Complete feed
Action required
Critical/high still unreviewed, or CISA KEV listed
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-10582] Server-Side Request Forgery (SSRF) leading to information disclosure.
Server-Side Request Forgery (SSRF) leading to information disclosure. Red Hat rates this important (CVSS 7.4). Weakness: CWE-918. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift GitOps; Red Hat OpenStack Platform 18.0.
High [CVE-2026-76172] URI parsing flaw enables server-side request forgery and redirects
URI parsing flaw enables server-side request forgery and redirects. Red Hat rates this important (CVSS 7.5). Weakness: CWE-76. Affected products named by the advisory: Migration Toolkit for Applications 8; Migration Toolkit for Containers; Multicluster Engine for Kubernetes; Network Observability Operator; and 29 more. Affected products named by the advisory: OpenShift Lightspeed; OpenShift Pipelines; OpenShift Serverless; Red Hat Advanced Cluster Management for Kubernetes 2; and 25 more.
High [CVE-2026-75975] Server-side request forgery via malformed IPv6 normalization
Server-side request forgery via malformed IPv6 normalization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-918. Affected products named by the advisory: Migration Toolkit for Applications 8; Migration Toolkit for Containers; Multicluster Engine for Kubernetes; Network Observability Operator; and 29 more. Affected products named by the advisory: OpenShift Lightspeed; OpenShift Pipelines; OpenShift Serverless; Red Hat Advanced Cluster Management for Kubernetes 2; and 25 more.
High [CVE-2026-75899] Server-Side Request Forgery via repeated hostname percent-decoding
Server-Side Request Forgery via repeated hostname percent-decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-140. Affected products named by the advisory: Migration Toolkit for Applications 8; Migration Toolkit for Containers; Multicluster Engine for Kubernetes; Network Observability Operator; and 29 more. Affected products named by the advisory: OpenShift Lightspeed; OpenShift Pipelines; OpenShift Serverless; Red Hat Advanced Cluster Management for Kubernetes 2; and 25 more.
High [CVE-2026-75931] Host confusion via skipped IDN canonicalization
Host confusion via skipped IDN canonicalization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-444. Affected products named by the advisory: Migration Toolkit for Applications 8; Migration Toolkit for Containers; Multicluster Engine for Kubernetes; Network Observability Operator; and 29 more. Affected products named by the advisory: OpenShift Lightspeed; OpenShift Pipelines; OpenShift Serverless; Red Hat Advanced Cluster Management for Kubernetes 2; and 25 more.
High [CVE-2026-78161] Out-of-bounds write in LECP CBOR Recording
Out-of-bounds write in LECP CBOR Recording. Red Hat rates this important (CVSS 7.3). Weakness: CWE-787.
High [CVE-2026-52492] Arbitrary code execution via crafted TIFF image
Arbitrary code execution via crafted TIFF image. Red Hat rates this important (CVSS 7.3). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:53467 with package libtiff-main-4.7.2-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: libtiff; Red Hat package: compat-libtiff3; and 1 more.
High [CVE-2026-52490] Arbitrary code execution via process_command_opts function
Arbitrary code execution via process_command_opts() function. Red Hat rates this important (CVSS 7.3). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:53467 with package libtiff-main-4.7.2-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: libtiff; Red Hat package: compat-libtiff3; and 1 more.
High [CVE-2026-10053] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.