VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2956 CVEsRSS

CVE-2026-73253Critical· 9.1
1mo ago

Mongoose is an embedded web server and network library

Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in TLS stack. The mg…

▾ MidnightRed HatEPSS 0.35%via NVD
CVE-2026-63385High· 7.7
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into literal NUL characters, which can cause dow…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 8)EPSS 0.55%via NVD
CVE-2026-63384High· 7.5
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode an attacker-controlled uint32 payload…

▾ TwilightRed Hat · Red Hat Enterprise Linux 6EPSS 0.52%via NVD
CVE-2026-63381Medium· 6.6
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains fre…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.16%via NVD
CVE-2026-63380Medium· 4.7
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters its error path after evhttp_start_ws_ succeeds but bufferevent_enable_locking_ fails. ev…

▾ SunlitRed Hat · Red Hat Enterprise Linux 6EPSS 0.14%via NVD
CVE-2026-76957Medium· 4.9
1mo ago

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.

▾ Sunlitlibexpat_project · libexpatEPSS 0.15%via NVD
CVE-2026-76956Medium· 5.9
1mo ago

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

▾ Sunlitlibexpat_project · libexpatEPSS 0.45%via NVD
CVE-2026-13097High· 8.7
1mo ago

A privilege escalation flaw was found in FreeIPA

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name…

▾ Twilightfreeipa · freeipaEPSS 0.40%via NVD
CVE-2026-71492Medium· 6.5
1mo ago

Banks generates meaningful LLM prompts using a simple template language

Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled Prompt.name and Prompt.version values in…

▾ Sunlitbanks · banksEPSS 0.47%via NVD
CVE-2026-54770Medium· 6.1
1mo ago

WebOb provides objects for HTTP requests and responses

WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips le…

▾ SunlitRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.38%via NVD
CVE-2026-49825High· 8.2
1mo ago

lxml is a library for processing XML and HTML in the Python language

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. cont…

▾ TwilightRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.43%via NVD
CVE-2026-43961High· 7.8
1mo ago

A flaw was found in Vim's netrw plugin

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be levera…

▾ Twilightvim · vimEPSS 0.22%via NVD
CVE-2026-55194Critical· 9.8PoC
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint …

▾ Abyssalfreerdp · freerdpEPSS 0.62%via NVD
CVE-2026-75593High· 7.2
1mo ago

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from …

▾ Twilightmoby · buildkitEPSS 0.72%via NVD
CVE-2026-63652Medium· 6.5
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing t…

▾ Sunlitfreerdp · freerdpEPSS 0.58%via NVD
CVE-2026-63633Critical· 9.8
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer even though opus_decode writes decoded PCM…

▾ Midnightfreerdp · freerdpEPSS 0.62%via NVD
CVE-2026-55564Medium· 5.4
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_cache_get function in libfreerdp/cache/glyph.c checks whether index is greater than cache->number instead of greater than or equal to it. A malic…

▾ Sunlitfreerdp · freerdpEPSS 0.44%via NVD
CVE-2026-55193High· 8.8
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c without bounding it to the 4088-byte …

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.47%via NVD
CVE-2026-55192High· 8.2
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP H.264 decoder backends can return YUV planes sized from the bitstream without comparing the decoded width and height to the RDPGFX surface dimensio…

▾ Twilightfreerdp · freerdpEPSS 0.59%via NVD
CVE-2026-55191Critical· 9.8
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX AVC444 with an H.264 decoder backend calculate the intermediate YUV444 allocation size in libfreerdp/codec/h264.c wit…

▾ Midnightfreerdp · freerdpEPSS 0.83%via NVD
CVE-2026-76232Medium· 6.7
1mo ago

Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the repository parameter is appended to helm registry login commands without proper sanitization

Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the repository parameter is appended to helm registry login commands without proper sanitization. Attackers with reposito…

▾ SunlitRed HatEPSS 1.0%via NVD
CVE-2026-76230Medium· 6.7
1mo ago

Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-provided packageName values are appended to npm install commands without proper sanitization

Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-provided packageName values are appended to npm install commands without proper sanitization. Attackers with repository…

▾ SunlitRed HatEPSS 1.0%via NVD
CVE-2026-76227Medium· 5.5
1mo ago

Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict enviro…

Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict enviro…

▾ SunlitRed HatEPSS 0.15%via NVD
CVE-2026-75595Critical· 9.1
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so…

▾ Midnightnetty · nettyEPSS 0.46%via NVD
CVE-2026-75569High· 7.7
1mo ago

A flaw was found in mce-operator-bundle

A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with wr…

▾ TwilightRed Hat · multicluster-engine/mce-operator-bundleEPSS 0.60%via NVD
CVE-2026-76827Medium· 6.8
1mo ago

A flaw was found in search-indexer

A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-in…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.11EPSS 0.53%via NVD
CVE-2026-76139High· 8.0
1mo ago

A flaw was found in acm-operator-bundle

A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as Gi…

▾ TwilightRed Hat · rhacm2/acm-operator-bundleEPSS 0.72%via NVD
CVE-2026-66794Critical· 9.3
1mo ago

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks…

▾ MidnightRed Hat · multicluster-engine/cluster-proxy-addon-rhel9EPSS 0.62%via NVD
CVE-2026-18874Medium· 6.2
1mo ago

A flaw was found in volsync-addon-controller

A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This is due to improper esc…

▾ SunlitRed Hat · rhacm2/acm-volsync-addon-controller-rhel9EPSS 0.54%via NVD
CVE-2026-55648High· 7.5⚖ disputed
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy_from_icon_data in libfreerdp/codec/color.c calculates nWidth multiplied by nHeight multiplied by FreeRDPGetBytesPerPixel(format) in 32-b…

▾ Twilightfreerdp · freerdpEPSS 0.43%via NVD
CVEs tagged “red-hat” — page 61 · VulnSea