VulnSea

enterprise_linux_appstream_eus_v_10_0 vulnerabilities

CVEs whose affected-version data names the enterprise_linux_appstream_eus_v_10_0 package (go, pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

34 CVEsRSS

CVE-2026-39819Medium· 4.4
4mo ago

cmd/go: golang: Go 'go bug' command: Arbitrary file overwrite via symlink attack (CVE-2026-39819)

A flaw was found in the 'go bug' command within the Go programming language tools. This command writes to temporary files with predictable names. A local attacker with access to the system's temporary directory could exploit this by creati…

SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.18%via CSAF
CVE-2026-35536Medium· 5.4
5mo ago

tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments (CVE-2026-35536)

A flaw was found in Tornado. A remote attacker could exploit this vulnerability by injecting specially crafted characters into the `domain`, `path`, and `samesite` arguments when setting cookies. This could lead to cookie attribute injecti…

SunlitRed Hat · Red Hat OpenShift AI 2.25EPSS 0.24%via CSAF
CVE-2026-27135High· 7.5
6mo ago

nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination (CVE-2026-27135)

A flaw was found in nghttp2. Due to missing internal state validation, the library continues to process incoming data even after a session has been terminated. A remote attacker could exploit this by sending a specially crafted HTTP/2 fram…

TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.78%via CSAF
CVE-2025-40149Medium· 5.0⚖ disputed
10mo ago

kernel: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock() (CVE-2025-40149)

A flaw was found in the Linux kernel’s TLS implementation (net/tls/tls_device.c). The function get_netdev_for_sock() is invoked during setsockopt(), which is not executed under RCU (Read-Copy-Update) protection. It previously used sk_dst_g…

SunlitRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.16%via CSAF
enterprise_linux_appstream_eus_v_10_0 vulnerabilities (CVEs) — page 2 · VulnSea