Complete feed
Security advisories & CVEs
2746 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-74540] fix UAF in l2cap_le_connect_rsp
fix UAF in l2cap_le_connect_rsp. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-63649] Privilege escalation via arbitrary configuration file loading
Privilege escalation via arbitrary configuration file loading. Red Hat rates this important (CVSS 8.8). Weakness: CWE-22.
High [CVE-2026-45699] Stack-based buffer overflow in copydir allows arbitrary code execution
Stack-based buffer overflow in copydir() allows arbitrary code execution. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-46603] Denial of Service via excessive memory allocation
VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. This is an Important severity flaw due to the potential for a remote attacker to trigger a denial of service. By providing a specially crafted VP8L image, an attacker can exploit a vulnerability in `golang.org/x/image/vp8l` that causes excessive memory allocation, leading to memory exhaustion in applications processing these images. This could impact the availability of services utilizing the affected component. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Cryostat 4; Red Hat Advanced Cluster Management for Kubernetes 2. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-46439] Remote Code Execution via Recursive Server-Side Template Injection
Remote Code Execution via Recursive Server-Side Template Injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-917. Affected product named by the advisory: File Integrity Operator.
High [CVE-2026-72813] Denial of Service via empty Range header in GET requests
Denial of Service via empty Range header in GET requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-617. Affected product named by the advisory: Red Hat OpenShift Update Service.
Medium [CVE-2026-74250] Autodetect deploy interface fails to run cleaning
Autodetect deploy interface fails to run cleaning. Red Hat rates this moderate. Weakness: CWE-367. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-74247] SSRF via build archive_url in Quay build API
SSRF via build archive_url in Quay build API. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-918. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.
Medium [CVE-2026-74245] Unauthenticated exported logs download in Quay
Unauthenticated exported logs download in Quay. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-306. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.
Medium [CVE-2026-74244] Stripe webhook accepts forged events without signature verification in Quay
Stripe webhook accepts forged events without signature verification in Quay. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-347. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.
Medium [CVE-2026-74243] Unauthenticated secscan notification endpoint in Quay when PSK is unset
Unauthenticated secscan notification endpoint in Quay when PSK is unset. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-306. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.
Medium [CVE-2026-74242] Repository notification UUID IDOR in Quay API
Repository notification UUID IDOR in Quay API. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-639. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.
Medium [CVE-2026-74241] LDAP referral filter injection in Quay external LDAP authentication
LDAP referral filter injection in Quay external LDAP authentication. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-90. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.
Medium [CVE-2026-74240] JWT claim validation bypasses in Quay federated robot and SSO authentication
JWT claim validation bypasses in Quay federated robot and SSO authentication. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-287. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.
Medium [CVE-2026-49263] Denial of Service and parser desynchronization via WebAssembly `br_table` instruction-size truncation
Denial of Service and parser desynchronization via WebAssembly `br_table` instruction-size truncation. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: capstone.
Medium [CVE-2026-49282] Denial of service via out-of-bounds read in M68K and RISCV backends
Denial of service via out-of-bounds read in M68K and RISCV backends. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: capstone.
Medium [CVE-2026-66807] dangerouslySetInnerHTML with unescaped subscription identifiers in SharedResourceWarning
dangerouslySetInnerHTML with unescaped subscription identifiers in SharedResourceWarning. Red Hat rates this low (CVSS 4.6). Weakness: CWE-79. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.
Medium [CVE-2026-46380] Server-Side Request Forgery via unvalidated URL in remote fetching subsystem
Server-Side Request Forgery via unvalidated URL in remote fetching subsystem. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-918. Affected product named by the advisory: File Integrity Operator.
Medium [CVE-2026-13002] Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing
A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients. Redhat confirms that the dnsmasq component is required for installations where DNNSEC service is in use. Red Hat severity: Low — CVSS 4.4 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7 as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: dnsmasq.
Medium [CVE-2026-19879] HTTP response header integrity issue due to character truncation
HTTP response header integrity issue due to character truncation. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-681. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 6 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7; and 2 more.