Skip to content
VulniPulse
Highest advisory severityHigh 2 vendors · 2 advisories

CVE-2026-42790

CVE-2026-42790: 2 tracked advisory records across NetApp, Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

NetApp

1 advisory
  • Advisory severityHigh7.6

    High [CVE-2026-42790] Erlang/OTP Vulnerability in NetApp Products

    NTAP-20260605-0010Source published Source updated

    Multiple NetApp products incorporate Erlang/OTP. Erlang/OTP versions 19.3 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. Affected products: ONTAP Select Deploy administration utility, SnapCenter. NetApp states there is no workaround available at this time.

    Affected products in this advisory
    • ONTAP Select Deploy administration utility
    • SnapCenter
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • SnapCenter: 6.2.2
    Mitigation guidance
    • Update affected NetApp products to a fixed release: SnapCenter: 6.2.2.

Red Hat

1 advisory
  • Advisory severityHigh7.4

    High [CVE-2026-42790] Erlang OTP public_key: Certificate validation bypass allows hostname spoofing

    CVE-2026-42790Source published

    Erlang OTP public_key: Certificate validation bypass allows hostname spoofing. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.

    Affected products in this advisory
    • Red Hat OpenStack Platform 16.2
    • Red Hat OpenStack Platform 17.1
    • Red Hat OpenStack Platform 18.0
    • Red Hat OpenStack Services on OpenShift 18.0

    1 more entries in the full advisory.

    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    • Red Hat rates this important; a fix erratum may not be out yet — apply the RHSA as soon as it publishes.

Android app · Google Play

Turn CVE research into alerts on your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery