Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-17350] pgAdmin 4: Permission bypass allows authenticated users to access restricted tools
pgAdmin 4: Permission bypass allows authenticated users to access restricted tools. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-425.
Medium [CVE-2026-17348] pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure
pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-306.
Medium [CVE-2026-44615] Path traversal vulnerability in Apache Zeppelin
Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a note, or access to folder operations, could supply traversal segments in note or folder paths. Zeppelin composed these values into filesystem paths using the server's filesystem or Hadoop identity without ensuring that the result remained under the configured notebook directory. This could allow notebook files or directories to be moved, written, or deleted outside the notebook root. This issue affects Apache Zeppelin versions 0.9.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.
Medium [CVE-2026-64607] Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.
Medium [CVE-2026-18214] Google external access-token exchange bypasses hosted-domain restriction
Google external access-token exchange bypasses hosted-domain restriction. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-862. Affected product named by the advisory: Red Hat Build of Keycloak.
Medium [CVE-2026-18203] Group policy extendChildren matches sibling group path prefixes
Group policy extendChildren matches sibling group path prefixes. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-863. Affected product named by the advisory: Red Hat Build of Keycloak.
Medium [CVE-2026-18211] secure-client-uris policy bypass via localhost-prefixed domains
secure-client-uris policy bypass via localhost-prefixed domains. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-20. Affected product named by the advisory: Red Hat Build of Keycloak.
Medium [CVE-2026-18208] Inactive out-of-audience token introspection leaks signed JWT claim
Inactive out-of-audience token introspection leaks signed JWT claim. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-862. Affected product named by the advisory: Red Hat Build of Keycloak.
Medium [CVE-2026-16105] Missing per-role authorization on RoleContainerResource composite endpoints
A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm permissions to remove essential child roles from built-in admin roles, potentially disrupting administrative functions within a realm. The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that exploitation requires the attacker to already possess high-level delegated administrative privileges (manage-realm). Successful exploitation allows an attacker to remove child roles from built-in admin roles, leading to a loss of integrity for administrative configurations. The vulnerability's root cause is an incomplete fix for a previous issue, where authorization checks were not consistently applied to name-based REST API endpoints. Affected Red Hat products: Red Hat Build of Keycloak. Red Hat lists Red Hat Data Grid 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7 as not affected. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-18215] Microsoft external access-token exchange bypasses configured tenant
Microsoft external access-token exchange bypasses configured tenant. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-287. Affected product named by the advisory: Red Hat Build of Keycloak.
Medium [CVE-2026-18218] Client not-before revocation ignored when realm not-before is older but nonzero
Client not-before revocation ignored when realm not-before is older but nonzero. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-862. Affected product named by the advisory: Red Hat Build of Keycloak.
Medium [CVE-2026-58039] Information disclosure due to improper permission enforcement
Information disclosure due to improper permission enforcement. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-73. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.
Medium [CVE-2026-3276] Python Vulnerability in NetApp Products
Python versions through 3.13.13, 3.14.0 through 3.14.5, and 3.15.0a1 through 3.15.0b1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Management Services for Element Software and NetApp HCI. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-42505] Golang Vulnerability in NetApp Products
Golang versions prior to 1.25.12, 1.26.0-0 prior to 1.26.5, and 1.27.0-0 prior to 1.27.0-rc.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-41839] Spring Framework Vulnerability in NetApp Products
Spring Framework versions 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-9828] Logback Vulnerability in NetApp Products
Logback versions prior to 1.5.33 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-63362] Denial of Service via unsigned integer underflow
Denial of Service via unsigned integer underflow. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-191.
Medium [CVE-2026-68563] Information disclosure of PostgreSQL data via insecure backup permissions
Information disclosure of PostgreSQL data via insecure backup permissions. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-732.
Medium [CVE-2026-68562] Information disclosure via Leapp report tampering
Information disclosure via Leapp report tampering. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-610.
Medium [CVE-2026-67550] Denial of Service via out-of-bounds read
Denial of Service via out-of-bounds read. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-125.