VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
Critical/high still unreviewed, or CISA KEV listed
Authentication bypass via forged Ed25519 cryptographic signatures. Red Hat rates this important (CVSS 7.5). Weakness: CWE-347. Affected package(s): rhdh/rhdh-hub-rhel9:1777903262, cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, automation-gateway, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`).
Signature Forgery via Weak RSASSA PKCS#1 v1.5 Verification. Red Hat rates this important (CVSS 7.5). Weakness: CWE-347. Affected package(s): quay/quay-rhel9:1779922205, quay/quay-rhel8:1779811473, rhdh/rhdh-hub-rhel9:1777903262, quay/quay-rhel8:1779689392, cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, quay/quay-rhel8:1779822261. Resolved in Red Hat advisory RHSA-2026:23361 — update the affected packages (`sudo dnf update`).
Denial of Service via infinite loop in BigInteger.modInverse(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Affected package(s): rhdh/rhdh-hub-rhel9:1777903262, cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, automation-platform-ui, automation-gateway, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`).
Denial of Service via HTTP/2 CONTINUATION frame flood. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): eap8-netty-transport-native-epoll, rhoai/odh-modelmesh-rhel9:1776756834, cryostat/jfr-datasource-rhel9:4.2.0, netty-codec-http, eap8-netty, cryostat/cryostat-rhel9:4.2.0. Resolved in Red Hat advisory RHSA-2026:8509 — update the affected packages (`sudo dnf update`).
Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values. Red Hat rates this important (CVSS 7.5). Weakness: CWE-444. Affected package(s): eap8-netty-transport-native-epoll, devspaces/pluginregistry-rhel9:1776717247, netty-codec-http, rhoai/odh-modelmesh-rhel9:1776756834, cryostat/jfr-datasource-rhel9:4.2.0, devspaces/server-rhel9:1776796445. Resolved in Red Hat advisory RHSA-2026:8509 — update the affected packages (`sudo dnf update`).
Information disclosure and unauthorized data modification via unprotected tracing and assessment endpoints. Red Hat rates this important (CVSS 8.1). Weakness: CWE-425. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. Request smuggling allows an attacker to bypass security mechanisms, access restricted information, or manipulate web caches, potentially leading to unauthorized actions or data exposure. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Data Grid 8; and 7 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 2 more.
Denial of Service via unbounded memory read in feature toggle evaluation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Information disclosure of data-source passwords via public dashboards. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected package(s): grafana. Resolved in Red Hat advisory RHSA-2026:11416 — update the affected packages (`sudo dnf update`).
Authentication bypass via non-canonical HTTP header injection. Red Hat rates this important (CVSS 7.7). Weakness: CWE-290. Affected package(s): devspaces/traefik-rhel9:1776718585. Resolved in Red Hat advisory RHSA-2026:10175 — update the affected packages (`sudo dnf update`).
Cross-tenant traffic exposure and host restriction bypass via rule-syntax injection in Knative provider. Red Hat rates this important (CVSS 7.7). Weakness: CWE-917. Affected package(s): devspaces/traefik-rhel9:1776718585. Resolved in Red Hat advisory RHSA-2026:10175 — update the affected packages (`sudo dnf update`).
denial of service via crafted message before authentication. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`).
denial of service via specially crafted NOOP command. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`).
Full access via timing oracle attack in credential verification. Red Hat rates this important (CVSS 7.4). Weakness: CWE-208. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`).
Authentication bypass and user enumeration due to cleared auth_username_chars configuration. Red Hat rates this important (CVSS 7.7). Weakness: CWE-89. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Denial of Service via crafted SASL initial response in AUTHENTICATE command. Red Hat rates this important (CVSS 7.5). Weakness: CWE-229. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`).
Arbitrary file write and code execution via untrusted frontend. Red Hat rates this moderate (CVSS 8.2). Weakness: CWE-22. Affected package(s): openshift-service-mesh/istio-proxyv2-rhel9:1776240392, quay/quay-rhel9:1779922205, multicluster-engine/must-gather-rhel9:1782158798, openshift-service-mesh/istio-proxyv2-rhel9:1776291540, openshift-service-mesh/istio-proxyv2-rhel9:1776315466, oadp/oadp-mustgather-rhel9:1779770049. Resolved in Red Hat advisory RHSA-2026:9453 — update the affected packages (`sudo dnf update`).
Denial of Service via crafted Styled Layer Descriptor. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
io.opentelemetry.javaagent/opentelemetry-javaagent: OpenTelemetry Java Instrumentation: Remote code execution via deserialization vulnerability in RMI. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Privilege escalation and denial of service via path traversal in systemd credential configuration. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.