VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2912 CVEsRSS

CVE-2026-18090Medium· 6.1
2w ago

A flaw was found in gdk-pixbuf

A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon…

▾ SunlitRed Hat · gdk-pixbuf2EPSS 0.17%via NVD
CVE-2026-19651High· 7.4
2w ago

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.

▾ TwilightIBM · Enterprise Build of QuarkusEPSS 0.26%via NVD
CVE-2026-19625Medium· 5.3⚖ disputed
2w ago

When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional…

When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional…

▾ SunlitIBM · Enterprise Build of QuarkusEPSS 0.23%via NVD
CVE-2026-85630Medium· 6.1
2w ago

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than lit…

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than lit…

▾ SunlitRed Hat · HTML-FormHandlerEPSS 0.24%via NVD
CVE-2026-85485Medium· 6.1⚖ disputed
2w ago

HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup

HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup. Version 0…

▾ SunlitRed Hat · HTML-FormHandlerEPSS 0.26%via NVD
CVE-2026-85484Medium· 6.1
2w ago

HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping. The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Sele…

HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping. The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Sele…

▾ SunlitRed Hat · HTML-FormHandlerEPSS 0.33%via NVD
CVE-2026-19872Medium· 6.1
2w ago

HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message. The wrappers and renderers that emit a form's errors interpolate the error string straight into…

HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message. The wrappers and renderers that emit a form's errors interpolate the error string straight into…

▾ SunlitRed Hat · HTML-FormHandlerEPSS 0.26%via NVD
CVE-2026-79721High· 8.6
2w ago

Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.

Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.

▾ Twilightmlflow · mlflowEPSS 0.47%via NVD
CVE-2026-69806High· 7.0
2w ago

Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.

Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.9%via NVD
CVE-2026-58649Medium· 6.5
2w ago

Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · .NET 10.0EPSS 0.27%via NVD
CVE-2026-57099High· 7.5
2w ago

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · AspNetCore.ODataEPSS 1.2%via NVD
CVE-2026-79602High· 8.8⚖ disputed
2w ago

A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.

A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.

▾ TwilightXen · XenEPSS 0.17%via NVD
CVE-2026-62437Medium· 6.5
2w ago

When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated removal of tracking structures for IRQs used by the devices occurs relatively early…

When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated removal of tracking structures for IRQs used by the devices occurs relatively early…

▾ SunlitXen · XenEPSS 0.12%via NVD
CVE-2026-19203High· 8.3
2w ago

A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused by…

A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused by…

▾ TwilightEclipse Foundation · Eclipse JettyEPSS 0.31%via NVD
CVE-2026-80219High· 8.7
2w ago

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

▾ TwilightRed Hat · rhbac-4/hawtio-operator-bundleEPSS 0.23%via NVD
CVE-2026-78234Critical· 9.9
2w ago

A flaw was found in hawtio-operator

A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author o…

▾ MidnightRed Hat · rhbac-4/hawtio-gateway-rhel9EPSS 0.39%via NVD
CVE-2026-77968High· 8.2
2w ago

A flaw was found in hawtio-operator

A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the Ser…

▾ TwilightRed Hat · rhbac-4/hawtio-operator-bundleEPSS 0.42%via NVD
CVE-2026-74860High· 8.5
2w ago

A flaw was found in libxml2 with Python bindings enabled

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This…

▾ TwilightRed Hat · libxml2EPSS 0.38%via NVD
CVE-2026-74859Medium· 6.8
2w ago

The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths

The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files outside ~/.themes by using ../ path traversal, absolute paths, or…

▾ SunlitRed Hat · gnome-tweaksEPSS 0.17%via NVD
CVE-2026-12611High· 8.7
2w ago

A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a race conditio…

A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a race conditio…

▾ TwilightEclipse Foundation · Eclipse JettyEPSS 0.25%via NVD
CVE-2026-11573High· 7.1
2w ago

Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase)

Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase). QDomElementPrivate::save() and QDomNodePrivate::save() recurse mutually, consuming one stack frame per level of elemen…

▾ Twilightqt · qtEPSS 0.39%via NVD
CVE-2026-86512Medium· 6.3PoC
2w ago

A vulnerability was identified in java-json-tools json-patch up to 1.13

A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move O…

▾ Twilightjava-json-tools · json-patchEPSS 0.37%via NVD
CVE-2026-78675High· 8.4⚖ disputed
2w ago

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables…

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

▾ Twilightgitpython · gitpythonEPSS 0.18%via OSV
CVE-2026-86425Low· 3.3
3w ago

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted list of images can trigger memory access after deallocation, result…

▾ Sunlitimagemagick · imagemagickEPSS 0.15%via NVD
CVE-2026-86424Low· 2.5
3w ago

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlin…

▾ Sunlitimagemagick · imagemagickEPSS 0.14%via NVD
CVE-2026-86422Low· 3.3
3w ago

ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions

ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap sym…

▾ Sunlitimagemagick · imagemagickEPSS 0.13%via NVD
CVE-2026-86420Low· 3.7
3w ago

ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails

ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service.

▾ Sunlitimagemagick · imagemagickEPSS 0.32%via NVD
CVE-2026-86404High· 8.8
3w ago

EAP's Artemis deserialization configuration permits deserialization by default

EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() met…

▾ TwilightRed Hat · eap7-activemq-artemisEPSS 0.85%via NVD
CVE-2026-18355High· 7.5
3w ago

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base)

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, …

▾ TwilightRed Hat · redhat-ds:11EPSS 0.84%via NVD
CVE-2026-84732High· 8.7
3w ago

Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow

Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow

▾ TwilightOpenVPN · OpenVPNEPSS 0.54%via NVD
CVEs tagged “red-hat” — page 49 · VulnSea