Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

2746 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.5Red Hat

Medium [CVE-2026-74540] fix UAF in l2cap_le_connect_rsp

fix UAF in l2cap_le_connect_rsp. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74540
Linux Kernel
Aug 15, 2026
High8.8Red Hat

High [CVE-2026-63649] Privilege escalation via arbitrary configuration file loading

Privilege escalation via arbitrary configuration file loading. Red Hat rates this important (CVSS 8.8). Weakness: CWE-22.

CVE-2026-63649
Unclassified
Aug 14, 2026
High7.5Red Hat

High [CVE-2026-45699] Stack-based buffer overflow in copydir allows arbitrary code execution

Stack-based buffer overflow in copydir() allows arbitrary code execution. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-45699
Unclassified
Aug 14, 2026
High7.5Red Hat Updated

High [CVE-2026-46603] Denial of Service via excessive memory allocation

VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. This is an Important severity flaw due to the potential for a remote attacker to trigger a denial of service. By providing a specially crafted VP8L image, an attacker can exploit a vulnerability in `golang.org/x/image/vp8l` that causes excessive memory allocation, leading to memory exhaustion in applications processing these images. This could impact the availability of services utilizing the affected component. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Cryostat 4; Red Hat Advanced Cluster Management for Kubernetes 2. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-46603
Unclassified
Aug 14, 2026
High7.8Red Hat Updated

High [CVE-2026-46439] Remote Code Execution via Recursive Server-Side Template Injection

Remote Code Execution via Recursive Server-Side Template Injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-917. Affected product named by the advisory: File Integrity Operator.

CVE-2026-46439
Unclassified
Aug 14, 2026
High7.5Red Hat Updated

High [CVE-2026-72813] Denial of Service via empty Range header in GET requests

Denial of Service via empty Range header in GET requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-617. Affected product named by the advisory: Red Hat OpenShift Update Service.

CVE-2026-72813
Unclassified
Aug 14, 2026
MediumRed Hat

Medium [CVE-2026-74250] Autodetect deploy interface fails to run cleaning

Autodetect deploy interface fails to run cleaning. Red Hat rates this moderate. Weakness: CWE-367. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-74250
Unclassified
Aug 14, 2026
Medium4.2Red Hat

Medium [CVE-2026-74247] SSRF via build archive_url in Quay build API

SSRF via build archive_url in Quay build API. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-918. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.

CVE-2026-74247
Unclassified
Aug 14, 2026
Medium5.9Red Hat

Medium [CVE-2026-74245] Unauthenticated exported logs download in Quay

Unauthenticated exported logs download in Quay. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-306. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.

CVE-2026-74245
Unclassified
Aug 14, 2026
Medium5.9Red Hat

Medium [CVE-2026-74244] Stripe webhook accepts forged events without signature verification in Quay

Stripe webhook accepts forged events without signature verification in Quay. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-347. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.

CVE-2026-74244
Unclassified
Aug 14, 2026
Medium6.5Red Hat

Medium [CVE-2026-74243] Unauthenticated secscan notification endpoint in Quay when PSK is unset

Unauthenticated secscan notification endpoint in Quay when PSK is unset. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-306. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.

CVE-2026-74243
Unclassified
Aug 14, 2026
Medium5.3Red Hat

Medium [CVE-2026-74242] Repository notification UUID IDOR in Quay API

Repository notification UUID IDOR in Quay API. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-639. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.

CVE-2026-74242
Unclassified
Aug 14, 2026
Medium4.8Red Hat

Medium [CVE-2026-74241] LDAP referral filter injection in Quay external LDAP authentication

LDAP referral filter injection in Quay external LDAP authentication. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-90. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.

CVE-2026-74241
Unclassified
Aug 14, 2026
Medium5.4Red Hat

Medium [CVE-2026-74240] JWT claim validation bypasses in Quay federated robot and SSO authentication

JWT claim validation bypasses in Quay federated robot and SSO authentication. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-287. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.

CVE-2026-74240
Unclassified
Aug 14, 2026
Medium6.8Red Hat Updated

Medium [CVE-2026-49263] Denial of Service and parser desynchronization via WebAssembly `br_table` instruction-size truncation

Denial of Service and parser desynchronization via WebAssembly `br_table` instruction-size truncation. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: capstone.

CVE-2026-49263
Red Hat Enterprise Linux
Aug 14, 2026
Medium6.2Red Hat Updated

Medium [CVE-2026-49282] Denial of service via out-of-bounds read in M68K and RISCV backends

Denial of service via out-of-bounds read in M68K and RISCV backends. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: capstone.

CVE-2026-49282
Red Hat Enterprise Linux
Aug 14, 2026
Medium4.6Vendor: LowRed Hat Updated

Medium [CVE-2026-66807] dangerouslySetInnerHTML with unescaped subscription identifiers in SharedResourceWarning

dangerouslySetInnerHTML with unescaped subscription identifiers in SharedResourceWarning. Red Hat rates this low (CVSS 4.6). Weakness: CWE-79. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66807
Unclassified
Aug 14, 2026
Medium6.7Red Hat Updated

Medium [CVE-2026-46380] Server-Side Request Forgery via unvalidated URL in remote fetching subsystem

Server-Side Request Forgery via unvalidated URL in remote fetching subsystem. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-918. Affected product named by the advisory: File Integrity Operator.

CVE-2026-46380
Unclassified
Aug 14, 2026
Medium4.4Vendor: LowRed Hat

Medium [CVE-2026-13002] Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing

A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients. Redhat confirms that the dnsmasq component is required for installations where DNNSEC service is in use. Red Hat severity: Low — CVSS 4.4 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7 as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: dnsmasq.

CVE-2026-13002
Red Hat Enterprise Linux
Aug 14, 2026
Medium5.3Red Hat

Medium [CVE-2026-19879] HTTP response header integrity issue due to character truncation

HTTP response header integrity issue due to character truncation. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-681. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 6 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7; and 2 more.

CVE-2026-19879
Red Hat Enterprise Linux
Aug 14, 2026