VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2912 CVEsRSS

CVE-2026-57967Critical· 9.8⚖ disputed
2w ago

An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 thr…

An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 thr…

▾ Midnightapache · artemisEPSS 1.1%via NVD
CVE-2026-88265Medium· 5.6
2w ago

A flaw was found in crun

A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configura…

▾ SunlitRed Hat · crunEPSS 0.15%via NVD
CVE-2026-45766High· 7.5
2w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state structures were insufficiently bounded. Crafted NFS traffi…

▾ Twilightoisf · suricataEPSS 0.62%via NVD
CVE-2026-88050Medium· 5.5PoC
2w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted .traineddata recoder component. UnicharCo…

▾ Twilighttesseract-ocr · tesseract_ocrEPSS 0.14%via NVD
CVE-2026-45769High· 7.5PoC
2w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5,IKEv2 parser state could grow without bounds while storing client transforms. Repeat…

▾ Midnightoisf · suricataEPSS 1.8%via NVD
CVE-2026-89046High· 8.2PoC
2w ago

zstd-jni: zstd-jni: Information disclosure or denial of service via out-of-bounds read (CVE-2026-89046)

A flaw was found in zstd-jni. This out-of-bounds read vulnerability in the Zstd.getFrameContentSize function occurs because it fails to validate negative srcPosition arguments. A remote attacker can supply negative offset values, bypassing…

▾ MidnightRed Hat · Red Hat Ceph Storage 9EPSS 0.65%via CSAF
CVE-2026-87933High· 8.6PoC
2w ago

cJSON: cJSON: Memory corruption via use after free in cJSONUtils_MergePatch (CVE-2026-87933)

A flaw was found in DaveGamble cJSON. The `cJSONUtils_MergePatch` function in `cJSON_Utils.c` is vulnerable to a use-after-free error. A remote attacker could exploit this memory corruption vulnerability, potentially leading to information…

▾ MidnightRed Hat · Red Hat Satellite 6EPSS 0.53%via CSAF
CVE-2026-49364Critical· 9.1
2w ago

An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache Act…

An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache Act…

▾ Midnightapache · artemisEPSS 0.57%via NVD
CVE-2026-89045Medium· 4.0PoC
2w ago

zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops

zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops. Attackers can pass negative length values to cause the read method…

▾ Twilightluben · zstd-jniEPSS 0.18%via NVD
CVE-2026-84042High· 7.8
2w ago

A flaw was found in crun

A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The iss…

▾ TwilightRed Hat · crunEPSS 0.14%via NVD
CVE-2026-88886High· 7.8
2w ago

Renovate is a dependency update automation tool

Renovate is a dependency update automation tool. In versions before 44.14.7 (and in Mend Renovate CE/EE distributions before 15.4.0, and the mend-renovate-enterprise-edition Helm chart before 10.4.0), the manager/gradle-wrapper module do…

▾ Twilightrenovatebot · renovateEPSS 0.23%via NVD
CVE-2026-88889High· 7.8
2w ago

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attacke…

▾ Twilightrenovatebot · renovateEPSS 1.0%via NVD
CVE-2026-88883High· 7.7⚖ disputed
2w ago

Renovate is an automated dependency update tool

Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0), log sanitisation for TLS private keys used for …

▾ Twilightrenovatebot · renovateEPSS 0.39%via NVD
CVE-2026-88879High· 8.2⚖ disputed
2w ago

Traefik is an HTTP reverse proxy and load balancer

Traefik is an HTTP reverse proxy and load balancer. In Traefik v1.x, v2.x through v2.11.55, and v3.0.0 through v3.7.11, header names are canonicalized only on dashes, so X-Auth-User, X_Auth_User and X.Auth.User are treated as three disti…

▾ Twilighttraefik · traefikEPSS 0.29%via NVD
CVE-2026-88878Medium· 5.3⚖ disputed
2w ago

Traefik is an HTTP reverse proxy and load balancer

Traefik is an HTTP reverse proxy and load balancer. In versions >= v2.8.2 through <= v2.11.55 and >= v3.0.0 through <= v3.7.11, the entryPoints.<name>.transport.respondingTimeouts settings — notably readTimeout, which is enabled by defau…

▾ Sunlittraefik · traefikEPSS 0.42%via NVD
CVE-2026-88859Medium· 6.3
2w ago

A flaw was found in Evolution

A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler in…

▾ SunlitRed Hat · evolutionEPSS 0.53%via NVD
CVE-2026-84828Medium· 6.5
2w ago

A flaw was found in PCS (Pacemaker Configuration System)

A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the fi…

▾ SunlitRed Hat · pcsEPSS 0.14%via NVD
CVE-2026-88770Medium· 6.5
2w ago

A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution

A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue occurs because the token redemption process fails to check if a user account is currently locked due to brute-forc…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.35%via NVD
CVE-2026-49837Medium· 5.9
2w ago

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4.6.0 contain a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the f…

▾ Sunlitosrg · gobgpEPSS 0.33%via NVD
CVE-2026-49838Medium· 5.9
2w ago

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.7.0, GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for …

▾ Sunlitosrg · gobgpEPSS 0.41%via NVD
CVE-2026-87795High· 8.2PoC
2w ago

com.github.luben/zstd-jni: zstd-jni: Out-of-bounds read in ZstdDictCompress constructor leads to denial of service (CVE-2026-87795)

A flaw was found in zstd-jni. This vulnerability occurs due to insufficient validation of offset and length parameters within the `ZstdDictCompress` constructor. An attacker can exploit this by providing untrusted values, leading to an out…

▾ MidnightRed Hat · Red Hat Ceph Storage 9EPSS 0.63%via CSAF
CVE-2026-87825High· 7.7PoC
2w ago

zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced

zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced. Attackers can close a dic…

▾ Midnightluben · zstd-jniEPSS 0.20%via NVD
CVE-2026-87877High· 7.7PoC
2w ago

zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes

zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointer…

▾ Midnightluben · zstd-jniEPSS 0.20%via NVD
CVE-2026-87823High· 8.2PoC
2w ago

zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets

zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets. Attackers can supply negative offset values near…

▾ Midnightluben · zstd-jniEPSS 0.43%via NVD
CVE-2026-61915Medium· 4.2
2w ago

An issue was discovered in Cyrus IMAP before 3.12.4

An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two o…

▾ Sunlitcyrus · imapEPSS 0.26%via NVD
CVE-2026-61909Low· 3.5
2w ago

An issue was discovered in Cyrus IMAP before 3.12.4

An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contact…

▾ Sunlitcyrus · imapEPSS 0.20%via NVD
CVE-2026-61910Low· 3.5
2w ago

An issue was discovered in Cyrus IMAP before 3.12.4

An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annot…

▾ Sunlitcyrus · imapEPSS 0.19%via NVD
CVE-2026-18147High· 8.1
2w ago

A flaw was found in FreeIPA

A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and comple…

▾ TwilightRed Hat · ipaEPSS 0.33%via NVD
CVE-2026-61908Low· 3.1
2w ago

An issue was discovered in Cyrus IMAP before 3.12.4

An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could rea…

▾ Sunlitcyrus · imapEPSS 0.22%via NVD
CVE-2026-87876Low· 3.0PoC
2w ago

Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certai…

Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certai…

▾ TwilightRed Hat · cups-mainEPSS 0.33%via NVD
CVEs tagged “red-hat” — page 41 · VulnSea