Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.3Red Hat Updated

Medium [CVE-2026-72814] Information Disclosure via relative path traversal

Information Disclosure via relative path traversal. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-22. Affected product named by the advisory: Red Hat OpenShift Update Service.

CVE-2026-72814
Unclassified
Aug 14, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-19617] Denial of Service via uncontrolled recursion in config parser

Denial of Service via uncontrolled recursion in config parser. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.

CVE-2026-19617
Unclassified
Aug 14, 2026
Low3.1Red Hat

Low [CVE-2026-63650] User misidentification via ignored X.509 identity field

User misidentification via ignored X.509 identity field. Red Hat rates this low (CVSS 3.1). Weakness: CWE-303.

CVE-2026-63650
Unclassified
Aug 14, 2026
Low3.1Red Hat

Low [CVE-2026-66807] potential XSS via dangerouslySetInnerHTML with unescaped resource name in getCodeSpan

potential XSS via dangerouslySetInnerHTML with unescaped resource name in getCodeSpan. Red Hat rates this low (CVSS 3.1). Weakness: CWE-79. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66807
Unclassified
Aug 14, 2026
High8.3Red Hat

High [CVE-2026-73417] Cross-site scripting (XSS) allows arbitrary code execution

Cross-site scripting (XSS) allows arbitrary code execution. Red Hat rates this important (CVSS 8.3). Weakness: CWE-79. Affected products named by the advisory: Migration Toolkit for Applications 8; Red Hat OpenShift AI (RHOAI).

CVE-2026-73417
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-56860] golang net/url: Denial of Service from quadratic complexity in path resolution

golang net/url: Denial of Service from quadratic complexity in path resolution. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-56860
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-56853] Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service

Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-56853
Unclassified
Aug 13, 2026
High8.1Red Hat

High [CVE-2026-56858] Go html/template: Cross-Site Scripting via pathological input

Go html/template: Cross-Site Scripting via pathological input. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-56858
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-56862] Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages

Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-56862
Unclassified
Aug 13, 2026
High8.8Red Hat Updated

High [CVE-2026-56865] Supply chain compromise via transparency log tile verification bypass

Supply chain compromise via transparency log tile verification bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-347.

CVE-2026-56865
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-33818] Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal

Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-33818
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-56859] Denial of Service via XML decoding recursion depth issue

Denial of Service via XML decoding recursion depth issue. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-56859
Unclassified
Aug 13, 2026
High7.2Red Hat

High [CVE-2026-73662] FreePBX Music on Hold: Arbitrary command execution by authenticated administrator

FreePBX Music on Hold: Arbitrary command execution by authenticated administrator. Red Hat rates this important (CVSS 7.2). Weakness: CWE-78.

CVE-2026-73662
Unclassified
Aug 13, 2026
High7.4Red Hat

High [CVE-2026-45774] Arbitrary file read via path traversal in profile import

Arbitrary file read via path traversal in profile import. Red Hat rates this important (CVSS 7.4). Weakness: CWE-22. Affected product named by the advisory: File Integrity Operator.

CVE-2026-45774
Unclassified
Aug 13, 2026
High7.4Red Hat

High [CVE-2026-45725] Arbitrary file write via path traversal in remote fetching mechanism

Arbitrary file write via path traversal in remote fetching mechanism. Red Hat rates this important (CVSS 7.4). Weakness: CWE-22. Affected product named by the advisory: File Integrity Operator.

CVE-2026-45725
Unclassified
Aug 13, 2026
High7.1Red Hat Updated

High [CVE-2026-48099] Filesystem path traversal via encoded dot segments

WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path layout. The issue is fixed with version 4.3.4. A remote attacker could exploit this vulnerability by sending a specially crafted WebDAV request path containing encoded parent-directory segments. This could allow the attacker to escape the configured filesystem share root, potentially leading to unauthorized access to sensitive files or directories outside the intended scope. Red Hat products do not ship WsgiDAV. The vulnerable code path is therefore not present in any Red Hat-shipped build, and no Red Hat product is affected by this flaw. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L). Weakness: CWE-22.

CVE-2026-48099
Unclassified
Aug 13, 2026
High7.5Red Hat Updated

High [CVE-2026-73643] Denial of Service via exponential parsing in flow collections

Denial of Service via exponential parsing in flow collections. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:61314 with package cluster-observability-operator/monitoring-console-plugin-pf6-rhel9:1787597578. Affected products named by the advisory: Cryostat 4; Gatekeeper 3; Migration Toolkit for Applications 8; Migration Toolkit for Containers; and 31 more. Affected products named by the advisory: Network Observability Operator; Node HealthCheck Operator; OpenShift Lightspeed; OpenShift Pipelines; and 27 more.

CVE-2026-73643
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-73569] Denial of Service via repeated DOCTYPE declarations

Denial of Service via repeated DOCTYPE declarations. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected products named by the advisory: Migration Toolkit for Applications 8; Red Hat Advanced Cluster Security 4; Red Hat Openshift Data Foundation 4; Red Hat OpenShift GitOps; and 2 more. Affected products named by the advisory: Red Hat OpenShift Virtualization 4; Self-service automation portal 2.

CVE-2026-73569
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-73566] Denial of Service via crafted long-path tar archive

Denial of Service via crafted long-path tar archive. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Migration Toolkit for Containers; Node HealthCheck Operator; and 30 more. Affected products named by the advisory: OpenShift Pipelines; OpenShift Service Mesh 3; Red Hat 3scale API Management Platform 2; Red Hat Advanced Cluster Management for Kubernetes 2; and 26 more.

CVE-2026-73566
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-58440] Information disclosure via incomplete webhook revocation

Information disclosure via incomplete webhook revocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-459. Affected product named by the advisory: OpenShift Pipelines.

CVE-2026-58440
Unclassified
Aug 13, 2026