Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5822 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium4.7Red Hat

Medium [CVE-2026-76883] Denial of Service via heap-based buffer overflow in Catapult DCT2000 file parser

Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service A flaw was found in Wireshark. A heap-based buffer overflow vulnerability exists within the Catapult DCT2000 file parser. This vulnerability could allow a local attacker to trigger a crash, leading to a denial of service, by enticing a user to open a specially crafted file. Red Hat Enterprise Linux 6, 7, 8, and 9 ship Wireshark versions prior to the affected range and are not vulnerable. Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-120. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.

CVE-2026-76883
Red Hat Enterprise Linux
Aug 19, 2026
Medium4.7Red Hat

Medium [CVE-2026-76882] Denial of Service via Bluetooth Attribute Protocol dissector out-of-bounds read

Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service A flaw was found in Wireshark. The Bluetooth Attribute Protocol dissector contains an out-of-bounds read vulnerability. A remote attacker could exploit this by crafting a malicious Bluetooth packet, leading to a crash of the Wireshark application. This crash results in a denial of service (DoS), preventing the user from analyzing network traffic. Red Hat Enterprise Linux 6, 7, 8, and 9 ship Wireshark versions prior to the affected range and are not vulnerable. Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-125. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.

CVE-2026-76882
Red Hat Enterprise Linux
Aug 19, 2026
Medium4.7Red Hat

Medium [CVE-2026-76881] Denial of service via CMS protocol dissector crash

CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service A flaw was found in Wireshark. A NULL pointer dereference vulnerability exists within the CMS (Cryptographic Message Syntax) protocol dissector. This issue can be triggered by processing a specially crafted network capture file, leading to an application crash. A remote attacker could exploit this to cause a denial of service (DoS). Red Hat Enterprise Linux 6, 7, 8, and 9 ship Wireshark versions prior to the affected range and are not vulnerable. Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-476. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.

CVE-2026-76881
Red Hat Enterprise Linux
Aug 19, 2026
Medium6.8Red Hat

Medium [CVE-2026-76827] UPDATE/DELETE operations not scoped to caller's cluster (cross-tenant data tampering)

A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. An attacker could exploit this by crafting specific user identifiers (UIDs) with a different cluster's prefix. This is a Moderate flaw in Red Hat Advanced Cluster Management for Kubernetes. Exploitation requires already holding legitimate, authenticated managed-cluster credentials, which is why this does not reach Important severity. Red Hat severity: Moderate — CVSS 6.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N). Weakness: CWE-693. Red Hat fixing advisory: RHSA-2026:60387, RHSA-2026:60390, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60391, RHSA-2026:60386. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more.

CVE-2026-76827
Unclassified
Aug 19, 2026
Medium5.4Red Hat

Medium [CVE-2026-68554] Unauthorized actions or resource manipulation via STUN request modification

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path attacker can append attributes after MESSAGE-INTEGRITY to an authenticated STUN request on plain UDP or TCP, adjust the STUN header length, and recompute the unkeyed FINGERPRINT while the original HMAC remains valid because it covers only the message prefix. Server-side parsing in src/server/ns_turn_server.c continues past MESSAGE-INTEGRITY through handle_turn_allocate(), handle_turn_create_permission(), handle_turn_refresh(), and handle_turn_command(), allowing trailing LIFETIME, XOR-PEER-ADDRESS, or ORIGIN attributes to override allocation lifetime, inject a permission, or bypass the origin check. TLS and DTLS deployments prevent this in-transit modification. This issue is fixed in version 4.15.0. This allows the attacker to modify the request by overriding allocation lifetime, injecting permissions, or bypassing origin checks, potentially leading to unauthorized actions or resource manipulation. Coturn is not shipped in any Red Hat product. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L). Weakness: CWE-354.

CVE-2026-68554
Unclassified
Aug 19, 2026
Medium6.5Red Hat

Medium [CVE-2026-75593] File escape vulnerability allows unauthorized file modification

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access BuildKit control API to issue builds, eg., bypass authentication, etc. This issue is fixed in version 0.31.2. This request allows files to escape from the BuildKit-controlled state directory, potentially leading to unauthorized modification or deletion of files on the system. A flaw in BuildKit allows a client with valid permissions to the BuildKit control API to perform unauthorized file modifications outside the intended build state directory. This issue is limited to authenticated clients, reducing the overall attack surface. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-22. Affected products named by the advisory: Logging Subsystem for Red Hat OpenShift 6.6; OpenShift API for Data Protection 1.5; OpenShift Developer Tools and Services 1.6.4; Red Hat Hardened Images; and 25 more. Affected products named by the advisory: Red Hat Quay 3.16; Assisted Installer for Red Hat OpenShift Container Platform 2; Compliance Operator; Kernel Module Management Operator for Red Hat Openshift; and 21 more.

CVE-2026-75593
Unclassified
Aug 19, 2026
Medium6.3Red Hat

Medium [CVE-2026-61711] Security bypass allows disabling container protections

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom frontend could place an invalid SecurityMode value in a crafted build request, and executor/oci/spec_linux.go treated the unsupported value as a non-sandbox mode without requiring the security.insecure entitlement. This disabled Seccomp and AppArmor protections for the build container even though Linux capabilities remained restricted. This issue is fixed in version 0.31.1. A flaw was found in BuildKit. A custom frontend could craft a build request with an invalid security mode, leading to the disabling of Seccomp and AppArmor protections for the build container. Red Hat severity: Moderate — CVSS 6.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L). Weakness: CWE-807. Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; Compliance Operator; Confidential Compute Attestation; Kernel Module Management Operator for Red Hat Openshift; and 31 more. Affected products named by the advisory: Logging Subsystem for Red Hat OpenShift; Logical Volume Manager Storage; Migration Toolkit for Applications 8; Migration Toolkit for Containers; and 27 more.

CVE-2026-61711
Unclassified
Aug 19, 2026
Medium5.5Red Hat

Medium [CVE-2026-61712] Denial of Service via unbounded group parsing

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, BuildKit read attacker-controlled /etc/passwd and /etc/group files without an upper bound while resolving a username to a user identifier or group identifier in executor/oci/user.go and solver/llbsolver/ops/user_linux.go. A malicious base image or build could provide oversized files that exhausted memory during user resolution and caused out-of-memory termination of the buildkitd process. This issue is fixed in version 0.31.1. A flaw was found in BuildKit. When BuildKit attempts to resolve usernames or group identifiers from these files, it reads them without an upper bound, leading to excessive memory consumption. This can cause the buildkitd process to terminate due to out-of-memory errors, resulting in a Denial of Service (DoS). Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; Compliance Operator; Confidential Compute Attestation; Kernel Module Management Operator for Red Hat Openshift; and 31 more.

CVE-2026-61712
Unclassified
Aug 19, 2026
Medium5.4Red Hat

Medium [CVE-2026-69159] Out-of-bounds read leads to denial of service and information disclosure

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.29.0, planar_decompress_plane_rle and planar_decompress_plane_rle_only in libfreerdp/codec/planar.c verify that a control byte exists but do not verify that the source buffer contains the zero to fifteen raw bytes declared by that control byte. A malicious RDP server can send a truncated planar bitmap or surface update whose final control byte claims additional raw bytes, causing the decoder to read beyond pSrcData while processing a color plane. This can crash the client and may disclose adjacent memory. This issue is fixed in version 3.29.0. This causes the client's decoder to read beyond its allocated buffer, which can lead to a client crash, resulting in a denial of service. Additionally, this flaw may disclose sensitive information from adjacent memory. An out-of-bounds read vulnerability was found in FreeRDP's planar bitmap decoder (`libfreerdp/codec/planar.c`). This can lead to a client application crash or partial disclosure of adjacent client memory. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-69159
Red Hat Enterprise Linux
Aug 19, 2026
Medium6.5Red Hat

Medium [CVE-2026-63652] Denial of Service and heap corruption via malformed RDP audio PDU

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0. A flaw was found in FreeRDP. An authenticated Remote Desktop Protocol (RDP) client can send a specially crafted Client Audio Formats Protocol Data Unit (PDU) to the server. This malformed PDU can cause a double-free vulnerability in the `rdpsnd_server_recv_formats` function, leading to the server reliably terminating. This issue can also result in allocator-dependent heap corruption, which may have further security implications. A double-free vulnerability exists in FreeRDP's `rdpsnd_server_recv_formats` function within the `rdpsnd` server channel. This results in server process termination and potential heap corruption, causing a denial of service. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2026-63652
Red Hat Enterprise Linux
Aug 19, 2026
Medium6.5Red Hat

Medium [CVE-2026-63117] Denial of Service via ADPCM frame size calculation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advertise DVI ADPCM with nBlockAlign equal to 8 and nChannels equal to 2 to make the `bs` calculation in rdpsnd_server_select_format in channels/rdpsnd/server/rdpsnd_main.c equal zero. The subsequent out_frames modulo `bs` operation raises SIGFPE and terminates the server-side rdpsnd channel process. This vulnerability fixed in 3.28.0. An authenticated Remote Desktop Protocol (RDP) client can trigger a denial of service by sending a specially crafted DVI ADPCM frame. By advertising specific nBlockAlign and nChannels values, a division-by-zero error occurs in the rdpsnd_server_select_format function. This vulnerability leads to the termination of the server-side rdpsnd channel process, causing a denial of service. A divide-by-zero flaw was found in FreeRDP's `rdpsnd` audio channel server implementation. An authenticated remote RDP client can send malformed DVI ADPCM audio parameters (`nBlockAlign=8`, `nChannels=2`) during format selection in `rdpsnd_server_select_format`. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-369. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-63117
Red Hat Enterprise Linux
Aug 19, 2026
Medium6.2Red Hat

Medium [CVE-2026-18874] annotation values rendered into YAML via text/template without escaping allows YAML injection into Subscription

A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This is due to improper escaping of annotation values when they are rendered into YAML. Successful exploitation could lead to unauthorized modification or control over OLM Subscription configurations, potentially impacting software management within the cluster. This issue primarily affects systems where the 'volsync-addon-deploy-type: olm' annotation is explicitly enabled. Red Hat severity: Moderate — CVSS 6.2 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H). Weakness: CWE-94. Affected Red Hat products: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17. Red Hat fixing advisory: RHSA-2026:60387, RHSA-2026:60390, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60391, RHSA-2026:60386.

CVE-2026-18874
Unclassified
Aug 19, 2026
Medium4.3Red Hat

Medium [CVE-2026-55648] Integer overflow allows out-of-bounds read via malicious RDP server

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy_from_icon_data in libfreerdp/codec/color.c calculates nWidth multiplied by nHeight multiplied by FreeRDPGetBytesPerPixel(format) in 32-bit arithmetic. A malicious RDP server can send a RAIL TS_ICON_INFO update with dimensions such as 32768 by 32768 and 32 bits per pixel so the required-size calculation wraps, bypassing the cbBitsColor source bounds check before freerdp_image_copy_no_overlap reads attacker-controlled icon data. This affects RemoteApp clients using the vulnerable library path, while xfreerdp has a caller-side mitigation. This issue is fixed in version 3.27.0. An integer overflow vulnerability in the `freerdp_image_copy_from_icon_data` function allows a malicious Remote Desktop Protocol (RDP) server to bypass a bounds check. By sending a specially crafted icon update with large dimensions, the server can cause the client to read attacker-controlled data beyond the intended memory buffer. This out-of-bounds read can lead to information disclosure or potentially arbitrary code execution on affected RemoteApp clients. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L). Weakness: CWE-125.

CVE-2026-55648
Red Hat Enterprise Linux
Aug 19, 2026
Medium5.4Red Hat

Medium [CVE-2026-55564] Out-of-bounds read in glyph cache leads to denial of service and information disclosure

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_cache_get function in libfreerdp/cache/glyph.c checks whether index is greater than cache->number instead of greater than or equal to it. A malicious RDP server can use GLYPH_FRAGMENT_USE replay in update_process_glyph_fragments to make the default cache receive index 254 when cache->number is 254, reading one pointer beyond the entries array and dereferencing it as a glyph. This can crash the client and may disclose adjacent heap data. This issue is fixed in version 3.27.0. A flaw was found in FreeRDP. A malicious Remote Desktop Protocol (RDP) server can exploit an out-of-bounds read vulnerability in the glyph_cache_get function. By sending crafted glyph fragments, the server can cause the client to read beyond the intended memory buffer. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-55564
Red Hat Enterprise Linux
Aug 19, 2026
Medium5.8Red Hat

Medium [CVE-2026-75145] Out-of-bounds memory access due to integer narrowing conversion

FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The OBU size is cast to long before comparison against the remaining frame size. On targets where long is 32 bits, including 64-bit Windows, sufficiently large OBU size values are sign-flipped by the narrowing cast, producing a negative value that passes the payload size check. This allows an oversized OBU to bypass the safety bound on affected platforms, leading to out-of-bounds memory access when the oversized value is subsequently used as a copy length. A flaw was found in FFmpeg. An incorrect integer narrowing conversion in the AV1 RTP packetizer can lead to an out-of-bounds memory access. This occurs when processing specially crafted AV1 RTP (Real-time Transport Protocol) packets, where a large OBU (Operating Block Unit) size is incorrectly handled due to a casting issue on certain platforms. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code. The ffmpeg package is not shipped in base Red Hat Enterprise Linux. It is available through EPEL, Red Hat Enterprise Linux AI, and as a bundled dependency in Red Hat OpenShift AI container images. The vulnerable code resides in the AV1 RTP packetizer (libavformat/rtpenc_av1.c), which is compiled and shipped in all FFmpeg builds across these products.

CVE-2026-75145
Unclassified
Aug 19, 2026
Medium5.3Red Hat

Medium [CVE-2026-19672] Python tarfile module: Directory traversal allows creation of empty directories outside extraction destination

The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given. Member contents are still extracted inside it. To return to the destination the member's name must contain the destination directory's own final component, so extraction into a secure randomised directory is not affected. This affects POSIX platforms only. On Windows,.. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created. This vulnerability allows an attacker to create empty directories outside of the intended extraction destination on POSIX (Portable Operating System Interface) platforms. This occurs when processing a specially crafted archive containing member names that use directory traversal sequences (e.g., `../`) to leave and then re-enter the target directory. While only empty directories are created outside the destination, this can lead to unintended file system modifications. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). Weakness: CWE-22. Affected Red Hat products: Red Hat Hardened Images.

CVE-2026-19672
Unclassified
Aug 19, 2026
Medium6.3Red Hat

Medium [CVE-2026-76878] aodh / python-watcher: cross-project alarm enumeration and webhook missing authorization

In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release (Watcher 4.0.0). A flaw was found in OpenStack Aodh and Watcher. In Watcher, the webhook trigger endpoint does not enforce oslo.policy authorization, allowing any authenticated user who learns an audit webhook URL to trigger EVENT audits and associated action plans regardless of project or role. RHOSP 16.2 is affected.

CVE-2026-76878
Unclassified
Aug 19, 2026
Medium6.7Red Hat

Medium [CVE-2026-76231] Arbitrary command execution via unsanitized dependency names

Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where user-provided dependency names are appended to install and uninstall commands without proper sanitization. Attackers with repository write access can provide maliciously named hermit dependencies to execute arbitrary commands on the machine running Renovate. A flaw was found in Renovate. This flaw has a MODERATE impact on Renovate. The version of Renovate shipped by Red Hat is beyond the upstream fix (40.33.0); the vulnerable hermit-manager code is not present in the shipped version, so Red Hat's product is not affected. Red Hat severity: Moderate — CVSS 6.7 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-78.

CVE-2026-76231
Unclassified
Aug 19, 2026
Medium6.7Red Hat

Medium [CVE-2026-76228] Arbitrary Code Execution via malicious Gradle Wrapper properties

Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) contain a command injection vulnerability in Gradle Wrapper artifact handling. When Renovate processes Gradle Wrapper updates, it invokes a wrapper update command via a shell (e.g. /bin/sh -c..../gradlew:wrapper --gradle-distribution-url ). If an attacker supplies a malicious gradle-wrapper.properties whose distributionUrl contains shell command substitution syntax such as $(...), the shell evaluates it before Gradle parses the URL, resulting in arbitrary command execution in the Renovate runtime. Exploitation requires the attacker to introduce the malicious file into a repository that Renovate scans; the issue occurs even when allowScripts is disabled. A flaw was found in Renovate. This allows an attacker to execute unauthorized commands on the system running Renovate. Red Hat does not ship or use an affected version of Renovate. Red Hat severity: Moderate — CVSS 6.7 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-78.

CVE-2026-76228
Unclassified
Aug 19, 2026
Medium6.7Red Hat

Medium [CVE-2026-76229] Arbitrary Command Injection via kustomize manager

Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize manager where user-provided chart names are appended to helm pull commands without proper sanitization. Attackers with repository write access can craft malicious kustomization.yaml files with specially crafted chart names to execute arbitrary commands on the Renovate host machine. A flaw was found in Renovate. Red Hat does not ship or use an affected version of Renovate. Red Hat severity: Moderate — CVSS 6.7 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-78.

CVE-2026-76229
Unclassified
Aug 19, 2026

← All vendors