VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2956 CVEsRSS

CVE-2026-6857High· 7.5PoC
5mo ago

A flaw was found in camel-infinispan

A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leadin…

▾ MidnightRed Hat · camel-infinispanEPSS 1.2%via NVD
CVE-2026-34282High· 7.5
5mo ago

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u481-perf, 11.0.30, 17.0.18, 21.…

▾ Twilightoracle · jreEPSS 0.89%via NVD
CVE-2026-22016High· 7.5PoC
5mo ago

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, …

▾ Midnightoracle · jreEPSS 0.70%via NVD
CVE-2026-40890High· 7.5
5mo ago

github.com/gomarkdown/markdown: github.com/gomarkdown/markdown: Denial of Service via malformed Markdown input (CVE-2026-40890)

A flaw was found in github.com/gomarkdown/markdown, a Go library for parsing Markdown text and rendering as HTML. A remote attacker could exploit this vulnerability by providing a specially crafted malformed input. Specifically, input cont…

▾ TwilightRed Hat · Multicluster Global Hub 1.4.9EPSS 0.52%via CSAF
CVE-2026-33813High· 7.5
5mo ago

Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.

Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.62%via NVD
CVE-2026-40293High· 7.5
5mo ago

OpenFGA: github.com/openfga/openfga: OpenFGA: Information disclosure of preshared API key via playground endpoint (CVE-2026-40293)

A flaw was found in OpenFGA, an authorization/permission engine. When OpenFGA is configured to use preshared-key authentication and the built-in playground is enabled and accessible beyond localhost or trusted networks, a remote attacker c…

▾ TwilightRed Hat · Multicluster Global Hub 1.7.3EPSS 0.50%via CSAF
CVE-2026-5598High· 7.5
5mo ago

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, f…

▾ TwilightLegion of the Bouncy Castle Inc. · coreEPSS 0.96%via NVD
CVE-2026-3505High· 7.5
5mo ago

Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc

Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program files AEADEncData…

▾ TwilightLegion of the Bouncy Castle Inc. · bcpgEPSS 0.88%via NVD
CVE-2026-40575Critical· 9.1
5mo ago

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing

▾ Midnightoauth2-proxy · github.com/oauth2-proxy/oauth2-proxy/v7EPSS 0.73%via OSV
CVE-2025-41118Critical· 9.1
5mo ago

Pyroscope is an open-source continuous profiling database

Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS). If the database is configured to use Tencent COS as the storage backend, an attacke…

▾ Midnightgrafana · pyroscopeEPSS 0.41%via NVD
CVE-2026-5588High· 7.5
5mo ago

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Cast…

▾ TwilightLegion of the Bouncy Castle Inc. · bcpkixEPSS 0.69%via NVD
CVE-2026-0636Medium· 6.5
5mo ago

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreH…

▾ SunlitLegion of the Bouncy Castle Inc. · bcprovEPSS 0.53%via NVD
CVE-2025-14813High· 7.5
5mo ago

: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc

: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBlockCipher. This issue affects B…

▾ TwilightLegion of the Bouncy Castle Inc. · bcprovEPSS 0.32%via NVD
CVE-2026-6855High· 7.1
5mo ago

instructlab: InstructLab: Path traversal allows arbitrary directory creation and file write (CVE-2026-6855)

A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbi…

▾ TwilightRed Hat · Red Hat Enterprise Linux AI (RHEL AI) 3EPSS 0.22%via CSAF
CVE-2026-40192High· 7.5
5mo ago

Pillow is a Python imaging library

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file coul…

▾ Twilightpython · pillowEPSS 0.87%via NVD
CVE-2026-40683High· 7.7
5mo ago

OpenStack Keystone: OpenStack Keystone: Unauthorized access due to incorrect LDAP user status handling (CVE-2026-40683)

A flaw was found in OpenStack Keystone. When using the LDAP identity backend, the system incorrectly processes the user enabled attribute if the user_enabled_invert configuration option is set to False. This error causes users marked as di…

▾ TwilightRed Hat · Red Hat OpenStack Platform 13 (Queens)EPSS 0.37%via CSAF
CVE-2026-2332High· 7.4PoC
5mo ago

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/…

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/…

▾ Midnighteclipse · jettyEPSS 1.3%via NVD
CVE-2026-34481High· 7.5
5mo ago

Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN…

Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN…

▾ Twilightapache · log4jEPSS 0.85%via NVD
CVE-2025-62718Critical· 9.9PoC⚖ disputed
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a tra…

▾ Abyssalaxios · axiosEPSS 1.2%via NVD
CVE-2026-4878Medium· 6.7
5mo ago

A flaw was found in libcap

A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file c…

▾ Sunlitlibcap_project · libcapEPSS 0.14%via NVD
CVE-2025-57847Medium· 6.4
5mo ago

A container privilege escalation flaw was found in certain Ansible Automation Platform images

A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an …

▾ Sunlitredhat · ansible_automation_platformEPSS 0.18%via NVD
CVE-2026-31411Medium· 5.5
5mo ago

In the Linux kernel, the following vulnerability has been resolved: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() Reproducer available at [1]. The ATM send path (sendmsg -> vcc_sendmsg -> sigd_send) reads the vcc p…

In the Linux kernel, the following vulnerability has been resolved: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() Reproducer available at [1]. The ATM send path (sendmsg -> vcc_sendmsg -> sigd_send) reads the vcc p…

▾ Sunlitlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-32288Medium· 5.5
5mo ago

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

▾ Sunlitgolang · goEPSS 0.18%via NVD
CVE-2026-5879High· 8.8
5mo ago

Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

▾ Twilightgoogle · chromeEPSS 0.41%via NVD
CVE-2026-5868High· 8.8
5mo ago

Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.45%via NVD
CVE-2026-32591Medium· 5.2
5mo ago

A flaw was found in Red Hat Quay's Proxy Cache configuration feature

A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verify…

▾ Sunlitredhat · mirror_registry_for_red_hat_openshiftEPSS 0.46%via NVD
CVE-2026-32289Medium· 5.4
5mo ago

html/template: golang: html/template: Cross-Site Scripting (XSS) via improper context and brace depth tracking in JS template literals (CVE…

A flaw was found in the `html/template` package. This vulnerability arises from improper tracking of context and brace depth within JavaScript (JS) template literals. A remote attacker could exploit these issues to cause content to be inco…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.33%via CSAF
CVE-2026-39883High· 7.0
5mo ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PAT…

▾ Twilightopentelemetry · opentelemetryEPSS 0.21%via NVD
CVE-2026-32281Medium· 5.9
5mo ago

crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)

A flaw was found in Go's `crypto/x509` package. A remote attacker could exploit this by presenting a specially crafted certificate chain containing a large number of policy mappings. This inefficient validation process consumes excessive r…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream EUS (v.9.6)EPSS 0.37%via CSAF
CVE-2026-32282High· 7.8
5mo ago

golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)

A flaw was found in the internal/syscall/unix package in the Go standard library. If the target of the `Root.Chmod` function is replaced with a symbolic link during execution, specifically after `Root.Chmod` checks the target but before ac…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.17%via CSAF
CVEs tagged “red-hat” — page 88 · VulnSea