Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-58164] Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling
Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-58163] Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-58162] The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI
The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-58159] Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors
Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-58158] Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack
Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-65324] Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory
Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-58151] Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control
Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-58150] Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling
Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-57834] Apache Traffic Server allows request smuggling if chunked messages are malformed
Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-33930] Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled
Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
High [CVE-2026-33267] Improper Input Validation vulnerability in Apache Traffic Server
Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
High [CVE-2026-41920] Improper Access Control vulnerability in Apache Traffic Server
Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue.
High [CVE-2026-64556] Detach event groups during remove_on_exec
Detach event groups during remove_on_exec. Red Hat rates this moderate (CVSS 7). Weakness: CWE-663.
High [CVE-2026-64557] Fix use-after-free in l2cap_sock_new_connection_cb
Fix use-after-free in l2cap_sock_new_connection_cb(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64558] Check length in pkey_pckmo handler implementation
Check length in pkey_pckmo handler implementation. Red Hat rates this important (CVSS 7). Weakness: CWE-787.
High [CVE-2026-64559] Check length in PKEY_VERIFYPROTK ioctl
Check length in PKEY_VERIFYPROTK ioctl. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805.
High [CVE-2026-64560] Prevent UAF caused by non-leader exec race
Prevent UAF caused by non-leader exec() race. Red Hat rates this important (CVSS 7). Weakness: CWE-364.
High [CVE-2026-18107] container escape via rseq critical section hijack during checkpoint/restore
container escape via rseq critical section hijack during checkpoint/restore. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-269. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.
High [CVE-2026-71190] Unauthenticated denial of service via catastrophic backtracking in Accept header parser
Unauthenticated denial of service via catastrophic backtracking in Accept header parser. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-1333.
High [CVE-2026-71191] S3API presigned URL unsigned header authorization bypass
S3API presigned URL unsigned header authorization bypass. Red Hat rates this important (CVSS 8.2). Weakness: CWE-863.