VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2956 CVEsRSS

CVE-2026-73625High· 8.8
1mo ago

gitpython: GitPython: Remote Code Execution via kwarg value smuggling (CVE-2026-73625)

A flaw was found in GitPython. Attackers can bypass the `check_unsafe_options` guard by smuggling git options within single-character keyword argument (kwarg) values. This allows them to supply specially crafted option dictionaries to vari…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.92%via CSAF
CVE-2026-73624High· 8.1
1mo ago

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter o…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.50%via NVD
CVE-2026-73623High· 7.5
1mo ago

gitpython: GitPython: Remote Code Execution via malicious Git template (CVE-2026-73623)

A flaw was found in GitPython. An incomplete denylist in the `unsafe_git_clone_options` function fails to restrict the `--template` option. This allows a remote attacker to supply a malicious Git template directory, leading to arbitrary co…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.83%via CSAF
CVE-2026-73620High· 8.8
1mo ago

gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding (CVE-2026-73620)

A flaw was found in GitPython. This vulnerability arises from insufficient guarding of git option forwarding within the `IndexFile.checkout()` and `TagReference.create()` functions. An authenticated attacker can exploit this by passing uns…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.57%via CSAF
CVE-2026-73417High· 8.3
1mo ago

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allows notebook settings to be shared and applied through an ov…

▾ Twilightjupyterlab · jupyterlabEPSS 0.75%via NVD
CVE-2026-58443Critical· 9.6
1mo ago

code.gitea.io/gitea: Gitea: Unauthorized update of private pull request branches via public-only tokens (CVE-2026-58443)

A flaw was found in Gitea. This vulnerability allows an attacker to use tokens intended for public repositories to modify private pull request (PR) branches. This could lead to unauthorized changes in private code, compromising the integri…

▾ MidnightRed Hat · OpenShift PipelinesEPSS 0.58%via CSAF
CVE-2026-49478High· 8.7⚖ disputed
1mo ago

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discover…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.28%via NVD
CVE-2026-48702High· 7.5
1mo ago

Rekor is a software supply chain transparency log

Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file i…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.46%via NVD
CVE-2026-73434Medium· 6.1
1mo ago

A flaw was found in GStreamer gst-plugins-good (avidemux)

A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled …

▾ Sunlitgstreamer · gstreamerEPSS 0.15%via NVD
CVE-2026-73433Medium· 6.6
1mo ago

A flaw was found in GStreamer gst-plugins-good (avidemux)

A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying suffici…

▾ Sunlitgstreamer · gstreamerEPSS 0.15%via NVD
CVE-2026-19654High· 7.5
1mo ago

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confide…

▾ Twilightrsyslog · rsyslogEPSS 0.47%via NVD
CVE-2026-71846Medium· 6.5
1mo ago

A flaw was found in insights-client

A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive…

▾ Sunlitredhat · advanced_cluster_management_for_kubernetesEPSS 0.16%via NVD
CVE-2026-64927Medium· 6.4
1mo ago

A flaw was found in the multicloud-operators-channel component

A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.11EPSS 0.33%via NVD
CVE-2026-73269Critical· 9.9
1mo ago

A flaw was found in the cluster-curator-controller component

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to…

▾ MidnightRed Hat · multicluster-engine/cluster-curator-controller-rhel9EPSS 0.56%via NVD
CVE-2026-73268Critical· 9.9
1mo ago

A flaw was found in the cluster-curator-controller component of multicluster engine (MCE)

A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the Cre…

▾ MidnightRed Hat · multicluster-engine/cluster-curator-controller-rhel9EPSS 0.88%via NVD
CVE-2026-13622High· 8.8
1mo ago

A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy

A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symli…

▾ TwilightRed Hat · container-native-virtualization/virt-handlerEPSS 0.20%via NVD
CVE-2026-19130Medium· 5.8
1mo ago

A flaw was found in the provider-credential-controller component of multicluster-engine (MCE)

A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vul…

▾ SunlitRed Hat · multicluster-engine/provider-credential-controller-rhel9EPSS 0.40%via NVD
CVE-2026-73501Critical· 9.1
1mo ago

kin-openapi is a Go project for handling OpenAPI files

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without …

▾ MidnightRed Hat · Red Hat Edge Manager 1EPSS 0.59%via NVD
CVE-2026-73500High· 7.5
1mo ago

etcd is a distributed key-value store for the data of a distributed system

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In…

▾ TwilightRed Hat · Red Hat Trusted Artifact SignerEPSS 0.70%via NVD
CVE-2026-73415High· 8.0
1mo ago

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObj…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.74%via NVD
CVE-2026-19550High· 8.2
1mo ago

A flaw was found in FreeIPA

A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged…

▾ Twilightfreeipa · freeipaEPSS 0.28%via NVD
CVE-2026-14180Medium· 5.3
1mo ago

A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding

A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the …

▾ SunlitRed Hat · eap8-activemq-artemisEPSS 1.0%via NVD
CVE-2026-73070Medium· 5.5
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to 9.2.0842, the socket server backend in src/socketserver.c accepts unbounded client connections in socketserver_accept(), causing descriptors to overflow fd_set structures in src/c…

▾ Sunlitvim · vimEPSS 0.19%via NVD
CVE-2025-31936Medium· 5.7
1mo ago

Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege

Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high comple…

▾ Sunlitintel · xeon_6337p_firmwareEPSS 0.10%via NVD
CVE-2026-15567High· 7.5
1mo ago

A flaw was found in Wildfly

A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that …

▾ TwilightRed Hat · org.jboss.eap/wildfly-iiop-openjdkEPSS 0.55%via NVD
CVE-2026-15565High· 7.5
1mo ago

A flaw was found in Undertow

A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service attack …

▾ TwilightRed Hat · io.undertow/undertow-websockets-jsrEPSS 0.61%via NVD
CVE-2026-15563High· 7.4
1mo ago

A flaw was found in EAP's IIOP

A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.

▾ TwilightRed Hat · org.jboss.eap/wildfly-iiop-openjdkEPSS 0.39%via NVD
CVE-2026-15562High· 7.5
1mo ago

A flaw was found in EAP's jboss-remoting

A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to den…

▾ TwilightRed Hat · org.jboss.remoting/jboss-remotingEPSS 0.55%via NVD
CVE-2026-15561High· 7.5
1mo ago

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the…

▾ TwilightRed Hat · io.undertow/undertow-coreEPSS 0.46%via NVD
CVE-2026-15556High· 8.1
1mo ago

A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the prot…

A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the prot…

▾ TwilightRed Hat · org.picketlink/picketlink-federationEPSS 0.24%via NVD
CVEs tagged “red-hat” — page 66 · VulnSea