VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2912 CVEsRSS

CVE-2026-85594Critical· 9.8⚖ disputed
3w ago

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from th…

▾ Midnighttraefik · traefikEPSS 0.48%via NVD
CVE-2026-85597Critical· 9.1
3w ago

Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host…

Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host…

▾ Midnighttraefik · traefikEPSS 0.35%via NVD
CVE-2026-85596Critical· 9.8⚖ disputed
3w ago

Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider

Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option generated for an Ingress carrying the nginx.ingress.kubernetes.io/auth-tls-secret annotation was named af…

▾ Midnighttraefik · traefikEPSS 0.43%via NVD
CVE-2026-85595Critical· 9.8
3w ago

Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection

Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute …

▾ Midnighttraefik · traefikEPSS 0.69%via NVD
CVE-2026-53769Medium· 6.5PoC
3w ago

Avo is a framework to create admin panels for Ruby on Rails apps

Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload…

▾ Twilightavo-hq · avoEPSS 0.42%via NVD
CVE-2026-85150High· 7.5
3w ago

A NULL pointer dereference flaw was found in GStreamer's RTSP support library

A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement aro…

▾ TwilightRed Hat · gstreamer1-plugins-baseEPSS 0.53%via NVD
CVE-2026-85180High· 7.5
3w ago

Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts

Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An attacker can control a registry, serve a malicious tensor-layer manifes…

▾ TwilightRed Hat · ollamaEPSS 0.50%via NVD
CVE-2026-85124High· 7.5
3w ago

@fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream

@fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handler skips the destination validation tha…

▾ Twilightfastify · fastify/http-proxyEPSS 0.74%via NVD
CVE-2026-85062Medium· 6.9
3w ago

Colord is a tiny yet powerful tool for high-performance color manipulations and conversions

Colord is a tiny yet powerful tool for high-performance color manipulations and conversions. Prior to 2.9.4, synchronous CSS color string matchers in src/colorModels/rgbString.ts, src/colorModels/hslString.ts, src/colorModels/hwbString.t…

▾ Sunlitomgovich · colordEPSS 0.51%via NVD
CVE-2026-85458Medium· 4.7
3w ago

Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height.

Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height.

▾ SunlitRed HatEPSS 0.14%via NVD
CVE-2026-85063Medium· 6.5
3w ago

node-csv is a full-featured CSV parser with a simple API that is tested against large datasets

node-csv is a full-featured CSV parser with a simple API that is tested against large datasets. Prior to 7.0.2, csv-parse with the columns and group_columns_by_name options enabled treats a duplicate __proto__ header as an existing prope…

▾ Sunlitcsv-parse · csv-parseEPSS 0.57%via NVD
CVE-2026-84968Medium· 5.3
3w ago

An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is …

An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is …

▾ Sunlitmongodb · php_driverEPSS 0.33%via NVD
CVE-2026-85049High· 8.8
3w ago

Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.41%via NVD
CVE-2026-63376High· 8.2⚖ disputed
3w ago

toml-node is a TOML parser for Node.js and the browser

toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Ob…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.68%via NVD
CVE-2026-77465High· 7.5⚖ disputed
3w ago

toml-node is a TOML parser for Node.js and the browser

toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() uses a Peggy 5.1.0 generated recursive-descent parser in lib/parser.js whose peg$parsevalue, peg$parsearray, and peg$parseinline_table_entry functions r…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.61%via NVD
CVE-2026-14199High· 7.1
3w ago

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a del…

▾ Twilightgrafana · grafanaEPSS 0.31%via NVD
CVE-2026-84377Medium· 6.5
3w ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination the user controls a…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.54%via NVD
CVE-2026-84382High· 7.5
3w ago

HTTPX2 is a next generation HTTP client for Python

HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bo…

▾ Twilighthttpx2 · httpx2EPSS 0.63%via NVD
CVE-2026-84380Medium· 5.6
3w ago

HTTPX2 is a next generation HTTP client for Python

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that already contains a caller-supplied Transfer-Encoding h…

▾ Sunlithttpx2 · httpx2EPSS 0.36%via NVD
CVE-2026-84379Medium· 5.3
3w ago

HTTPX2 is a next generation HTTP client for Python

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the files= three-ele…

▾ Sunlithttpx2 · httpx2EPSS 0.45%via NVD
CVE-2026-84378Medium· 5.9
3w ago

HTTPX2 is a next generation HTTP client for Python

HTTPX2 is a next generation HTTP client for Python. From 2.5.0 until 2.10.0, the HTTPX2 Server-Sent Events parser in src/httpx2/httpx2/_sse.py repeatedly copies and rescans buffered text in _SSELineDecoder.decode() when an attacker-contr…

▾ Sunlithttpx2 · httpx2EPSS 0.53%via NVD
CVE-2026-84330Medium· 5.4
3w ago

UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page

UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.26%via NVD
CVE-2026-84327Medium· 6.5⚖ disputed
3w ago

Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page

Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.31%via NVD
CVE-2026-84333Critical· 9.6
3w ago

Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.46%via NVD
CVE-2026-56855Medium· 5.3
3w ago

Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh

Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh

▾ Sunlitx · golang.org/x/cryptoEPSS 0.50%via OSV
CVE-2026-78662Medium· 5.3
3w ago

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding (CVE-2026-78662)

A flaw was found in golang.org/x/crypto/ssh. A malicious remote attacker could flood a channel's incoming requests before it is established, leading to a deadlock of the entire connection. This could result in a denial of service (DoS) for…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.43%via CSAF
CVE-2026-84470Medium· 6.4
3w ago

A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard…

A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard…

▾ SunlitRed Hat · automation-controllerEPSS 0.30%via NVD
CVE-2026-53682Medium· 5.3
3w ago

An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsy…

An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsy…

▾ SunlitRed Hat · pki-coreEPSS 0.21%via NVD
CVE-2026-84639High· 7.5
3w ago

thunderbird: Uninitialized memory in MIME parsing (CVE-2026-84639)

A flaw was found in Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.32%via CSAF
CVE-2026-84332Medium· 5.4
3w ago

chromium-browser: Google Chrome: System access restriction bypass via crafted HTML page (CVE-2026-84332)

A flaw was found in Google Chrome. This incorrect authorization vulnerability in SiteSettings allows a remote attacker to bypass system access restrictions by enticing a user to visit a specially crafted HTML page. This could lead to unaut…

▾ SunlitRed Hat · ChromeEPSS 0.29%via CSAF
CVEs tagged “red-hat” — page 53 · VulnSea