Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-66299] Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue. Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.
High [CVE-2026-66713] Remote code execution via deserialization of untrusted data in Tribes clustering
Remote code execution via deserialization of untrusted data in Tribes clustering. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502.
High [CVE-2026-59878] Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All
Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value. This cause the NIO threads to die and if done rapidly enough can lead to exhaustion of the NIO thread pool denying service to other connections. This issue affects Apache ActiveMQ AMQP: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ All: before 5.19.9, from 6.0.0 before 6.2.8. Users are recommended to upgrade to version 5.19.9, 6.2.8, or 6.3.0 which fixes the issue.
High [CVE-2026-49332] underscore header smuggling enables identity impersonation on WSGI/PHP upstreams
underscore header smuggling enables identity impersonation on WSGI/PHP upstreams. Red Hat rates this important (CVSS 8.5). Weakness: CWE-436. Red Hat lists fixing advisory RHSA-2026:50681 with package openshift4/ose-oauth-proxy-rhel9:1785851359, openshift4/ose-oauth-proxy-rhel9:1785521728, openshift4/ose-oauth-proxy-rhel9:1785529735, openshift4/ose-oauth-proxy-rhel9:1785544039. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.14; Red Hat OpenShift Container Platform 4.16; Red Hat OpenShift Container Platform 4.18; Red Hat OpenShift Container Platform 4.19; and 3 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.20; Red Hat OpenShift Container Platform 4.21; Red Hat OpenShift Container Platform 4.22; Red Hat OpenShift Container Platform 4.12; and 2 more.
High [CVE-2026-65624] Denial of Service via HTTP/1.1 duplicate header names
Denial of Service via HTTP/1.1 duplicate header names. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Red Hat lists fixing advisory RHSA-2026:47231 with package rabbitmq-server4-3-main-4.3.4-0.2.hum1, rabbitmq-server4-2-main-4.2.9-0.2.hum1.
High [CVE-2026-6949] TSIG packet with crafted name compression can crash DNS server
TSIG packet with crafted name compression can crash DNS server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.
High [CVE-2026-58222] Samba AD LDAP Compare filter injection and trusted-request confusion disclose protected attributes
Samba AD LDAP Compare filter injection and trusted-request confusion disclose protected attributes. Red Hat rates this important (CVSS 8.8). Weakness: CWE-90.
High [CVE-2026-58221] authenticated LDAP access to internal LDB special DNs permits domain takeover
authenticated LDAP access to internal LDB special DNs permits domain takeover. Red Hat rates this important (CVSS 8.8). Weakness: CWE-284.
High [CVE-2026-59248] Denial of Service due to unbounded HPACK/QPACK prefixed-integer decoding
Denial of Service due to unbounded HPACK/QPACK prefixed-integer decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:47231 with package rabbitmq-server4-3-main-4.3.4-0.2.hum1, rabbitmq-server4-2-main-4.2.9-0.2.hum1.
High [CVE-2026-58662] Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings
Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
High [CVE-2026-58389] Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
High [CVE-2026-55969] Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings
Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
High [CVE-2026-55968] Apache Thrift Node: Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache…
Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
High [CVE-2026-49158] Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
High [CVE-2026-48586] Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go…
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
High [CVE-2026-48145] Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
High [CVE-2026-43871] Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java…
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
High [CVE-2026-41608] Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
High [CVE-2026-45816] NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event
NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.
High [CVE-2026-45815] Reachable Assertion vulnerability in Apache NimBLE
Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser. Severity is medium as this requires DUT to first send ATT Read Multiple Variable Request. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.