VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2912 CVEsRSS

CVE-2026-18924Critical· 9.1PoC⚖ disputed
3w ago

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

▾ Abyssalhaxx · curlEPSS 0.58%via NVD
CVE-2026-13608High· 7.4PoC⚖ disputed
3w ago

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a …

▾ Midnighthaxx · curlEPSS 0.48%via NVD
CVE-2026-83534Medium· 6.4
3w ago

PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege

PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and late…

▾ SunlitDALIBO · PostgreSQL AnonymizerEPSS 0.19%via NVD
CVE-2026-19634Medium· 6.4
3w ago

PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions

PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_database_rules() o…

▾ SunlitDALIBO · PostgreSQL AnonymizerEPSS 0.18%via NVD
CVE-2026-19633High· 8.8
3w ago

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in t…

▾ TwilightDALIBO · PostgreSQL AnonymizerEPSS 0.42%via NVD
CVE-2026-86253Medium· 5.9
3w ago

h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic()

h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname is not normalized, so percent-encoded dot segments (%2e%2e) are passed to decodeURI() and decode…

▾ Sunlith3js · h3EPSS 0.62%via NVD
CVE-2026-86252Medium· 5.3PoC
3w ago

h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns

h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns. Attackers can inject event type di…

▾ Twilighth3js · h3EPSS 0.36%via NVD
CVE-2026-86251Medium· 5.9PoC
3w ago

h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility

h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allows a request path containing double-encoded dot sequences (e.g. %252e%252e) to be decoded to %2e%2e, which survives r…

▾ Twilighth3js · h3EPSS 0.43%via NVD
CVE-2026-86250High· 7.5
3w ago

h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions

h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted cookie header with an extremely large chunk…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.49%via NVD
CVE-2026-86205Medium· 5.4PoC
3w ago

h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pathname

h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pathname. Attackers can craft a same-origin URL with a double-slash …

▾ Twilighth3js · h3EPSS 0.27%via NVD
CVE-2026-6554Medium· 5.5
3w ago

libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does not limit the number of loop iterations

libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does not limit the number of loop iterations. In particular uncommon use cases a crafted filter …

▾ SunlitThe Tcpdump Group · libpcapEPSS 0.14%via NVD
CVE-2026-6244Medium· 5.5
3w ago

libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero

libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero.

▾ SunlitThe Tcpdump Group · libpcapEPSS 0.14%via NVD
CVE-2026-31912Medium· 5.5
3w ago

libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer

libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer. In particular …

▾ SunlitThe Tcpdump Group · libpcapEPSS 0.14%via NVD
CVE-2026-31911Medium· 5.5
3w ago

libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode

libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process.

▾ SunlitThe Tcpdump Group · libpcapEPSS 0.14%via NVD
CVE-2026-18313Medium· 4.3
3w ago

rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use

rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious client can cause …

▾ SunlitThe Tcpdump Group · libpcapEPSS 0.23%via NVD
CVE-2026-18238Medium· 5.0
3w ago

The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers

The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process…

▾ SunlitThe Tcpdump Group · libpcapEPSS 0.18%via NVD
CVE-2026-0799High· 8.7
3w ago

In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value

In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use c…

▾ TwilightThe Tcpdump Group · libpcapEPSS 0.11%via NVD
CVE-2025-15614Low· 3.3
3w ago

ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files

ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files that cause the decompressor to read one byte past the allocated h…

▾ SunlitGenivia · ugrepEPSS 0.12%via NVD
CVE-2026-86145High· 8.2
3w ago

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a …

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a …

▾ TwilightPCRE · PCRE2EPSS 0.39%via NVD
CVE-2026-86144Medium· 5.6
3w ago

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses th…

▾ Sunlitxmlsoft · libxml2EPSS 0.19%via NVD
CVE-2026-86143Medium· 6.9
3w ago

In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback

In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security rele…

▾ Sunlitxmlsoft · libxml2EPSS 0.19%via NVD
CVE-2026-86142Medium· 6.9
3w ago

In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.

In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.

▾ Sunlitxmlsoft · libxml2EPSS 0.16%via NVD
CVE-2026-86141Low· 2.9
3w ago

xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.

xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.

▾ Sunlitxmlsoft · libxml2EPSS 0.17%via NVD
CVE-2026-86140High· 8.0
3w ago

In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.

In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.

▾ Twilightxmlsoft · libxml2EPSS 0.16%via NVD
CVE-2026-86139Medium· 6.9
3w ago

In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

▾ Sunlitxmlsoft · libxml2EPSS 0.17%via NVD
CVE-2026-86138Medium· 6.9
3w ago

In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.

In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.

▾ Sunlitxmlsoft · libxml2EPSS 0.13%via NVD
CVE-2026-86137Low· 2.9
3w ago

In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.

In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.

▾ Sunlitxmlsoft · libxml2EPSS 0.18%via NVD
CVE-2026-85666High· 7.5
3w ago

OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an unauthenticated server-side request forgery vulnerability in the OpenAI-compatible POST /v1/responses endpoint

OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an unauthenticated server-side request forgery vulnerability in the OpenAI-compatible POST /v1/responses endpoint. MCP tool definitions accept a server_url parameter (along …

▾ Twilightogx-ai · ogxEPSS 0.73%via NVD
CVE-2026-85676Medium· 4.3
3w ago

Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement

Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attackers can append the redir_url parameter to any short link to redir…

▾ Sunlitdubinc · dubEPSS 0.42%via NVD
CVE-2026-85625High· 8.1PoC
3w ago

sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, and dispatches any matched operator key including $where

sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, and dispatches any matched operator key including $where. The $where operation compiles a string value into a function using new Function …

▾ Midnightcrcn · sift.jsEPSS 0.73%via NVD
CVEs tagged “red-hat” — page 51 · VulnSea