VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2956 CVEsRSS

CVE-2026-71576High· 8.5
1mo ago

A flaw was found in multicluster-global-hub

A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka clien…

▾ TwilightRed Hat · multicluster-globalhub/multicluster-globalhub-manager-rhel9EPSS 0.23%via NVD
CVE-2026-18982High· 8.8
1mo ago

A flaw was found in the RHOAI training-operator

A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can imperson…

▾ TwilightRed Hat · rhoai/odh-training-operator-rhel9EPSS 0.79%via NVD
CVE-2026-18951High· 8.8
1mo ago

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with …

▾ TwilightRed Hat · rhoai/odh-training-operator-rhel9EPSS 0.89%via NVD
CVE-2026-6426Medium· 4.4
1mo ago

A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling

A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size is stored as a uint64_t but read by the VMS_VBUFFER load path as a signed int32_t. On little-endian hosts, a crafted…

▾ SunlitRed Hat · qemu-kvmEPSS 0.39%via NVD
CVE-2026-72913High· 7.8
1mo ago

Kitty is a cross-platform GPU based terminal

Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell command…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.21%via NVD
CVE-2026-72903High· 8.1
1mo ago

Tabby (formerly Terminus) is a highly configurable terminal emulator

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _ma…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4EPSS 0.49%via NVD
CVE-2026-18620High· 7.1
1mo ago

A flaw was found in Data Science Pipelines

A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRu…

▾ TwilightRed Hat · rhoai/odh-ml-pipelines-api-server-v2-rhel9EPSS 0.48%via NVD
CVE-2026-18611High· 7.5
1mo ago

A flaw was found in the Data Science Pipelines Operator

A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinI…

▾ TwilightRed Hat · rhoai/odh-data-science-pipelines-operator-controller-rhel9EPSS 0.61%via NVD
CVE-2026-15581High· 8.0
1mo ago

A flaw was found in the TrustyAI Service (TAS) deployment

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or d…

▾ TwilightRed Hat · rhoai/odh-trustyai-service-operator-rhel9EPSS 0.42%via NVD
CVE-2026-18608High· 8.7
1mo ago

A flaw was found in the Data Science Pipelines Operator (DSPO)

A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the…

▾ TwilightRed Hat · rhoai/odh-data-science-pipelines-operator-controller-rhel9EPSS 0.70%via NVD
CVE-2026-18621High· 7.6
1mo ago

A flaw was found in Data Science Pipelines (DSP)

A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with …

▾ TwilightRed Hat · rhoai/odh-ml-pipelines-api-server-v2-rhel9EPSS 0.51%via NVD
CVE-2026-18617High· 8.8
1mo ago

A flaw was found in the Data Science Pipelines Operator (DSPO)

A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Sourc…

▾ TwilightRed Hat · rhoai/odh-data-science-pipelines-operator-controller-rhel9EPSS 0.73%via NVD
CVE-2026-69112High· 7.1
1mo ago

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers can…

▾ Twilightaccelerate · accelerateEPSS 0.19%via NVD
CVE-2026-63622High· 7.8
1mo ago

A flaw was found in libvirt

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `sw…

▾ TwilightRed Hat · libvirtEPSS 0.18%via NVD
CVE-2026-68166High· 7.3
1mo ago

In the Linux kernel, the following vulnerability has been resolved: userfaultfd: prevent registration of special VMAs Vova Tokarev says: userfaultfd allows registration on shadow stack VMAs

In the Linux kernel, the following vulnerability has been resolved: userfaultfd: prevent registration of special VMAs Vova Tokarev says: userfaultfd allows registration on shadow stack VMAs. With userfaultfd access, you can regis…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.21%via NVD
CVE-2026-68162High· 7.8
1mo ago

In the Linux kernel, the following vulnerability has been resolved: sctp: avoid auth_enable sysctl UAF during netns teardown proc_sctp_do_auth() updates the SCTP control socket after changing net.sctp.auth_enable

In the Linux kernel, the following vulnerability has been resolved: sctp: avoid auth_enable sysctl UAF during netns teardown proc_sctp_do_auth() updates the SCTP control socket after changing net.sctp.auth_enable. The handler gets the …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via NVD
CVE-2026-68159Critical· 9.8
1mo ago

In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to over…

In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to over…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS (v. 9)EPSS 0.74%via NVD
CVE-2026-68138High· 7.8PoC
1mo ago

In the Linux kernel, the following vulnerability has been resolved: net/sched: serialize qdisc_rtab_list against concurrent get/put qdisc_get_rtab() and qdisc_put_rtab() mutate the process-global singly linked list qdisc_rtab_list and …

In the Linux kernel, the following vulnerability has been resolved: net/sched: serialize qdisc_rtab_list against concurrent get/put qdisc_get_rtab() and qdisc_put_rtab() mutate the process-global singly linked list qdisc_rtab_list and …

▾ MidnightRed Hat · Red Hat Enterprise Linux 9EPSS 0.28%via NVD
CVE-2026-19389High· 7.1
1mo ago

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled l…

▾ TwilightRed Hat · gstreamer1-plugins-ugly-freeEPSS 0.58%via NVD
CVE-2026-19387High· 7.6
1mo ago

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV …

▾ TwilightRed Hat · gstreamer1-plugins-bad-freeEPSS 0.38%via NVD
CVE-2026-15534Medium· 5.7
1mo ago

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each…

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each…

▾ SunlitRed Hat · perlEPSS 0.26%via NVD
CVE-2026-13505High· 7.5
1mo ago

org.bouncycastle/bc-fips: Bouncy Castle for Java FIPS: Sensitive key material remains in memory due to delayed zeroisation (CVE-2026-13505)

A flaw was found in Bouncy Castle for Java FIPS (BC-FJA). Sensitive cryptographic key material, intended to be securely erased from memory (zeroised) upon garbage collection, may persist longer than expected. This occurs because the zerois…

▾ TwilightRed Hat · Red Hat JBoss Enterprise Application Platform Expansion PackEPSS 0.25%via CSAF
CVE-2026-65819High· 7.5
1mo ago

gopacket provides packet processing capabilities for Go

gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffers, allowing a crafted packet decoded …

▾ TwilightRed Hat · Network Observability (NETOBSERV) 1.12.3EPSS 0.66%via NVD
CVE-2026-62296High· 7.5
1mo ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded…

▾ TwilightRed Hat · Red Hat build of Apache Camel 4 for Quarkus 3EPSS 0.49%via NVD
CVE-2026-15816High· 7.5
1mo ago

A flaw was found in dracut

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROO…

▾ TwilightRed Hat · dracutEPSS 0.37%via NVD
CVE-2026-71851Critical· 9.0PoC
1mo ago

crypto-js is a JavaScript library of crypto standards

crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded …

▾ Abyssalcrypto-js · crypto-jsEPSS 0.55%via NVD
CVE-2026-56818Medium· 6.5
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, b…

▾ Sunlitnetty · nettyEPSS 0.47%via NVD
CVE-2026-71556High· 7.1
1mo ago

go-git is an extensible git implementation library written in pure Go

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resoluti…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.36%via NVD
CVE-2026-18649High· 7.5PoC
1mo ago

A flaw was found in the GStreamer gst-plugins-good package

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, u…

▾ MidnightRed Hat · gstreamer1-plugins-goodEPSS 0.96%via NVD
CVE-2026-7867High· 7.8PoC
1mo ago

A flaw was found in udisks2

A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker…

▾ MidnightRed Hat · udisksEPSS 0.17%via NVD
CVEs tagged “red-hat” — page 68 · VulnSea