Complete feed
Security advisories & CVEs
1905 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-67591] Apache Qpid ProtonJ2: authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.
Medium [CVE-2026-67553] Apache Qpid Proton-Dotnet: authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Medium [CVE-2026-68075] Apache Qpid Broker-J: authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Medium [CVE-2026-66275] Denial of Service via exceeding session flow control window
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. This action could lead to a denial of service (DoS), making the system unavailable to legitimate users. All affected versions are set to AFFECTED/DEFER as the CVSS score (6.5) is below the 7.0 threshold for immediate remediation. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat AMQ Broker 7; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Quarkus; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-66275] Apache Qpid Proton-J: authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Medium [CVE-2026-64579] preallocate inexact bins before xfrm_hash_rebuild reinsert
preallocate inexact bins before xfrm_hash_rebuild reinsert. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-64569] fix NULL deref in mpls_valid_fib_dump_req on CONFIG_INET=n
fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-64574] tear down new links on vif update error path
tear down new links on vif update error path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-64567] reject free space cache with more entries than pages
reject free space cache with more entries than pages. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.
Medium [CVE-2026-64566] propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags
propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-821.
Medium [CVE-2026-64571] validate RX frame length in p54_rx_eeprom_readback
validate RX frame length in p54_rx_eeprom_readback(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-64578] validate compound request size before reading StructureSize2
validate compound request size before reading StructureSize2. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-64575] fix double sock release on batch realloc
fix double sock release on batch realloc. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-64576] initialize extack in nh_res_bucket_migrate
initialize extack in nh_res_bucket_migrate(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-824. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
Medium [CVE-2026-64570] fix fils_discovery double free on alloc failure
fix fils_discovery double free on alloc failure. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1341. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9.
Medium [CVE-2026-18103] Persistent denial of service due to buffer overflow via OMAPI
Persistent denial of service due to buffer overflow via OMAPI. Red Hat rates this low (CVSS 4.9). Weakness: CWE-120.
Medium [CVE-2026-18785] Use-after-free vulnerability via local manipulation
Use-after-free vulnerability via local manipulation. Red Hat rates this moderate. Weakness: CWE-825.
Medium [CVE-2026-15920] Cross-site scripting via unvalidated URLField values in the admin
Cross-site scripting via unvalidated URLField values in the admin. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79.
Medium [CVE-2026-15830] Denial of Service via parsing deeply nested geometry collections
Denial of Service via parsing deeply nested geometry collections. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-606.
Medium [CVE-2026-15337] Denial-of-service vulnerability due to excessive memory consumption
Denial-of-service vulnerability due to excessive memory consumption. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1050.