VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2912 CVEsRSS

CVE-2026-94368High· 7.1
6d ago

A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway

A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when the service processes S3 presigned URLs using Signature Version 4 (SigV4). Due to impr…

▾ TwilightRed Hat · odf4/mcg-core-rhel9EPSS 0.23%via NVD
CVE-2026-91865High· 7.5
6d ago

A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgr…

A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgr…

▾ Twilightapache · neethiEPSS 0.74%via NVD
CVE-2026-91866High· 7.5
6d ago

A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes…

A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes…

▾ Twilightapache · neethiEPSS 0.74%via NVD
CVE-2026-91863High· 7.5
6d ago

A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service). Users are recommended to upgrade to version 3.2.4, w…

A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service). Users are recommended to upgrade to version 3.2.4, w…

▾ Twilightapache · neethiEPSS 0.76%via NVD
CVE-2026-91864High· 7.5
6d ago

A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to u…

A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to u…

▾ Twilightapache · neethiEPSS 0.74%via NVD
CVE-2026-92574High· 8.8
6d ago

A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context

A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities…

▾ TwilightRed Hat · openshift-sandboxed-containers/osc-monitor-rhel9EPSS 0.65%via NVD
CVE-2026-15801High· 8.0⚖ disputed
6d ago

A vulnerability was found in CRI-O related to the container checkpoint and restore feature

A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow a user with suffic…

▾ TwilightRed Hat · cri-oEPSS 0.32%via NVD
CVE-2026-47321High· 7.5
6d ago

The CompressionFilter class uses ZLib to deflate and inflate data sent and received

The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what. Some compressed data may have a comp…

▾ TwilightApache Software Foundation · org.apache.mina:mina-filter-compressionEPSS 0.49%via NVD
CVE-2026-94218Low· 3.1
6d ago

A flaw was found in the authentication session management of Keycloak, an identity and access management solution

A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a stronger authentication flow, such as mandatory two-factor authenticatio…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.31%via NVD
CVE-2026-94217Low· 3.5
6d ago

A flaw was found in the User-Managed Access (UMA) implementation of Keycloak

A flaw was found in the User-Managed Access (UMA) implementation of Keycloak. The issue occurs in the authorization token endpoint when processing permission tickets. If two different users own resources with the same name, the system in…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.24%via NVD
CVE-2026-94213Medium· 4.9
6d ago

A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution

A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue occurs in the policy evaluation endpoint, which is used by administrators to test how access policies…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.39%via NVD
CVE-2026-94215Medium· 5.5
6d ago

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses a per-request in-memory cache to resolve clients by their unique identifier without verifyi…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.30%via NVD
CVE-2026-93990High· 7.5
1w ago

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following c…

▾ Twilightlibexpat · libexpatEPSS 0.37%via NVD
CVE-2026-93989Low· 3.1
1w ago

vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer()

vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). Attackers can supply out-of-bounds token indices that corrupt logits memory of …

▾ Sunlitvllm-project · vllmEPSS 0.32%via NVD
CVE-2026-94055Low· 3.7
1w ago

Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.

Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.

▾ Sunlitexim · eximEPSS 0.29%via NVD
CVE-2026-94000Medium· 6.6
1w ago

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges be…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.40%via NVD
CVE-2026-93999Medium· 4.2
1w ago

A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution

A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh process when the server restores requested audiences from stored client I…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.23%via NVD
CVE-2026-94001Medium· 6.5
1w ago

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials does not correctly check for fine-grained reset-password permissions. This allows…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.44%via NVD
CVE-2026-93981Medium· 4.7
1w ago

hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the roo…

hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the roo…

▾ Sunlithonojs · honoEPSS 0.23%via NVD
CVE-2026-93986Low· 3.1
1w ago

rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names

rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and parent…

▾ Sunlitrclone · rcloneEPSS 0.29%via NVD
CVE-2026-93987Low· 3.4PoC⚖ disputed
1w ago

rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin

rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/docker/volume.go computes a volume's mountpoint as filepath.Join(drv.root, name) from the a…

▾ Twilightrclone · rcloneEPSS 0.15%via NVD
CVE-2026-75885Critical· 9.3
1w ago

A flaw was found in the OpenShift console

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF)…

▾ MidnightRed Hat · openshift4/ose-consoleEPSS 0.53%via NVD
CVE-2026-93574Medium· 6.5
1w ago

A flaw was found in Netty's `netty-codec-http` component

A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/1.1 chunk-size token that includes post-digit whitespace. This incorrect parsing of the chun…

▾ SunlitRed Hat · netty-codec-httpEPSS 0.86%via NVD
CVE-2026-93562Medium· 6.5PoC
1w ago

A flaw was found in Netty's HTTP/1 decoder

A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending specially crafted HTTP requests, an attacker can inject arbit…

▾ TwilightRed Hat · netty-codec-httpEPSS 0.58%via NVD
CVE-2026-61822Medium· 6.5
1w ago

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance() handles exceptions outside the loop that processes rows from part_config, so an exception for one partition set immedia…

▾ Sunlitpgpartman · pg_partmanEPSS 0.53%via NVD
CVE-2026-61821High· 8.5
1w ago

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, drop_partition_id() and drop_partition_time() use part_config.retention_schema as the target for ALTER TABLE SET SCHEMA and accept any no…

▾ Twilightpgpartman · pg_partmanEPSS 0.38%via NVD
CVE-2026-61820High· 8.5
1w ago

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, inherit_template_properties() manually surrounds primary-key column names from pg_attribute.attname with double quotes without escaping e…

▾ Twilightpgpartman · pg_partmanEPSS 0.73%via NVD
CVE-2026-61819High· 8.5
1w ago

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jobmon is installed and part_config.jobmon is true, exception handlers in multiple pg_partman functions place p_parent_table verb…

▾ Twilightpgpartman · pg_partmanEPSS 0.73%via NVD
CVE-2026-61818High· 8.5
1w ago

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, undo_partition() reads part_config.time_encoder as unrestricted text and interpolates it without identifier quoting into a dynamically ex…

▾ Twilightpgpartman · pg_partmanEPSS 0.51%via NVD
CVE-2026-61817High· 8.5
1w ago

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance(), show_partitions(), show_partition_info(), undo_partition(), and partition_data_time() interpolate the writable part_co…

▾ Twilightpgpartman · pg_partmanEPSS 0.73%via NVD
CVEs tagged “red-hat” — page 9 · VulnSea