← Browse

Redhat

86 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-15041 LOW 3.7 Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcm… 2026-07-08 CVE-2026-15154 MEDIUM 6.5 Red Hat Openshift Ai (Rhoai) — A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as … 2026-07-08 CVE-2026-14940 MEDIUM 5.3 Red Hat Directory Server 11 — A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished … 2026-07-07 CVE-2026-14969 MEDIUM 4.4 Red Hat Directory Server 11 — A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initializa… 2026-07-07 CVE-2026-58384 HIGH 7.3 Red Hat Enterprise Linux 9 — A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap … 2026-07-07 CVE-2026-58380 HIGH 7.3 Red Hat Enterprise Linux 9 — A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_g… 2026-07-06 CVE-2026-59089 MEDIUM 5.5 Red Hat Enterprise Linux 6 — A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorr…● PoC 2026-07-06 CVE-2026-5135 MEDIUM 6.5 Red Hat Satellite 6.16 For Rhel 8 — A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-e… 2026-07-01 CVE-2026-5136 HIGH 8.8 Red Hat Satellite 6.16 For Rhel 8 — A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments agains… 2026-07-01 CVE-2026-5138 MEDIUM 4.3 Red Hat Satellite 6.16 For Rhel 8 — A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant inf… 2026-07-01 CVE-2026-5142 MEDIUM 6.5 Red Hat Satellite 6.16 For Rhel 8 — A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, … 2026-07-01 CVE-2026-12388 MEDIUM 6.5 Red Hat Build Of Keycloak — A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user… 2026-06-30 CVE-2026-12610 MEDIUM 6.4 Red Hat Enterprise Linux 10 — A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-af… 2026-06-30 CVE-2026-13316 MEDIUM 4.4 Red Hat Satellite 6 — A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy f… 2026-06-30 CVE-2026-14209 MEDIUM 4.3 Red Hat Build Of Keycloak — A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to by… 2026-06-30 CVE-2026-4629 MEDIUM 6.5 Red Hat Build Of Keycloak — A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulne… 2026-06-30 CVE-2026-58010 MEDIUM 6.5 Glib — A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvaria… 2026-06-30 CVE-2026-58011 MEDIUM 6.5 Glib — A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function …● PoC 2026-06-30 CVE-2026-58012 MEDIUM 6.5 Glib — A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_R… 2026-06-30 CVE-2026-58013 MEDIUM 6.5 Glib — A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c… 2026-06-30 CVE-2026-58014 HIGH 7.3 Glib — A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in t…● PoC 2026-06-30 CVE-2026-58015 MEDIUM 5.9 Glib — A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mec… 2026-06-30 CVE-2026-58016 HIGH 7.5 Glib — A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusint… 2026-06-30 CVE-2026-12856 HIGH 8.8 Red Hat Openshift Dev Spaces 3.29 — A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. Th… 2026-06-29 CVE-2026-13595 MEDIUM 6.8 Red Hat Hardened Images — A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solar… 2026-06-29 CVE-2026-13601 HIGH 7.1 Red Hat Enterprise Linux 6 — A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by … 2026-06-29 CVE-2026-13757 MEDIUM 6.2 Red Hat Hardened Images — A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p… 2026-06-29 CVE-2026-57965 MEDIUM 5.1 Red Hat Enterprise Linux 10 — A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by se… 2026-06-29 CVE-2026-57966 MEDIUM 4.4 Red Hat Enterprise Linux 10 — A path traversal vulnerability was found in spice-vdagent. This flaw allows a malicious or compromised SPICE h… 2026-06-29 CVE-2026-13322 LOW 3.8 Red Hat Openshift Virtualization 4 — A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using te… 2026-06-26 CVE-2026-13325 HIGH 8.5 Red Hat Openshift Virtualization 4 — A flaw was found in KubeVirt's migration proxy. When spec.configuration.migrations.disableTLS is set to true o… 2026-06-26 CVE-2026-13434 MEDIUM 4.9 Red Hat Openshift Virtualization 4 — A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance wi… 2026-06-26 CVE-2026-11800 HIGH 8.1 Red Hat Build Of Keycloak 26.6 — A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow a… 2026-06-25 CVE-2026-12975 HIGH 8.5 Red Hat Build Of Apicurio Registry 3 — A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory w… 2026-06-25 CVE-2026-12992 HIGH 7.4 Red Hat Build Of Apicurio Registry 3 — A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling th… 2026-06-25 CVE-2026-12993 MEDIUM 6.5 Red Hat Build Of Apicurio Registry 3 — A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema ac… 2026-06-25 CVE-2026-13083 MEDIUM 6.9 Pen Drive Powered By Red Hat Lightspeed — A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without… 2026-06-25 CVE-2026-13218 MEDIUM 4.2 Red Hat Openshift Virtualization 4 — A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data… 2026-06-25 CVE-2026-13318 MEDIUM 6.4 Red Hat Openshift Virtualization 4 — A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processi… 2026-06-25 CVE-2026-53145 HIGH 7.8 Linux — In the Linux kernel, the following vulnerability has been resolved: drm/gem: Try to fix change_handle ioctl, … 2026-06-25 CVE-2026-53153 HIGH 7.8 Linux — In the Linux kernel, the following vulnerability has been resolved: mm/list_lru: drain before clearing xarray… 2026-06-25 CVE-2026-9083 MEDIUM 4.9 Red Hat Build Of Keycloak 26.4 — A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerabilit… 2026-06-25 CVE-2026-9086 HIGH 7.3 Red Hat Build Of Keycloak 26.4 — A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manag… 2026-06-25 CVE-2026-9099 HIGH 7.7 Red Hat Build Of Keycloak 26.4 — A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within th… 2026-06-25 CVE-2026-9705 MEDIUM 6.5 Red Hat Build Of Keycloak 26.4 — A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued … 2026-06-25 CVE-2026-9799 MEDIUM 4.6 Red Hat Build Of Keycloak 26.4 — A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA)… 2026-06-25 CVE-2026-9800 HIGH 8.1 Red Hat Build Of Keycloak 26.4 — A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all a… 2026-06-25 CVE-2026-13201 HIGH 7.3 Red Hat Openshift Virtualization 4 — A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|… 2026-06-24 CVE-2026-13208 MEDIUM 6.5 Red Hat Openshift Virtualization 4 — A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and … 2026-06-24 CVE-2026-53000 HIGH 7.8 Linux — In the Linux kernel, the following vulnerability has been resolved: netfilter: nat: use kfree_rcu to release … 2026-06-24 CVE-2026-53002 CRITICAL 9.8 Linux — In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usag… 2026-06-24 CVE-2026-53006 CRITICAL 9.8 Linux — In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() C… 2026-06-24 CVE-2026-53009 HIGH 7.8 Linux — In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ic… 2026-06-24 CVE-2026-10609 MEDIUM 6.8 Logging Subsystem For Red Hat Openshift — A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and for… 2026-06-23 CVE-2026-11819 MEDIUM 5.5 Red Hat Enterprise Linux 10 — Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: …● PoC 2026-06-23 CVE-2026-11820 MEDIUM 6.5 Red Hat Enterprise Linux 10 — A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP reques… 2026-06-23 CVE-2026-12112 HIGH 7.8 Red Hat Satellite 6.18 — A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauth… 2026-06-23 CVE-2026-12891 MEDIUM 4.3 Red Hat Enterprise Linux 10 — A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream … 2026-06-23 CVE-2026-12892 MEDIUM 4.4 Red Hat Enterprise Linux 10 — A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file … 2026-06-23 CVE-2026-12969 MEDIUM 5.3 Red Hat Enterprise Linux 10 — An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS … 2026-06-23 CVE-2026-55653 MEDIUM 4.3 Red Hat Hardened Images — A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hell… 2026-06-23 CVE-2026-55654 LOW 3.7 Red Hat Hardened Images — A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAP… 2026-06-23 CVE-2026-55655 MEDIUM 5 Red Hat Hardened Images — A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 f… 2026-06-23 CVE-2026-9073 MEDIUM 6.2 Red Hat Satellite 6.18 — A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expos… 2026-06-23 CVE-2026-12549 MEDIUM 4.8 Red Hat Enterprise Linux 10 — The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks w… 2026-06-22 CVE-2026-12725 MEDIUM 5.9 Red Hat Enterprise Linux 10 — A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, … 2026-06-22 CVE-2026-54099 HIGH 8.8 Red Hat Openshift Container Platform 4 — A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The W… 2026-06-22 CVE-2026-54100 HIGH 8.3 Red Hat Openshift Container Platform 4 — A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO … 2026-06-22 CVE-2026-11791 MEDIUM 5 Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function uncondition… 2026-06-18 CVE-2026-12528 MEDIUM 5.4 Red Hat Directory Server 11 — A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed… 2026-06-17 CVE-2026-47774 HIGH 7.5 Envoy — Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.… 2026-06-17 CVE-2026-1764 MEDIUM 5.6 Red Hat Enterprise Linux 10 — A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing spec… 2026-06-16 CVE-2026-1766 MEDIUM 5.6 Red Hat Enterprise Linux 10 — A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within … 2026-06-16 CVE-2026-1767 MEDIUM 5.6 Red Hat Enterprise Linux 10 — A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-… 2026-06-16 CVE-2026-54230 HIGH 7 Red Hat Enterprise Linux 6 — A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event … 2026-06-13 CVE-2026-54231 MEDIUM 5.5 Red Hat Enterprise Linux 6 — A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The ev… 2026-06-13 CVE-2026-44172 MEDIUM 6.9 Server — MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application tha… 2026-06-12 CVE-2026-11785 MEDIUM 4.3 Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes … 2026-06-09 CVE-2026-11786 LOW 1.9 Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing … 2026-06-09 CVE-2026-11787 MEDIUM 5 Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffe… 2026-06-09 CVE-2026-11788 MEDIUM 5.9 Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure… 2026-06-09 CVE-2026-11789 MEDIUM 4.9 Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow… 2026-06-09 CVE-2026-11790 MEDIUM 4.9 Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper … 2026-06-09 CVE-2026-11793 MEDIUM 4.9 Red Hat Directory Server 11 — A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an a… 2026-06-09 CVE-2026-41731 HIGH 8.1 Spring For Apache Kafka — JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted package… 2026-06-09 CVE-2026-11611 MEDIUM 6.5 Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounde… 2026-06-08