VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2956 CVEsRSS

CVE-2026-59187High· 7.1
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 are vulnerable to a heap out-of-bounds write w…

▾ TwilightRed HatEPSS 0.40%via NVD
CVE-2026-59186High· 7.1
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, a crafted tiled EXR can trigger a …

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.41%via NVD
CVE-2026-59184High· 7.1
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dat…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.40%via NVD
CVE-2026-52491High· 8.4
1mo ago

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component

▾ TwilightRed Hat · Red Hat Enterprise Linux 7EPSS 0.19%via NVD
CVE-2026-78679Medium· 6.5
1mo ago

GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard

GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arb…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.26%via NVD
CVE-2026-78701Medium· 6.5
1mo ago

A flaw was found in 389-ds-base

A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a conne…

▾ SunlitRed Hat · 389-ds-baseEPSS 0.78%via NVD
CVE-2023-54354Medium· 5.9
1mo ago

Rejected reason: This CVE ID has been rejected as a duplicate.

Rejected reason: This CVE ID has been rejected as a duplicate.

▾ SunlitRed Hat · Red Hat Satellite 6EPSS 0.35%via NVD
CVE-2022-50999High· 7.0
1mo ago

Rejected reason: This CVE ID has been rejected as a duplicate.

Rejected reason: This CVE ID has been rejected as a duplicate.

▾ TwilightRed HatEPSS 0.30%via NVD
CVE-2022-50998High· 7.5
1mo ago

Rejected reason: This CVE ID has been rejected as a duplicate.

Rejected reason: This CVE ID has been rejected as a duplicate.

▾ TwilightRed HatEPSS 0.35%via NVD
CVE-2021-47996High· 7.5
1mo ago

Rejected reason: This CVE ID has been rejected as a duplicate.

Rejected reason: This CVE ID has been rejected as a duplicate.

▾ TwilightRed HatEPSS 0.50%via NVD
CVE-2026-78678Medium· 6.5
1mo ago

gitpython: GitPython: Arbitrary file read via Repo.blame() (CVE-2026-78678)

A flaw was found in GitPython. An incomplete denylist in the `unsafe_git_revision_options` guard omits `--contents` and `-S` options. This allows an attacker to read arbitrary files by passing these options to the `Repo.blame()` function. …

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.41%via CSAF
CVE-2026-78677High· 7.5
1mo ago

GitPython: GitPython: Arbitrary Code Execution via Path Traversal (CVE-2026-78677)

A flaw was found in GitPython. This vulnerability allows a remote attacker to create arbitrary Git directories outside the intended clone destination. By manipulating the `separate_git_dir` parameter during repository cloning, an attacker …

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.65%via CSAF
CVE-2026-78676Critical· 9.8
1mo ago

gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection (CVE-2026-78676)

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlin…

▾ MidnightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.78%via CSAF
CVE-2026-79674High· 7.5
1mo ago

nltk: NLTK: Information disclosure via path traversal in corpus-reader constructors (CVE-2026-79674)

A flaw was found in NLTK. A path traversal vulnerability in corpus-reader constructors allows a remote attacker to bypass the intended data root sandbox. By supplying arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCo…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.39%via CSAF
CVE-2026-78682High· 7.5
1mo ago

nltk: NLTK: Server-Side Request Forgery via HTTP Proxy Configuration (CVE-2026-78682)

A flaw was found in NLTK. When an HTTP proxy is configured, a server-side request forgery (SSRF) vulnerability exists in the `nltk.pathsec.urlopen` function. An attacker can exploit this by providing a seemingly valid public URL, which the…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.43%via CSAF
CVE-2026-79675High· 8.1
1mo ago

nltk: NLTK before 3.10.3 JVM Argument Injection via Per-Call Options (CVE-2026-79675)

A flaw was found in NLTK. When processing untrusted input for its `per-call options` parameter in the `java()` function, NLTK fails to validate Java Virtual Machine (JVM) options. A remote attacker could exploit this by injecting dangerous…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.78%via CSAF
CVE-2026-68513High· 7.1
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 contain a heap buffer overflow in PyOpenEXR triggered …

▾ TwilightRed HatEPSS 0.19%via NVD
CVE-2026-59981High· 7.1
1mo ago

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library retu…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.42%via NVD
CVE-2026-79779Medium· 5.3
1mo ago

rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects

rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker obse…

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.15%via NVD
CVE-2026-79781Medium· 6.5
1mo ago

rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys

rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys. Attackers can send requests with object keys like ../root-sec…

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.34%via NVD
CVE-2026-79780Medium· 5.3
1mo ago

rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes

rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes. Attackers observing network traffic from a trusted …

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.13%via NVD
CVE-2026-55553High· 7.5
1mo ago

urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features

urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prior to 4.9.1 and 2.44.1, urllib follows redirects through followRedirect but reuses caller-supplied options across orig…

▾ Twilighturllib · urllibEPSS 0.66%via NVD
CVE-2026-10582High· 7.4
1mo ago

Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone

Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern list and…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.32%via NVD
CVE-2026-78376High· 8.8
1mo ago

A flaw was found in WebKitGTK

A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.

▾ TwilightWebKit · webkitEPSS 0.29%via NVD
CVE-2026-76816Low· 3.5
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names before encoding, al…

▾ SunlitRed Hat · Red Hat JBoss Enterprise Application Platform 7EPSS 0.27%via NVD
CVE-2026-52492High· 7.8
1mo ago

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF…

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF…

▾ TwilightRed Hat · Red Hat Enterprise Linux 7EPSS 0.19%via NVD
CVE-2026-52490Critical· 9.8⚖ disputed
1mo ago

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c

▾ MidnightRed Hat · Red Hat Enterprise Linux 8EPSS 0.51%via NVD
CVE-2026-76172High· 7.5
1mo ago

fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects (CVE-2026-76172)

A flaw was found in fast-uri, a software component used for parsing Uniform Resource Identifiers (URIs) in Node.js applications. This vulnerability arises from an issue in how fast-uri processes the scheme part of a URI, specifically when …

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.40%via CSAF
CVE-2026-75899High· 7.5
1mo ago

fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899)

A flaw was found in fast-uri, a URI parser for Node.js. The component incorrectly decodes percent escapes in a hostname twice during URI parsing and authority recomposition. This double decoding can allow a remote attacker to manipulate a …

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.38%via CSAF
CVE-2026-75975High· 7.5
1mo ago

fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975)

A flaw was found in fast-uri, a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not fully validate the IPv6 grammar, allowing invalid trailing text in an authority to be silently discarded. This can lead to a mal…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.38%via CSAF
CVEs tagged “red-hat” — page 59 · VulnSea