VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2956 CVEsRSS

CVE-2025-54518High· 7.0
4mo ago

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.

▾ TwilightAMD · AMD EPYC™ 7002 Series ProcessorsEPSS 0.29%via NVD
CVE-2026-44513High· 8.8
4mo ago

Diffusers is the a library for pretrained diffusion models

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omi…

▾ Twilighthuggingface · diffusersEPSS 0.89%via NVD
CVE-2026-44673High· 7.5PoC
4mo ago

libyang is a YANG data modeling language library

libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attack…

▾ MidnightCESNET · libyangEPSS 0.95%via NVD
CVE-2026-44283Medium· 4.3⚖ disputed
4mo ago

etcd: etcd: Authenticated user can bypass RBAC for unauthorized data access (CVE-2026-44283)

A flaw was found in etcd, a distributed key-value store. An authenticated user, without sufficient read or lease-related permissions, could bypass Role-Based Access Control (RBAC) authorization checks. This bypass occurs during transaction…

▾ SunlitRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.27%via CSAF
CVE-2026-7168Medium· 5.3PoC
4mo ago

Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wr…

Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wr…

▾ Twilighthaxx · curlEPSS 0.59%via NVD
CVE-2026-6429Medium· 5.3
4mo ago

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

▾ Sunlithaxx · curlEPSS 0.51%via NVD
CVE-2026-6276High· 7.5PoC⚖ disputed
4mo ago

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information…

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information…

▾ Midnighthaxx · curlEPSS 0.35%via NVD
CVE-2026-6253Medium· 5.9PoC
4mo ago

curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1

curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy nee…

▾ Twilighthaxx · curlEPSS 0.75%via NVD
CVE-2026-5545Medium· 6.5
4mo ago

libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that sub…

libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that sub…

▾ Sunlithaxx · curlEPSS 0.51%via NVD
CVE-2026-42945High· 8.1PoC
4mo ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expre…

▾ Midnightf5 · dosEPSS 3.4%via NVD
CVE-2026-44248Medium· 5.3⚖ disputed
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDec…

▾ Sunlitnetty · nettyEPSS 0.72%via NVD
CVE-2026-42584High· 7.3PoC
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If …

▾ Midnightnetty · nettyEPSS 0.72%via NVD
CVE-2026-42581Medium· 5.8PoC
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Conten…

▾ Twilightnetty · nettyEPSS 0.68%via NVD
CVE-2026-42579High· 7.5PoC
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirec…

▾ Midnightnetty · nettyEPSS 0.85%via NVD
CVE-2026-42578High· 7.5PoC⚖ disputed
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() …

▾ Midnightnetty · nettyEPSS 1.2%via NVD
CVE-2026-42587High· 7.5PoC
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb at…

▾ Midnightnetty · nettyEPSS 1.0%via NVD
CVE-2026-44432High· 7.5
4mo ago

urllib3 is an HTTP client library for Python

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed…

▾ Twilightpython · urllib3EPSS 0.88%via NVD
CVE-2026-8328Medium· 5.3
4mo ago

The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed

The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse…

▾ SunlitRed Hat · Red Hat Hardened ImagesEPSS 0.68%via NVD
CVE-2026-44431Medium· 5.3PoC
4mo ago

urllib3 is an HTTP client library for Python

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive hea…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.34%via NVD
CVE-2026-41293High· 7.3PoC⚖ disputed
4mo ago

tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated (CVE-2026-41293)

Apache Tomcat did not validate HTTP/2 request headers, triggering unexpected application behavior, as applications may presume that header values exposed through the Servlet API would be valid.

▾ MidnightRed Hat · Red Hat Enterprise Linux AppStream EUS (v. 10.0)EPSS 1.7%via CSAF
CVE-2026-31221High· 8.0
4mo ago

pytorch-lightning: PyTorch-Lightning: Arbitrary code execution via insecure deserialization of checkpoint files (CVE-2026-31221)

A flaw was found in PyTorch-Lightning. This vulnerability, categorized as insecure deserialization (CWE-502), exists in the checkpoint loading mechanism. A remote attacker can exploit this by providing a maliciously crafted checkpoint file…

▾ TwilightRed Hat · Red Hat Enterprise Linux AI (RHEL AI) 3EPSS 0.55%via CSAF
CVE-2026-42338Medium· 6.1PoC⚖ disputed
4mo ago

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they…

▾ Twilightbeaugunderson · ip-addressEPSS 0.51%via NVD
CVE-2026-44223Medium· 6.5
4mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.18.0 to before 0.20.0, the extract_hidden_states speculative decoding proposer in vLLM returns a tensor with an incorrect shape after the first decode step,…

▾ SunlitRed Hat · Red Hat Enterprise Linux AI 3.4EPSS 0.43%via NVD
CVE-2026-7210High· 7.5⚖ disputed
4mo ago

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating …

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating …

▾ Twilightpython · pythonEPSS 1.4%via NVD
CVE-2026-45186Low· 2.9⚖ disputed
4mo ago

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

▾ Sunlitlibexpat_project · libexpatEPSS 0.48%via NVD
CVE-2026-8177High· 7.5
4mo ago

XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read…

XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.88%via NVD
CVE-2026-6722Critical· 9.8⚖ disputed
4mo ago

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their referenc…

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their referenc…

▾ Midnightphp · phpEPSS 1.3%via NVD
CVE-2026-42308Medium· 6.2
4mo ago

Pillow: Pillow: Denial of Service via integer overflow in font processing (CVE-2026-42308)

A flaw was found in Pillow, a Python imaging library. If a font advances for each glyph by an exceeding large amount, an integer overflow can occur when Pillow tracks the current position. This could lead to a denial of service (DoS) condi…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.16%via CSAF
CVE-2026-42301High· 7.3
4mo ago

pyp2spec: pyp2spec: Arbitrary command execution via unescaped RPM macro directives (CVE-2026-42301)

A flaw was found in pyp2spec, a tool that generates Fedora RPM spec files for Python projects. This vulnerability allows a malicious Python Package Index (PyPI) package to execute arbitrary commands on a build machine. This occurs because …

▾ TwilightRed Hat · pyp2specEPSS 0.23%via CSAF
CVE-2026-42311High· 7.8
4mo ago

Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing (CVE-2026-42311)

A flaw was found in Pillow, a Python imaging library. An attacker could exploit this vulnerability by tricking a user into processing a specially crafted malicious PSD file. This could lead to memory corruption, potentially causing the app…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.22%via CSAF
CVEs tagged “red-hat” — page 85 · VulnSea