VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
Critical/high still unreviewed, or CISA KEV listed
Apache Camel camel-infinispan: Arbitrary code execution via deserialization of untrusted data. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Affected package(s): camel-infinispan, camel-infinispan-common, camel-infinispan-embedded. Resolved in Red Hat advisory RHSA-2026:22453 — update the affected packages (`sudo dnf update`).
Remote Code Execution via deserialization of JMS ObjectMessage. Red Hat rates this important (CVSS 7.5). Weakness: CWE-502. Affected package(s): camel-jms, camel-amqp. Resolved in Red Hat advisory RHSA-2026:22453 — update the affected packages (`sudo dnf update`).
Arbitrary code execution via insecure deserialization of crafted key files. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Apache Camel camel-mina: Arbitrary code execution via insecure deserialization. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Local privilege escalation via race condition and kernel heap overflow. Red Hat rates this important (CVSS 7). Weakness: CWE-368. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
CCO Mint-mode CredentialsRequest manifests grant account-wide IAM access beyond cluster scope on AWS. Red Hat rates this important (CVSS 7.2). Weakness: CWE-250. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Remote Code Execution due to incomplete fix bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-88. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
validate nested VLAN headers. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-1285. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:21745 — update the affected packages (`sudo dnf update`).
tekton-scheduler-rolebinding grants system:authenticated write access to Kueue and cert-manager resources. Red Hat rates this important (CVSS 7.1). Weakness: CWE-732. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
reject invalid MAC header for all packets. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-1287. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:26462 — update the affected packages (`sudo dnf update`).
Denial of service via malformed Content-ID URI in SIP multipart message. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Denial of Service via unbounded recursion in toFormData with deeply nested request data. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): openshift-service-mesh/kiali-rhel9:1778164042, rhoai/odh-mod-arch-model-registry-rhel9:1780467147, openshift4/ose-agent-installer-ui-rhel9:1778539338, satellite/iop-advisor-frontend-rhel9:1781181673, openshift-service-mesh/kiali-rhel8:1778191378, rhacm2/console-rhel9:1780600823. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`).
Authentication bypass due to prototype pollution of HTTP error handling. Red Hat rates this important (CVSS 8.2). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-rhel9:1778164042, rhoai/odh-mod-arch-model-registry-rhel9:1780467147, openshift4/ose-agent-installer-ui-rhel9:1778539338, satellite/iop-advisor-frontend-rhel9:1781181673, openshift-service-mesh/kiali-rhel8:1778191378, rhacm2/console-rhel9:1780600823. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`).
NO_PROXY bypass via crafted URL. Red Hat rates this important (CVSS 7.2). Weakness: CWE-918. Affected package(s): openshift-service-mesh/kiali-rhel9:1778164042, rhoai/odh-mod-arch-model-registry-rhel9:1780467147, openshift4/ose-agent-installer-ui-rhel9:1778539338, satellite/iop-advisor-frontend-rhel9:1781181673, openshift-service-mesh/kiali-rhel8:1778191378, rhacm2/console-rhel9:1780600823. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`).
Invisible JSON Response Tampering via Prototype Pollution Gadget. Red Hat rates this important (CVSS 7.4). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-rhel9:1778164042, network-observability/network-observability-console-plugin-rhel9:1780556069, satellite/iop-advisor-frontend-rhel9:1781181673, rhacm2/console-rhel9:1780600823, devspaces/code-rhel9:1779814592, multicluster-engine/console-mce-rhel9:1778383863. Resolved in Red Hat advisory RHSA-2026:26068 — update the affected packages (`sudo dnf update`).
Arbitrary HTTP header injection via prototype pollution. Red Hat rates this moderate (CVSS 7.4). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-rhel9:1778164042, cluster-observability-operator/monitoring-console-plugin-pf5-rhel9:1781116667, satellite/iop-advisor-frontend-rhel9:1781181673, rhacm2/console-rhel9:1780600823, cluster-observability-operator/distributed-tracing-console-plugin-pf6-rhel9:1781116387, quay/quay-rhel9:1779922205. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`).
HTTP Transport Hijacking via Prototype Pollution. Red Hat rates this important (CVSS 7.4). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-rhel9:1778164042, rhoai/odh-mod-arch-model-registry-rhel9:1780467147, openshift4/ose-agent-installer-ui-rhel9:1778539338, satellite/iop-advisor-frontend-rhel9:1781181673, openshift-service-mesh/kiali-rhel8:1778191378, rhacm2/console-rhel9:1780600823. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`).
Denial of Service via specific input sequence. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-835. Affected package(s): satellite/iop-advisor-frontend-rhel9:1781181673, satellite/iop-vulnerability-frontend-rhel9:1781032495. Resolved in Red Hat advisory RHSA-2026:26214 — update the affected packages (`sudo dnf update`).
Path traversal vulnerability allows arbitrary file write via malicious package extraction. Red Hat rates this important (CVSS 8.7). Weakness: CWE-22. Affected package(s): ansible-automation-platform. Resolved in Red Hat advisory RHSA-2026:24866 — update the affected packages (`sudo dnf update`).
Command injection allows arbitrary code execution via malicious tag files. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-78. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, vim, discovery/discovery-ui-rhel9:1782756541. Resolved in Red Hat advisory RHSA-2026:28049 — update the affected packages (`sudo dnf update`).