VulnSea

devspaces/udi-base-rhel9 vulnerabilities

CVEs whose affected-version data names the devspaces/udi-base-rhel9 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2026-91149High· 7.5
3d ago

A flaw was found in Cockpit

A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded nu…

TwilightRed Hat · cockpitEPSS 0.35%via NVD
CVE-2026-91147Medium· 5.9
3d ago

A flaw was found in `cockpit-ws`

A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is made t…

SunlitRed Hat · cockpitEPSS 0.33%via NVD
CVE-2026-91142Low· 3.6
3d ago

A flaw was found in Cockpit

A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A low-privileg…

SunlitRed Hat · cockpitEPSS 0.09%via NVD
CVE-2025-11395Medium· 5.5
6d ago

A flaw was found in Podman

A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman.

SunlitRed Hat · buildahEPSS 0.19%via NVD
CVE-2026-79699Medium· 4.4
6d ago

A flaw was found in the containers/storage library

A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file when processed by st…

SunlitRed Hat · ansible-automation-platform-24/eda-controller-rhel8EPSS 0.13%via NVD
CVE-2026-79705Medium· 4.5
6d ago

A flaw was found in the buildah/copier Go package

A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended de…

SunlitRed Hat · ansible-automation-platform-24/eda-controller-rhel8EPSS 0.25%via NVD
CVE-2025-9566High· 8.1
1y ago

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In…

TwilightRed Hat · podmanEPSS 1.1%via NVD
devspaces/udi-base-rhel9 vulnerabilities (CVEs) · VulnSea