rpm vulnerabilities
CVEs whose affected-version data names the rpm package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-95521High· 7.8A command injection flaw was found in rpm
A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating th…
▾ TwilightRed Hat · rpmvia NVD
CVE-2026-95519High· 7.8A flaw was found in rpm
A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest …
▾ TwilightRed Hat · rpmvia NVD