Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-53790] rsync < 3.5.0 Command Injection via Multiple Code Paths
rsync < 3.5.0 Command Injection via Multiple Code Paths. Red Hat rates this important (CVSS 8.1). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-53785] Arbitrary file write via path traversal in --relative mode
Arbitrary file write via path traversal in --relative mode. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-53784] Unauthorized File Access via Symlink Module Root
Unauthorized File Access via Symlink Module Root. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-53783] Directory escape via TOCTOU race condition in rrsync
Directory escape via TOCTOU race condition in rrsync. Red Hat rates this important (CVSS 8.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: rsync.
High [CVE-2026-53803] Local Privilege Escalation via Symlink Following
Local Privilege Escalation via Symlink Following. Red Hat rates this important (CVSS 7). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-73508] Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names
Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected products named by the advisory: OpenShift Serverless; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Data Grid 8; and 7 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 3 more.
High [CVE-2026-73507] Denial of Service via CPU Exhaustion in XmlFrameDecoder
Denial of Service via CPU Exhaustion in XmlFrameDecoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Single Sign-On 7.
High [CVE-2026-73505] Arbitrary command execution via template injection in directory names
Arbitrary command execution via template injection in directory names. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78.
High [CVE-2026-14456] Denial of Service via unbounded memory growth in QUIC server
Denial of Service via unbounded memory growth in QUIC server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:56097 with package openssl-main-3.5.6-0.5.hum1. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: openssl.
High [CVE-2026-66804] authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure
authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure. Red Hat rates this important (CVSS 7.7). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:57194 with package multicluster-engine/console-mce-rhel9:1787079359, rhacm2/console-rhel9:1787339248, multicluster-engine/console-mce-rhel9:1787264250, multicluster-engine/console-mce-rhel9:1786668856. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-6471] Arbitrary code execution via logical decoding plugin
Arbitrary code execution via logical decoding plugin. Red Hat rates this important (CVSS 7.2). Weakness: CWE-94. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2; and 2 more. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.
High [CVE-2026-14671] Arbitrary code execution via type confusion in 'refint' module
Arbitrary code execution via type confusion in 'refint' module. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Self-service automation portal 2; Red Hat package: postgresql16; Red Hat package: postgresql18.
High [CVE-2026-19385] PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. An authenticated object creator can exploit this by providing a specially crafted transform list. Attackers with object-creation privileges can use crafted function transform lists to run OS commands as the backup user. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-122. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat fixing advisory: RHSA-2026:57198. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.
High [CVE-2026-16239] Arbitrary code execution via type confusion in cursor lifecycle
Arbitrary code execution via type confusion in cursor lifecycle. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Self-service automation portal 2; Red Hat package: postgresql16; Red Hat package: postgresql18.
High [CVE-2026-16238] Arbitrary code execution via type confusion in pg_restore_attribute_stats
Arbitrary code execution via type confusion in pg_restore_attribute_stats(). Red Hat rates this important (CVSS 8.8). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: postgresql18.
High [CVE-2026-15742] PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. This vulnerability in the PostgreSQL `fuzzystrmatch` extension is rated as Important. This risk is present only when the `fuzzystrmatch` extension is explicitly installed and utilized, as it is not enabled by default in Red Hat deployments. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Hardened Images as not affected. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.
High [CVE-2026-14680] Arbitrary code execution via type confusion with "internal" arguments
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. This type confusion flaw bypasses intended security boundaries for 'internal' data types, leading to a significant privilege escalation and potential compromise of the entire database server. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-843. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Hardened Images as not affected. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.
High [CVE-2026-14679] Stack buffer overflow via OUT parameter count manipulation
Stack buffer overflow via OUT parameter count manipulation. Red Hat rates this important (CVSS 7.1). Weakness: CWE-121. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Self-service automation portal 2; Red Hat package: postgresql16; Red Hat package: postgresql18.
High [CVE-2026-14677] Arbitrary code execution in 32-bit pltcl and plperl
Arbitrary code execution in 32-bit pltcl and plperl. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Self-service automation portal 2; Red Hat package: postgresql16; Red Hat package: postgresql18.
High [CVE-2026-14676] PostgreSQL pg_stat_statements: Arbitrary code execution via heap buffer overflow
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.5 are affected. The pg_stat_statements extension must be loaded (via shared_preload_libraries) for the vulnerability to be exploitable. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql18.