuubi.frontend.rest.engine.ui.proxy.enabled=true and configure allowed target hosts with kyuubi.frontend.rest.engine.ui.proxy.hosts.

CVE-2026-23904
Unclassified
Jul 29, 2026
High8.2Apache

High [CVE-2026-58189] Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification

Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58189
Infra & Gateways
Jul 29, 2026
High8.4Apache

High [CVE-2026-58188] Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors

Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58188
Infra & Gateways
Jul 29, 2026
High8.2Apache

High [CVE-2026-58186] The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses

The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58186
Infra & Gateways
Jul 29, 2026
High8.2Apache

High [CVE-2026-58185] The Apache Traffic Server intercept plugin has a use-after-free

The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58185
Infra & Gateways
Jul 29, 2026
High8.3Apache

High [CVE-2026-58184] The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching

The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58184
Infra & Gateways
Jul 29, 2026
High8.2Apache

High [CVE-2026-58183] The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input

The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58183
Infra & Gateways
Jul 29, 2026
High8.2Apache

High [CVE-2026-58182] The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state

The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58182
Infra & Gateways
Jul 29, 2026
High8.2Apache

High [CVE-2026-58181] The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input

The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58181
Infra & Gateways
Jul 29, 2026
High8.2Apache

High [CVE-2026-58180] The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input

The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58180
Infra & Gateways
Jul 29, 2026
High8.2Apache

High [CVE-2026-58178] The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs

The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58178
Infra & Gateways
Jul 29, 2026
High8.3Apache

High [CVE-2026-58177] The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors

The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue.

CVE-2026-58177
Infra & Gateways
Jul 29, 2026
High8.2Apache

High [CVE-2026-58175] Apache Traffic Server leaks memory when handling HostDB SRV records

Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58175
Infra & Gateways
Jul 29, 2026