VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2956 CVEsRSS

CVE-2026-33997Medium· 6.8
6mo ago

Moby is an open source container framework

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privile…

▾ Sunlitdocker · engineEPSS 0.51%via NVD
CVE-2026-33748Medium· 6.5
6mo ago

github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components (CVE-2026-33748)

A flaw was found in BuildKit. Insufficient validation of Git URL fragment subdirectory components may allow a remote attacker to access files outside the checked-out Git repository root. This access is limited to files on the same mounted …

▾ SunlitRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.53%via CSAF
CVE-2026-33747High· 8.2
6mo ago

BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend (CVE-2026-33747)

A flaw was found in BuildKit, a toolkit for converting source code to build artifacts. An untrusted BuildKit frontend can be leveraged to craft a malicious API message, allowing files to be written outside of the designated BuildKit state …

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.58%via CSAF
CVE-2026-4948Medium· 5.5
6mo ago

A flaw was found in firewalld

A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify …

▾ Sunlitfirewalld · firewalldEPSS 0.18%via NVD
CVE-2026-28369High· 8.7
6mo ago

A flaw was found in Undertow

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP s…

▾ Twilightredhat · build_of_apache_camel_-_hawtioEPSS 0.89%via NVD
CVE-2026-33871High· 7.5
6mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUAT…

▾ Twilightnetty · nettyEPSS 1.2%via NVD
CVE-2026-33870High· 7.5PoC
6mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request s…

▾ Midnightnetty · nettyEPSS 0.70%via NVD
CVE-2026-33894High· 7.5PoC
6mo ago

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3). Attack…

▾ Midnightdigitalbazaar · forgeEPSS 0.45%via NVD
CVE-2026-28368High· 8.7
6mo ago

A flaw was found in Undertow

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretati…

▾ Twilightredhat · build_of_apache_camel_-_hawtioEPSS 0.89%via NVD
CVE-2026-28367High· 8.7
6mo ago

A flaw was found in Undertow

A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic …

▾ Twilightredhat · build_of_apache_camel_-_hawtioEPSS 0.89%via NVD
CVE-2026-4897Medium· 5.5
6mo ago

A flaw was found in polkit

A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory…

▾ Sunlitfreedesktop · polkitEPSS 0.15%via NVD
CVE-2026-4926High· 7.5
6mo ago

Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`

Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of servic…

▾ Twilightpillarjs · path-to-regexpEPSS 0.89%via NVD
CVE-2026-33487High· 7.5PoC
6mo ago

goxmlsig provides XML Digital Signatures implemented in Go

goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo` block to find one that matches the signed element's ID.…

▾ Midnightgoxmldsig_project · goxmldsigEPSS 0.42%via NVD
CVE-2026-32285High· 7.5PoC
6mo ago

The Delete function fails to properly validate offsets when processing malformed JSON input

The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.

▾ Midnightjsonparser_project · jsonparserEPSS 0.97%via NVD
CVE-2026-32286High· 7.5PoC
6mo ago

The DataRow.Decode function fails to properly validate field lengths

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

▾ Midnightjackc · pgproto3EPSS 0.92%via NVD
CVE-2026-33247High· 7.4
6mo ago

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentials for all clients provided via argv (the command-line), t…

▾ Twilightlinuxfoundation · nats-serverEPSS 0.54%via NVD
CVE-2026-33219Medium· 5.3⚖ disputed
6mo ago

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-…

▾ Sunlitlinuxfoundation · nats-serverEPSS 1.0%via NVD
CVE-2026-33218High· 7.5
6mo ago

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed mess…

▾ Twilightlinuxfoundation · nats-serverEPSS 0.84%via NVD
CVE-2026-33217High· 7.1
6mo ago

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace, allowing M…

▾ Twilightlinuxfoundation · nats-serverEPSS 0.37%via NVD
CVE-2026-33216High· 8.6
6mo ago

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-auth…

▾ Twilightlinuxfoundation · nats-serverEPSS 0.63%via NVD
CVE-2026-29785High· 7.5
6mo ago

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect …

▾ Twilightlinuxfoundation · nats-serverEPSS 0.97%via NVD
CVE-2026-27889High· 7.5PoC
6mo ago

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a server panic…

▾ Midnightlinuxfoundation · nats-serverEPSS 0.84%via NVD
CVE-2025-67030High· 8.8
6mo ago

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

▾ Twilightcodehaus-plexus · plexus-utilsEPSS 0.66%via NVD
CVE-2026-1519High· 7.5
6mo ago

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritati…

▾ Twilightisc · bindEPSS 1.6%via NVD
CVE-2026-26209Medium· 5.5⚖ disputed
6mo ago

cbor2: cbor2: Denial of Service due to uncontrolled recursion via crafted CBOR payloads (CVE-2026-26209)

A flaw was found in cbor2, a library for encoding and decoding Concise Binary Object Representation (CBOR) data. A remote attacker can exploit this vulnerability by sending a specially crafted CBOR payload containing deeply nested structur…

▾ SunlitRed Hat · Red Hat Enterprise Linux AI (RHEL AI) 3EPSS 0.65%via CSAF
CVE-2026-4601High· 8.7
6mo ago

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s…

▾ Twilightkjur · jsrsasignEPSS 0.47%via NVD
CVE-2026-4602High· 7.5PoC
6mo ago

Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js

Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and brea…

▾ Midnightkjur · jsrsasignEPSS 0.88%via NVD
CVE-2026-4599Critical· 9.1
6mo ago

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker …

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker …

▾ Midnightkjur · jsrsasignEPSS 0.78%via NVD
CVE-2026-4598High· 7.5PoC
6mo ago

Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang th…

Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang th…

▾ Midnightkjur · jsrsasignEPSS 0.96%via NVD
CVE-2026-4600High· 7.4PoC
6mo ago

Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/ds…

Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/ds…

▾ Midnightkjur · jsrsasignEPSS 0.32%via NVD
CVEs tagged “red-hat” — page 90 · VulnSea