VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2956 CVEsRSS

CVE-2026-69219High· 7.5
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept a wire-…

▾ Twilightrabbitmq · com.rabbitmq:amqp-clientEPSS 0.73%via NVD
CVE-2026-63337High· 8.8
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.tools.jsonrpc.ProcedureDescription receives a javaReturnType value in an untrusted syst…

▾ Twilightrabbitmq · com.rabbitmq:amqp-clientEPSS 0.56%via NVD
CVE-2026-61634Low· 7.5
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value, but src/main/java/com/r…

▾ Sunlitrabbitmq · com.rabbitmq:amqp-clientEPSS 0.49%via NVD
CVE-2026-73502Medium· 5.3
1mo ago

kin-openapi is a Go project for handling OpenAPI files

kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.ValidateRequest can encounter a NULL-pointer-dereference denial of service when an operation declares a content parameter whose application/…

▾ SunlitRed Hat · Red Hat Edge Manager 1EPSS 0.51%via NVD
CVE-2026-66792Critical· 9.9
1mo ago

A flaw was found in the multicloud-operators-subscription component

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitatio…

▾ MidnightRed Hat · multicluster-globalhub/multicluster-globalhub-agent-rhel9EPSS 0.69%via NVD
CVE-2026-73646High· 7.5
1mo ago

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL values to joi…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.53%via NVD
CVE-2026-65332Medium· 4.3⚖ disputed
1mo ago

This issue was addressed through improved state management

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content m…

▾ Sunlitapple · safariEPSS 0.46%via NVD
CVE-2026-64780Medium· 4.3⚖ disputed
1mo ago

The issue was addressed with improved checks

The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an …

▾ Sunlitapple · ipadosEPSS 0.53%via NVD
CVE-2026-64779Low· 3.1⚖ disputed
1mo ago

A memory corruption vulnerability was addressed with improved locking

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted we…

▾ Sunlitapple · ipadosEPSS 0.38%via NVD
CVE-2026-64715Medium· 6.5⚖ disputed
1mo ago

A use-after-free issue was addressed with improved memory management

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing ma…

▾ Sunlitapple · safariEPSS 0.39%via NVD
CVE-2026-64778Medium· 6.5
1mo ago

The issue was addressed with improved checks

The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Visiting a maliciously crafted websit…

▾ Sunlitapple · safariEPSS 0.34%via NVD
CVE-2026-65338Medium· 4.3⚖ disputed
1mo ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may le…

▾ Sunlitapple · safariEPSS 0.46%via NVD
CVE-2026-65334Medium· 4.3⚖ disputed
1mo ago

A memory corruption issue was addressed with improved state management

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted w…

▾ Sunlitapple · safariEPSS 0.46%via NVD
CVE-2026-65335Medium· 4.3⚖ disputed
1mo ago

This issue was addressed through improved state management

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content m…

▾ Sunlitapple · ipadosEPSS 0.46%via NVD
CVE-2026-64787Medium· 6.5⚖ disputed
1mo ago

A use-after-free issue was addressed with improved memory management

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing ma…

▾ Sunlitapple · safariEPSS 0.33%via NVD
CVE-2026-65341Medium· 5.4⚖ disputed
1mo ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously craft…

▾ Sunlitapple · safariEPSS 0.24%via NVD
CVE-2026-64784Medium· 4.3⚖ disputed
1mo ago

An out-of-bounds access issue was addressed with improved bounds checking

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafte…

▾ Sunlitapple · safariEPSS 0.46%via NVD
CVE-2026-65336Medium· 4.3⚖ disputed
1mo ago

This issue was addressed through improved state management

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content m…

▾ Sunlitapple · ipadosEPSS 0.46%via NVD
CVE-2026-65337Medium· 4.3⚖ disputed
1mo ago

This issue was addressed through improved state management

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content m…

▾ Sunlitapple · safariEPSS 0.46%via NVD
CVE-2026-65340Medium· 4.3⚖ disputed
1mo ago

This issue was addressed through improved state management

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content m…

▾ Sunlitapple · safariEPSS 0.46%via NVD
CVE-2026-43795Medium· 4.3⚖ disputed
1mo ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may le…

▾ Sunlitapple · safariEPSS 0.46%via NVD
CVE-2026-64782Low· 3.1⚖ disputed
1mo ago

A memory corruption vulnerability was addressed with improved locking

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted we…

▾ Sunlitapple · safariEPSS 0.34%via NVD
CVE-2026-65351Medium· 4.3PoC⚖ disputed
1mo ago

This issue was addressed through improved state management

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content m…

▾ Twilightapple · safariEPSS 0.46%via NVD
CVE-2026-65331Medium· 4.3⚖ disputed
1mo ago

This issue was addressed through improved state management

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content m…

▾ Sunlitapple · safariEPSS 0.46%via NVD
CVE-2026-19693High· 8.1
1mo ago

extract-zip: extract-zip: Arbitrary file write via symlink in archive (CVE-2026-19693)

A flaw was found in extract-zip. This vulnerability allows a remote attacker to perform an arbitrary file write outside the intended destination directory. By crafting a malicious zip archive containing a symbolic link (symlink) and a regu…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.28%via CSAF
CVE-2026-66795Critical· 9.9
1mo ago

A flaw was found in the managedcluster-import-controller

A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. …

▾ MidnightRed Hat · multicluster-engine/managedcluster-import-controller-rhel9EPSS 0.49%via NVD
CVE-2026-64849High· 8.5CISA KEVPoC
1mo ago

mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS …

A flaw was found in MLflow. An unauthenticated remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability by sending a specially crafted request to the webhook test endpoint. This occurs because the system validates onl…

▾ AbyssalRed Hat · Red Hat OpenShift AI 3.4EPSS 9.8%via CSAF
CVE-2026-69146Medium· 6.5
1mo ago

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any a…

▾ Sunlitmlflow · mlflowEPSS 0.39%via NVD
CVE-2026-69148High· 7.1
1mo ago

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in…

▾ Twilightmlflow · mlflowEPSS 0.37%via NVD
CVE-2026-59903Medium· 6.5PoC
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie w…

▾ Twilightnetty · nettyEPSS 0.25%via NVD
CVEs tagged “red-hat” — page 63 · VulnSea