VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3138 CVEsRSS

CVE-2026-73282Medium· 4.8
1mo ago

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

▾ Sunlitopenbsd · opensshEPSS 0.16%via NVD
CVE-2026-73281Low· 3.5
1mo ago

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bin…

▾ Sunlitopenbsd · opensshEPSS 0.16%via NVD
CVE-2026-73088High· 7.5
1mo ago

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist()…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.66%via NVD
CVE-2026-73089High· 7.5
1mo ago

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCac…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.66%via NVD
CVE-2026-18710Medium· 6.5
1mo ago

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs automatic…

▾ Sunlitmongodb · java_driverEPSS 0.14%via NVD
CVE-2026-70622Medium· 6.5
1mo ago

tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-con…

tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-con…

▾ SunlitRed Hat · Red Hat OpenShift Update ServiceEPSS 0.46%via NVD
CVE-2026-18618High· 7.5
1mo ago

A flaw was found in ml-metadata

A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker, with network access to the MLMD pod, could exploit…

▾ TwilightRed Hat · rhoai/odh-mlmd-grpc-server-rhel9EPSS 0.83%via NVD
CVE-2026-71577Medium· 6.3
1mo ago

A flaw was found in multicluster-global-hub

A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised managed hub to intercept and collect sen…

▾ SunlitRed Hat · multicluster-globalhub/multicluster-globalhub-rhel9-operatorEPSS 0.40%via NVD
CVE-2026-15467High· 8.1
1mo ago

A flaw was found in the trustyai-service-operator's LMEvalJob controller

A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the us…

▾ TwilightRed Hat · rhoai/odh-trustyai-service-operator-rhel9EPSS 0.60%via NVD
CVE-2026-71576High· 8.5
1mo ago

A flaw was found in multicluster-global-hub

A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka clien…

▾ TwilightRed Hat · multicluster-globalhub/multicluster-globalhub-manager-rhel9EPSS 0.23%via NVD
CVE-2026-18982High· 8.8
1mo ago

A flaw was found in the RHOAI training-operator

A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can imperson…

▾ TwilightRed Hat · rhoai/odh-training-operator-rhel9EPSS 0.79%via NVD
CVE-2026-18951High· 8.8
1mo ago

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with …

▾ TwilightRed Hat · rhoai/odh-training-operator-rhel9EPSS 0.89%via NVD
CVE-2026-6426Medium· 4.4
1mo ago

A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling

A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size is stored as a uint64_t but read by the VMS_VBUFFER load path as a signed int32_t. On little-endian hosts, a crafted…

▾ SunlitRed Hat · qemu-kvmEPSS 0.39%via NVD
CVE-2026-72913High· 7.8
1mo ago

Kitty is a cross-platform GPU based terminal

Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell command…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.21%via NVD
CVE-2026-72903High· 8.1
1mo ago

Tabby (formerly Terminus) is a highly configurable terminal emulator

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _ma…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4EPSS 0.49%via NVD
CVE-2026-18620High· 7.1
1mo ago

A flaw was found in Data Science Pipelines

A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRu…

▾ TwilightRed Hat · rhoai/odh-ml-pipelines-api-server-v2-rhel9EPSS 0.48%via NVD
CVE-2026-18611High· 7.5
1mo ago

A flaw was found in the Data Science Pipelines Operator

A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinI…

▾ TwilightRed Hat · rhoai/odh-data-science-pipelines-operator-controller-rhel9EPSS 0.61%via NVD
CVE-2026-15581High· 8.0
1mo ago

A flaw was found in the TrustyAI Service (TAS) deployment

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or d…

▾ TwilightRed Hat · rhoai/odh-trustyai-service-operator-rhel9EPSS 0.42%via NVD
CVE-2026-18608High· 8.7
1mo ago

A flaw was found in the Data Science Pipelines Operator (DSPO)

A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the…

▾ TwilightRed Hat · rhoai/odh-data-science-pipelines-operator-controller-rhel9EPSS 0.70%via NVD
CVE-2026-18621High· 7.6
1mo ago

A flaw was found in Data Science Pipelines (DSP)

A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with …

▾ TwilightRed Hat · rhoai/odh-ml-pipelines-api-server-v2-rhel9EPSS 0.51%via NVD
CVE-2026-18617High· 8.8
1mo ago

A flaw was found in the Data Science Pipelines Operator (DSPO)

A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Sourc…

▾ TwilightRed Hat · rhoai/odh-data-science-pipelines-operator-controller-rhel9EPSS 0.73%via NVD
CVE-2026-69112High· 7.1
1mo ago

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers can…

▾ Twilightaccelerate · accelerateEPSS 0.19%via NVD
CVE-2026-63622High· 7.8
1mo ago

A flaw was found in libvirt

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `sw…

▾ TwilightRed Hat · libvirtEPSS 0.18%via NVD
CVE-2026-68166High· 7.3
1mo ago

In the Linux kernel, the following vulnerability has been resolved: userfaultfd: prevent registration of special VMAs Vova Tokarev says: userfaultfd allows registration on shadow stack VMAs

In the Linux kernel, the following vulnerability has been resolved: userfaultfd: prevent registration of special VMAs Vova Tokarev says: userfaultfd allows registration on shadow stack VMAs. With userfaultfd access, you can regis…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.21%via NVD
CVE-2026-68162High· 7.8
1mo ago

In the Linux kernel, the following vulnerability has been resolved: sctp: avoid auth_enable sysctl UAF during netns teardown proc_sctp_do_auth() updates the SCTP control socket after changing net.sctp.auth_enable

In the Linux kernel, the following vulnerability has been resolved: sctp: avoid auth_enable sysctl UAF during netns teardown proc_sctp_do_auth() updates the SCTP control socket after changing net.sctp.auth_enable. The handler gets the …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via NVD
CVE-2026-68159Critical· 9.8
1mo ago

In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to over…

In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to over…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS (v. 9)EPSS 0.74%via NVD
CVE-2026-68138High· 7.8PoC
1mo ago

In the Linux kernel, the following vulnerability has been resolved: net/sched: serialize qdisc_rtab_list against concurrent get/put qdisc_get_rtab() and qdisc_put_rtab() mutate the process-global singly linked list qdisc_rtab_list and …

In the Linux kernel, the following vulnerability has been resolved: net/sched: serialize qdisc_rtab_list against concurrent get/put qdisc_get_rtab() and qdisc_put_rtab() mutate the process-global singly linked list qdisc_rtab_list and …

▾ MidnightRed Hat · Red Hat Enterprise Linux 9EPSS 0.28%via NVD
CVE-2026-19389High· 7.1
1mo ago

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled l…

▾ TwilightRed Hat · gstreamer1-plugins-ugly-freeEPSS 0.58%via NVD
CVE-2026-19387High· 7.6
1mo ago

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV …

▾ TwilightRed Hat · gstreamer1-plugins-bad-freeEPSS 0.38%via NVD
CVE-2026-15534Medium· 5.7
1mo ago

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each…

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each…

▾ SunlitRed Hat · perlEPSS 0.26%via NVD
CVEs tagged “csaf” — page 71 · VulnSea