Tagged “red-hat”
CVEs tagged red-hat, newest first.
2956 CVEsRSS
CVE-2026-79006Medium· 4.3chromium-browser: Google Chrome: Web origin policy bypass via crafted network traffic (CVE-2026-79006)
A flaw was found in Google Chrome. This vulnerability, located in the HttpsUpgrades component, allows a remote attacker to bypass the web origin policy. By sending specially crafted network traffic, an attacker could circumvent security re…
CVE-2026-79136Medium· 5.4chromium-browser: Chromium: Web origin policy bypass via incorrect ServiceWorker authorization (CVE-2026-79136)
A flaw was found in Chromium. This incorrect authorization vulnerability in the ServiceWorker component allows a remote attacker to bypass the web origin policy. By crafting a malicious HTML page, an attacker can circumvent security restri…
CVE-2026-79143Medium· 4.3chromium-browser: Google Chrome FileSystem: System access bypass through crafted HTML and social engineering (CVE-2026-79143)
A flaw was found in Google Chrome's FileSystem component. This incorrect authorization vulnerability allows a remote attacker to bypass system access restrictions. By leveraging social engineering techniques with a specially crafted HTML p…
CVE-2026-79199Medium· 4.3chromium-browser: Chromium-browser: System access restriction bypass via crafted HTML page (CVE-2026-79199)
A flaw was found in chromium-browser. This incorrect authorization vulnerability allows a remote attacker to bypass system access restrictions. By crafting a malicious HTML page, an attacker can gain unauthorized access within the network …
CVE-2026-79151Medium· 6.5⚖ disputedchromium-browser: Chromium-browser Safebrowsing: Bypass system access restrictions via improper input validation. (CVE-2026-79151)
A flaw was found in Chromium-browser's Safebrowsing component. A remote attacker could exploit this vulnerability by providing a specially crafted file. This could allow the attacker to bypass system access restrictions.
CVE-2026-79251Medium· 6.5⚖ disputedchromium-browser: Google Chrome: Web origin policy bypass via improper input validation (CVE-2026-79251)
A flaw was found in Google Chrome. Improper input validation in the Network component allows a remote attacker to potentially bypass the web origin policy. This can be achieved by enticing a user to visit a specially crafted HTML page. The…
CVE-2026-79217Medium· 5.4chromium-browser: chromium-browser: Incorrect authorization in Mobile (CVE-2026-79217)
An incorrect authorization flaw was found in the Mobile component of the Chromium browser. Upstream bug(s): https://code.google.com/p/chromium/issues/detail?id=514055709
CVE-2026-79020Medium· 4.3⚖ disputedchromium-browser: skia: chromium-browser: skia: Out of bounds read in Skia (CVE-2026-79020)
An out of bounds read flaw was found in the Skia component of the Chromium browser. Upstream bug(s): https://code.google.com/p/chromium/issues/detail?id=514017820
CVE-2026-79099Medium· 6.5chromium-browser: Google Chrome: System access restriction bypass via crafted HTML page (CVE-2026-79099)
A flaw was found in Google Chrome's Network component. A remote attacker could exploit this vulnerability by enticing a user to visit a specially crafted HTML page. This could allow the attacker to bypass system access restrictions, leadin…
CVE-2026-79173Medium· 4.3chromium-browser: Chromium-browser: UI spoofing via crafted HTML page (CVE-2026-79173)
A flaw was found in chromium-browser. A remote attacker could exploit this vulnerability by crafting a malicious HTML page, leading to user interface (UI) misrepresentation. This misrepresentation allows the attacker to spoof UI elements, …
CVE-2026-79191High· 7.6⚖ disputedchromium-browser: chromium-browser: Incorrect authorization in SiteIsolation (CVE-2026-79191)
An incorrect authorization flaw was found in the SiteIsolation component of the Chromium browser. Upstream bug(s): https://code.google.com/p/chromium/issues/detail?id=517606780
CVE-2026-79229Medium· 6.8chromium-browser: angle: Chromium: Information disclosure via uninitialized resource in ANGLE (CVE-2026-79229)
A flaw was found in ANGLE, a component within Chromium. This uninitialized resource vulnerability could allow a remote attacker, who has already compromised the renderer process, to read sensitive memory outside of the security sandbox. Th…
CVE-2026-79221Medium· 6.5chromium-browser: chromium-browser: Uninitialized resource in Dawn (CVE-2026-79221)
An uninitialized resource flaw was found in the Dawn component of the Chromium browser. Upstream bug(s): https://code.google.com/p/chromium/issues/detail?id=532923954
CVE-2026-79270High· 7.4chromium-browser: angle: Chromium-browser: Memory disclosure via uninitialized resource in ANGLE (CVE-2026-79270)
A flaw was found in chromium-browser. A remote attacker could exploit an uninitialized resource vulnerability in ANGLE by crafting a malicious HTML page. This could allow the attacker to read sensitive memory outside of the browser's secur…
CVE-2026-79042Medium· 5.4chromium-browser: Google Chrome: Missing authorization in Payments allows system access restriction bypass (CVE-2026-79042)
A flaw was found in Google Chrome on Android. Missing authorization in the Payments functionality allows a remote attacker, leveraging social engineering, to potentially bypass system access restrictions. This can be achieved by enticing a…
CVE-2026-79652Medium· 5.9A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak
A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access token…
CVE-2026-79776Medium· 5.3PoC⚖ disputedrclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler
rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler. Attackers can access the /debug/pprof/cmdline endpoint unauthenticated to retrieve the full p…
CVE-2026-14457High· 7.5Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solic…
Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solic…
CVE-2026-63072High· 7.5PoCIssue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-b…
Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-b…
CVE-2026-63076High· 7.5Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter
Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a d…
CVE-2026-75803Critical· 9.1⚖ disputedIssue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: …
Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: …
CVE-2026-63075High· 7.5Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection.…
Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection.…
CVE-2026-63074Medium· 5.9Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid)
Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequentl…
CVE-2026-63073Critical· 9.8⚖ disputedIssue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client t…
Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client t…
CVE-2026-54874High· 7.5Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic to mak…
Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic to mak…
CVE-2026-68515High· 7.1OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, exrmultiview can write past a heap…
CVE-2026-65979Medium· 5.5OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.12, the HTJ2K decoder parses a header-length field (PLEN) from a chunk's compr…
CVE-2026-59983Medium· 5.5OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds…
CVE-2026-59982High· 7.1OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 can return an out-of-bounds po…
CVE-2026-59189High· 7.1OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In OpenEXRUtil versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.12, the documented TypedDeepImageChannel<T…