Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.4Red Hat Updated

High [CVE-2026-10582] Server-Side Request Forgery (SSRF) leading to information disclosure.

Server-Side Request Forgery (SSRF) leading to information disclosure. Red Hat rates this important (CVSS 7.4). Weakness: CWE-918. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift GitOps; Red Hat OpenStack Platform 18.0.

CVE-2026-10582
Unclassified
Aug 24, 2026
High7.5Red Hat Updated

High [CVE-2026-76172] URI parsing flaw enables server-side request forgery and redirects

URI parsing flaw enables server-side request forgery and redirects. Red Hat rates this important (CVSS 7.5). Weakness: CWE-76. Affected products named by the advisory: Migration Toolkit for Applications 8; Migration Toolkit for Containers; Multicluster Engine for Kubernetes; Network Observability Operator; and 29 more. Affected products named by the advisory: OpenShift Lightspeed; OpenShift Pipelines; OpenShift Serverless; Red Hat Advanced Cluster Management for Kubernetes 2; and 25 more.

CVE-2026-76172
Red Hat Enterprise Linux
Aug 24, 2026
High7.5Red Hat Updated

High [CVE-2026-75975] Server-side request forgery via malformed IPv6 normalization

Server-side request forgery via malformed IPv6 normalization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-918. Affected products named by the advisory: Migration Toolkit for Applications 8; Migration Toolkit for Containers; Multicluster Engine for Kubernetes; Network Observability Operator; and 29 more. Affected products named by the advisory: OpenShift Lightspeed; OpenShift Pipelines; OpenShift Serverless; Red Hat Advanced Cluster Management for Kubernetes 2; and 25 more.

CVE-2026-75975
Red Hat Enterprise Linux
Aug 24, 2026
High7.5Red Hat Updated

High [CVE-2026-75899] Server-Side Request Forgery via repeated hostname percent-decoding

Server-Side Request Forgery via repeated hostname percent-decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-140. Affected products named by the advisory: Migration Toolkit for Applications 8; Migration Toolkit for Containers; Multicluster Engine for Kubernetes; Network Observability Operator; and 29 more. Affected products named by the advisory: OpenShift Lightspeed; OpenShift Pipelines; OpenShift Serverless; Red Hat Advanced Cluster Management for Kubernetes 2; and 25 more.

CVE-2026-75899
Red Hat Enterprise Linux
Aug 24, 2026
High7.5Red Hat Updated

High [CVE-2026-75931] Host confusion via skipped IDN canonicalization

Host confusion via skipped IDN canonicalization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-444. Affected products named by the advisory: Migration Toolkit for Applications 8; Migration Toolkit for Containers; Multicluster Engine for Kubernetes; Network Observability Operator; and 29 more. Affected products named by the advisory: OpenShift Lightspeed; OpenShift Pipelines; OpenShift Serverless; Red Hat Advanced Cluster Management for Kubernetes 2; and 25 more.

CVE-2026-75931
Red Hat Enterprise Linux
Aug 24, 2026
High7.3Red Hat Updated

High [CVE-2026-78161] Out-of-bounds write in LECP CBOR Recording

Out-of-bounds write in LECP CBOR Recording. Red Hat rates this important (CVSS 7.3). Weakness: CWE-787.

CVE-2026-78161
Unclassified
Aug 24, 2026
High7.3Red Hat Updated

High [CVE-2026-52492] Arbitrary code execution via crafted TIFF image

Arbitrary code execution via crafted TIFF image. Red Hat rates this important (CVSS 7.3). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:53467 with package libtiff-main-4.7.2-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: libtiff; Red Hat package: compat-libtiff3; and 1 more.

CVE-2026-52492
Red Hat Enterprise Linux
Aug 24, 2026
High7.3Red Hat Updated

High [CVE-2026-52490] Arbitrary code execution via process_command_opts function

Arbitrary code execution via process_command_opts() function. Red Hat rates this important (CVSS 7.3). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:53467 with package libtiff-main-4.7.2-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: libtiff; Red Hat package: compat-libtiff3; and 1 more.

CVE-2026-52490
Red Hat Enterprise Linux
Aug 24, 2026
High8.5GitLab Updated

High [CVE-2026-10053] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.

CVE-2026-10053
Unclassified
Aug 23, 2026
High7.5Red Hat Updated

High [CVE-2026-62384] Information Disclosure via Symlink Sandbox Bypass

Information Disclosure via Symlink Sandbox Bypass. Red Hat rates this important (CVSS 7.5). Weakness: CWE-41. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-62384
Unclassified
Aug 22, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-74730] Pin the 'struct nfs_server' during a FREE_STATEID call

Pin the 'struct nfs_server' during a FREE_STATEID call. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74730
Linux Kernel
Aug 22, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-74677] fix carrier_work UAF on disconnect

fix carrier_work UAF on disconnect. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-74677
Linux Kernel
Aug 22, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-74666] synchronize pressure clearing with ring reconfiguration

synchronize pressure clearing with ring reconfiguration. Red Hat rates this moderate (CVSS 7). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-74666
Linux Kernel
Aug 22, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-74624] defer invalid log until after unlock

defer invalid log until after unlock. Red Hat rates this moderate (CVSS 7). Weakness: CWE-833. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-74624
Linux Kernel
Aug 22, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-74700] Always acquire rtnl_lock when destroying locked classifiers

Always acquire rtnl_lock when destroying locked classifiers. Red Hat rates this moderate (CVSS 7). Weakness: CWE-763. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-74700
Linux Kernel
Aug 22, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-74668] use consistent hard_header_len in TX_RING send path

use consistent hard_header_len in TX_RING send path. Red Hat rates this moderate (CVSS 7). Weakness: CWE-131. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74668
Linux Kernel
Aug 22, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-74715] Fix netns reference imbalance in conntrack kfuncs

Fix netns reference imbalance in conntrack kfuncs. Red Hat rates this moderate (CVSS 7). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74715
Linux Kernel
Aug 22, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-74621] fix sk_buff leak when the header checks reject a packet

fix sk_buff leak when the header checks reject a packet. Red Hat rates this moderate (CVSS 7). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74621
Linux Kernel
Aug 22, 2026
High7.0Red Hat Updated

High [CVE-2026-74669] clear IPv4 options after rebasing tunnel ICMP errors

clear IPv4 options after rebasing tunnel ICMP errors. Red Hat rates this important (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-74669
Linux Kernel
Aug 22, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-74714] Fix use-after-free in bpf_iter_tcp_established_batch

Fix use-after-free in bpf_iter_tcp_established_batch(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74714
Linux Kernel
Aug 22, 2026