Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-73627] Plugin manager lock-rule bypass allows unauthorized plugin control
Plugin manager lock-rule bypass allows unauthorized plugin control. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-414. Affected products named by the advisory: Migration Toolkit for Applications 8; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-73624] Arbitrary File Overwrite via improper git option validation
Arbitrary File Overwrite via improper git option validation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-88. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.
High [CVE-2026-73625] Remote Code Execution via kwarg value smuggling
Remote Code Execution via kwarg value smuggling. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.
High [CVE-2026-73623] Remote Code Execution via malicious Git template
Remote Code Execution via malicious Git template. Red Hat rates this important (CVSS 7.5). Weakness: CWE-78. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.
High [CVE-2026-73622] Information disclosure via environment variable expansion in URL handling
Information disclosure via environment variable expansion in URL handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-914. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.
High [CVE-2026-73620] Arbitrary file overwrite and read via unsafe git option forwarding
Arbitrary file overwrite and read via unsafe git option forwarding. Red Hat rates this important (CVSS 8.8). Weakness: CWE-88. Red Hat lists fixing advisory RHSA-2026:59135 with package python3.12-gitpython-0:3.1.59-1.el8ap, python3.12-gitpython-0:3.1.59-1.el9ap. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.
High [CVE-2026-45819] Denial of Service via improper input handling
Denial of Service via improper input handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-617. Red Hat lists fixing advisory RHSA-2026:54517 with package grafana13-1-main-13.1.3-0.1.1.hum1, grafana12-4-main-12.4.8-0.1.1.hum1. Affected products named by the advisory: Cryostat 4; OpenShift Lightspeed; OpenShift Pipelines; OpenShift Service Mesh 3; and 21 more. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; Red Hat Build of Keycloak; Red Hat Build of Podman Desktop; and 17 more.
High [CVE-2026-19484] Denial of Service via oversized multipart boundary
Denial of Service via oversized multipart boundary. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606.
High [CVE-2026-19481] Denial of Service from crafted form-data headers
Denial of Service from crafted form-data headers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-915. Affected products named by the advisory: OpenShift Pipelines; Red Hat AMQ Broker 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4.
High [CVE-2026-67986] Arbitrary code execution via Ruby code injection in AwesomeMethodArray#grep
Arbitrary code execution via Ruby code injection in AwesomeMethodArray#grep. Red Hat rates this important (CVSS 7.8). Weakness: CWE-94.
High [CVE-2026-68453] Fix buffer over-read in cca_cipher2protkey
Fix buffer over-read in cca_cipher2protkey. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68452] Validate length for CCA AES cipher key requests
Validate length for CCA AES cipher key requests. Red Hat rates this moderate (CVSS 7). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68451] Validate length for CCA ECC private key requests
Validate length for CCA ECC private key requests. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-73416] Extension blocklist bypass via weak package-name canonicalization
Extension blocklist bypass via weak package-name canonicalization. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-1289.
Medium [CVE-2026-73428] Stored Cross-Site Scripting via HTML paste allows arbitrary code execution.
Stored Cross-Site Scripting via HTML paste allows arbitrary code execution. Red Hat rates this moderate (CVSS 4.6). Weakness: CWE-79.
Medium [CVE-2026-73479] Terminal escape sequence injection via unfiltered marked file paths
Terminal escape sequence injection via unfiltered marked file paths. Red Hat rates this moderate (CVSS 5). Weakness: CWE-117.
Medium [CVE-2026-73480] Terminal Injection via Unstripped Escape Sequences
Terminal Injection via Unstripped Escape Sequences. Red Hat rates this moderate (CVSS 5). Weakness: CWE-838.
Medium [CVE-2026-72647] Denial of Service via uncontrolled recursion in search requests
Denial of Service via uncontrolled recursion in search requests. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-606. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-72656] Denial of Service via excessive memory allocation in ES|QL queries
Denial of Service via excessive memory allocation in ES|QL queries. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-789.
Medium [CVE-2026-72678] Denial of Service via excessive memory allocation
Denial of Service via excessive memory allocation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770.