VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2956 CVEsRSS

CVE-2026-75931High· 7.5
1mo ago

fast-uri: fast-uri: Host confusion via skipped IDN canonicalization (CVE-2026-75931)

A flaw was found in fast-uri, a URI parser for Node.js. This vulnerability arises because the parser fails to consistently convert internationalized domain names (IDN) to their standard ASCII form when processing scheme-relative references…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.40%via CSAF
CVE-2026-63310High· 7.1
1mo ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.12%via NVD
CVE-2026-62384High· 7.5
1mo ago

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators i…

▾ Twilightnltk · nltkEPSS 0.65%via NVD
CVE-2026-62243High· 7.5
1mo ago

Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is use…

Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is use…

▾ TwilightRed Hat · Red Hat Ceph Storage 9EPSS 0.25%via NVD
CVE-2026-63343Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file o…

▾ MidnightRed HatEPSS 0.48%via NVD
CVE-2026-54789High· 7.5
1mo ago

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream E4S (v.8.8)EPSS 0.72%via NVD
CVE-2026-73267High· 7.7
1mo ago

A flaw was found in the clusterclaims-controller component of multicluster engine (MCE)

A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This all…

▾ TwilightRed Hat · multicluster-engine/clusterclaims-controller-rhel9EPSS 0.63%via NVD
CVE-2026-76905High· 7.5⚖ disputed
1mo ago

kin-openapi is a Go project for handling OpenAPI files

kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_error_encoder.go dereferences e.Parameter.In without checking whether e.Parameter is nil. A …

▾ TwilightRed Hat · Red Hat Edge Manager 1EPSS 0.61%via NVD
CVE-2026-77354High· 7.5
1mo ago

kin-openapi is a Go project for handling OpenAPI files

kin-openapi is a Go project for handling OpenAPI files. From 0.124.0 until 0.142.0, openapi3filter.sliceMapToSlice in openapi3filter/req_resp_decoder.go converts attacker-controlled sparse indexes from a deepObject query parameter into a…

▾ Twilightgetkin · github.com/getkin/kin-openapiEPSS 0.52%via NVD
CVE-2026-77413Critical· 9.8
1mo ago

JSONata is a JSON query and transformation language

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to access inherited prototype members. An…

▾ Midnightjsonata · jsonataEPSS 0.72%via NVD
CVE-2026-68508High· 7.8
1mo ago

Hydra is a framework for elegantly configuring complex applications

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.4, hydra.utils.instantiate() resolves and calls Python objects selected by configuration through _resolve_target() in hydra/_internal/instantiate/_instanti…

▾ Twilighthydra-core · hydra-coreEPSS 0.46%via NVD
CVE-2026-77414Critical· 9.8
1mo ago

JSONata is a JSON query and transformation language

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check. Crafted expressions could use $hasOwnProperty, $spread, $string, protot…

▾ Midnightjsonata · jsonataEPSS 0.57%via NVD
CVE-2026-77415Critical· 9.8
1mo ago

JSONata is a JSON query and transformation language

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code. The chain could overwrite $clone to mutate objects thro…

▾ Midnightjsonata · jsonataEPSS 0.89%via NVD
CVE-2026-48050High· 8.2
1mo ago

Arc is an open, SQL-native time-series database for telemetry

Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof` handlers at `/debug/pprof/*` via `app.Use(pprof.New())` in `internal/api/server.go`, and `/debug/pprof` is added to `…

▾ TwilightRed Hat · Red Hat Edge Manager 1EPSS 0.64%via NVD
CVE-2026-76641High· 7.5
1mo ago

Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate

Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.61%via NVD
CVE-2026-75140High· 7.5
1mo ago

jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-…

jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.53%via NVD
CVE-2026-73197High· 7.5
1mo ago

A flaw was found in FreeIPA

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-c…

▾ Twilightfreeipa · freeipaEPSS 0.41%via NVD
CVE-2026-11861Critical· 9.6
1mo ago

A flaw was found in FreeIPA

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This …

▾ Midnightfreeipa · freeipaEPSS 0.21%via NVD
CVE-2026-73198High· 7.5
1mo ago

A flaw was found in FreeIPA

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leadin…

▾ Twilightfreeipa · freeipaEPSS 0.41%via NVD
CVE-2026-19611High· 7.4
1mo ago

A flaw was found in WildFly Elytron

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using a…

▾ TwilightRed Hat · wildfly-elytron-password-implEPSS 0.56%via NVD
CVE-2026-55765High· 8.5
1mo ago

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by Set…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4EPSS 0.50%via NVD
CVE-2026-64846Low· 2.8
1mo ago

Nix is a package manager for Linux and other Unix systems

Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit a time-of-check/time-of-use race involving final symlink handling in the …

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.11%via NVD
CVE-2026-18917High· 7.8
1mo ago

A flaw was found in libvirt

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. …

▾ TwilightRed Hat · libvirtEPSS 0.18%via NVD
CVE-2026-63382Critical· 9.2PoC
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-Encoding values, and bare line feeds in…

▾ Abyssallibevent · libeventEPSS 0.78%via NVD
CVE-2026-53587High· 7.5PoC
1mo ago

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in…

▾ Midnightlibgit2 · libgit2EPSS 0.68%via NVD
CVE-2026-63383High· 8.7PoC
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c when decode_tag_internal requests at most five bytes from evbuffer_pullup but iterates u…

▾ Midnightlibevent · libeventEPSS 0.52%via NVD
CVE-2026-63495High· 7.5PoC
1mo ago

Libevent is an event notification library

Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frames in evws->incomplete_frames without enforcing a total message-size limit. An unauthenti…

▾ Midnightlibevent · libeventEPSS 0.61%via NVD
CVE-2026-63388High· 8.4
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when bufferevent_socket_set_conn_address_ copies a kernel-supplied AF_UNIX peer address into buffer…

▾ Twilightlibevent · libeventEPSS 0.20%via NVD
CVE-2026-63387High· 7.0PoC
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocat…

▾ Midnightlibevent · libeventEPSS 0.45%via NVD
CVE-2026-63379Medium· 6.3
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in http.c through evhttp_read_trailer and merges them into request headers. The fix introduces evhttp_parse_headers_impl…

▾ Sunlitlibevent · libeventEPSS 0.71%via NVD
CVEs tagged “red-hat” — page 60 · VulnSea