Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-72814] Information Disclosure via relative path traversal
Information Disclosure via relative path traversal. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-22. Affected product named by the advisory: Red Hat OpenShift Update Service.
Medium [CVE-2026-19617] Denial of Service via uncontrolled recursion in config parser
Denial of Service via uncontrolled recursion in config parser. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.
Low [CVE-2026-63650] User misidentification via ignored X.509 identity field
User misidentification via ignored X.509 identity field. Red Hat rates this low (CVSS 3.1). Weakness: CWE-303.
Low [CVE-2026-66807] potential XSS via dangerouslySetInnerHTML with unescaped resource name in getCodeSpan
potential XSS via dangerouslySetInnerHTML with unescaped resource name in getCodeSpan. Red Hat rates this low (CVSS 3.1). Weakness: CWE-79. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-73417] Cross-site scripting (XSS) allows arbitrary code execution
Cross-site scripting (XSS) allows arbitrary code execution. Red Hat rates this important (CVSS 8.3). Weakness: CWE-79. Affected products named by the advisory: Migration Toolkit for Applications 8; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-56860] golang net/url: Denial of Service from quadratic complexity in path resolution
golang net/url: Denial of Service from quadratic complexity in path resolution. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-56853] Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-56858] Go html/template: Cross-Site Scripting via pathological input
Go html/template: Cross-Site Scripting via pathological input. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-56862] Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-56865] Supply chain compromise via transparency log tile verification bypass
Supply chain compromise via transparency log tile verification bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-347.
High [CVE-2026-33818] Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-56859] Denial of Service via XML decoding recursion depth issue
Denial of Service via XML decoding recursion depth issue. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-73662] FreePBX Music on Hold: Arbitrary command execution by authenticated administrator
FreePBX Music on Hold: Arbitrary command execution by authenticated administrator. Red Hat rates this important (CVSS 7.2). Weakness: CWE-78.
High [CVE-2026-45774] Arbitrary file read via path traversal in profile import
Arbitrary file read via path traversal in profile import. Red Hat rates this important (CVSS 7.4). Weakness: CWE-22. Affected product named by the advisory: File Integrity Operator.
High [CVE-2026-45725] Arbitrary file write via path traversal in remote fetching mechanism
Arbitrary file write via path traversal in remote fetching mechanism. Red Hat rates this important (CVSS 7.4). Weakness: CWE-22. Affected product named by the advisory: File Integrity Operator.
High [CVE-2026-48099] Filesystem path traversal via encoded dot segments
WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path layout. The issue is fixed with version 4.3.4. A remote attacker could exploit this vulnerability by sending a specially crafted WebDAV request path containing encoded parent-directory segments. This could allow the attacker to escape the configured filesystem share root, potentially leading to unauthorized access to sensitive files or directories outside the intended scope. Red Hat products do not ship WsgiDAV. The vulnerable code path is therefore not present in any Red Hat-shipped build, and no Red Hat product is affected by this flaw. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L). Weakness: CWE-22.
High [CVE-2026-73643] Denial of Service via exponential parsing in flow collections
Denial of Service via exponential parsing in flow collections. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:61314 with package cluster-observability-operator/monitoring-console-plugin-pf6-rhel9:1787597578. Affected products named by the advisory: Cryostat 4; Gatekeeper 3; Migration Toolkit for Applications 8; Migration Toolkit for Containers; and 31 more. Affected products named by the advisory: Network Observability Operator; Node HealthCheck Operator; OpenShift Lightspeed; OpenShift Pipelines; and 27 more.
High [CVE-2026-73569] Denial of Service via repeated DOCTYPE declarations
Denial of Service via repeated DOCTYPE declarations. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected products named by the advisory: Migration Toolkit for Applications 8; Red Hat Advanced Cluster Security 4; Red Hat Openshift Data Foundation 4; Red Hat OpenShift GitOps; and 2 more. Affected products named by the advisory: Red Hat OpenShift Virtualization 4; Self-service automation portal 2.
High [CVE-2026-73566] Denial of Service via crafted long-path tar archive
Denial of Service via crafted long-path tar archive. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Migration Toolkit for Containers; Node HealthCheck Operator; and 30 more. Affected products named by the advisory: OpenShift Pipelines; OpenShift Service Mesh 3; Red Hat 3scale API Management Platform 2; Red Hat Advanced Cluster Management for Kubernetes 2; and 26 more.
High [CVE-2026-58440] Information disclosure via incomplete webhook revocation
Information disclosure via incomplete webhook revocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-459. Affected product named by the advisory: OpenShift Pipelines.