VulnSea

enterprise_linux vulnerabilities

CVEs whose affected-version data names the enterprise_linux package (go, npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

660 CVEsRSS

CVE-2026-89439Medium· 5.5
1w ago

kernel: platform/x86: ISST: Add a NULL check for sst_inst[] (CVE-2026-89439)

A flaw was found in the Linux kernel's Intel Speed Select Technology (ISST) driver. A missing NULL check for `isst_common.sst_inst[]` during failed socket loading could allow a local attacker to trigger a NULL pointer dereference. This vul…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.20%via CSAF
CVE-2026-80996Medium· 5.5
1w ago

kernel: net: l2tp: do not propagate multicast notification errors (CVE-2026-80996)

A flaw was found in the Linux kernel's L2TP (Layer 2 Tunneling Protocol) networking component. Specifically, the netlink handlers responsible for creating and modifying L2TP tunnels and sessions may fail to propagate multicast notification…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-80993Medium· 5.5
1w ago

kernel: net: phylink: correctly validate returned PCS in phylink_inband_caps (CVE-2026-80993)

A flaw was found in the Linux kernel's `net: phylink` component. The `phylink_inband_caps()` function does not correctly validate the return value from `mac_select_pcs`, which can return an error pointer instead of a valid Physical Coding …

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-80974Medium· 5.5
1w ago

kernel: mfd: sm501: Fix potential memory leaks during remove (CVE-2026-80974)

A flaw was found in the `mfd: sm501` component of the Linux kernel. This vulnerability arises from a failure to properly free allocated memory for `struct sm501_devdata` during the device removal process. A local attacker could potentially…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.20%via CSAF
CVE-2026-89484Medium· 5.5
1w ago

kernel: lockd: fix NULL dereference on lockowner allocation failure (CVE-2026-89484)

A flaw was found in the Linux kernel's `lockd` component. This vulnerability occurs when the Network Lock Manager (NLM) client attempts to initialize file lock operations without successfully allocating a lockowner. This can lead to a NULL…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.20%via CSAF
CVE-2026-87859Medium· 5.3
1w ago

morgan is an HTTP request logger middleware for Node.js

morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the Apache combined log format that morgan …

SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.39%via NVD
CVE-2026-89046High· 8.2PoC
1w ago

zstd-jni: zstd-jni: Information disclosure or denial of service via out-of-bounds read (CVE-2026-89046)

A flaw was found in zstd-jni. This out-of-bounds read vulnerability in the Zstd.getFrameContentSize function occurs because it fails to validate negative srcPosition arguments. A remote attacker can supply negative offset values, bypassing…

MidnightRed Hat · Red Hat Ceph Storage 9EPSS 0.57%via CSAF
CVE-2026-87795High· 8.2PoC
2w ago

com.github.luben/zstd-jni: zstd-jni: Out-of-bounds read in ZstdDictCompress constructor leads to denial of service (CVE-2026-87795)

A flaw was found in zstd-jni. This vulnerability occurs due to insufficient validation of offset and length parameters within the `ZstdDictCompress` constructor. An attacker can exploit this by providing untrusted values, leading to an out…

MidnightRed Hat · Red Hat Ceph Storage 9EPSS 0.34%via CSAF
CVE-2026-71224Medium· 4.7
2w ago

A stack overflow vulnerability was found in gfs2-utils

A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata without bounds validation, causing stack exhaustion and a denial of ser…

Sunlitredhat · enterprise_linuxEPSS 0.12%via NVD
CVE-2026-71221High· 7.0
2w ago

A stack out-of-bounds write vulnerability was found in gfs2-utils

A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code…

Twilightredhat · enterprise_linuxEPSS 0.14%via NVD
CVE-2026-71220High· 7.0
2w ago

A stack out-of-bounds write vulnerability was found in gfs2-utils

A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds checking, causing a stack buffer overflow that may lead to arbitrar…

Twilightredhat · enterprise_linuxEPSS 0.14%via NVD
CVE-2026-71219Medium· 4.7
2w ago

A stack overflow vulnerability was found in gfs2-utils

A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 file…

Sunlitredhat · enterprise_linuxEPSS 0.12%via NVD
CVE-2026-71222Medium· 5.3
2w ago

A heap out-of-bounds read vulnerability was found in gfs2-utils

A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory con…

Sunlitredhat · enterprise_linuxEPSS 0.11%via NVD
CVE-2026-63376High· 8.2⚖ disputed
2w ago

toml-node is a TOML parser for Node.js and the browser

toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Ob…

TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.38%via NVD
CVE-2026-77465High· 7.5⚖ disputed
2w ago

toml-node is a TOML parser for Node.js and the browser

toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() uses a Peggy 5.1.0 generated recursive-descent parser in lib/parser.js whose peg$parsevalue, peg$parsearray, and peg$parseinline_table_entry functions r…

TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.36%via NVD
CVE-2026-56855Medium· 5.3
3w ago

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages (CVE-2026-56855)

A flaw was found in golang.org/x/crypto/ssh. After a channel has been established, a remote malicious peer could send specially crafted messages. This could lead to a deadlock of the entire connection, resulting in a Denial of Service (DoS…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.38%via CSAF
CVE-2026-78662Medium· 5.3
3w ago

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding (CVE-2026-78662)

A flaw was found in golang.org/x/crypto/ssh. A malicious remote attacker could flood a channel's incoming requests before it is established, leading to a deadlock of the entire connection. This could result in a denial of service (DoS) for…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.32%via CSAF
CVE-2026-83557Medium· 5.6
3w ago

DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator

DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of "unsafe bas…

SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.59%via NVD
CVE-2026-84371Medium· 5.4
3w ago

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value…

SunlitRed Hat · Red Hat Satellite 6EPSS 0.18%via NVD
CVE-2026-82853Medium· 4.9
3w ago

Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands

Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return a…

SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.73%via NVD
CVE-2026-82660Medium· 5.4
3w ago

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content field…

SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.19%via NVD
CVE-2024-58379Medium· 5.3
3w ago

nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments

nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicio…

SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.30%via NVD
CVE-2026-82562Low· 3.7
3w ago

### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the …

### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the …

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.32%via NVD
CVE-2026-82417Medium· 5.3⚖ disputed
3w ago

### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member

### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)`…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.26%via NVD
CVE-2026-82474High· 7.8
3w ago

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve…

TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.13%via NVD
CVE-2025-30156High· 8.9
3w ago

Ceph is an open-source distributed storage platform providing object, block, and file storage

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol encrypts tickets with AES-128-CBC in an unauthenticated mode that us…

TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.09%via NVD
CVE-2026-37236Critical· 9.8⚖ disputed
3w ago

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-ww…

MidnightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.44%via NVD
CVE-2026-56854Medium· 6.8
3w ago

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions (CVE-2026-56854)

A flaw was found in golang.org/x/crypto/ssh. The component failed to properly enforce source-address restrictions for several authentication methods, including password and keyboard-interactive callbacks. In applications that misuse the Se…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.33%via CSAF
CVE-2026-80212High· 7.5
3w ago

An issue was discovered in the resolv gem before 0.7.2 for Ruby

An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::Resource.get_class, Resolv::DNS::Resource::Generic.create, and Resolv::DNS::SvcParam::Generic.create generate a new class for each unknown DNS resource record …

TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.57%via NVD
CVE-2026-79020Medium· 4.3⚖ disputed
4w ago

chromium-browser: skia: chromium-browser: skia: Out of bounds read in Skia (CVE-2026-79020)

An out of bounds read flaw was found in the Skia component of the Chromium browser. Upstream bug(s): https://code.google.com/p/chromium/issues/detail?id=514017820

SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.36%via CSAF
enterprise_linux vulnerabilities (CVEs) — page 9 · VulnSea