Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5820 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.5Red Hat

Medium [CVE-2026-59183] Integer Overflow Vulnerability Leading to Application Crash

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, an int32_t multiplication in OpenEXRCore's unpack_sample_table() can overflow while decoding a crafted deep tiled EXR file, producing an invalid pointer that leads to a read from an unmapped memory address and a crash. Because the overflow occurs in the standard decoding path (exr_decoding_run), any application that decodes deep tiled EXR files is affected. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14. A flaw was found in OpenEXR. This overflow can lead to an invalid memory pointer, causing applications that process these files to crash. This issue results in a denial of service. Red Hat has determined that versions of OpenEXR shipped in Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, and Red Hat In-Vehicle OS 2 are within the affected version range (3.1.0 through 3.4.13). This flaw has been rated Moderate and is not currently planned to be addressed in future updates. For additional information, refer to the Mitigation section or the linked CVE page. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected products named by the advisory: Red Hat package: openexr.

CVE-2026-59183
Red Hat Enterprise Linux
Aug 25, 2026
Medium6.2Red Hat

Medium [CVE-2026-55373] Denial of Service via infinite loop in sample count processing.

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12, and 3.4.13 contain an infinite-loop vulnerability in SampleCountChannel. The helper roundListSizeUp() rounds a sample-list size up to the next power of two using repeated unsigned left shifts, which terminates for normal values but fails for UINT_MAX: the sequence reaches 0x80000000, and the next left shift wraps the 32-bit value to 0. Because 0 remains less than UINT_MAX, the loop never progresses and never exits. The bug is reachable through public OpenEXRUtil APIs, either by editing the sample-count buffer through SampleCountChannel::Edit (whose destructor calls endEdit()) or by calling SampleCountChannel::set(x, y, UINT_MAX) on a valid pixel. This issue has been fixed in versions 3.2.10, 3.3.12, and 3.4.13. A flaw was found in OpenEXR. An attacker could trigger an infinite loop by providing a specially crafted sample count value (UINT_MAX) when processing image data. This vulnerability, located in the `SampleCountChannel` component, prevents the application from progressing, leading to a denial of service. Red Hat Enterprise Linux 6 and 7 ship OpenEXR 1.x, which does not include this component and is not affected.

CVE-2026-55373
Red Hat Enterprise Linux
Aug 25, 2026
Medium5.5Red Hat

Medium [CVE-2026-55371] Denial of Service via NULL pointer dereference in exr_attr_set_bytes

OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry. Versions 3.4.0 through 3.4.12 contain a NULL pointer dereference in the OpenEXRCore function exr_attr_set_bytes(). The public setter validates the top-level exr_attr_bytes_t value pointer but does not verify that the nested type_hint pointer is non-NULL when hint_length is greater than zero. When a caller supplies a positive hint_length together with a NULL type_hint, exr_attr_bytes_create() allocates a destination type-hint buffer and then copies from the NULL source pointer, causing a deterministic crash. The flaw is reachable through the public OpenEXRCore C API and results in a denial of service. The issue is fixed in version 3.4.13. A flaw was found in OpenEXR. This can lead to a deterministic crash, resulting in a denial of service (DoS), which makes the affected system or application unavailable. This vulnerability only affects OpenEXR versions 3.4.0 through 3.4.12. No Red Hat products or Fedora community distributions ship a version within this range. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-476.

CVE-2026-55371
Unclassified
Aug 25, 2026
Medium5.5Red Hat

Medium [CVE-2026-55059] Heap out-of-bounds write leads to denial of service

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12 and 3.4.13 contain a heap out-of-bounds write in Imf_4_0::SampleCountChannel::set(int r, unsigned int newNumSamples[]). The row-based sample-count setter computes the target Y coordinate with dataWindow.min.x instead of dataWindow.min.y. For a valid deep image data window where min.x!= min.y, a valid row index can be translated into an invalid Y coordinate, causing writes before the allocated _numSamples buffer. The vulnerability is reachable through the public OpenEXRUtil DeepImage API and can lead to heap corruption and process crashes. This issue has been fixed in versions 3.2.10, 3.3.12 and 3.4.13. A user processing a specially crafted image file could trigger a heap out-of-bounds write vulnerability in the `SampleCountChannel::set` function. This occurs due to an incorrect computation of the target Y coordinate, leading to writes before an allocated buffer. Successful exploitation can result in heap corruption and process crashes, potentially causing a denial of service. This flaw affects the SampleCountChannel component of OpenEXR, which was introduced in version 2.0. Red Hat Enterprise Linux 6 and 7 ship OpenEXR 1.x, which does not include this component and is not affected.

CVE-2026-55059
Red Hat Enterprise Linux
Aug 25, 2026
Medium6.5Red Hat

Medium [CVE-2026-54920] Denial of Service via crafted HTJ2K-compressed EXR file

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a reachable assertion failure in the HTJ2K decode path allows a crafted HTJ2K-compressed EXR file to cause an unconditional process abort in any application that calls exr_start_read() on untrusted input, resulting in denial of service. The crash is triggered by a QCD marker whose lower five bits are zero, which OpenEXR passes into the vendored OpenJPH library while constructing the codestream and evaluating its quantization delta parameters. OpenJPH uses an assertion rather than a recoverable error to validate those bits, so any invalid value calls abort() directly and cannot be intercepted by surrounding error handling, a problem compounded by OpenEXR wrapping only its internal HT header parser in error handling while leaving the later codestream read and construction calls unprotected. This issue has been resolved in version 3.4.13. A flaw was found in OpenEXR. This file, containing a QCD marker with specific invalid bits, causes an unconditional process abort in applications that read untrusted input, leading to a Denial of Service (DoS). This vulnerability only affects OpenEXR versions 3.4.0 through 3.4.12, which include HTJ2K compression support.

CVE-2026-54920
Unclassified
Aug 25, 2026
Medium5.9Vendor: LowRed Hat

Medium [CVE-2026-63073] untrusted sender DN used as format string in CMP response validation

Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a pinned server certificate whose subject becomes the default expected sender. Percent characters survive the conversion, so a sender DN such as "CN=%s%n" reaches BIO_vsnprintf() as an attacker-controlled format string with no matching variadic arguments. This path is only reached when the caller configures an expected sender or pins a server certificate, which is the normal configuration for a CMP client validating server responses. Since the attacker controls the format string but none of the variadic arguments, such specifiers as %s and %n dereference or write through unrelated stack contents and crash the client. The reliable consequence is a denial of service, when the response comes from a malicious or intercepted CMP endpoint. There is no controlled memory write, arbitrary-address read, or reliable path to remote code execution. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. A flaw was found in OpenSSL. This can lead to a crash in the CMP client, resulting in a denial of service.

CVE-2026-63073
Red Hat Enterprise Linux
Aug 25, 2026
Medium6.5Red Hat

Medium [CVE-2026-53532] Denial of Service via crafted HTJ2K-compressed EXR file

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file causes an unconditional process abort in any application that calls exr_start_read() on untrusted input, resulting in denial of service. The crash is triggered by a QCD marker whose lower five bits are zero, which OpenEXR passes into the vendored OpenJPH library while constructing the codestream and evaluating its quantization delta parameters. OpenJPH uses an assertion rather than a recoverable error to validate those bits, so any invalid value calls abort() directly and cannot be intercepted by surrounding error handling, a problem compounded by OpenEXR wrapping only its internal HT header parser in error handling while leaving the later codestream read and construction calls unprotected. This issue has been resolved in version 3.4.13. A flaw was found in OpenEXR. This denial of service occurs because OpenEXR passes a malformed QCD marker to the vendored OpenJPH library, triggering an assertion that cannot be gracefully handled. This vulnerability can lead to the unavailability of services using OpenEXR to process image files. This vulnerability only affects OpenEXR versions 3.4.0 through 3.4.12, which include HTJ2K compression support.

CVE-2026-53532
Unclassified
Aug 24, 2026
Medium6.5Red Hat

Medium [CVE-2026-68516] Denial of service via crafted HTJ2K-compressed EXR with invalid image-offset

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal decode. An HTJ2K-compressed EXR whose JPEG 2000 SIZ fields place the first tile outside the visible image can reach invalid tile and codeblock geometry in the vendored OpenJPH AVX2 decoder, causing a stack out-of-bounds write and denial of service. OpenEXR's HTJ2K path validates the decoded codestream dimensions against the EXR chunk size, but it does not reject SIZ image-offset/tile-grid geometry where the first tile does not intersect the image. This issue is fixed in version 3.4.14. A flaw was found in OpenEXR. A remote attacker could provide a specially crafted HTJ2K-compressed EXR image file. This vulnerability only affects OpenEXR versions 3.4.0 through 3.4.13, which include HTJ2K compression support. No Red Hat products or Fedora community distributions ship a version within this range. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-787. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2026-68516
Unclassified
Aug 24, 2026
Medium6.0Red Hat

Medium [CVE-2026-17113] unvalidated image env var causes daemon crash

A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). When a `CreateContainer` request supplies a `nil` CRI `Envs` field, CRI-O falls back to using the target OCI image's `config. Env` entries unfiltered, in contrast to the normal merge path, which validates each entry for a `key=value` form before use. Env` contains an entry with no `=` character (e.g. a bare `NOEQUALS` string) causes CRI-O to split that entry into a single-element slice and then index its second element, which is out of range. This triggers an unrecovered Go runtime panic in the `crio` daemon process, crashing it and terminating the container-runtime service for all workloads on the node until it is restarted. Under a specific internal condition, CRI-O skips validating whether a container image's environment variable entries are properly formatted before using them. If an image contains a malformed environment variable, CRI-O crashes while processing it. Red Hat severity: Moderate — CVSS 6 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H). Weakness: CWE-1287. Affected Red Hat products: Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-17113
Unclassified
Aug 24, 2026
Medium6.2Red Hat

Medium [CVE-2026-45404] go.opentelemetry.io/otel/bridge/opentracing: OpenTelemetry-Go: Denial of Service via unsynchronized baggage map

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not safe for concurrent read/write access, concurrent SetBaggageItem and correlation. MapFromContext calls on the same hooked bridgeSpan can trigger a fatal runtime error—such as concurrent map read and map write or concurrent map iteration and map write—terminating the process and causing denial of service. This issue is fixed in version 1.45.0. A flaw was found in OpenTelemetry-Go. Red Hat severity: Moderate — CVSS 6.2 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-820. Affected Red Hat products: Multicluster Global Hub; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-45404
Unclassified
Aug 24, 2026
Medium6.5Red Hat

Medium [CVE-2026-75509] Issuer-validation bypass via array-valued claims

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims, allowing an array-valued iss that contains the expected issuer to pass an intended equality check and enabling issuer-validation bypass. This issue is fixed in version 1.7.3. A remote attacker could exploit a vulnerability in the JWTClaimsRegistry by crafting a JSON Web Token (JWT) with an array-valued issuer (iss) claim. This flaw allows the attacker to bypass the intended issuer validation, potentially leading to impersonation or unauthorized access. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N). Weakness: CWE-480. Affected Red Hat products: Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux command line assistant; Red Hat OpenShift Virtualization 4; Red Hat Satellite 6. Red Hat lists Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-75509
Unclassified
Aug 24, 2026
Medium5.3Red Hat

Medium [CVE-2026-77310] com.fasterxml.jackson.core/jackson-databind: jackson-databind: Server-Side Request Forgery and internal host enumeration via eager DNS resolution

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines, the java.net. InetAddress branch of FromStringDeserializer. Std._deserialize() calls InetAddress.getByName() on attacker-controlled input, causing eager DNS resolution during deserialization and enabling DNS-based server-side request forgery and internal-host enumeration. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1. A remote attacker can exploit this vulnerability by providing specially crafted input during data deserialization, specifically when `java.net. InetAddress` objects are processed. This allows for out-of-band data exfiltration or the enumeration of internal network hosts. Moderate impact. Red Hat products utilizing `jackson-databind` are susceptible to server-side request forgery (SSRF) and internal host enumeration. This occurs when attacker-controlled input, containing hostnames or IP addresses, is deserialized, leading to eager DNS resolution and potential information disclosure or internal network probing. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-918.

CVE-2026-77310
Red Hat Enterprise Linux
Aug 24, 2026
Medium6.1Red Hat

Medium [CVE-2026-78475] Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file. To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted PIX image with GIMP, reducing the likelihood of exploitation. Due to this reason, this flaw has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-78475
Red Hat Enterprise Linux
Aug 24, 2026
Medium6.5Red Hat

Medium [CVE-2026-76845] Arbitrary File Overwrite via Symlink Following

adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. When a path component at the destination already exists as a symbolic link pointing outside the extraction root, extractAllTo, extractAllToAsync and extractEntryTo write the entry contents through that link and then chmod its target, placing attacker-controlled content in a file outside the root without any traversal sequence appearing in the archive. Reaching the write requires overwrite to be enabled, because the preceding fs.existsSync check also resolves the link and otherwise declines. An attacker able to create a symbolic link inside a shared, reused or predictable extraction directory, such as a temporary directory or a continuous integration workspace, can overwrite any file the extracting process is permitted to write. A flaw was found in `adm-zip`, a Node.js library used for handling zip archives. This vulnerability allows a local attacker to overwrite arbitrary files on the system. An attacker can exploit this by placing a symbolic link within a temporary extraction directory, redirecting the extraction process to write data outside the intended secure location. This could lead to unauthorized modification of system files. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N). Weakness: CWE-59.

CVE-2026-76845
Red Hat Enterprise Linux
Aug 24, 2026
Medium6.5Red Hat

Medium [CVE-2026-78323] JSSTrustManager does not verify NSS trust flags on CA certificates

A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections. This flaw exists in the JSSTrustManager class but is mitigated in default product configurations by the native revocation verification check. Exploitation requires non-default configuration changes (disabling certificate revocation verification) that are not documented or recommended. The server-side TLS validation path (TomcatJSS) uses a different trust manager (JSSNativeTrustManager) that properly delegates to NSS native verification and is not affected. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N). Weakness: CWE-295. Affected Red Hat products: Red Hat Certificate System 10; Red Hat Certificate System 11; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9. Red Hat lists Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8 as not affected. Will not fix / out of support: Red Hat Enterprise Linux 6.

CVE-2026-78323
Red Hat Enterprise Linux
Aug 24, 2026
Medium5.4Red Hat

Medium [CVE-2026-10618] Stored Cross-Site Scripting via unescaped code-fence attribute values

Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every attribute value from a byte slice to a string as it is stored, deliberately dropping the escaping that used to happen there, and RenderAttributes in the same file escapes only values that are still byte slices, so its escaping branch is never reached and every value is written verbatim. The function's documentation states that it performs HTML escaping of string attributes, which it does not. A quote inside an attribute value in the info string therefore terminates the attribute and allows a further attribute, including an event handler, to be placed on the wrapper element, and the script runs for every visitor who loads the page. This path is reached under the default configuration, with code fences enabled and without goldmark's unsafe setting or any custom render hook. Attribute names beginning with on are filtered when the attributes are parsed, so injection is achieved through the value rather than the name. This vulnerability allows a remote attacker to inject arbitrary script code into the rendered HTML by providing specially crafted input in the code-fence info string.

CVE-2026-10618
Red Hat Enterprise Linux
Aug 24, 2026
MediumRed Hat

Medium [CVE-2026-59295] Micrometer Instrumentation for Apache HttpAsyncClient: Denial of Service via asynchronous request failures

Micrometer-instrumented Apache HttpAsyncClient (4.x or 5.x) usage via MicrometerHttpClientInterceptor can leak memory unboundedly when asynchronous requests fail before receiving a response (e.g. connection resets or timeouts). Tracking state for these requests remains in memory indefinitely, and sustained failures lead to heap exhaustion and OutOfMemoryError crashes. A flaw was found in Micrometer Instrumentation for Apache HttpAsyncClient. This continuous memory leak leads to heap exhaustion and OutOfMemoryError crashes, resulting in a Denial of Service (DoS) for the affected application. This Moderate severity flaw impacts Red Hat products utilizing Micrometer-instrumented Apache HttpAsyncClient. The vulnerability can lead to a denial of service due to unbounded memory growth when asynchronous requests fail before a response is received. Exploitation requires specific network conditions or failures, making the attack complexity high. Weakness: CWE-772. Affected Red Hat products: Red Hat AMQ Broker 7; Red Hat build of Quarkus.

CVE-2026-59295
Unclassified
Aug 24, 2026
Medium6.2Red Hat

Medium [CVE-2026-70626] Information disclosure via symlink escape in CorpusReader.open

NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability exists because path validation is lexical and does not account for symlink resolution, enabling attackers to place symlinks inside the corpus root to access files outside the intended boundary. A flaw was found in NLTK. By placing symbolic links (symlinks) within the corpus root, an attacker can bypass path validation in the `CorpusReader.open()` function, which does not properly account for symlink resolution. This could lead to unauthorized information disclosure. The vulnerability arises from improper path validation in CorpusReader.open() when handling symlinks, enabling an attacker with local access to bypass security restrictions and access sensitive data. This affects components within Red Hat Ansible Automation Platform and Red Hat OpenShift AI that utilize the vulnerable NLTK library. Red Hat severity: Moderate — CVSS 6.2 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-22. Red Hat lists Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat OpenShift AI (RHOAI) as not affected.

CVE-2026-70626
Unclassified
Aug 22, 2026
Medium6.5Red Hat

Medium [CVE-2026-65915] Arbitrary file read due to logic bug in FileSystemPathPointer

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to nltk.data.load() to read arbitrary files accessible to the process user, including credentials and configuration files. A flaw was found in NLTK. A remote attacker can exploit this by providing specially crafted `file://` Uniform Resource Locators (URLs) to `nltk.data.load()`. This enables the attacker to read arbitrary files on the system, potentially leading to the disclosure of sensitive information such as credentials and configuration files. This could lead to information disclosure, including sensitive credentials or configuration data, within affected Red Hat products such as Lightspeed Core, OpenShift Lightspeed, Red Hat Ansible Automation Platform, and Red Hat OpenShift AI. Exploitation requires the application to process untrusted input that can be interpreted as a `file://` URL by NLTK. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-22. Red Hat lists OpenShift Lightspeed as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Exploit Intelligence; Red Hat Ansible Automation Platform 2; Red Hat OpenShift AI (RHOAI).

CVE-2026-65915
Unclassified
Aug 22, 2026
Medium4.2Red Hat

Medium [CVE-2026-63311] Server-Side Request Forgery bypass via DNS resolution failures

NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in nltk/pathsec.py. The _resolve_hostname() helper catches OSError and ValueError during socket.getaddrinfo() and returns an empty list; when DNS resolution fails, the validation loop executes no IP checks and the function fails open, allowing urlopen() to proceed without validation. An attacker who can trigger DNS resolution failures or use DNS rebinding can bypass SSRF protections and reach restricted network resources, including cloud metadata endpoints (e.g., 169.254.169.254). A flaw was found in NLTK. This server-side request forgery (SSRF) vulnerability allows an attacker to bypass network access restrictions. By triggering DNS resolution failures or using DNS rebinding, an attacker can cause the `validate_network_url()` function to incorrectly validate URLs. This flaw in NLTK allows a server-side request forgery (SSRF) bypass when DNS resolution fails or through DNS rebinding. This could enable an attacker to access restricted internal network resources, including cloud metadata endpoints, within Red Hat environments utilizing affected NLTK versions. Red Hat severity: Moderate — CVSS 4.2 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-918.

CVE-2026-63311
Unclassified
Aug 22, 2026

← All vendors