VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2912 CVEsRSS

CVE-2026-90679Medium· 4.3
2w ago

Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not allow account takeover or content modification

Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not allow account takeover or content modification. It does not verify that the HTTP Signature on an …

▾ SunlitForgejo · ForgejoEPSS 0.18%via NVD
CVE-2026-90678High· 7.5
2w ago

An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5

An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.77%via NVD
CVE-2026-90668High· 7.5
2w ago

The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request w…

The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request w…

▾ TwilightUnrealIRCd · UnrealIRCdEPSS 0.58%via NVD
CVE-2026-90771Low· 3.7PoC⚖ disputed
2w ago

joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code

joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the retur…

▾ Twilighthapijs · joiEPSS 0.39%via NVD
CVE-2026-90783High· 7.8
2w ago

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cau…

▾ TwilightMoritz Bunkus · MKVToolNixEPSS 0.20%via NVD
CVE-2026-90781Medium· 4.4PoC
2w ago

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long cont…

▾ TwilightALSA Project · alsa-libEPSS 0.17%via NVD
CVE-2026-90780High· 7.5
2w ago

SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes

SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP…

▾ TwilightSIPp · sippEPSS 0.86%via NVD
CVE-2026-90779High· 7.5
2w ago

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to …

▾ TwilightRed Hat · sippEPSS 0.80%via NVD
CVE-2026-90778High· 7.5
2w ago

SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more

SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversize…

▾ TwilightSIPp · sippEPSS 0.86%via NVD
CVE-2026-90776High· 7.5PoC
2w ago

Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments

Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separ…

▾ Midnightnodemailer · nodemailerEPSS 0.68%via NVD
CVE-2026-90584Medium· 5.3PoC
2w ago

A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1

A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameContinuousAndNonFin of the file Draft_6455.java of the component Fragmentation Handler. Executing a manipulation c…

▾ TwilightTooTallNate · Java-WebSocketEPSS 0.72%via NVD
CVE-2026-52297Low· 2.9⚖ disputed
2w ago

FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.

FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.

▾ SunlitFFmpeg · FFmpegEPSS 0.15%via NVD
CVE-2026-52296Low· 2.9⚖ disputed
2w ago

FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.

FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.

▾ SunlitFFmpeg · FFmpegEPSS 0.15%via NVD
CVE-2026-89266High· 8.2PoC
2w ago

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimension…

▾ Midnightnothings · stb_vorbisEPSS 0.64%via NVD
CVE-2026-90555Medium· 6.5
2w ago

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigge…

▾ Sunlitvllm · vllmEPSS 0.52%via NVD
CVE-2026-90554Medium· 6.2
2w ago

vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video input for NanoNemotronVL models

vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video input for NanoNemotronVL models. In nano_nemotron_vl.py, _extract_audio_from_videos calls load_audio_pyav(BytesIO(vi…

▾ Sunlitvllm · vllmEPSS 0.20%via NVD
CVE-2026-90553High· 7.8
2w ago

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbi…

▾ Twilightvllm · vllmEPSS 0.31%via NVD
CVE-2026-90616High· 7.4
2w ago

In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925

In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925. Flatpak c…

▾ TwilightFlatpak · FlatpakEPSS 0.18%via NVD
CVE-2026-90560High· 8.2PoC
2w ago

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply …

▾ MidnightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.62%via NVD
CVE-2026-90558Critical· 9.8
2w ago

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or…

▾ Midnightirontec · sngrepEPSS 0.88%via NVD
CVE-2026-90557Medium· 6.1
2w ago

Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices

Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-r…

▾ Sunlitfreeciv · freecivEPSS 0.18%via NVD
CVE-2026-90556High· 7.8
2w ago

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files th…

▾ Twilightfreeciv · freecivEPSS 0.20%via NVD
CVE-2026-87910Medium· 5.7
2w ago

When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive

When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the loca…

▾ SunlitPython Software Foundation · CPythonEPSS 0.54%via NVD
CVE-2026-80948Medium· 5.5
2w ago

kernel: wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() (CVE-2026-80948)

A flaw was found in the Linux kernel's iwlwifi driver. An error handling issue within the `iwl_op_mode_dvm_start()` function can cause a memory leak. This occurs when certain error paths bypass a memory deallocation step, leading to unrele…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.22%via CSAF
CVE-2026-89773Medium· 5.5
2w ago

kernel: drm/amd/display: Skip Update HDCP Config In Transition State (CVE-2026-89773)

A flaw was found in the `drm/amd/display` component of the Linux kernel. This vulnerability occurs because the High-bandwidth Digital Content Protection (HDCP) configuration routine is skipped during a transition state when an invalid `dm_…

▾ SunlitRed Hat · Red Hat Enterprise Linux 6EPSS 0.20%via CSAF
CVE-2026-89722Medium· 5.5
2w ago

kernel: PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io() (CVE-2026-89722)

A flaw was found in the Linux kernel's PCI/sysfs component. A local user with root privileges could trigger an out-of-bounds read in the `pci_write_legacy_io()` function by writing to the `legacy_io` sysfs file with a size less than four b…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89642High· 7.0
2w ago

kernel: cifs: call pagecache_isize_extended() in cifs_setsize() when extending (CVE-2026-89642)

A flaw was found in the Linux kernel's Common Internet File System (CIFS) implementation. When a client extends a file, the `cifs_setsize()` function fails to properly zero out the newly extended portion of the page cache. This oversight c…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.20%via CSAF
CVE-2026-89637High· 7.0⚖ disputed
2w ago

kernel: smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 (CVE-2026-89637)

A flaw was found in the Linux kernel's Server Message Block (SMB) client. When processing a malformed secondary TRANSACT2 response, a use-after-free (UAF) vulnerability and a buffer leak can occur in the `cifs_check_trans2()` function. Thi…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.63%via CSAF
CVE-2026-89556Medium· 5.5
2w ago

kernel: module: validate string table section types (CVE-2026-89556)

A flaw was found in the Linux kernel. This vulnerability arises from insufficient validation of string table section types within ELF (Executable and Linkable Format) files. A local attacker could exploit this by providing a specially craf…

▾ SunlitRed Hat · LinuxEPSS 0.21%via CSAF
CVE-2026-81004Medium· 5.5⚖ disputed
2w ago

kernel: ipmi:msghandler: Cancel work cleanly on an error (CVE-2026-81004)

A flaw was found in the Linux kernel's Intelligent Platform Management Interface (IPMI) message handler. When an error occurs during the startup of an IPMI interface, scheduled work may not be properly canceled. This can prevent the interf…

▾ SunlitRed Hat · LinuxEPSS 0.19%via CSAF
CVEs tagged “red-hat” — page 25 · VulnSea