Complete feed
Security advisories & CVEs
1905 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-50749] Improper Authorization vulnerability in Apache Answer
Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Medium [CVE-2026-48912] Improper Input Validation vulnerability in Apache Answer
Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users' uploaded files by supplying their file URLs. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Medium [CVE-2026-49331] unauthenticated identity header injection on whitelisted paths
unauthenticated identity header injection on whitelisted paths. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-345. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-16100] Unbounded metric cardinality in user event metrics via request-controlled error text
Unbounded metric cardinality in user event metrics via request-controlled error text. Red Hat rates this moderate (CVSS 6.5). Red Hat lists fixing advisory RHSA-2026:50848 with package rhbk/keycloak-rhel9:26.6-11, rhbk-keycloak-rhel9/rhbk-keycloak-rhel9, keycloak-services, rhbk/keycloak-rhel9-operator:26.6-11. Affected product named by the advisory: Red Hat build of Keycloak 26.6.
Medium [CVE-2026-16071] LDAP entry-DN user search bypasses configured users DN boundary
LDAP entry-DN user search bypasses configured users DN boundary. Red Hat rates this moderate (CVSS 5.4). Red Hat lists fixing advisory RHSA-2026:50848 with package rhbk/keycloak-rhel9:26.6-11, rhbk/keycloak-operator-bundle:26.4.14-1, rhbk-keycloak-rhel9/rhbk-keycloak-rhel9, keycloak-services. Affected products named by the advisory: Red Hat build of Keycloak 26.4.14; Red Hat build of Keycloak 26.6.5.
Medium [CVE-2026-71227] Infinite loop denial of service in libkcapi _kcapi_aio_read_all due to unhandled io_getevents timeout return
Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return. Red Hat rates this moderate (CVSS 5.1). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:56985 with package libkcapi-main-1.5.1-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-71225] IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries
IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-330. Red Hat lists fixing advisory RHSA-2026:56985 with package libkcapi-main-1.5.1-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-0516] SonicOS: improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipu…
A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.
Medium [CVE-2026-71201] Information disclosure via crafted request
In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project. A project reader can exploit this vulnerability by sending a specially crafted request to the Ironic service. This allows the reader to access Portgroups that are assigned to Nodes belonging to or leased by other projects, leading to unauthorized information disclosure. This flaw has a moderate impact as OpenStack Ironic contains an authorization flaw in the Portgroups listing API. When a project-scoped reader lists portgroups by shard name, the service fails to apply the per-project ownership filter that it correctly applies on other listing paths, allowing the reader to enumerate portgroups belonging to nodes owned or leased by other projects. Exploitation requires valid project-reader credentials and knowledge of a target shard name, and discloses only portgroup metadata (no modification or availability impact), so the severity is limited to information disclosure across project boundaries. Red Hat OpenShift's baremetal (metal3) deployment runs Ironic as a single-tenant control-plane service and does not expose the multi-project reader RBAC path required for exploitation. Red Hat severity: Moderate — CVSS 5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N). Weakness: CWE-639.
Medium [CVE-2026-68080] Apache Qpid Broker-J: It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service
It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Medium [CVE-2026-67592] Denial of Service via uncontrolled incoming data transfers
Denial of Service via uncontrolled incoming data transfers. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat AMQ Clients.
Medium [CVE-2026-67555] It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service This issue affects Apache Qpid Proton-Dotnet: through 1.0.0
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Medium [CVE-2026-68078] Apache Qpid Broker-J: It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Medium [CVE-2026-66277] Denial of Service via uncontrolled transfer frames
Denial of Service via uncontrolled transfer frames. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat AMQ Clients; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 2 more. Affected products named by the advisory: Red Hat build of Quarkus; Red Hat JBoss Enterprise Application Platform Expansion Pack.
Medium [CVE-2026-66277] Apache Qpid Proton-J: It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Medium [CVE-2026-67554] Apache Qpid Proton-Dotnet: authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Medium [CVE-2026-68077] Apache Qpid Broker-J: authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Medium [CVE-2026-66276] Denial of service via unbounded disposition range handling
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. All affected versions are set to AFFECTED/DEFER as the CVSS score (6.5) is below the 7.0 threshold for immediate remediation. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-606. Affected Red Hat products: Red Hat AMQ Broker 7; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Quarkus; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-66276] Apache Qpid Proton-J: authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Medium [CVE-2026-67591] Denial of Service via exceeding session flow control window
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue. This can lead to a denial of service (DoS), making the system unavailable to legitimate users. The affected components are set to AFFECTED/DEFER as the CVSS score (6.5) is below the 7.0 threshold for immediate remediation. Note: the substring-matched artifacts are ancillary (parent POM, test driver) — the core protonj2-client library was not found via strict search. The affects are precautionary. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat AMQ Broker 7. Red Hat does not currently list a fixing RHSA for this CVE.