Redhat
86 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-15041
LOW 3.7
Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcm…
2026-07-08
CVE-2026-15154
MEDIUM 6.5
Red Hat Openshift Ai (Rhoai) — A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as …
2026-07-08
CVE-2026-14940
MEDIUM 5.3
Red Hat Directory Server 11 — A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When
normalizing a Distinguished …
2026-07-07
CVE-2026-14969
MEDIUM 4.4
Red Hat Directory Server 11 — A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initializa…
2026-07-07
CVE-2026-58384
HIGH 7.3
Red Hat Enterprise Linux 9 — A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap …
2026-07-07
CVE-2026-58380
HIGH 7.3
Red Hat Enterprise Linux 9 — A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_g…
2026-07-06
CVE-2026-59089
MEDIUM 5.5
Red Hat Enterprise Linux 6 — A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorr…● PoC
2026-07-06
CVE-2026-5135
MEDIUM 6.5
Red Hat Satellite 6.16 For Rhel 8 — A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-e…
2026-07-01
CVE-2026-5136
HIGH 8.8
Red Hat Satellite 6.16 For Rhel 8 — A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments agains…
2026-07-01
CVE-2026-5138
MEDIUM 4.3
Red Hat Satellite 6.16 For Rhel 8 — A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant inf…
2026-07-01
CVE-2026-5142
MEDIUM 6.5
Red Hat Satellite 6.16 For Rhel 8 — A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, …
2026-07-01
CVE-2026-12388
MEDIUM 6.5
Red Hat Build Of Keycloak — A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user…
2026-06-30
CVE-2026-12610
MEDIUM 6.4
Red Hat Enterprise Linux 10 — A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-af…
2026-06-30
CVE-2026-13316
MEDIUM 4.4
Red Hat Satellite 6 — A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy f…
2026-06-30
CVE-2026-14209
MEDIUM 4.3
Red Hat Build Of Keycloak — A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to by…
2026-06-30
CVE-2026-4629
MEDIUM 6.5
Red Hat Build Of Keycloak — A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulne…
2026-06-30
CVE-2026-58010
MEDIUM 6.5
Glib — A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvaria…
2026-06-30
CVE-2026-58011
MEDIUM 6.5
Glib — A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function …● PoC
2026-06-30
CVE-2026-58012
MEDIUM 6.5
Glib — A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_R…
2026-06-30
CVE-2026-58013
MEDIUM 6.5
Glib — A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c…
2026-06-30
CVE-2026-58014
HIGH 7.3
Glib — A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in t…● PoC
2026-06-30
CVE-2026-58015
MEDIUM 5.9
Glib — A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mec…
2026-06-30
CVE-2026-58016
HIGH 7.5
Glib — A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusint…
2026-06-30
CVE-2026-12856
HIGH 8.8
Red Hat Openshift Dev Spaces 3.29 — A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. Th…
2026-06-29
CVE-2026-13595
MEDIUM 6.8
Red Hat Hardened Images — A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solar…
2026-06-29
CVE-2026-13601
HIGH 7.1
Red Hat Enterprise Linux 6 — A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by …
2026-06-29
CVE-2026-13757
MEDIUM 6.2
Red Hat Hardened Images — A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p…
2026-06-29
CVE-2026-57965
MEDIUM 5.1
Red Hat Enterprise Linux 10 — A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by se…
2026-06-29
CVE-2026-57966
MEDIUM 4.4
Red Hat Enterprise Linux 10 — A path traversal vulnerability was found in spice-vdagent. This flaw allows a malicious or compromised SPICE h…
2026-06-29
CVE-2026-13322
LOW 3.8
Red Hat Openshift Virtualization 4 — A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using te…
2026-06-26
CVE-2026-13325
HIGH 8.5
Red Hat Openshift Virtualization 4 — A flaw was found in KubeVirt's migration proxy. When spec.configuration.migrations.disableTLS is set to true o…
2026-06-26
CVE-2026-13434
MEDIUM 4.9
Red Hat Openshift Virtualization 4 — A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance wi…
2026-06-26
CVE-2026-11800
HIGH 8.1
Red Hat Build Of Keycloak 26.6 — A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow a…
2026-06-25
CVE-2026-12975
HIGH 8.5
Red Hat Build Of Apicurio Registry 3 — A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory w…
2026-06-25
CVE-2026-12992
HIGH 7.4
Red Hat Build Of Apicurio Registry 3 — A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling th…
2026-06-25
CVE-2026-12993
MEDIUM 6.5
Red Hat Build Of Apicurio Registry 3 — A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema ac…
2026-06-25
CVE-2026-13083
MEDIUM 6.9
Pen Drive Powered By Red Hat Lightspeed — A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without…
2026-06-25
CVE-2026-13218
MEDIUM 4.2
Red Hat Openshift Virtualization 4 — A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data…
2026-06-25
CVE-2026-13318
MEDIUM 6.4
Red Hat Openshift Virtualization 4 — A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processi…
2026-06-25
CVE-2026-53145
HIGH 7.8
Linux — In the Linux kernel, the following vulnerability has been resolved:
drm/gem: Try to fix change_handle ioctl, …
2026-06-25
CVE-2026-53153
HIGH 7.8
Linux — In the Linux kernel, the following vulnerability has been resolved:
mm/list_lru: drain before clearing xarray…
2026-06-25
CVE-2026-9083
MEDIUM 4.9
Red Hat Build Of Keycloak 26.4 — A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerabilit…
2026-06-25
CVE-2026-9086
HIGH 7.3
Red Hat Build Of Keycloak 26.4 — A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manag…
2026-06-25
CVE-2026-9099
HIGH 7.7
Red Hat Build Of Keycloak 26.4 — A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within th…
2026-06-25
CVE-2026-9705
MEDIUM 6.5
Red Hat Build Of Keycloak 26.4 — A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued …
2026-06-25
CVE-2026-9799
MEDIUM 4.6
Red Hat Build Of Keycloak 26.4 — A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA)…
2026-06-25
CVE-2026-9800
HIGH 8.1
Red Hat Build Of Keycloak 26.4 — A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all a…
2026-06-25
CVE-2026-13201
HIGH 7.3
Red Hat Openshift Virtualization 4 — A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|…
2026-06-24
CVE-2026-13208
MEDIUM 6.5
Red Hat Openshift Virtualization 4 — A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and …
2026-06-24
CVE-2026-53000
HIGH 7.8
Linux — In the Linux kernel, the following vulnerability has been resolved:
netfilter: nat: use kfree_rcu to release …
2026-06-24
CVE-2026-53002
CRITICAL 9.8
Linux — In the Linux kernel, the following vulnerability has been resolved:
netfilter: conntrack: remove sprintf usag…
2026-06-24
CVE-2026-53006
CRITICAL 9.8
Linux — In the Linux kernel, the following vulnerability has been resolved:
ipv6: fix possible UAF in icmpv6_rcv()
C…
2026-06-24
CVE-2026-53009
HIGH 7.8
Linux — In the Linux kernel, the following vulnerability has been resolved:
ice: fix double-free of tx_buf skb
If ic…
2026-06-24
CVE-2026-10609
MEDIUM 6.8
Logging Subsystem For Red Hat Openshift — A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and for…
2026-06-23
CVE-2026-11819
MEDIUM 5.5
Red Hat Enterprise Linux 10 — Module: plugins/modules/keyring_info.py
CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Issue: …● PoC
2026-06-23
CVE-2026-11820
MEDIUM 6.5
Red Hat Enterprise Linux 10 — A flaw was found in the community.general Ansible collection's nexmo module.
The module constructs HTTP reques…
2026-06-23
CVE-2026-12112
HIGH 7.8
Red Hat Satellite 6.18 — A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauth…
2026-06-23
CVE-2026-12891
MEDIUM 4.3
Red Hat Enterprise Linux 10 — A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream …
2026-06-23
CVE-2026-12892
MEDIUM 4.4
Red Hat Enterprise Linux 10 — A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file …
2026-06-23
CVE-2026-12969
MEDIUM 5.3
Red Hat Enterprise Linux 10 — An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS …
2026-06-23
CVE-2026-55653
MEDIUM 4.3
Red Hat Hardened Images — A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hell…
2026-06-23
CVE-2026-55654
LOW 3.7
Red Hat Hardened Images — A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAP…
2026-06-23
CVE-2026-55655
MEDIUM 5
Red Hat Hardened Images — A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 f…
2026-06-23
CVE-2026-9073
MEDIUM 6.2
Red Hat Satellite 6.18 — A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expos…
2026-06-23
CVE-2026-12549
MEDIUM 4.8
Red Hat Enterprise Linux 10 — The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks w…
2026-06-22
CVE-2026-12725
MEDIUM 5.9
Red Hat Enterprise Linux 10 — A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and
query logging are both enabled, …
2026-06-22
CVE-2026-54099
HIGH 8.8
Red Hat Openshift Container Platform 4 — A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The W…
2026-06-22
CVE-2026-54100
HIGH 8.3
Red Hat Openshift Container Platform 4 — A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO …
2026-06-22
CVE-2026-11791
MEDIUM 5
Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function uncondition…
2026-06-18
CVE-2026-12528
MEDIUM 5.4
Red Hat Directory Server 11 — A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed…
2026-06-17
CVE-2026-47774
HIGH 7.5
Envoy — Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.…
2026-06-17
CVE-2026-1764
MEDIUM 5.6
Red Hat Enterprise Linux 10 — A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing spec…
2026-06-16
CVE-2026-1766
MEDIUM 5.6
Red Hat Enterprise Linux 10 — A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within …
2026-06-16
CVE-2026-1767
MEDIUM 5.6
Red Hat Enterprise Linux 10 — A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-…
2026-06-16
CVE-2026-54230
HIGH 7
Red Hat Enterprise Linux 6 — A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event …
2026-06-13
CVE-2026-54231
MEDIUM 5.5
Red Hat Enterprise Linux 6 — A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The ev…
2026-06-13
CVE-2026-44172
MEDIUM 6.9
Server — MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application tha…
2026-06-12
CVE-2026-11785
MEDIUM 4.3
Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes …
2026-06-09
CVE-2026-11786
LOW 1.9
Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing …
2026-06-09
CVE-2026-11787
MEDIUM 5
Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffe…
2026-06-09
CVE-2026-11788
MEDIUM 5.9
Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure…
2026-06-09
CVE-2026-11789
MEDIUM 4.9
Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow…
2026-06-09
CVE-2026-11790
MEDIUM 4.9
Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper …
2026-06-09
CVE-2026-11793
MEDIUM 4.9
Red Hat Directory Server 11 — A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an a…
2026-06-09
CVE-2026-41731
HIGH 8.1
Spring For Apache Kafka — JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted package…
2026-06-09
CVE-2026-11611
MEDIUM 6.5
Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounde…
2026-06-08