VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
Critical/high still unreviewed, or CISA KEV listed
Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 150.0.1. Red Hat rates this important (CVSS 7.5). Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:19370 — update the affected packages (`sudo dnf update`).
Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:19370 — update the affected packages (`sudo dnf update`).
Information disclosure due to incorrect boundary conditions in the Audio/Video component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:19370 — update the affected packages (`sudo dnf update`).
Node.js skip() recursion. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-776. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhacm2/acm-grafana-rhel9:1780677003. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`).
Denial of Service via uncontrolled recursion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`).
Integer Overflow or Wraparound Vulnerability. Red Hat rates this important (CVSS 7.7). Weakness: CWE-190. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`).
Out-of-bounds Read vulnerability. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`).
Security Bypass via Improper Certificate Hostname Validation. Red Hat rates this important (CVSS 8.2). Weakness: CWE-295. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`).
Integer Overflow in TFramedTransport Go implementation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779925273, rhosdt/opentelemetry-collector-rhel9:1778056267, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`).
Apache Thrift c_glib: Denial of Service via specially crafted requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-763. Affected package(s): cryostat/cryostat-storage-rhel9:4.2.0, rhosdt/tempo-rhel9:1781589494, rhacm2/acm-grafana-rhel9:1780926805, rhacm2/acm-grafana-rhel9:1780677003. Resolved in Red Hat advisory RHSA-2026:24539 — update the affected packages (`sudo dnf update`).
Heap buffer overflow in Skia. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Use after free in Codecs. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Insufficient validation of untrusted input in Compositing. Red Hat rates this important (CVSS 8.7). Weakness: CWE-1173. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Inappropriate implementation in Tint. Red Hat rates this important (CVSS 8.8). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Insufficient validation of untrusted input in Feedback. Red Hat rates this important (CVSS 8). Weakness: CWE-1286. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Security bypass due to ineffective default web security. Red Hat rates this important (CVSS 9.1). Weakness: CWE-305. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Altered application behavior via header injection. Red Hat rates this critical (CVSS 9.4). Weakness: CWE-1173. Affected package(s): camel-mail. Resolved in Red Hat advisory RHSA-2026:19835 — update the affected packages (`sudo dnf update`).
Arbitrary code execution via classname allowlist bypass. Red Hat rates this low (CVSS 9.8). Weakness: CWE-502. Affected package(s): mina-core. Resolved in Red Hat advisory RHSA-2026:17668 — update the affected packages (`sudo dnf update`).
Remote Code Execution and Arbitrary File Write via case-variant header injection. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-178. Affected package(s): camel-http-starter, camel-google-pubsub, camel-http-common, camel-jms, camel-http-base, camel-http. Resolved in Red Hat advisory RHSA-2026:19835 — update the affected packages (`sudo dnf update`).
Weak pseudo-random number generation can lead to information disclosure.. Red Hat rates this important (CVSS 8.2). Weakness: CWE-338. Affected package(s): devspaces/openvsx-rhel9:1779528224, spring-boot, devspaces/pluginregistry-rhel9:1779359423. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`).