VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2912 CVEsRSS

CVE-2026-92933Medium· 5.8PoC
1w ago

vm2 is a sandbox for running untrusted Node.js code

vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to the sandbox as an unfiltered shallow copy (`Object.assign({}, util)` in `defaultBuiltinLoaderUtil`), and the deprecated …

▾ Twilightpatriksimek · vm2EPSS 0.37%via NVD
CVE-2026-89418High· 8.7PoC
1w ago

google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields

google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nested START_GROUP wire bytes to any Node.js service that calls the generated deserializeB…

▾ MidnightGoogle · protobuf-javascript (aka google-protobuf npm package)EPSS 0.28%via NVD
CVE-2026-81829Medium· 5.3
1w ago

A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers

A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch UR…

▾ SunlitRed Hat · exploit-intelligence/agent-client-rhel9EPSS 0.58%via NVD
CVE-2026-92904Medium· 4.3
1w ago

A flaw was found in the foreman_remote_execution plugin's template invocations controller

A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller's view_job_invocations permission filt…

▾ SunlitRed Hat · rubygem-foreman_remote_executionEPSS 0.34%via NVD
CVE-2026-92925High· 7.1
1w ago

A flaw was found in Redis community

A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacke…

▾ TwilightRed Hat · redis:7EPSS 0.57%via NVD
CVE-2026-92893Medium· 4.3
1w ago

A flaw was found in the foreman_ansible plugin's Ansible inventory API

A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an unscoped Host.where call that does not enforce the search filter associated with the caller's view_hosts permission. An…

▾ SunlitRed Hat · rubygem-foreman_ansibleEPSS 0.28%via NVD
CVE-2026-92894Medium· 4.3
1w ago

A flaw was found in the foreman_ansible plugin's Ansible override values API

A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target LookupValue record by ID without verifying it belongs to an AnsibleVariable the caller is authorized to edit. An authent…

▾ SunlitRed Hat · rubygem-foreman_ansibleEPSS 0.26%via NVD
CVE-2026-86320High· 7.8PoC
1w ago

A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true

A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on…

▾ MidnightRed Hat · flatpak-builderEPSS 0.22%via NVD
CVE-2026-90982Medium· 5.3
1w ago

@fastify/static is a Fastify plugin that serves static files from a configured root directory

@fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4, on a case-insensitive filesystem such as Windows or the default macOS volume, a route guard or allowedPath restrict…

▾ Sunlit@fastify/static · @fastify/staticEPSS 0.58%via NVD
CVE-2026-54451High· 8.2PoC
1w ago

Elixir protobuf is a pure Elixir implementation of Google Protobuf

Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be taken offline when the schema contains a self-referential o…

▾ Midnightelixir-protobuf · protobufEPSS 0.52%via NVD
CVE-2026-64684Medium· 6.8
1w ago

RMCP is an official Rust SDK for the Model Context Protocol

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest…

▾ Sunlitmodelcontextprotocol · rust-sdkEPSS 0.50%via NVD
CVE-2026-85469High· 8.0
1w ago

A flaw was found in quay-builder-qemu

A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inj…

▾ TwilightRed Hat · quay/quay-builder-qemu-rhcos-rhel8EPSS 0.52%via NVD
CVE-2026-92595Medium· 5.9PoC
1w ago

Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` us…

Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` us…

▾ Twilightnodemailer · nodemailerEPSS 0.29%via NVD
CVE-2026-92597Medium· 6.5
1w ago

Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comme…

Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comme…

▾ Sunlitnodemailer · nodemailerEPSS 0.38%via NVD
CVE-2026-92598Medium· 6.5PoC
1w ago

Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers

Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient add…

▾ Twilightnodemailer · nodemailerEPSS 0.40%via NVD
CVE-2026-92596High· 7.5PoC
1w ago

Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list

Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a s…

▾ Midnightnodemailer · nodemailerEPSS 0.82%via NVD
CVE-2026-92599High· 7.5
1w ago

joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().isoDate()` validation rule

joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().isoDate()` validation rule. One of the regular expressions the rule applies to t…

▾ Twilighthapijs · joiEPSS 0.58%via NVD
CVE-2026-81872Medium· 6.3PoC
1w ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/log BatchingProcessor can enter a tight CPU loop when attacker-driven log emission fills its asynchronous export buffer…

▾ Twilightopen-telemetry · opentelemetry-goEPSS 0.52%via NVD
CVE-2026-81869Medium· 5.1PoC
1w ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail to enforce AttributeValueLengthLimit for string and string-slice attributes containing…

▾ Twilightopen-telemetry · opentelemetry-goEPSS 0.18%via NVD
CVE-2026-81871Medium· 6.3
1w ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate…

▾ Sunlitopen-telemetry · opentelemetry-goEPSS 0.33%via NVD
CVE-2026-81870Low· 2.0PoC
1w ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively includ…

▾ Twilightopen-telemetry · opentelemetry-goEPSS 0.19%via NVD
CVE-2026-62949Medium· 6.5
1w ago

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.24.0, _process_channel_open and _process_channel_open_confirmation in a…

▾ Sunlitronf · asyncsshEPSS 0.55%via NVD
CVE-2026-46352High· 7.5
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, Suricata's IP defragmentation code could deadlock when processing…

▾ TwilightOISF · suricataEPSS 0.47%via NVD
CVE-2026-75516High· 8.7
1w ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.34.0, AMQConnection.start() applies Math.min(maxInboundMessageBodySize, frameMax) after Connection.Tune ne…

▾ Twilightrabbitmq · rabbitmq-java-clientEPSS 0.55%via NVD
CVE-2026-81176Medium· 5.3
1w ago

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. Prior to 5.9.2, devalue.parse does not reject out-of-bounds indices that are greater than or equal to values.len…

▾ Sunlitsveltejs · devalueEPSS 0.51%via NVD
CVE-2026-91097Critical· 9.8PoC⚖ disputed
1w ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

▾ Abyssalhp · linux_imaging_and_printingEPSS 1.0%via NVD
CVE-2026-82399High· 7.5PoC
1w ago

CoreDNS is a DNS server written in Go

CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC request paths in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call d…

▾ Midnightcoredns · corednsEPSS 0.61%via NVD
CVE-2026-68536Critical· 9.8⚖ disputed
1w ago

Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affected.  Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.

Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affected.  Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.

▾ MidnightApache Software Foundation · org.apache.myfaces.core:myfaces-implEPSS 0.49%via NVD
CVE-2026-86003High· 7.5
1w ago

CoreDNS is a DNS server written in Go

CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC listeners in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call dns.M…

▾ Twilightcoredns · corednsEPSS 0.44%via NVD
CVE-2026-91099Critical· 9.8⚖ disputed
1w ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

▾ Midnighthp · linux_imaging_and_printingEPSS 0.98%via NVD
CVEs tagged “red-hat” — page 14 · VulnSea