Complete feed
Security advisories & CVEs
302 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Low [CVE-2026-61865] Memory leak in hough lines operation can lead to denial of service
Memory leak in hough lines operation can lead to denial of service. Red Hat rates this low (CVSS 2.9). Weakness: CWE-772.
Low [CVE-2026-61866] Memory leak in JNG encoder can lead to denial of service
Memory leak in JNG encoder can lead to denial of service. Red Hat rates this low (CVSS 2.9). Weakness: CWE-772.
Low [CVE-2026-61864] Memory leak in color transformation to log colorspace
Memory leak in color transformation to log colorspace. Red Hat rates this low (CVSS 2.9). Weakness: CWE-772.
Low [CVE-2026-61863] Memory leak in TIFF encoder
Memory leak in TIFF encoder. Red Hat rates this low (CVSS 2.9). Weakness: CWE-772.
Low [CVE-2026-61862] Information disclosure via out-of-bounds read when displaying profiles with debug enabled
Information disclosure via out-of-bounds read when displaying profiles with debug enabled. Red Hat rates this low (CVSS 2.9). Weakness: CWE-125.
Low [CVE-2026-61860] Denial of Service via use-after-free during freetype initialization
Denial of Service via use-after-free during freetype initialization. Red Hat rates this low (CVSS 3.7). Weakness: CWE-825.
Low [CVE-2026-61464] ImageMagick before 7.1.2-26 Heap Buffer Over-Write via X11
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can result in heap memory corruption and denial of service. Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification:. Red Hat severity: Low. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.
Low [CVE-2026-61859] Information disclosure via policy bypass in -script operation
Information disclosure via policy bypass in -script operation. Red Hat rates this low (CVSS 3.3). Weakness: CWE-639.
Low [CVE-2026-56764] Hono - Timing Attack in basicAuth and bearerAuth Middleware
Hono - Timing Attack in basicAuth and bearerAuth Middleware. Red Hat rates this low (CVSS 3.7). Weakness: CWE-208. Red Hat lists fixing advisory RHSA-2026:47618 with package grafana13-1-main-13.1.1-0.2.hum1, grafana12-4-main-12.4.6-0.2.hum1.
Low [CVE-2026-56375] Magick.NET-Q8-AnyCPU: Magick.NET-Q8-OpenMP-arm64: Ma…
Magick.NET-Q8-AnyCPU: Magick.NET-Q8-OpenMP-arm64: Magick.NET-Q8-OpenMP-x64: Magick.NET-Q8-arm64: Magick.NET-Q8-x64: Magick.NET-Q8-x86: ImageMagick: Denial of Service due to memory leak in ASHLAR coder. Red Hat rates this low (CVSS 3.3). Weakness: CWE-770.
Low [CVE-2026-60082] Denial of Service via out-of-bounds read
Denial of Service via out-of-bounds read. Red Hat rates this moderate (CVSS 3.3). Weakness: CWE-125.
Low [CVE-2026-60081] DBI::ProfileData: Denial of Service due to unbounded path index
DBI::ProfileData: Denial of Service due to unbounded path index. Red Hat rates this moderate (CVSS 2.8). Weakness: CWE-770.
Low [CVE-2026-59084] Insufficient documentation for EncryptInterceptor may lead to insecure configurations
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue. Insufficient technical documentation regarding the secure configuration of the EncryptInterceptor component may lead to deployments with insecure settings. This vulnerability could allow an attacker to exploit misconfigurations that arise from unclear guidance, potentially compromising the confidentiality or integrity of data processed by the affected system. Without clear guidance on secure configuration, administrators might inadvertently deploy the interceptor in a way that weakens security, rather than a direct code flaw. This issue affects Red Hat products utilizing Apache Tomcat, including Red Hat Enterprise Linux and Red Hat JBoss Web Server. Red Hat severity: Low — CVSS 3.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-1188. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.
Low [CVE-2026-59083] Security constraint bypass via improper URL encoding in rewrite valve
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue. A remote attacker could exploit this to bypass security constraints in certain configurations, potentially gaining unauthorized access or performing actions that should be restricted. Exploitation requires specific configurations and has high attack complexity, limiting its overall risk to Red Hat products. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-807. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat JBoss Web Server 5. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat fixing advisory: RHSA-2026:36872, RHSA-2026:37767.
Low [CVE-2026-15605] Information disclosure due to weak hash in artifact integrity validation
Information disclosure due to weak hash in artifact integrity validation. Red Hat rates this low (CVSS 3.1). Weakness: CWE-328.
Low [CVE-2026-40469] Denial of Service due to integer overflow
Denial of Service due to integer overflow. Red Hat rates this moderate (CVSS 2.8). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:40041 with package gawk-main-5.4.0-3.1.hum1.
Low [CVE-2026-61870] Denial of Service via specially crafted VIFF images
Denial of Service via specially crafted VIFF images. Red Hat rates this low (CVSS 2.9). Weakness: CWE-772.
Low [CVE-2026-61858] Policy bypass allows unauthorized file writing via APNG encoder
Policy bypass allows unauthorized file writing via APNG encoder. Red Hat rates this low (CVSS 3.3). Weakness: CWE-22.
Low [CVE-2026-59180] Information disclosure via HTTP redirect following with credential resending
Information disclosure via HTTP redirect following with credential resending. Red Hat rates this low (CVSS 3.1). Weakness: CWE-201.
Low [CVE-2026-56366] Denial of Service via memory leak in APP1JPEG image processing
Denial of Service via memory leak in APP1JPEG image processing. Red Hat rates this low (CVSS 3.3). Weakness: CWE-772.