Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.7Red Hat

High [CVE-2026-58439] Branch protection bypass via stale approval flag in PR retargeting

Branch protection bypass via stale approval flag in PR retargeting. Red Hat rates this important (CVSS 7.7). Weakness: CWE-472.

CVE-2026-58439
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-58436] Denial of Service via ParseAcceptLanguage and Locale middleware on unauthenticated requests

Denial of Service via ParseAcceptLanguage and Locale middleware on unauthenticated requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333.

CVE-2026-58436
Unclassified
Aug 13, 2026
High7.1Red Hat

High [CVE-2026-58437] Repository visibility manipulation via Git push options

Repository visibility manipulation via Git push options. Red Hat rates this important (CVSS 7.1). Weakness: CWE-1220. Affected product named by the advisory: OpenShift Pipelines.

CVE-2026-58437
Unclassified
Aug 13, 2026
High8.6Red Hat Updated

High [CVE-2026-58314] Server-Side Request Forgery via webhooks, repository migration, and OpenID discovery

Two SSRF findings in Gitea 1.26.2 A flaw was found in Gitea. This vulnerability, known as Server-Side Request Forgery (SSRF), allows an attacker to trick the server into making requests to internal network resources. A logged-in user can exploit this by crafting malicious webhooks or repository migration configurations, leading to the disclosure of sensitive information from internal hosts. Additionally, if OpenID sign-in is enabled, an unauthenticated attacker can trigger blind GET requests to internal IPs through the OpenID discovery process, which can be used for internal network reconnaissance. A flaw in Gitea's URL parsing logic allows both authenticated users (via webhooks or repository migrations) and unauthenticated users (via OpenID discovery) to trigger HTTP GET requests to internal endpoints. By manipulating these parameters, an attacker can bypass boundary controls to perform Server-Side Request Forgery (SSRF), allowing internal network reconnaissance and disclosure of sensitive information from internal hosts. Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N). Weakness: CWE-918. Affected Red Hat products: OpenShift Pipelines. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-58314
Unclassified
Aug 13, 2026
High8.1Red Hat

High [CVE-2026-56750] Unauthorized access due to remember-me token theft not invalidating attacker sessions.

Unauthorized access due to remember-me token theft not invalidating attacker sessions. Red Hat rates this important (CVSS 8.1). Weakness: CWE-613. Affected product named by the advisory: OpenShift Pipelines.

CVE-2026-56750
Unclassified
Aug 13, 2026
High8.8Red Hat

High [CVE-2026-56654] Privilege Escalation via API Access Token Scope Escalation

Privilege Escalation via API Access Token Scope Escalation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-266.

CVE-2026-56654
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-54481] Insecure TLS verification in internal API client

Insecure TLS verification in internal API client. Red Hat rates this important (CVSS 7.5). Weakness: CWE-295. Affected product named by the advisory: OpenShift Pipelines.

CVE-2026-54481
Unclassified
Aug 13, 2026
High8.1Red Hat

High [CVE-2026-73515] Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer

Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer. Red Hat rates this important (CVSS 8.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: postgresql16-postgis; Red Hat package: postgresql18-postgis.

CVE-2026-73515
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-73556] Denial of Service via Regular Expression processing

Denial of Service via Regular Expression processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-73556
Unclassified
Aug 13, 2026
High7.4Red Hat

High [CVE-2026-70452] rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure

rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure. Red Hat rates this important (CVSS 7.4). Weakness: CWE-636. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-70452
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-70455] Denial of Service via Zstandard compression thread exhaustion

Denial of Service via Zstandard compression thread exhaustion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: rsync.

CVE-2026-70455
Red Hat Enterprise Linux
Aug 13, 2026
High8.2Red Hat

High [CVE-2026-70456] Heap Out-of-Bounds Write via crafted argument list

Heap Out-of-Bounds Write via crafted argument list. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-70456
Red Hat Enterprise Linux
Aug 13, 2026
High8.2Red Hat Updated

High [CVE-2026-70458] Memory corruption via crafted file entries

Memory corruption via crafted file entries. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-70458
Red Hat Enterprise Linux
Aug 13, 2026
High8.1Red Hat Updated

High [CVE-2026-70460] rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink

rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink. Red Hat rates this important (CVSS 8.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-70460
Red Hat Enterprise Linux
Aug 13, 2026
High8.2Red Hat

High [CVE-2026-70461] Information disclosure and denial of service via crafted files-from entry

Information disclosure and denial of service via crafted files-from entry. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-70461
Red Hat Enterprise Linux
Aug 13, 2026
High8.1Red Hat Updated

High [CVE-2026-70463] Authorization bypass via `auth users` directive parsing

Authorization bypass via `auth users` directive parsing. Red Hat rates this important (CVSS 8.1). Weakness: CWE-863. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-70463
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat Updated

High [CVE-2026-70464] Denial of Service via handshake stall

Denial of Service via handshake stall. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-70464
Red Hat Enterprise Linux
Aug 13, 2026
High8.1Red Hat

High [CVE-2026-53795] Arbitrary file write via --temp-dir or --link-dest options

Arbitrary file write via --temp-dir or --link-dest options. Red Hat rates this important (CVSS 8.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-53795
Red Hat Enterprise Linux
Aug 13, 2026
High7.4Red Hat

High [CVE-2026-53793] rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode

rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode. Red Hat rates this important (CVSS 7.4). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-53793
Red Hat Enterprise Linux
Aug 13, 2026
High7.4Red Hat

High [CVE-2026-53791] rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header

rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header. Red Hat rates this important (CVSS 7.4). Weakness: CWE-290. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-53791
Red Hat Enterprise Linux
Aug 13, 2026