VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2956 CVEsRSS

CVE-2026-42789Medium· 4.8⚖ disputed
4mo ago

Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be accepted as an intermediate issuer, enabling certificate chain forgery. In lib/public_key…

Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be accepted as an intermediate issuer, enabling certificate chain forgery. In lib/public_key…

▾ Sunliterlang · erlang/otpEPSS 0.35%via NVD
CVE-2026-49017Medium· 6.5
4mo ago

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-s…

▾ Sunlitopenstack · swiftEPSS 0.36%via NVD
CVE-2026-44660High· 7.5
4mo ago

python-ujson: UltraJSON: Memory leak leading to Denial of Service (CVE-2026-44660)

A flaw was found in UltraJSON, a fast JSON encoder and decoder. When the `ujson.dump()` function attempts to write data to a file-like object and an error occurs during this operation, the memory allocated for the serialized JSON string is…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.64%via CSAF
CVE-2026-45570Medium· 6.3
4mo ago

github.com/go-git/go-git: go-git: Shell command injection in SSH transport (CVE-2026-45570)

A flaw was found in go-git, a library used for Git operations. The component responsible for secure shell (SSH) communication does not correctly handle special characters in repository paths. This oversight allows a remote attacker to mani…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.17EPSS 0.43%via CSAF
CVE-2026-45984High· 7.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix use-after-free in iomap inline data write path The inline data buffer head (dibh) is being released prematurely in gfs2_iomap_begin() via release_metapath() …

In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix use-after-free in iomap inline data write path The inline data buffer head (dibh) is being released prematurely in gfs2_iomap_begin() via release_metapath() …

▾ Twilightlinux · linux_kernelEPSS 0.47%via NVD
CVE-2026-46054High· 7.1
4mo ago

In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access t…

In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access t…

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-45998High· 7.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix potential UAF after skb_unshare() failure If skb_unshare() fails to unshare a packet due to allocation failure in rxrpc_input_packet(), the skb pointer in t…

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix potential UAF after skb_unshare() failure If skb_unshare() fails to unshare a packet due to allocation failure in rxrpc_input_packet(), the skb pointer in t…

▾ Twilightlinux · linux_kernelEPSS 0.19%via NVD
CVE-2026-2340Medium· 6.5
4mo ago

A flaw was found in Samba’s vfs_worm module

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename o…

▾ Sunlitredhat · openshift_container_platformEPSS 0.94%via NVD
CVE-2026-1933High· 7.1
4mo ago

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete re…

▾ Twilightredhat · openshift_container_platformEPSS 0.86%via NVD
CVE-2026-3012High· 8.0
4mo ago

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store…

▾ Twilightredhat · openshift_container_platformEPSS 0.23%via NVD
CVE-2026-7374Critical· 9.9
4mo ago

A flaw was found in KubeVirt's virt-handler component

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine consol…

▾ MidnightRed Hat · kubevirtEPSS 0.83%via NVD
CVE-2026-48864High· 7.8
4mo ago

A flaw was found in libsolv

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` …

▾ Twilightopensuse · libsolvEPSS 0.26%via NVD
CVE-2026-48710Medium· 6.5CISA KEVPoC
4mo ago

Starlette is a lightweight ASGI framework/toolkit

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `…

▾ Midnightstarlette · starletteEPSS 7.1%via NVD
CVE-2026-5260High· 8.2
4mo ago

A flaw was found in libgnutls

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corrupti…

▾ TwilightRed Hat · gnutlsEPSS 0.95%via NVD
CVE-2026-42502Medium· 6.1
4mo ago

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

▾ Sunlitx · golang.org/x/netEPSS 0.22%via OSV
CVE-2026-46598Medium· 5.3
4mo ago

Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent

Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent

▾ Sunlitx · golang.org/x/cryptoEPSS 0.52%via OSV
CVE-2026-39833Medium· 5.5⚖ disputed
4mo ago

golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation (CVE-2026-39833)

A flaw was found in golang.org/x/crypto/ssh/agent. The NewKeyring() function, which creates an in-memory keyring, failed to enforce the ConfirmBeforeUse constraint on keys. This allowed keys configured to require user confirmation before u…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.49%via CSAF
CVE-2026-39832Critical· 9.1
4mo ago

When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request

When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of…

▾ Midnightgolang · cryptoEPSS 0.72%via NVD
CVE-2026-39828Medium· 6.3⚖ disputed
4mo ago

Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succee…

▾ Sunlitgolang.org/x/crypto · golang.org/x/crypto/sshEPSS 0.54%via CVEORG
CVE-2026-39827Medium· 6.5
4mo ago

Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh

Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh

▾ Sunlitx · golang.org/x/cryptoEPSS 0.28%via OSV
CVE-2026-39830Critical· 9.1
4mo ago

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connec…

▾ Midnightgolang · cryptoEPSS 0.62%via NVD
CVE-2026-39831High· 8.1
4mo ago

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check (CVE-2026-39831)

A flaw was found in golang.org/x/crypto/ssh. The Verify() method, responsible for FIDO/U2F security key types, did not properly check for user presence. This allowed signatures to be accepted without requiring a physical touch on the hardw…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.49%via CSAF
CVE-2026-42508Critical· 9.1
4mo ago

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

▾ Midnightgolang · cryptoEPSS 0.65%via NVD
CVE-2026-39834Medium· 6.5⚖ disputed
4mo ago

Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh

Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh

▾ Sunlitx · golang.org/x/cryptoEPSS 0.64%via OSV
CVE-2026-46595High· 7.1PoC⚖ disputed
4mo ago

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation (CVE-2026-46595)

A flaw was found in golang.org/x/crypto/ssh. Source-address validation can be skipped when an SSH server configuration uses an authentication callback type other than public key, allowing authorization bypass in misconfigured servers. This…

▾ MidnightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.60%via CSAF
CVE-2026-43499High· 7.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_…

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_…

▾ Midnightlinux · linux_kernelEPSS 0.28%via NVD
CVE-2026-47783High· 8.1
4mo ago

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.

▾ Twilightmemcached · memcachedEPSS 1.3%via NVD
CVE-2026-3039High· 7.5
4mo ago

BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets

BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be found in …

▾ Twilightisc · bindEPSS 2.3%via NVD
CVE-2026-5946High· 7.5
4mo ago

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question sec…

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question sec…

▾ Twilightisc · bindEPSS 1.7%via NVD
CVE-2026-42009High· 7.5
4mo ago

A flaw was found in gnutls

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not cor…

▾ Twilightgnu · gnutlsEPSS 1.1%via NVD
CVEs tagged “red-hat” — page 84 · VulnSea