VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2912 CVEsRSS

CVE-2026-57176Medium· 6.8
3d ago

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same appli…

▾ Sunlitpython-social-auth · social-coreEPSS 0.22%via NVD
CVE-2026-57177Medium· 4.3
3d ago

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login C…

▾ Sunlitpython-social-auth · social-coreEPSS 0.11%via NVD
CVE-2026-57179Medium· 4.2
3d ago

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it…

▾ Sunlitpython-social-auth · social-coreEPSS 0.16%via NVD
CVE-2026-88372High· 7.5PoC⚖ disputed
3d ago

libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files.

libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files.

▾ MidnightRed Hat · Red Hat Enterprise Linux 10EPSS 0.39%via NVD
CVE-2026-93542Medium· 6.5
3d ago

An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client.

An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client.

▾ Sunlitx.org · libXiEPSS 0.25%via NVD
CVE-2026-97417High· 7.5
3d ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() The timestamp-only fast path dereferences the option stream as *(__be32 *)ptr, which assumes 4-byte ali…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() The timestamp-only fast path dereferences the option stream as *(__be32 *)ptr, which assumes 4-byte ali…

▾ TwilightLinux · LinuxEPSS 0.43%via NVD
CVE-2026-88367Medium· 6.5PoC
3d ago

NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization

NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization. A specially crafted SVG document containing an extremely large stroke-width can cause floating-point rounding …

▾ TwilightRed HatEPSS 0.15%via NVD
CVE-2026-93543High· 7.4
3d ago

An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

▾ Twilightx.org · libXiEPSS 0.25%via NVD
CVE-2026-93544Medium· 6.5
3d ago

An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.

An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.

▾ Sunlitx.org · libXiEPSS 0.24%via NVD
CVE-2026-93545Medium· 6.5
3d ago

An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

▾ Sunlitx.org · libXiEPSS 0.20%via NVD
CVE-2026-88385High· 7.5
3d ago

Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() during malformed XML parsing

Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() during malformed XML parsing. Specially crafted XML input can cause text nodes allocated by mxmlNewText() to become unlinked before a parse error transfers control t…

▾ TwilightRed HatEPSS 0.15%via NVD
CVE-2026-94281Medium· 6.5
3d ago

An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

▾ Sunlitx.org · libXiEPSS 0.20%via NVD
CVE-2026-88384Medium· 5.5PoC
3d ago

OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path

OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path. A specially crafted EXR file containing an unknown-type attribute with dataSize set to zero causes the parser to create an opaque attribute with a NULL…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.19%via NVD
CVE-2026-88383Medium· 6.5
3d ago

libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind()

libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind(). When parsing iCalendar data containing a parameterized property, the function passes icalparameter_compare_kind_map() to bsearch() through an inco…

▾ SunlitRed Hat · Red Hat Enterprise Linux 7EPSS 0.17%via NVD
CVE-2026-96746Medium· 6.5
3d ago

An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the en…

An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the en…

▾ SunlitMongoDB · C DriverEPSS 0.37%via NVD
CVE-2026-96745Medium· 5.6
3d ago

Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects

Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application registers…

▾ SunlitMongoDB · PHP DriverEPSS 0.30%via NVD
CVE-2026-93541Medium· 6.5
3d ago

An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a

An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a

▾ SunlitX.org · libXiEPSS 0.24%via NVD
CVE-2026-67233Medium· 6.0
3d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The shovel management resource's is_authorized/2 delegates to rabbit_mgmt_util:is_authorized_monitor/2, which accepts the monitori…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.30%via NVD
CVE-2026-90959High· 8.1
3d ago

A path traversal vulnerability was found in pulpcore

A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme valida…

▾ TwilightRed Hat · ansible-automation-platform-24/hub-rhel8EPSS 0.32%via NVD
CVE-2026-77874High· 8.6
3d ago

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to vie…

▾ TwilightIBM · Enterprise Build of QuarkusEPSS 0.43%via NVD
CVE-2026-73064Low· 2.9
3d ago

In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream

In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 servers.

▾ Sunlittrustedfirmware · Mbed TLSEPSS 0.10%via NVD
CVE-2026-97059High· 8.2
3d ago

DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames

DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. Attackers can craft malicious DICOM inst…

▾ TwilightOFFIS · DCMTKEPSS 0.35%via NVD
CVE-2026-97058Medium· 5.3PoC
3d ago

sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions

sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision value…

▾ Twilightalexei · sprintf-jsEPSS 0.37%via NVD
CVE-2026-97057High· 7.5
3d ago

redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length

redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis e…

▾ TwilightNodeRedis · redis-parserEPSS 0.39%via NVD
CVE-2026-88360Medium· 5.5
3d ago

libvips 8.19.0 contains a memory access vulnerability when processing little-endian PFM images

libvips 8.19.0 contains a memory access vulnerability when processing little-endian PFM images. If the PFM text header length is not a multiple of four bytes, the mmap-based loader can expose pixel data at an address that is not properly…

▾ SunlitRed HatEPSS 0.14%via NVD
CVE-2026-88359Medium· 6.5PoC
3d ago

libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format()

libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML document containing a very large literal or folded block scalar, the function repeatedly grows an internal buffer…

▾ TwilightRed HatEPSS 0.15%via NVD
CVE-2026-95521High· 7.8
3d ago

A command injection flaw was found in rpm

A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating th…

▾ TwilightRed Hat · rpmEPSS 0.58%via NVD
CVE-2026-95519High· 7.8
3d ago

A flaw was found in rpm

A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest …

▾ TwilightRed Hat · rpmEPSS 0.14%via NVD
CVE-2026-94416Medium· 6.8
3d ago

An authorization bypass was found in the Ansible Automation Platform (AAP) gateway

An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because service-key creation is not…

▾ SunlitRed Hat · ansible-automation-platform-25/gateway-rhel8EPSS 0.45%via NVD
CVE-2026-97311Medium· 4.3
3d ago

A flaw was found in the Admin REST API of Keycloak, an identity and access management solution

A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specific role do not properly check for individual group visibility permissions. This…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.24%via NVD
CVEs tagged “red-hat” — page 3 · VulnSea