Complete feed
Security advisories & CVEs
3478 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-78684] Denial of Service via DeepStream backend resource control bypass.
Denial of Service via DeepStream backend resource control bypass. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-79652] JWT Bearer authorization grant does not enforce consentRequired
JWT Bearer authorization grant does not enforce consentRequired. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-862. Affected product named by the advisory: Red Hat Build of Keycloak.
Medium [CVE-2026-77117] Non-progress DoS in SHIFT_JISX0213 ->
Non-progress DoS in SHIFT_JISX0213 ->. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Hardened Images; Red Hat package: glibc.
Medium [CVE-2026-11610 +1] incomplete fix may introduce a connection-stall DoS
CVE-2026-11610 incomplete fix may introduce a connection-stall DoS. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Directory Server 11; Red Hat Directory Server 12; Red Hat Directory Server 13; Red Hat Enterprise Linux 10; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.
Medium [CVE-2026-19499] Buffer Overflow in strfmon right-justification padding
Buffer Overflow in strfmon right-justification padding. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Hardened Images; Red Hat package: glibc.
Medium [CVE-2026-78322] stack buffer overflow in parse_progress_line for 7z and RAR handlers
stack buffer overflow in parse_progress_line for 7z and RAR handlers. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat package: file-roller.
Medium [CVE-2026-19542] Fix out-of-bounds array write in tdelete
Fix out-of-bounds array write in tdelete. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:59721 with package glibc-main-2.43-8.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: glibc.
Medium [CVE-2026-59183] Integer Overflow Vulnerability Leading to Application Crash
Integer Overflow Vulnerability Leading to Application Crash. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: openexr.
Medium [CVE-2026-55373] Denial of Service via infinite loop in sample count processing.
Denial of Service via infinite loop in sample count processing. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: openexr.
Medium [CVE-2026-55371] Denial of Service via NULL pointer dereference in exr_attr_set_bytes
Denial of Service via NULL pointer dereference in exr_attr_set_bytes(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-55059] Heap out-of-bounds write leads to denial of service
Heap out-of-bounds write leads to denial of service. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-124. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: openexr.
Medium [CVE-2026-54920] Denial of Service via crafted HTJ2K-compressed EXR file
Denial of Service via crafted HTJ2K-compressed EXR file. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-617.
Medium [CVE-2026-63073] untrusted sender DN used as format string in CMP response validation
untrusted sender DN used as format string in CMP response validation. Red Hat rates this low (CVSS 5.9). Weakness: CWE-134. Red Hat lists fixing advisory RHSA-2026:59641 with package openssl3-main-3.5.8-0.1.hum1, openssl-main-3.5.8-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 6 more. Affected products named by the advisory: Red Hat JBoss Core Services; Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7; Red Hat OpenShift Container Platform 4; and 2 more.
Medium [CVE-2026-58070] Vulnerability Resolved in Veeam Backup & Replication 13.1
Vulnerability Resolved in Veeam Backup & Replication 13.1 KB ID: 4902 Product: Published: 2026-08-25 Last Modified: Veeam Software Security Commitment Veeam® is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a Vulnerability Disclosure Program (VDP) for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay. Issue Details A vulnerability that causes guest OS credentials used for Application Aware processing to be recorded in cleartext in logs on the guest machine. Severity: Medium CVSS v4.0 Score: 6.8CVSS: AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Medium [CVE-2026-68516] Denial of service via crafted HTJ2K-compressed EXR with invalid image-offset
Denial of service via crafted HTJ2K-compressed EXR with invalid image-offset. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-787.
Medium [CVE-2026-17113] unvalidated image env var causes daemon crash
unvalidated image env var causes daemon crash. Red Hat rates this moderate (CVSS 6). Weakness: CWE-1287. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-75509] Issuer-validation bypass via array-valued claims
Issuer-validation bypass via array-valued claims. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-480. Affected products named by the advisory: Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux command line assistant; Red Hat OpenShift Virtualization 4; Red Hat Satellite 6.
Medium [CVE-2026-78475] Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader
A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file. To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted PIX image with GIMP, reducing the likelihood of exploitation. Due to this reason, this flaw has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gimp.
Medium [CVE-2026-75099] Unauthenticated REST disclosure of certain content items in Apache Allura
Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through 1.19.1. Users are recommended to upgrade to version 1.20.0, which fixes the issue.
Medium [CVE-2025-27636 +5] Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Knative component The Knative consumer in camel-knative maps inbound CloudEvent attributes onto Camel message headers
Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Knative component The Knative consumer in camel-knative maps inbound CloudEvent attributes onto Camel message headers. In binary content mode the HTTP-header path filters Camel-internal headers through KnativeHttpHeaderFilterStrategy, but in structured content mode (Content-Type application/cloudevents+json) the CloudEvent extension fields are read directly from the JSON body and every extension key is copied into the Exchange headers without applying any HeaderFilterStrategy (CloudEventProcessors, spec versions 1.0, 1.0.1 and 1.0.2). As a result, an unauthenticated attacker can inject Camel-internal headers (e.g. CamelHttpUri, CamelHttpPath, CamelFileName) via a structured-mode CloudEvent request, matched case-insensitively against Camel's header map. When a route forwards messages from a Knative consumer to a header-driven component such as camel-http or camel-file, the injected headers override configured values, enabling server-side request forgery (SSRF), path traversal or message-dispatch redirection depending on the route.