Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

3284 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5Red Hat Updated

High [CVE-2026-54789] Denial of Service via malformed state cookie parsing

Denial of Service via malformed state cookie parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: mod_auth_openidc.

CVE-2026-54789
Red Hat Enterprise Linux
Aug 21, 2026
High7.3Red Hat Updated

High [CVE-2026-49114] Arbitrary file write via symlink following and path traversal

Arbitrary file write via symlink following and path traversal. Red Hat rates this important (CVSS 7.3). Weakness: CWE-367.

CVE-2026-49114
Unclassified
Aug 21, 2026
High7.1Red Hat

High [CVE-2026-77682] JavaScript code injection in autofill via unsanitized CSS selector from element id

JavaScript code injection in autofill via unsanitized CSS selector from element id. Red Hat rates this important (CVSS 7.1). Weakness: CWE-94.

CVE-2026-77682
Unclassified
Aug 21, 2026
High7.8Red Hat Updated

High [CVE-2026-74581] use-after-free in fib6_rule_suppress due to stale res->rt6 pointer

use-after-free in fib6_rule_suppress due to stale res->rt6 pointer. Red Hat rates this important (CVSS 7.8). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:60485 with package kernel-0:5.14.0-427.147.1.el9_4, kernel-0:5.14.0-687.42.1.el9_8, kernel-0:5.14.0-570.136.1.el9_6, kernel-0:4.18.0-372.209.1.el8_6. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-74581
Unclassified
Aug 21, 2026
High7.8Red Hat Updated

High [CVE-2026-74583] fix fastmap use-after-free on filter

fix fastmap use-after-free on filter. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat package: kernel-rt.

CVE-2026-74583
Linux Kernel
Aug 21, 2026
High7.3Red Hat Updated

High [CVE-2026-74580] reset the vring metadata cache on vring reconfiguration

reset the vring metadata cache on vring reconfiguration. Red Hat rates this important (CVSS 7.3). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74580
Linux Kernel
Aug 21, 2026
High7.0Red Hat Updated

High [CVE-2026-74582] use consistent hard_header_len in non-ring send paths

use consistent hard_header_len in non-ring send paths. Red Hat rates this important (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74582
Linux Kernel
Aug 21, 2026
High7.8Red Hat

High [CVE-2026-77652] heap buffer overflow in WPG colormap parser via out-of-bounds palette index

heap buffer overflow in WPG colormap parser via out-of-bounds palette index. Red Hat rates this important (CVSS 7.8). Weakness: CWE-122.

CVE-2026-77652
Unclassified
Aug 21, 2026
High7.8Red Hat

High [CVE-2026-77658] stack buffer overflow in Bus object via unvalidated handle count in project files

stack buffer overflow in Bus object via unvalidated handle count in project files. Red Hat rates this important (CVSS 7.8). Weakness: CWE-121.

CVE-2026-77658
Unclassified
Aug 21, 2026
High8.6Red Hat Updated

High [CVE-2026-72848] Server-Side Request Forgery and Information Disclosure via nested sitemap entries

Server-Side Request Forgery and Information Disclosure via nested sitemap entries. Red Hat rates this important (CVSS 8.6). Weakness: CWE-918. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-72848
Unclassified
Aug 20, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-55893] Heap buffer overflow with potential code execution

Heap buffer overflow with potential code execution. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805. Red Hat lists fixing advisory RHSA-2026:59419 with package capstone-main-5.0.8-0.3.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: capstone.

CVE-2026-55893
Red Hat Enterprise Linux
Aug 20, 2026
High7.7Red Hat Updated

High [CVE-2026-73137] cross-namespace Secret exfiltration via HelmRelease.repo.secretRef.namespace

cross-namespace Secret exfiltration via HelmRelease.repo.secretRef.namespace. Red Hat rates this important (CVSS 7.7). Weakness: CWE-200. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicluster-operators-subscription-rhel9:1787242108, rhacm2/multicluster-operators-subscription-rhel9:1787263693, rhacm2/multicluster-operators-subscription-rhel9:1787242321, rhacm2/multicluster-operators-subscription-rhel9:1787240030. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-73137
Unclassified
Aug 20, 2026
High7.5Red Hat Updated

High [CVE-2026-43678] Denial of Service via specially crafted WebSocket frame

Denial of Service via specially crafted WebSocket frame. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-43678
Unclassified
Aug 20, 2026
High7.5Red Hat Updated

High [CVE-2026-53587] Denial of Service due to heap out-of-bounds read from malicious Git server

Denial of Service due to heap out-of-bounds read from malicious Git server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:59361 with package libgit2-main-1.9.7-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat package: rust; Red Hat package: libgit2.

CVE-2026-53587
Red Hat Enterprise Linux
Aug 20, 2026
High8.7Red Hat

High [CVE-2026-66787] cross-cluster DNS spoofing via unvalidated EndpointSlice and ServiceImport IPs

cross-cluster DNS spoofing via unvalidated EndpointSlice and ServiceImport IPs. Red Hat rates this important (CVSS 8.7). Weakness: CWE-345. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66787
Unclassified
Aug 20, 2026
High8.6Red Hat Updated

High [CVE-2026-63387] Off-by-one stack buffer overflow leading to denial of service or data corruption

Off-by-one stack buffer overflow leading to denial of service or data corruption. Red Hat rates this important (CVSS 8.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.

CVE-2026-63387
Red Hat Enterprise Linux
Aug 20, 2026
High7.5Red Hat Updated

High [CVE-2026-63384] Denial of Service via integer conversion error in `evtag_unmarshal_header`

Denial of Service via integer conversion error in `evtag_unmarshal_header`. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.

CVE-2026-63384
Red Hat Enterprise Linux
Aug 20, 2026
High7.5Red Hat Updated

High [CVE-2026-63495] Remote denial of service via unbounded memory accumulation in WebSocket server

Remote denial of service via unbounded memory accumulation in WebSocket server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:41176 with package libevent-main-2.1.12-19.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.

CVE-2026-63495
Red Hat Enterprise Linux
Aug 20, 2026
High7.5Red Hat Updated

High [CVE-2026-63383] Denial of Service via malformed RPC data

Denial of Service via malformed RPC data. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.

CVE-2026-63383
Red Hat Enterprise Linux
Aug 20, 2026
High8.4Red Hat Updated

High [CVE-2026-63388] Arbitrary code execution via heap out-of-bounds write in AF_UNIX handling

Arbitrary code execution via heap out-of-bounds write in AF_UNIX handling. Red Hat rates this important (CVSS 8.4). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.

CVE-2026-63388
Red Hat Enterprise Linux
Aug 20, 2026