Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-67214] Denial of Service via negative size input in non-secure module functions
Denial of Service via negative size input in non-secure module functions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-839. Red Hat lists fixing advisory RHSA-2026:48241 with package grafana13-1-main-13.1.1-0.3.hum1. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-67213] Denial of Service via infinite loop in random ID generation
Denial of Service via infinite loop in random ID generation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:47619 with package jaeger-main-2.20.0-0.6.hum1, grafana13-1-main-13.1.1-0.3.hum1, grafana12-4-main-12.4.6-0.2.hum1.
High [CVE-2026-16308] io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service
io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:54435 with package rhbk/keycloak-rhel9:26.6-11, rhbk/keycloak-operator-bundle:26.4.14-1, rhbk-keycloak-rhel9/rhbk-keycloak-rhel9, rhbk-openshift-rhel9/rhbk-openshift-rhel9.
High [CVE-2026-44944] Authentication bypass in iscsiuio control socket
Authentication bypass in iscsiuio control socket. Red Hat rates this important (CVSS 7.8). Weakness: CWE-1220. Red Hat lists fixing advisory RHSA-2026:53844 with package iscsi-initiator-utils-0:6.2.1.11-1.git4b3e853.el10_2.2, iscsi-initiator-utils-0:6.2.1.11-1.git4b3e853.el9_8.2. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
High [CVE-2026-44943] Privilege Escalation via Path Traversal
Privilege Escalation via Path Traversal. Red Hat rates this important (CVSS 8.6). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:53844 with package iscsi-initiator-utils-0:6.2.1.11-1.git4b3e853.el10_2.2, iscsi-initiator-utils-0:6.2.1.11-1.git4b3e853.el9_8.2. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
High [CVE-2026-18220] Out-of-bounds write in BFD DLX ELF backend relocation processing
Out-of-bounds write in BFD DLX ELF backend relocation processing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787.
High [CVE-2026-50622] Description: Missing Authorization in Apache Atlas
Missing Authorization in Apache Atlas. Affect Version: This issue affects Apache Atlas: from 0.8 through 2.5.0.
High [CVE-2026-23904] Apache Kyuubi: Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination
Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, resulting in SSRF or open-proxy behavior. This issue affects Apache Kyuubi: from 1.8.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which disables the proxy by default. To restore proxied Engine UI, set kyuubi.frontend.rest.engine.ui.proxy.enabled=true and configure allowed target hosts with kyuubi.frontend.rest.engine.ui.proxy.hosts.
High [CVE-2026-58189] Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification
Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-58188] Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors
Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-58186] The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses
The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-58185] The Apache Traffic Server intercept plugin has a use-after-free
The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-58184] The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching
The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-58183] The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input
The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-58182] The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state
The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-58181] The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input
The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-58180] The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input
The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-58178] The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs
The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-58177] The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue.
High [CVE-2026-58175] Apache Traffic Server leaks memory when handling HostDB SRV records
Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.