VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
2035 advisories across 32 monitored vendors.
Linux kernel: Use-after-free in teql queueing discipline can lead to privilege escalation. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:3634 — update the affected packages (`sudo dnf update`).
Linux kernel: Denial of Service via unsafe requeue in rxrpc_recvmsg. Red Hat rates this moderate (CVSS 7.4). Weakness: CWE-416. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:9112 — update the affected packages (`sudo dnf update`).
fix typo in frequency notification. Red Hat rates this moderate (CVSS 7.6). Weakness: CWE-476. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:18134 — update the affected packages (`sudo dnf update`).
Linux kernel: Denial of Service due to a deadlock in hugetlb folio migration. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-833. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:13936 — update the affected packages (`sudo dnf update`).
Validation bypass due to malformed Content-Type header leading to integrity impact. Red Hat rates this important (CVSS 7.5). Weakness: CWE-179. Affected package(s): rhoai/odh-dashboard-rhel8:1774282136, rhoai/odh-mod-arch-model-registry-rhel9:1776742141, rhoai/odh-dashboard-rhel9:1776742021, devspaces/dashboard-rhel9:1774476526. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`).
Denial of Service via crafted request with duplicate headers. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-167. Affected package(s): foreman, rubygem-katello, rubygem-fog-kubevirt, discovery/discovery-server-rhel9:1770913597, satellite/iop-advisor-backend-rhel9:1773451075, python-pulp-container. Resolved in Red Hat advisory RHSA-2026:3958 — update the affected packages (`sudo dnf update`).
SQL injection via crafted column aliases in QuerySet.order_by(). Red Hat rates this important (CVSS 8.5). Weakness: CWE-89. Affected package(s): foreman, rubygem-katello, rubygem-fog-kubevirt, discovery/discovery-server-rhel9:1770913597, satellite/iop-advisor-backend-rhel9:1773451075, ansible-automation-platform. Resolved in Red Hat advisory RHSA-2026:3958 — update the affected packages (`sudo dnf update`).
SQL Injection via crafted column aliases. Red Hat rates this important (CVSS 8.3). Weakness: CWE-89. Affected package(s): foreman, rubygem-katello, rubygem-fog-kubevirt, discovery/discovery-server-rhel9:1770913597, satellite/iop-advisor-backend-rhel9:1773451075, ansible-automation-platform. Resolved in Red Hat advisory RHSA-2026:3958 — update the affected packages (`sudo dnf update`).
Denial of Service via crafted HTML inputs. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-770. Affected package(s): foreman, rubygem-katello, rubygem-fog-kubevirt, discovery/discovery-server-rhel9:1770913597, satellite/iop-advisor-backend-rhel9:1773451075, python-pulp-container. Resolved in Red Hat advisory RHSA-2026:3958 — update the affected packages (`sudo dnf update`).
SQL Injection via RasterField band index parameter. Red Hat rates this important (CVSS 8.3). Weakness: CWE-89. Affected package(s): foreman, rubygem-katello, rubygem-fog-kubevirt, discovery/discovery-server-rhel9:1770913597, satellite/iop-advisor-backend-rhel9:1773451075, ansible-automation-platform. Resolved in Red Hat advisory RHSA-2026:3958 — update the affected packages (`sudo dnf update`).
Cross-site Scripting vulnerability via improper input neutralization. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Cross-User Data Leakage via race condition in addJS method. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-820. Affected package(s): advanced-cluster-security/rhacs-main-rhel8:1773235860, advanced-cluster-security/rhacs-main-rhel8:1773235880. Resolved in Red Hat advisory RHSA-2026:4466 — update the affected packages (`sudo dnf update`).
Arbitrary code execution via unsanitized input in Acroform module. Red Hat rates this important (CVSS 8.3). Weakness: CWE-917. Affected package(s): advanced-cluster-security/rhacs-main-rhel8:1773235860, advanced-cluster-security/rhacs-main-rhel8:1773235880. Resolved in Red Hat advisory RHSA-2026:4466 — update the affected packages (`sudo dnf update`).
Stack-Based Buffer Overflow in libsoup Multipart Response Parsingmultipart HTTP response. Red Hat rates this important (CVSS 8.6). Weakness: CWE-121. Affected package(s): libsoup3, libsoup, spice-client-win, devspaces/pluginregistry-rhel9:1770918006, devspaces/openvsx-rhel9:1770851052, devspaces/udi-rhel9:1770913862. Resolved in Red Hat advisory RHSA-2026:2513 — update the affected packages (`sudo dnf update`).
@backstage/plugin-techdocs-node: @backstage/plugin-techdocs-node vulnerable to arbitrary code execution via MkDocs hooks. Red Hat rates this important (CVSS 7.7). Weakness: CWE-94. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:6174 — update the affected packages (`sudo dnf update`).
Code injection in Active Storage when used in conjunction with the image_processing gem. Red Hat rates this important (CVSS 8.1). Weakness: CWE-88. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
OutOfMemoryError in HttpServletRequestImpl.getParameterNames() can cause remote DoS attacks. Red Hat rates this important (CVSS 7.5). Weakness: CWE-20. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Excessive CPU consumption when building archive index in archive/zip. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-770. Affected package(s): openshift4/ose-csi-livenessprobe-rhel8:1776999947, openshift4/ose-csi-external-snapshotter-rhel8:1776999951, openshift4/ose-multus-route-override-cni-rhel8:1777001628, openshift4/ose-tests:1777002345, openshift4/ose-hypershift-rhel8:1777001784, openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator:1774582496. Resolved in Red Hat advisory RHSA-2026:3469 — update the affected packages (`sudo dnf update`).
Memory exhaustion in query parameter parsing in net/url. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): openshift4/ose-csi-livenessprobe-rhel8:1776999947, openshift4/ose-csi-external-snapshotter-rhel8:1776999951, openshift4/ose-multus-route-override-cni-rhel8:1777001628, openshift4/ose-tests:1777002345, skopeo, openshift4/ose-hypershift-rhel8:1777001784. Resolved in Red Hat advisory RHSA-2026:11749 — update the affected packages (`sudo dnf update`).
Arbitrary file write via malicious pkg-config directive. Red Hat rates this important (CVSS 8.6). Weakness: CWE-88. Affected package(s): openshift4/ose-csi-livenessprobe-rhel8:1776999947, openshift4/ose-csi-external-snapshotter-rhel8:1776999951, openshift4/ose-prometheus-node-exporter-rhel9:1774294099, openshift4/oc-mirror-plugin-rhel9:1776961082, openshift4/ose-azure-file-csi-driver-operator-rhel9:1773363768, openshift4/ose-multus-route-override-cni-rhel8:1777001628. Resolved in Red Hat advisory RHSA-2026:5948 — update the affected packages (`sudo dnf update`).