VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3138 CVEsRSS

CVE-2026-76227Medium· 5.5
1mo ago

Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict enviro…

Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict enviro…

▾ SunlitRed HatEPSS 0.15%via NVD
CVE-2026-75595Critical· 9.1
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so…

▾ Midnightnetty · nettyEPSS 0.46%via NVD
CVE-2026-75569High· 7.7
1mo ago

A flaw was found in mce-operator-bundle

A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with wr…

▾ TwilightRed Hat · multicluster-engine/mce-operator-bundleEPSS 0.60%via NVD
CVE-2026-76827Medium· 6.8
1mo ago

A flaw was found in search-indexer

A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-in…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.11EPSS 0.53%via NVD
CVE-2026-76139High· 8.0
1mo ago

A flaw was found in acm-operator-bundle

A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as Gi…

▾ TwilightRed Hat · rhacm2/acm-operator-bundleEPSS 0.72%via NVD
CVE-2026-66794Critical· 9.3
1mo ago

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks…

▾ MidnightRed Hat · multicluster-engine/cluster-proxy-addon-rhel9EPSS 0.62%via NVD
CVE-2026-18874Medium· 6.2
1mo ago

A flaw was found in volsync-addon-controller

A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This is due to improper esc…

▾ SunlitRed Hat · rhacm2/acm-volsync-addon-controller-rhel9EPSS 0.54%via NVD
CVE-2026-55648High· 7.5⚖ disputed
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy_from_icon_data in libfreerdp/codec/color.c calculates nWidth multiplied by nHeight multiplied by FreeRDPGetBytesPerPixel(format) in 32-b…

▾ Twilightfreerdp · freerdpEPSS 0.43%via NVD
CVE-2026-76220High· 8.8
1mo ago

gitpython: GitPython: Arbitrary command execution via crafted kwargs (CVE-2026-76220)

A flaw was found in GitPython. A remote attacker can bypass the `check_unsafe_options` guard by combining a single-character keyword argument with `split_single_char_options=False`. This allows the attacker to supply a crafted dictionary o…

▾ TwilightRed Hat · Red Hat Satellite 6.19 for RHEL 9EPSS 0.91%via CSAF
CVE-2026-76221High· 8.8
1mo ago

gitpython: GitPython: Arbitrary code execution via config-name injection (CVE-2026-76221)

A flaw was found in GitPython. This vulnerability allows attackers to inject malicious configuration options by manipulating option names within the option-name validator. By injecting special characters, an attacker can forge arbitrary gi…

▾ TwilightRed Hat · Red Hat Satellite 6.19 for RHEL 9EPSS 0.77%via CSAF
CVE-2026-76222High· 8.2
1mo ago

gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names (CVE-2026-76222)

A flaw was found in GitPython where it fails to properly validate submodule names within .gitmodules files. A remote attacker could craft a malicious Git repository containing specially formed submodule names with directory traversal seque…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.42%via CSAF
CVE-2026-76218High· 7.5
1mo ago

gitpython: GitPython: Remote Code Execution via malicious Git hooks (CVE-2026-76218)

A flaw was found in GitPython. This vulnerability allows a remote attacker to achieve arbitrary code execution. By supplying a specially crafted template parameter to the `Repo.init` function, an attacker can point to a directory containin…

▾ TwilightRed Hat · Red Hat Satellite 6.19 for RHEL 9EPSS 0.83%via CSAF
CVE-2026-76219High· 8.1
1mo ago

gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection (CVE-2026-76219)

A flaw was found in GitPython. This vulnerability allows an attacker to overwrite arbitrary files on the system. By injecting specific options into the `git read-tree` command through methods like `IndexFile.from_tree`, `IndexFile.reset`, …

▾ TwilightRed Hat · Red Hat Satellite 6.19 for RHEL 9EPSS 0.54%via CSAF
CVE-2026-75838Medium· 6.1
1mo ago

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that ex…

▾ SunlitRed Hat · Red Hat Ceph Storage 9EPSS 0.30%via NVD
CVE-2026-66780Medium· 6.5
1mo ago

A flaw was found in the submariner-operator component

A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, sp…

▾ SunlitRed Hat · rhacm2/submariner-addon-rhel9EPSS 0.56%via NVD
CVE-2026-12564Critical· 9.6
1mo ago

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-c…

▾ MidnightRed Hat · automation-controllerEPSS 0.35%via NVD
CVE-2026-50161Critical· 9.8
1mo ago

libre is a generic library for real-time communications with asynchronous input and output support

libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4.8.1, the websock_decode() function in src/websock/websock.c contains an integer overflow when validating a masked WebSocket fr…

▾ MidnightRed HatEPSS 0.52%via NVD
CVE-2026-73073High· 7.3
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficiently escaped typeref: or typename: value from a tags file,…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.20%via NVD
CVE-2026-73426Medium· 4.6
1mo ago

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can …

▾ SunlitRed HatEPSS 0.32%via NVD
CVE-2026-50187High· 8.8
1mo ago

Oh My Zsh is a community-driven framework for managing Zsh configuration

Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to source after a directory change into a folder containing a .en…

▾ TwilightRed Hat · Red Hat Ansible Automation Platform 2EPSS 0.54%via NVD
CVE-2026-66046High· 7.5
1mo ago

Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) li…

Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) li…

▾ Twilightlibexpat_project · libexpatEPSS 0.74%via NVD
CVE-2026-75485Medium· 5.5
1mo ago

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This e…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.11EPSS 0.19%via NVD
CVE-2026-73834Medium· 5.5
1mo ago

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, cre…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.11EPSS 0.11%via NVD
CVE-2026-17084Medium· 6.0
1mo ago

The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0

The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processin…

▾ SunlitPython Software Foundation · CPythonEPSS 0.72%via NVD
CVE-2026-16732Medium· 6.1
1mo ago

fastify: fastify: Request spoofing via numeric trustProxy configuration (CVE-2026-16732)

A flaw was found in fastify. When configured with a numeric `trustProxy` value, an attacker who can directly access the Fastify origin, bypassing the front-facing proxy, can spoof forwarded request fields. This vulnerability allows for hos…

▾ SunlitRed Hat · Red Hat OpenShift Dev SpacesEPSS 0.16%via CSAF
CVE-2026-70906High· 7.5
1mo ago

Vulnerability in Oracle Java SE (component: 2D)

Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 25.0.4 and 26.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to…

▾ TwilightRed Hat · Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)EPSS 0.46%via NVD
CVE-2026-61308Medium· 6.8
1mo ago

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12,…

▾ SunlitOracle Corporation · Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise EditionEPSS 0.31%via NVD
CVE-2026-74960High· 8.1⚖ disputed
1mo ago

Site isolation issue in the WebExtensions component

Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.22%via NVD
CVE-2026-74959Critical· 9.1⚖ disputed
1mo ago

Mitigation bypass in the Storage: Cache API component

Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

▾ MidnightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.48%via NVD
CVE-2026-74957High· 8.1⚖ disputed
1mo ago

Mitigation bypass in the Safe Browsing component

Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.43%via NVD
CVEs tagged “csaf” — page 65 · VulnSea