Complete feed
Security advisories & CVEs
3521 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-49263] Denial of Service and parser desynchronization via WebAssembly `br_table` instruction-size truncation
Denial of Service and parser desynchronization via WebAssembly `br_table` instruction-size truncation. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: capstone.
Medium [CVE-2026-49282] Denial of service via out-of-bounds read in M68K and RISCV backends
Denial of service via out-of-bounds read in M68K and RISCV backends. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: capstone.
Medium [CVE-2026-66807] dangerouslySetInnerHTML with unescaped subscription identifiers in SharedResourceWarning
dangerouslySetInnerHTML with unescaped subscription identifiers in SharedResourceWarning. Red Hat rates this low (CVSS 4.6). Weakness: CWE-79. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.
Medium [CVE-2026-46380] Server-Side Request Forgery via unvalidated URL in remote fetching subsystem
Server-Side Request Forgery via unvalidated URL in remote fetching subsystem. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-918. Affected product named by the advisory: File Integrity Operator.
Medium [CVE-2026-13002] Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing
A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients. Redhat confirms that the dnsmasq component is required for installations where DNNSEC service is in use. Red Hat severity: Low — CVSS 4.4 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7 as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: dnsmasq.
Medium [CVE-2026-19879] HTTP response header integrity issue due to character truncation
HTTP response header integrity issue due to character truncation. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-681. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 6 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7; and 2 more.
Medium [CVE-2026-19880] Path traversal allows arbitrary log file creation
Path traversal allows arbitrary log file creation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22. Affected products named by the advisory: Migration Toolkit for Applications 8; OpenShift Serverless; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; and 16 more. Affected products named by the advisory: Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; and 12 more.
Medium [CVE-2026-73051] HTTP Request Smuggling via malformed HTTP/1.1 headers
HTTP Request Smuggling via malformed HTTP/1.1 headers. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-444. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Update Service; Red Hat package: keylime-agent-rust; and 1 more. Affected products named by the advisory: Red Hat package: trustee.
Medium [CVE-2026-72816] IP Spoofing via RealIP Middleware allows bypassing access controls
IP Spoofing via RealIP Middleware allows bypassing access controls. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-346. Red Hat lists fixing advisory RHSA-2026:49718 with package cosign-main-3.1.3-0.1.hum1, spire1-14-main-1.14.7-0.4.hum1, spire1-15-main-1.15.2-0.4.hum1. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Gatekeeper 3; Logging Subsystem for Red Hat OpenShift; and 18 more. Affected products named by the advisory: Migration Toolkit for Applications 8; Multicluster Engine for Kubernetes; OpenShift Pipelines; OpenShift Serverless; and 14 more.
Medium [CVE-2026-72817] IP spoofing via X-Forwarded-For header manipulation
IP spoofing via X-Forwarded-For header manipulation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-501. Red Hat lists fixing advisory RHSA-2026:49718 with package cosign-main-3.1.3-0.1.hum1, spire1-14-main-1.14.7-0.4.hum1, spire1-15-main-1.15.2-0.4.hum1. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Gatekeeper 3; Logging Subsystem for Red Hat OpenShift; and 19 more. Affected products named by the advisory: Migration Toolkit for Applications 8; Multicluster Engine for Kubernetes; OpenShift Pipelines; OpenShift Serverless; and 15 more.
Medium [CVE-2026-72815] go-chi chi: IP spoofing via X-Forwarded-For header allows bypass of access controls
go-chi chi: IP spoofing via X-Forwarded-For header allows bypass of access controls. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-940. Red Hat lists fixing advisory RHSA-2026:49718 with package prometheus3-13-main-3.13.2-0.2.hum1, cosign-main-3.1.3-0.1.hum1, spire1-14-main-1.14.7-0.4.hum1, spire1-15-main-1.15.2-0.4.hum1. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Gatekeeper 3; Migration Toolkit for Applications 8; and 12 more. Affected products named by the advisory: OpenShift Pipelines; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Advanced Cluster Security 4; Red Hat Edge Manager 1; and 8 more.
Medium [CVE-2026-72814] Information Disclosure via relative path traversal
Information Disclosure via relative path traversal. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-22. Affected product named by the advisory: Red Hat OpenShift Update Service.
Medium [CVE-2025-71405] Open Redirect vulnerability via RedirectSlashes middleware
Open Redirect vulnerability via RedirectSlashes middleware. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-601.
Medium [CVE-2026-19617] Denial of Service via uncontrolled recursion in config parser
Denial of Service via uncontrolled recursion in config parser. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-45205] IBM Db2 Vulnerability in NetApp Products
IBM Db2 Server versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 on Linux and Unix are susceptible to a vulnerability in commons-configuration2-2.10.1. Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp states there is no workaround available at this time.
Medium [CVE-2026-18097] IBM Db2 Vulnerability in NetApp Products
IBM Db2 Server versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 on all platforms are susceptible to a vulnerability which could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-16480] IBM Db2 Vulnerability in NetApp Products
IBM Db2 Server versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 on all platforms are susceptible to a vulnerability which could allow a non-privileged user to bypass authority checks and modify database catalog data. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-58084] FreeBSD Vulnerability in NetApp Products
FreeBSD versions 15.1 and 15.0 are susceptible to a vulnerability which when successfully exploited could allow an unprivileged local user who can obtain uninitialized kernel stack memory by creating a POSIX timer with CLOCK_TAI and calling timer_settime(2) disclose sensitive kernel data. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-73416] Extension blocklist bypass via weak package-name canonicalization
Extension blocklist bypass via weak package-name canonicalization. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-1289.
Medium [CVE-2026-73428] Stored Cross-Site Scripting via HTML paste allows arbitrary code execution.
Stored Cross-Site Scripting via HTML paste allows arbitrary code execution. Red Hat rates this moderate (CVSS 4.6). Weakness: CWE-79.