Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

2746 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.5Red Hat Updated

Medium [CVE-2026-19880] Path traversal allows arbitrary log file creation

Path traversal allows arbitrary log file creation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22. Affected products named by the advisory: Migration Toolkit for Applications 8; OpenShift Serverless; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; and 16 more. Affected products named by the advisory: Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; and 12 more.

CVE-2026-19880
Red Hat Enterprise Linux
Aug 14, 2026
Medium5.3Red Hat Updated

Medium [CVE-2026-73051] HTTP Request Smuggling via malformed HTTP/1.1 headers

HTTP Request Smuggling via malformed HTTP/1.1 headers. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-444. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Update Service; Red Hat package: keylime-agent-rust; and 1 more. Affected products named by the advisory: Red Hat package: trustee.

CVE-2026-73051
Red Hat Enterprise Linux
Aug 14, 2026
Medium6.5Red Hat

Medium [CVE-2026-72816] IP Spoofing via RealIP Middleware allows bypassing access controls

IP Spoofing via RealIP Middleware allows bypassing access controls. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-346. Red Hat lists fixing advisory RHSA-2026:49718 with package cosign-main-3.1.3-0.1.hum1, spire1-14-main-1.14.7-0.4.hum1, spire1-15-main-1.15.2-0.4.hum1. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Gatekeeper 3; Logging Subsystem for Red Hat OpenShift; and 18 more. Affected products named by the advisory: Migration Toolkit for Applications 8; Multicluster Engine for Kubernetes; OpenShift Pipelines; OpenShift Serverless; and 14 more.

CVE-2026-72816
Red Hat Enterprise Linux
Aug 14, 2026
Medium6.5Red Hat

Medium [CVE-2026-72817] IP spoofing via X-Forwarded-For header manipulation

IP spoofing via X-Forwarded-For header manipulation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-501. Red Hat lists fixing advisory RHSA-2026:49718 with package cosign-main-3.1.3-0.1.hum1, spire1-14-main-1.14.7-0.4.hum1, spire1-15-main-1.15.2-0.4.hum1. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Gatekeeper 3; Logging Subsystem for Red Hat OpenShift; and 19 more. Affected products named by the advisory: Migration Toolkit for Applications 8; Multicluster Engine for Kubernetes; OpenShift Pipelines; OpenShift Serverless; and 15 more.

CVE-2026-72817
Red Hat Enterprise Linux
Aug 14, 2026
Medium6.5Red Hat

Medium [CVE-2026-72815] go-chi chi: IP spoofing via X-Forwarded-For header allows bypass of access controls

go-chi chi: IP spoofing via X-Forwarded-For header allows bypass of access controls. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-940. Red Hat lists fixing advisory RHSA-2026:49718 with package prometheus3-13-main-3.13.2-0.2.hum1, cosign-main-3.1.3-0.1.hum1, spire1-14-main-1.14.7-0.4.hum1, spire1-15-main-1.15.2-0.4.hum1. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Gatekeeper 3; Migration Toolkit for Applications 8; and 12 more. Affected products named by the advisory: OpenShift Pipelines; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Advanced Cluster Security 4; Red Hat Edge Manager 1; and 8 more.

CVE-2026-72815
Unclassified
Aug 14, 2026
Medium5.3Red Hat Updated

Medium [CVE-2026-72814] Information Disclosure via relative path traversal

Information Disclosure via relative path traversal. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-22. Affected product named by the advisory: Red Hat OpenShift Update Service.

CVE-2026-72814
Unclassified
Aug 14, 2026
Medium5.4Red Hat Updated

Medium [CVE-2025-71405] Open Redirect vulnerability via RedirectSlashes middleware

Open Redirect vulnerability via RedirectSlashes middleware. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-601.

CVE-2025-71405
Unclassified
Aug 14, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-19617] Denial of Service via uncontrolled recursion in config parser

Denial of Service via uncontrolled recursion in config parser. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.

CVE-2026-19617
Unclassified
Aug 14, 2026
Low3.1Red Hat

Low [CVE-2026-63650] User misidentification via ignored X.509 identity field

User misidentification via ignored X.509 identity field. Red Hat rates this low (CVSS 3.1). Weakness: CWE-303.

CVE-2026-63650
Unclassified
Aug 14, 2026
Critical9.4Red Hat Updated

Critical [CVE-2026-73653] Browser Mode provider commands bypass the file-access permission gate

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or confining paths to the project root. A client that can reach the Browser Mode API can read arbitrary local files, create or overwrite image and trace files, or delete files accessible to the Vitest process even when allowWrite is false. A flaw was found in Vitest. A remote attacker, by sending specially crafted commands to the Browser Mode API, could bypass file access restrictions. This allows the attacker to read, create, overwrite, or delete arbitrary files on the system where Vitest is running, even when file write permissions are explicitly disabled. Red Hat severity: Critical — CVSS 9.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L). Weakness: CWE-22. Affected Red Hat products: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop. Red Hat lists Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; Red Hat Build of Keycloak; Red Hat Hardened Images; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Trusted Artifact Signer as not affected.

CVE-2026-73653
Unclassified
Aug 13, 2026
High8.3Red Hat

High [CVE-2026-73417] Cross-site scripting (XSS) allows arbitrary code execution

Cross-site scripting (XSS) allows arbitrary code execution. Red Hat rates this important (CVSS 8.3). Weakness: CWE-79. Affected products named by the advisory: Migration Toolkit for Applications 8; Red Hat OpenShift AI (RHOAI).

CVE-2026-73417
Unclassified
Aug 13, 2026
High7.5Red Hat Updated

High [CVE-2026-56860] golang net/url: Denial of Service from quadratic complexity in path resolution

golang net/url: Denial of Service from quadratic complexity in path resolution. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:59566 with package golang-github-openprinting-ipp-usb-0:0.9.27-7.el10_2.3, rhdh/rhdh-rhel9-operator:1788278786, golang1-25-main-1.25.13-0.1.hum1, osbuild-composer-0:101.3-4.el9_4.6. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-56860
Unclassified
Aug 13, 2026
High7.5Red Hat Updated

High [CVE-2026-56853] Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service

Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:59566 with package golang-github-openprinting-ipp-usb-0:0.9.27-7.el10_2.3, golang1-25-main-1.25.13-0.1.hum1, osbuild-composer-0:101.3-4.el9_4.6, grafana-0:9.2.10-33.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-56853
Unclassified
Aug 13, 2026
High8.1Red Hat Updated

High [CVE-2026-56858] Go html/template: Cross-Site Scripting via pathological input

Go html/template: Cross-Site Scripting via pathological input. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:59566 with package rhdh/rhdh-rhel9-operator:1788278786, golang1-25-main-1.25.13-0.1.hum1, osbuild-composer-0:101.3-4.el9_4.6, grafana-0:9.2.10-33.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-56858
Unclassified
Aug 13, 2026
High7.5Red Hat Updated

High [CVE-2026-56862] Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages

Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Red Hat lists fixing advisory RHSA-2026:59566 with package golang-github-openprinting-ipp-usb-0:0.9.27-7.el10_2.3, rhdh/rhdh-rhel9-operator:1788278786, golang1-25-main-1.25.13-0.1.hum1, osbuild-composer-0:101.3-4.el9_4.6. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-56862
Unclassified
Aug 13, 2026
High8.8Red Hat

High [CVE-2026-56865] Supply chain compromise via transparency log tile verification bypass

Supply chain compromise via transparency log tile verification bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-347.

CVE-2026-56865
Unclassified
Aug 13, 2026
High7.5Red Hat Updated

High [CVE-2026-33818] Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal

Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Red Hat lists fixing advisory RHSA-2026:59566 with package golang-github-openprinting-ipp-usb-0:0.9.27-7.el10_2.3, rhdh/rhdh-rhel9-operator:1788278786, golang1-25-main-1.25.13-0.1.hum1, osbuild-composer-0:101.3-4.el9_4.6. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-33818
Unclassified
Aug 13, 2026
High7.5Red Hat Updated

High [CVE-2026-56859] Denial of Service via XML decoding recursion depth issue

Denial of Service via XML decoding recursion depth issue. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Red Hat lists fixing advisory RHSA-2026:59566 with package golang-github-openprinting-ipp-usb-0:0.9.27-7.el10_2.3, rhdh/rhdh-rhel9-operator:1788278786, golang1-25-main-1.25.13-0.1.hum1, osbuild-composer-0:101.3-4.el9_4.6. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-56859
Unclassified
Aug 13, 2026
High7.2Red Hat

High [CVE-2026-73662] FreePBX Music on Hold: Arbitrary command execution by authenticated administrator

FreePBX Music on Hold: Arbitrary command execution by authenticated administrator. Red Hat rates this important (CVSS 7.2). Weakness: CWE-78.

CVE-2026-73662
Unclassified
Aug 13, 2026
High7.4Red Hat

High [CVE-2026-45774] Arbitrary file read via path traversal in profile import

Arbitrary file read via path traversal in profile import. Red Hat rates this important (CVSS 7.4). Weakness: CWE-22. Affected product named by the advisory: File Integrity Operator.

CVE-2026-45774
Unclassified
Aug 13, 2026