VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3138 CVEsRSS

CVE-2026-13505High· 7.5
1mo ago

org.bouncycastle/bc-fips: Bouncy Castle for Java FIPS: Sensitive key material remains in memory due to delayed zeroisation (CVE-2026-13505)

A flaw was found in Bouncy Castle for Java FIPS (BC-FJA). Sensitive cryptographic key material, intended to be securely erased from memory (zeroised) upon garbage collection, may persist longer than expected. This occurs because the zerois…

▾ TwilightRed Hat · Red Hat JBoss Enterprise Application Platform Expansion PackEPSS 0.25%via CSAF
CVE-2026-65819High· 7.5
1mo ago

gopacket provides packet processing capabilities for Go

gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffers, allowing a crafted packet decoded …

▾ TwilightRed Hat · Network Observability (NETOBSERV) 1.12.3EPSS 0.66%via NVD
CVE-2026-62296High· 7.5
1mo ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded…

▾ TwilightRed Hat · Red Hat build of Apache Camel 4 for Quarkus 3EPSS 0.49%via NVD
CVE-2026-15816High· 7.5
1mo ago

A flaw was found in dracut

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROO…

▾ TwilightRed Hat · dracutEPSS 0.37%via NVD
CVE-2026-71851Critical· 9.0PoC
1mo ago

crypto-js is a JavaScript library of crypto standards

crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded …

▾ Abyssalcrypto-js · crypto-jsEPSS 0.55%via NVD
CVE-2026-56818Medium· 6.5
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, b…

▾ Sunlitnetty · nettyEPSS 0.47%via NVD
CVE-2026-71556High· 7.1
1mo ago

go-git is an extensible git implementation library written in pure Go

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resoluti…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.36%via NVD
CVE-2026-18649High· 7.5PoC
1mo ago

A flaw was found in the GStreamer gst-plugins-good package

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, u…

▾ MidnightRed Hat · gstreamer1-plugins-goodEPSS 0.96%via NVD
CVE-2026-7867High· 7.8PoC
1mo ago

A flaw was found in udisks2

A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker…

▾ MidnightRed Hat · udisksEPSS 0.17%via NVD
CVE-2026-18427High· 7.5
1mo ago

@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass

@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dot…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.66%via NVD
CVE-2026-19173High· 8.3
1mo ago

Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.32%via NVD
CVE-2026-64597Critical· 9.8⚖ disputed
1mo ago

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails b…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.67%via NVD
CVE-2026-67422High· 7.5
1mo ago

pymdown-extensions is a collection of extensions for the Python Markdown library

pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can parti…

▾ TwilightRed Hat · Red Hat Developer HubEPSS 0.61%via NVD
CVE-2026-71497Medium· 4.7
1mo ago

jsoup is a Java library for working with real-world HTML

jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior of a dif…

▾ Sunlitjsoup · org.jsoup:jsoupEPSS 0.30%via NVD
CVE-2026-71430Medium· 6.2
1mo ago

node-re2 provides RE2 regular expression bindings for Node.js

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty MaybeLocal that…

▾ SunlitRed Hat · re2EPSS 0.16%via NVD
CVE-2026-71498Medium· 5.1
1mo ago

node-re2 provides RE2 regular expression bindings for Node.js

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read past the end of the…

▾ SunlitRed Hat · re2EPSS 0.17%via NVD
CVE-2026-67434High· 7.8
1mo ago

PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards

PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgbl…

▾ TwilightRed Hat · squizlabs/php_codesnifferEPSS 1.1%via NVD
CVE-2026-71436Medium· 7.5
1mo ago

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1, Mermaid XY Charts are vulnerable to an infinite loop denial of service in the setXAxisR…

▾ Sunlitmermaid · mermaidEPSS 0.58%via NVD
CVE-2026-71326Low· 3.8
1mo ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key bui…

▾ Sunlittraefik · traefikEPSS 0.34%via NVD
CVE-2026-71327High· 8.1
1mo ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go bui…

▾ Twilighttraefik · traefikEPSS 0.48%via NVD
CVE-2026-71325Medium· 4.4⚖ disputed
1mo ago

Traefik is an open-source edge router that makes publishing services a fun and easy experience

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolv…

▾ Sunlittraefik · traefikEPSS 0.15%via NVD
CVE-2026-71324Critical· 9.1
1mo ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default HTTP reverse proxy forwards a plain HTTP/2 or HTTP/3 CONNECT request and its body to an HTTP/1.1 upstream through a sh…

▾ Midnighttraefik · traefikEPSS 0.69%via NVD
CVE-2026-20288Medium· 6.5
1mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevat…

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevat…

▾ Sunlitcisco · unified_computing_systemEPSS 0.64%via NVD
CVE-2026-20308Medium· 4.3
1mo ago

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerabilit…

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerabilit…

▾ SunlitCisco · Cisco IOS XE SoftwareEPSS 0.32%via NVD
CVE-2026-44950High· 7.5
1mo ago

libxfonts2: libXfont2: Privilege Escalation via Heap Buffer Overflow in Font Server Client (CVE-2026-44950)

A flaw was found in the libXfont2 font-server client. This heap buffer overflow vulnerability allows a malicious font server to send specially crafted glyph data. The fs_read_glyphs() function fails to properly validate the total size of t…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.44%via CSAF
CVE-2026-70429Medium· 6.5
1mo ago

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters t…

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters t…

▾ Sunlitjenkins · jenkinsEPSS 0.42%via NVD
CVE-2026-10090Critical· 9.0
1mo ago

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM)

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can cre…

▾ MidnightRed Hat · rhacm2/multicluster-operators-subscription-rhel9EPSS 0.58%via NVD
CVE-2026-10059Critical· 9.1
1mo ago

A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller

A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertent…

▾ MidnightRed Hat · multicluster-engine/cluster-curator-controller-rhel9EPSS 0.64%via NVD
CVE-2026-54876High· 7.5
1mo ago

Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an attacker…

Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an attacker…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.52%via NVD
CVE-2026-20273High· 8.6
1mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that…

▾ TwilightCisco · Cisco IOS XE SoftwareEPSS 0.47%via NVD
CVEs tagged “csaf” — page 72 · VulnSea