VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2956 CVEsRSS

CVE-2026-18427High· 7.5
1mo ago

@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass

@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dot…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.66%via NVD
CVE-2026-19173High· 8.3
1mo ago

Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.32%via NVD
CVE-2026-64597Critical· 9.8⚖ disputed
1mo ago

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails b…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.67%via NVD
CVE-2026-67422High· 7.5
1mo ago

pymdown-extensions is a collection of extensions for the Python Markdown library

pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can parti…

▾ TwilightRed Hat · Red Hat Developer HubEPSS 0.61%via NVD
CVE-2026-71497Medium· 4.7
1mo ago

jsoup is a Java library for working with real-world HTML

jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior of a dif…

▾ Sunlitjsoup · org.jsoup:jsoupEPSS 0.30%via NVD
CVE-2026-71430Medium· 6.2
1mo ago

node-re2 provides RE2 regular expression bindings for Node.js

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty MaybeLocal that…

▾ SunlitRed Hat · re2EPSS 0.16%via NVD
CVE-2026-71498Medium· 5.1
1mo ago

node-re2 provides RE2 regular expression bindings for Node.js

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read past the end of the…

▾ SunlitRed Hat · re2EPSS 0.17%via NVD
CVE-2026-67434High· 7.8
1mo ago

PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards

PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgbl…

▾ TwilightRed Hat · squizlabs/php_codesnifferEPSS 1.1%via NVD
CVE-2026-71436Medium· 7.5
1mo ago

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1, Mermaid XY Charts are vulnerable to an infinite loop denial of service in the setXAxisR…

▾ Sunlitmermaid · mermaidEPSS 0.58%via NVD
CVE-2026-71326Low· 3.8
1mo ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key bui…

▾ Sunlittraefik · traefikEPSS 0.34%via NVD
CVE-2026-71327High· 8.1
1mo ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go bui…

▾ Twilighttraefik · traefikEPSS 0.48%via NVD
CVE-2026-71325Medium· 4.4⚖ disputed
1mo ago

Traefik is an open-source edge router that makes publishing services a fun and easy experience

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolv…

▾ Sunlittraefik · traefikEPSS 0.15%via NVD
CVE-2026-71324Critical· 9.1
1mo ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default HTTP reverse proxy forwards a plain HTTP/2 or HTTP/3 CONNECT request and its body to an HTTP/1.1 upstream through a sh…

▾ Midnighttraefik · traefikEPSS 0.69%via NVD
CVE-2026-44950High· 7.5
1mo ago

libxfonts2: libXfont2: Privilege Escalation via Heap Buffer Overflow in Font Server Client (CVE-2026-44950)

A flaw was found in the libXfont2 font-server client. This heap buffer overflow vulnerability allows a malicious font server to send specially crafted glyph data. The fs_read_glyphs() function fails to properly validate the total size of t…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.44%via CSAF
CVE-2026-70429Medium· 6.5
1mo ago

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters t…

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters t…

▾ Sunlitjenkins · jenkinsEPSS 0.42%via NVD
CVE-2026-10090Critical· 9.0
1mo ago

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM)

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can cre…

▾ MidnightRed Hat · rhacm2/multicluster-operators-subscription-rhel9EPSS 0.58%via NVD
CVE-2026-10059Critical· 9.1
1mo ago

A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller

A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertent…

▾ MidnightRed Hat · multicluster-engine/cluster-curator-controller-rhel9EPSS 0.64%via NVD
CVE-2026-54876High· 7.5
1mo ago

Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an attacker…

Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an attacker…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.52%via NVD
CVE-2026-71235High· 8.8
1mo ago

Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive

Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. The Lua script engine (re/lua.go) performs no input validation at all and preloads danger…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.52%via NVD
CVE-2026-71227Medium· 5.1
1mo ago

A flaw was found in libkcapi

A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can …

▾ Sunlitredhat · hardened_imagesEPSS 0.17%via NVD
CVE-2026-71226High· 7.3
1mo ago

Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.

Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.

▾ Twilightredhat · hardened_imagesEPSS 0.18%via NVD
CVE-2026-71225Medium· 6.5
1mo ago

A flaw was found in libkcapi

A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vec…

▾ Sunlitredhat · hardened_imagesEPSS 0.52%via NVD
CVE-2026-64582High· 7.8
1mo ago

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list and releases pending_lock while the struct's k…

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list and releases pending_lock while the struct's k…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.13%via NVD
CVE-2026-66274High· 7.5
1mo ago

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35…

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35…

▾ Twilightapache · qpid_proton-jEPSS 0.77%via NVD
CVE-2026-67589High· 7.5
1mo ago

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to ver…

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to ver…

▾ Twilightapache · qpid_protonj2EPSS 0.77%via NVD
CVE-2026-67588High· 7.5
1mo ago

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version …

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version …

▾ Twilightapache · qpid_protonj2EPSS 0.77%via NVD
CVE-2026-67551High· 7.5
1mo ago

pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to …

pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to …

▾ Twilightapache · qpid_proton-dotnetEPSS 0.77%via NVD
CVE-2026-68494High· 7.5
1mo ago

The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete

The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass. The earlier fix wired valida…

▾ TwilightRed Hat · Red Hat JBoss EAP 7.4 ELS for RHEL 7 ServerEPSS 0.62%via NVD
CVE-2026-64564Critical· 9.8PoC⚖ disputed
1mo ago

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport …

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport …

▾ AbyssalRed Hat · Red Hat Enterprise Linux 9EPSS 1.4%via NVD
CVE-2026-64563High· 7.8PoC
1mo ago

In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhashtable_walk_start_check() has two restart paths when resuming a walk. When iter->walker.tbl is valid, it re-valida…

In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhashtable_walk_start_check() has two restart paths when resuming a walk. When iter->walker.tbl is valid, it re-valida…

▾ MidnightRed Hat · Red Hat Enterprise Linux 9EPSS 0.12%via NVD
CVEs tagged “red-hat” — page 69 · VulnSea