Skip to content
VulniPulse

Complete feed

Exploited / KEV

Known exploitation or KEV-listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.5Red Hat Exploited CISA KEV Updated

High [CVE-2026-64849] Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding). Red Hat rates this important (CVSS 8.5). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:60520 with package rhoai/odh-mlflow-rhel9:1787226790. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-64849
Unclassified
Aug 17, 2026