VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3138 CVEsRSS

CVE-2026-69152High· 7.5
1mo ago

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation (CVE-2026-69152)

A flaw was found in the brace-expansion library. The `expand()` function does not apply `maxLength` when constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block …

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.65%via CSAF
CVE-2026-69153High· 7.5
1mo ago

postcss: PostCSS: Information disclosure via crafted sourceMappingURL (CVE-2026-69153)

A flaw was found in PostCSS. A remote attacker can exploit this vulnerability by providing a specially crafted sourceMappingURL when a specific configuration (the 'from' parameter) is not set. This can cause the application to read and exp…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.45%via CSAF
CVE-2026-68945High· 8.2
1mo ago

@angular/common: Angular: Cross-Request Response Reuse and State Poisoning in HttpTransferCache (CVE-2026-68945)

A flaw was found in Angular's HttpTransferCache component. This component, used for caching HTTP requests during server-side rendering, incorrectly generates cache keys when repeated request parameters are present, causing semantically dif…

▾ TwilightRed Hat · Red Hat Ceph Storage 4EPSS 0.18%via CSAF
CVE-2026-8763High· 7.4
1mo ago

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.…

▾ TwilightRed Hat · Red Hat Ceph Storage 9EPSS 0.45%via NVD
CVE-2026-59651High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key

In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.24%via NVD
CVE-2026-59650High· 7.4
1mo ago

In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value

In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.45%via NVD
CVE-2026-59649High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory

In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1…

▾ TwilightRed Hat · Red Hat JBoss Enterprise Application Platform 7EPSS 0.49%via NVD
CVE-2026-59647High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count

In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.42%via NVD
CVE-2026-59645High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema

In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcu…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.49%via NVD
CVE-2026-59643High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored

In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.

▾ Twilightbouncycastle · bc-javaEPSS 0.24%via NVD
CVE-2026-59642High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present

In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips …

▾ TwilightRed Hat · Red Hat Ceph Storage 9EPSS 0.19%via NVD
CVE-2026-59639High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0…

▾ TwilightRed Hat · Red Hat Ceph Storage 9EPSS 0.24%via NVD
CVE-2026-59638High· 7.4
1mo ago

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc…

▾ TwilightRed HatEPSS 0.34%via NVD
CVE-2026-15055High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input

In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 …

▾ TwilightRed Hat · Red Hat Ceph Storage 9EPSS 0.34%via NVD
CVE-2026-18573Medium· 6.5
1mo ago

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication…

▾ Sunlitredhat · build_of_keycloakEPSS 0.48%via NVD
CVE-2026-18572Medium· 6.5
1mo ago

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours)

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake ti…

▾ Sunlitredhat · build_of_keycloakEPSS 0.39%via NVD
CVE-2026-18571Medium· 6.6
1mo ago

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups t…

▾ Sunlitredhat · build_of_keycloakEPSS 0.55%via NVD
CVE-2026-18570Medium· 5.4
1mo ago

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Key…

▾ Sunlitredhat · build_of_keycloakEPSS 0.30%via NVD
CVE-2026-67326High· 7.0
1mo ago

GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config

GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] se…

▾ Twilightgitpython_project · gitpythonEPSS 0.25%via NVD
CVE-2026-67325High· 8.8
1mo ago

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like uplo…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 2.2%via NVD
CVE-2026-67324Critical· 9.8
1mo ago

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Re…

▾ MidnightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.64%via NVD
CVE-2026-67323High· 8.4
1mo ago

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command exe…

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command exe…

▾ TwilightGitPython · GitPythonEPSS 1.3%via NVD
CVE-2026-67322High· 7.5
1mo ago

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from()

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL befor…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.33%via NVD
CVE-2026-67321Medium· 7.5
1mo ago

axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'

axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serializati…

▾ Sunlitaxios · axiosEPSS 0.53%via NVD
CVE-2026-67320High· 7.4
1mo ago

axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy

axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but request interceptors run after the merge; a…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.52%via NVD
CVE-2026-67317Medium· 5.3
1mo ago

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload siz…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.60%via NVD
CVE-2026-67314High· 7.4
1mo ago

axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js)

axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js). When an application is already affected by a separate prototype-po…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.41%via NVD
CVE-2026-67313High· 7.5
1mo ago

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brac…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.52%via NVD
CVE-2026-67312High· 7.5
1mo ago

axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData with Content-Type: application/json)

axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData with Content-Type: application/json). Whe…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.52%via NVD
CVE-2026-67309High· 7.5
1mo ago

Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider's RewriteTarget middleware (generated from the nginx.ingress.kubernetes.io/rewrite-target annotation)

Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider's RewriteTarget middleware (generated from the nginx.ingress.kubernetes.io/rewrite-target annotation). When an Ingre…

▾ Twilighttraefik · traefikEPSS 0.66%via NVD
CVEs tagged “csaf” — page 74 · VulnSea