VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2956 CVEsRSS

CVE-2025-15613Medium· 6.5
3w ago

Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality

Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission to create Kyverno (Cluster)Policies can specify an external URL in a policy's apiCall/service conf…

▾ Sunlitkyverno · github.com/kyverno/kyvernoEPSS 0.27%via NVD
CVE-2026-83610Medium· 5.3
3w ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createEntityReference(name) a…

▾ Sunlitxmldom · @xmldom/xmldomEPSS 0.59%via NVD
CVE-2026-84371Medium· 5.4
3w ago

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value…

▾ SunlitRed Hat · Red Hat Satellite 6EPSS 0.30%via NVD
CVE-2026-84309Medium· 5.5
3w ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a …

▾ Sunlitpypdf · pypdfEPSS 0.18%via NVD
CVE-2026-84311Medium· 5.5
3w ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of reused fo…

▾ Sunlitpypdf · pypdfEPSS 0.18%via NVD
CVE-2026-84310Medium· 5.5
3w ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines wi…

▾ Sunlitpypdf · pypdfEPSS 0.18%via NVD
CVE-2026-17615High· 7.5
4w ago

A flaw was found in RESTEasy's SourceProvider

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external …

▾ TwilightRed Hat · keycloak-rhel9-containerEPSS 0.35%via NVD
CVE-2026-82662Medium· 6.5PoC
4w ago

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth…

▾ Twilightnodemailer · nodemailerEPSS 0.19%via NVD
CVE-2026-82661Medium· 5.4PoC
4w ago

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF se…

▾ Twilightnodemailer · nodemailerEPSS 0.26%via NVD
CVE-2026-82853Medium· 4.9
4w ago

Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands

Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return a…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 1.0%via NVD
CVE-2026-82660Medium· 5.4
4w ago

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content field…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.26%via NVD
CVE-2026-82659High· 7.1
4w ago

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href pr…

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href pr…

▾ TwilightRed Hat · Red Hat Developer HubEPSS 0.35%via NVD
CVE-2024-58379Medium· 5.3
4w ago

nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments

nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicio…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.30%via NVD
CVE-2026-81624High· 7.5
4w ago

Undertow is a flexible performant web server used in JBoss EAP and WildFly

Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot …

▾ TwilightRed Hat · undertow-coreEPSS 0.58%via NVD
CVE-2026-83596High· 8.8
4w ago

A flaw was found in WebKitGTK

A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.

▾ TwilightWebKit · webkitEPSS 0.29%via NVD
CVE-2026-82393High· 7.5
4w ago

pnpm is a package manager

pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for…

▾ Twilightpnpm · pnpmEPSS 0.63%via NVD
CVE-2026-82392High· 7.1
4w ago

pnpm is a package manager

pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builde…

▾ Twilightpnpm · pnpmEPSS 0.61%via NVD
CVE-2026-82398Medium· 5.3
4w ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without…

▾ Sunlitpypdf · pypdfEPSS 0.52%via NVD
CVE-2026-62993Medium· 8.6
4w ago

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 4.5.7 and 5.8.2, depending on the release line, Smarty's {fetch} handling in libs/plugins/function.fetch.php and…

▾ Sunlitsmarty · smarty/smartyEPSS 0.57%via NVD
CVE-2026-82556Medium· 6.3
4w ago

A vulnerability was found in Forgejo up to 15.0.4

A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration Handler. Performing a manipulation resu…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.37%via NVD
CVE-2026-82562Low· 3.7
4w ago

### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the …

### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.54%via NVD
CVE-2026-82417Medium· 5.3⚖ disputed
4w ago

### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member

### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)`…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.42%via NVD
CVE-2026-82474High· 7.8
1mo ago

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.13%via NVD
CVE-2026-37237High· 7.5
1mo ago

vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion

vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.fetch_audio and AsyncMediaIO.fetch_image functions in multimodal/inputs.py fetch user-supplied media URLs using …

▾ TwilightRed Hat · Red Hat AI Inference ServerEPSS 0.75%via NVD
CVE-2026-82333High· 7.5
1mo ago

multer: Multer: Denial of Service via oversized array index in field names (CVE-2026-82333)

A flaw was found in Multer, a Node.js middleware for handling multipart/form-data. A remote attacker can send a specially crafted multipart request containing oversized array indices in field names. This can cause Multer's field parser to …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.49%via CSAF
CVE-2026-77078High· 7.5PoC
1mo ago

multer: Multer: Denial of Service via crafted multipart field names (CVE-2026-77078)

A flaw was found in multer, a Node.js middleware for handling multipart/form-data. A remote attacker can send a small multipart request containing two specially crafted text field names. This can cause an uncaught error that terminates the…

▾ MidnightRed Hat · Red Hat Developer HubEPSS 0.49%via CSAF
CVE-2026-77063Low· 3.7
1mo ago

multer: Multer: File size limit bypass via asynchronous file filter race condition (CVE-2026-77063)

A flaw was found in multer, a software component used in Node.js applications to handle file uploads. When an application configures an asynchronous file filter along with a file size limit, a race condition can occur. This vulnerability a…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.23%via CSAF
CVE-2026-77037High· 7.5
1mo ago

multer: Multer: Denial of Service via file descriptor leak on aborted uploads (CVE-2026-77037)

A flaw was found in multer, a Node.js middleware for handling multipart/form-data. A remote attacker can exploit a file descriptor leak by sending repeated aborted or malformed multipart uploads. This can exhaust system resources, leading …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.58%via CSAF
CVE-2025-30156High· 8.9
1mo ago

Ceph is an open-source distributed storage platform providing object, block, and file storage

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol encrypts tickets with AES-128-CBC in an unauthenticated mode that us…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.09%via NVD
CVE-2026-37236Critical· 9.8⚖ disputed
1mo ago

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-ww…

▾ MidnightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.43%via NVD
CVEs tagged “red-hat” — page 56 · VulnSea