Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-58439] Branch protection bypass via stale approval flag in PR retargeting
Branch protection bypass via stale approval flag in PR retargeting. Red Hat rates this important (CVSS 7.7). Weakness: CWE-472.
High [CVE-2026-58436] Denial of Service via ParseAcceptLanguage and Locale middleware on unauthenticated requests
Denial of Service via ParseAcceptLanguage and Locale middleware on unauthenticated requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333.
High [CVE-2026-58437] Repository visibility manipulation via Git push options
Repository visibility manipulation via Git push options. Red Hat rates this important (CVSS 7.1). Weakness: CWE-1220. Affected product named by the advisory: OpenShift Pipelines.
High [CVE-2026-58314] Server-Side Request Forgery via webhooks, repository migration, and OpenID discovery
Two SSRF findings in Gitea 1.26.2 A flaw was found in Gitea. This vulnerability, known as Server-Side Request Forgery (SSRF), allows an attacker to trick the server into making requests to internal network resources. A logged-in user can exploit this by crafting malicious webhooks or repository migration configurations, leading to the disclosure of sensitive information from internal hosts. Additionally, if OpenID sign-in is enabled, an unauthenticated attacker can trigger blind GET requests to internal IPs through the OpenID discovery process, which can be used for internal network reconnaissance. A flaw in Gitea's URL parsing logic allows both authenticated users (via webhooks or repository migrations) and unauthenticated users (via OpenID discovery) to trigger HTTP GET requests to internal endpoints. By manipulating these parameters, an attacker can bypass boundary controls to perform Server-Side Request Forgery (SSRF), allowing internal network reconnaissance and disclosure of sensitive information from internal hosts. Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N). Weakness: CWE-918. Affected Red Hat products: OpenShift Pipelines. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-56750] Unauthorized access due to remember-me token theft not invalidating attacker sessions.
Unauthorized access due to remember-me token theft not invalidating attacker sessions. Red Hat rates this important (CVSS 8.1). Weakness: CWE-613. Affected product named by the advisory: OpenShift Pipelines.
High [CVE-2026-56654] Privilege Escalation via API Access Token Scope Escalation
Privilege Escalation via API Access Token Scope Escalation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-266.
High [CVE-2026-54481] Insecure TLS verification in internal API client
Insecure TLS verification in internal API client. Red Hat rates this important (CVSS 7.5). Weakness: CWE-295. Affected product named by the advisory: OpenShift Pipelines.
High [CVE-2026-73515] Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer
Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer. Red Hat rates this important (CVSS 8.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: postgresql16-postgis; Red Hat package: postgresql18-postgis.
High [CVE-2026-73556] Denial of Service via Regular Expression processing
Denial of Service via Regular Expression processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-70452] rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure
rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure. Red Hat rates this important (CVSS 7.4). Weakness: CWE-636. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-70455] Denial of Service via Zstandard compression thread exhaustion
Denial of Service via Zstandard compression thread exhaustion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: rsync.
High [CVE-2026-70456] Heap Out-of-Bounds Write via crafted argument list
Heap Out-of-Bounds Write via crafted argument list. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-70458] Memory corruption via crafted file entries
Memory corruption via crafted file entries. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-70460] rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink
rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink. Red Hat rates this important (CVSS 8.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-70461] Information disclosure and denial of service via crafted files-from entry
Information disclosure and denial of service via crafted files-from entry. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-70463] Authorization bypass via `auth users` directive parsing
Authorization bypass via `auth users` directive parsing. Red Hat rates this important (CVSS 8.1). Weakness: CWE-863. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-70464] Denial of Service via handshake stall
Denial of Service via handshake stall. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-53795] Arbitrary file write via --temp-dir or --link-dest options
Arbitrary file write via --temp-dir or --link-dest options. Red Hat rates this important (CVSS 8.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-53793] rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode
rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode. Red Hat rates this important (CVSS 7.4). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-53791] rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header
rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header. Red Hat rates this important (CVSS 7.4). Weakness: CWE-290. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.