VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2912 CVEsRSS

CVE-2026-17615High· 7.5
4w ago

A flaw was found in RESTEasy's SourceProvider

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external …

▾ TwilightRed Hat · keycloak-rhel9-containerEPSS 0.35%via NVD
CVE-2026-82662Medium· 6.5PoC
4w ago

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth…

▾ Twilightnodemailer · nodemailerEPSS 0.19%via NVD
CVE-2026-82661Medium· 5.4PoC
4w ago

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF se…

▾ Twilightnodemailer · nodemailerEPSS 0.26%via NVD
CVE-2026-82853Medium· 4.9
4w ago

Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands

Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return a…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 1.0%via NVD
CVE-2026-82660Medium· 5.4
4w ago

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content field…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.26%via NVD
CVE-2026-82659High· 7.1
4w ago

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href pr…

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href pr…

▾ TwilightRed Hat · Red Hat Developer HubEPSS 0.35%via NVD
CVE-2024-58379Medium· 5.3
4w ago

nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments

nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicio…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.30%via NVD
CVE-2026-81624High· 7.5
4w ago

Undertow is a flexible performant web server used in JBoss EAP and WildFly

Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot …

▾ TwilightRed Hat · undertow-coreEPSS 0.58%via NVD
CVE-2026-83596High· 8.8
4w ago

A flaw was found in WebKitGTK

A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.

▾ TwilightWebKit · webkitEPSS 0.29%via NVD
CVE-2026-82393High· 7.5
4w ago

pnpm is a package manager

pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for…

▾ Twilightpnpm · pnpmEPSS 0.63%via NVD
CVE-2026-82392High· 7.1
4w ago

pnpm is a package manager

pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builde…

▾ Twilightpnpm · pnpmEPSS 0.61%via NVD
CVE-2026-82398Medium· 5.3
4w ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without…

▾ Sunlitpypdf · pypdfEPSS 0.52%via NVD
CVE-2026-62993Medium· 8.6
4w ago

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 4.5.7 and 5.8.2, depending on the release line, Smarty's {fetch} handling in libs/plugins/function.fetch.php and…

▾ Sunlitsmarty · smarty/smartyEPSS 0.57%via NVD
CVE-2026-82556Medium· 6.3
4w ago

A vulnerability was found in Forgejo up to 15.0.4

A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration Handler. Performing a manipulation resu…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.37%via NVD
CVE-2026-82562Low· 3.7
4w ago

### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the …

### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.54%via NVD
CVE-2026-82417Medium· 5.3⚖ disputed
4w ago

### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member

### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)`…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.42%via NVD
CVE-2026-82474High· 7.8
1mo ago

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.13%via NVD
CVE-2026-37237High· 7.5
1mo ago

vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion

vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.fetch_audio and AsyncMediaIO.fetch_image functions in multimodal/inputs.py fetch user-supplied media URLs using …

▾ TwilightRed Hat · Red Hat AI Inference ServerEPSS 0.75%via NVD
CVE-2025-30156High· 8.9
1mo ago

Ceph is an open-source distributed storage platform providing object, block, and file storage

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol encrypts tickets with AES-128-CBC in an unauthenticated mode that us…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.09%via NVD
CVE-2026-37236Critical· 9.8⚖ disputed
1mo ago

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-ww…

▾ MidnightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.43%via NVD
CVE-2026-56854Medium· 6.8
1mo ago

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions (CVE-2026-56854)

A flaw was found in golang.org/x/crypto/ssh. The component failed to properly enforce source-address restrictions for several authentication methods, including password and keyboard-interactive callbacks. In applications that misuse the Se…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.44%via CSAF
CVE-2026-47885High· 7.5
1mo ago

The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28

The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28

▾ Twilightvmware · spring_frameworkEPSS 0.37%via NVD
CVE-2026-80213Medium· 4.0
1mo ago

An issue was discovered in the resolv gem before 0.7.2 for Ruby

An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length into a single octet without checking its range. A label longer than 255 octets had its length stored modulo 256 but t…

▾ SunlitRuby · resolvEPSS 0.35%via NVD
CVE-2026-47883Medium· 6.1PoC
1mo ago

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6…

▾ Twilightvmware · spring_frameworkEPSS 0.26%via NVD
CVE-2026-47886High· 7.5
1mo ago

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent…

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent…

▾ Twilightvmware · spring_frameworkEPSS 0.46%via NVD
CVE-2026-47888High· 7.5
1mo ago

A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 -…

A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 -…

▾ Twilightvmware · spring_frameworkEPSS 0.46%via NVD
CVE-2026-47887Medium· 6.1
1mo ago

A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spri…

A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spri…

▾ Sunlitvmware · spring_frameworkEPSS 0.24%via NVD
CVE-2026-80212High· 7.5
1mo ago

An issue was discovered in the resolv gem before 0.7.2 for Ruby

An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::Resource.get_class, Resolv::DNS::Resource::Generic.create, and Resolv::DNS::SvcParam::Generic.create generate a new class for each unknown DNS resource record …

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.57%via NVD
CVE-2026-5680High· 7.5
1mo ago

A flaw was found in Undertow

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDef…

▾ TwilightRed Hat · undertow-coreEPSS 1.1%via NVD
CVE-2026-47857Medium· 5.9
1mo ago

In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.5.0 - 3.7.19 Reactor Core 3.4.41 and ea…

In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.5.0 - 3.7.19 Reactor Core 3.4.41 and ea…

▾ Sunlitbroadcom · reactor_coreEPSS 0.37%via NVD
CVEs tagged “red-hat” — page 55 · VulnSea