VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2912 CVEsRSS

CVE-2026-93841Low· 3.7
1w ago

vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset without bounds checking against vocabulary size

vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset without bounds checking against vocabulary size. Attackers can submit multimoda…

▾ Sunlitvllm-project · vllmEPSS 0.39%via NVD
CVE-2026-93840Low· 3.7
1w ago

vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids()

vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids(). Attackers can supply token IDs above the output vocabulary that pass validation…

▾ Sunlitvllm-project · vllmEPSS 0.41%via NVD
CVE-2026-91205Medium· 6.0
1w ago

A flaw was found in cockpit-files

A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable parent directory, the attacker can replace a newly created directory…

▾ SunlitRed Hat · cockpit-filesEPSS 0.10%via NVD
CVE-2026-91203Medium· 6.0PoC
1w ago

A flaw was found in cockpit-files

A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By manipulating…

▾ TwilightRed Hat · cockpit-filesEPSS 0.10%via NVD
CVE-2026-91202Medium· 6.1
1w ago

A flaw was found in cockpit-files

A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged "Paste as owner" function. This allows for arbitrary…

▾ SunlitRed Hat · cockpit-filesEPSS 0.16%via NVD
CVE-2026-61781Critical· 9.9
1w ago

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier quoting into a dyna…

▾ Midnightpgpartman · pg_partmanEPSS 0.80%via NVD
CVE-2026-93752High· 7.5PoC
1w ago

CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names

CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a declaration named length to replace the internal…

▾ MidnightNV · CSSOMEPSS 0.68%via NVD
CVE-2026-93751Medium· 6.5
1w ago

uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters

uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platfor…

▾ Sunlitgarycourt · uri-jsEPSS 0.40%via NVD
CVE-2026-93750Medium· 5.9PoC
1w ago

http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison

http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs previous…

▾ Twilightkornelski · http-cache-semanticsEPSS 0.45%via NVD
CVE-2026-93749High· 7.5
1w ago

source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values

source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronou…

▾ Twilight7rulnik · source-map-jsEPSS 0.63%via NVD
CVE-2026-93748High· 7.5PoC
1w ago

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers …

▾ Midnightkornelski · http-cache-semanticsEPSS 0.53%via NVD
CVE-2026-93432Medium· 6.1
1w ago

A flaw was found in the Quarkus Qute template engine

A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's content type information. This bypasses standard escaping mechanisms, allowing untrust…

▾ SunlitRed Hat · exploit-intelligence/agent-client-rhel9EPSS 0.42%via NVD
CVE-2026-92768Medium· 5.5PoC
1w ago

A flaw was found in cockpit-machines

A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-line arguments during VM creation or inst…

▾ TwilightRed Hat · cockpit-machinesEPSS 0.15%via NVD
CVE-2026-92747Medium· 5.0PoC
1w ago

A flaw was found in `cockpit-machines`

A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This …

▾ TwilightRed Hat · cockpit-machinesEPSS 0.14%via NVD
CVE-2026-92745Medium· 5.0
1w ago

A flaw was found in cockpit-machines

A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is p…

▾ SunlitRed Hat · cockpit-machinesEPSS 0.14%via NVD
CVE-2026-84975High· 7.4
1w ago

PJSIP is a free and open source multimedia communication library written in C

PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuTLS backends in pjlib/src/pj/ssl_sock_ossl.c and pjlib/src/pj/ssl_sock_gtls.c copy DNS SubjectAltName values with stri…

▾ Twilightpjsip · pjprojectEPSS 0.23%via NVD
CVE-2026-77396Medium· 6.9
1w ago

PJSIP is a free and open source multimedia communication library written in C

PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser in pjmedia/src/pjmedia/avi_player.c uses an input-file video chunk length as the number of bytes copied into a frame…

▾ Sunlitpjsip · pjprojectEPSS 0.17%via NVD
CVE-2026-69186Medium· 5.3PoC⚖ disputed
1w ago

c-ares is an asynchronous resolver library

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed records. Beca…

▾ Twilightc-ares · c-aresEPSS 0.52%via NVD
CVE-2026-69184High· 7.5
1w ago

c-ares is an asynchronous resolver library

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A malicious DNS server can send a response …

▾ Twilightc-ares · c-aresEPSS 0.68%via NVD
CVE-2026-64847Medium· 6.8
1w ago

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts process-pool workers with standard error connected to a pipe that the parent never drains,…

▾ Sunlitagronholm · anyioEPSS 0.16%via NVD
CVE-2026-63349High· 7.0⚖ disputed
1w ago

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but open_proce…

▾ Twilightagronholm · anyioEPSS 0.11%via NVD
CVE-2026-61548High· 8.1
1w ago

Rsyslog is a rocket-fast system for log processing

Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseSD_PARAM function in plugins/mmpstrucdata/mmpstrucdata.c stores RFC5424 parameter values in a fixed pVal[32 * 1024] st…

▾ Twilightrsyslog · rsyslogEPSS 0.94%via NVD
CVE-2026-55556High· 8.2PoC
1w ago

Rsyslog is a rocket-fast system for log processing

Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_auth_header function in contrib/imhttp/imhttp.c allocates a zero-byte heap buffer with calloc(0, len) when an HTTP Basic…

▾ Midnightrsyslog · rsyslogEPSS 0.85%via NVD
CVE-2026-46655High· 7.8PoC
1w ago

virtio-win provides Windows paravirtualized drivers for QEMU and KVM

virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*]…

▾ Midnightvirtio-win · kvm-guest-drivers-windowsEPSS 0.18%via NVD
CVE-2026-62943High· 8.7
1w ago

btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes

btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_filter_btrbk.sh constructs allow_stream_match with a start anchor but without an end-of-string anchor for the complete c…

▾ Twilightdigint · btrbkEPSS 0.50%via NVD
CVE-2026-93579Medium· 6.5
1w ago

A flaw was found in Netty's HTTP/2 stack

A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage Return, into HTTP/2 header field values due to insufficient validation. When thes…

▾ SunlitRed Hat · netty-codec-http2EPSS 0.58%via NVD
CVE-2026-91147Medium· 5.9PoC
1w ago

A flaw was found in `cockpit-ws`

A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is made t…

▾ TwilightRed Hat · cockpitEPSS 0.51%via NVD
CVE-2026-91142Low· 3.6
1w ago

A flaw was found in Cockpit

A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A low-privileg…

▾ SunlitRed Hat · cockpitEPSS 0.13%via NVD
CVE-2026-84449Low· 3.7PoC
1w ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() stores image-plane strides in an integer width that can overflow for extremely large RGB images created through heif_…

▾ Twilightstrukturag · libheifEPSS 0.43%via NVD
CVE-2026-84383Critical· 9.8PoC⚖ disputed
1w ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item graph using nested iden and auxl references can make HeifPixelImage::transfer_channel_from_image_as() append duplica…

▾ Abyssalstrukturag · libheifEPSS 0.61%via NVD
CVEs tagged “red-hat” — page 10 · VulnSea