VulnSea

cert-manager/cert-manager-trust-manager-rhel9 vulnerabilities

CVEs whose affected-version data names the cert-manager/cert-manager-trust-manager-rhel9 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

12 CVEsRSS

CVE-2026-15588Medium· 5.3PoC
2mo ago

A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib

A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticat…

▾ TwilightRed Hat · glib2via NVD
CVE-2026-16118High· 7.1PoC
2mo ago

A flaw was found in xdgmime

A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data …

▾ Midnightxdg · xdgmimevia NVD
CVE-2026-14164High· 7.5PoC
3mo ago

A double free issue has been identified in libarchive's RAR5 reader

A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent proc…

▾ MidnightRed Hat · libarchivevia NVD
CVE-2026-42014Medium· 6.6
3mo ago

A flaw was found in GnuTLS

A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN f…

▾ SunlitRed Hat · gnutlsvia NVD
CVE-2026-5419Low· 3.7
4mo ago

A flaw was found in gnutls

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through ob…

▾ SunlitRed Hat · gnutlsvia NVD
CVE-2026-5260High· 8.2
4mo ago

A flaw was found in libgnutls

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corrupti…

▾ TwilightRed Hat · gnutlsvia NVD
CVE-2026-42015Medium· 5.3
4mo ago

A flaw was found in gnutls

A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains …

▾ SunlitRed Hat · gnutlsvia NVD
CVE-2026-42013High· 8.2
4mo ago

A flaw was found in gnutls

A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker …

▾ TwilightRed Hat · gnutlsvia NVD
CVE-2026-42012High· 7.1
4mo ago

A flaw was found in gnutls

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could ca…

▾ TwilightRed Hat · gnutlsvia NVD
CVE-2026-42011High· 7.4
4mo ago

A flaw was found in gnutls

A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to byp…

▾ TwilightRed Hat · gnutlsvia NVD
CVE-2026-33846High· 7.5
4mo ago

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type,…

▾ TwilightRed Hat · gnutlsvia NVD
CVE-2025-5278Medium· 4.4
1y ago

A flaw was found in GNU Coreutils

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key fo…

▾ SunlitRed Hat · coreutilsvia NVD
cert-manager/cert-manager-trust-manager-rhel9 vulnerabilities (CVEs) · VulnSea