Red Hat Linux OS and other open source products
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Red Hat product.
RSS Feeds for Red Hat security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Red Hat products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Red Hat Sorted by Most Security Vulnerabilities since 2018
Red Hat Enterprise Linux Server1534 vulnerabilities
RedHat Enterprise Linux (RHEL) Server. Includes software bundeled with RHEL server.
Red Hat Enterprise Linux Workstation1504 vulnerabilities
RedHat Enterprise Linux (RHEL) Workstation. Includes software bundled with RHEL Workstation.
Red Hat Enterprise Linux Desktop1493 vulnerabilities
RedHat Enterprise Linux (RHEL) Desktop. Includes software bundled with RHEL desktop
Recent Red Hat Security Advisories
| Advisory | Title | Published |
|---|---|---|
| RHSA-2026:42694 | (RHSA-2026:42694) Moderate: glibc security update | July 21, 2026 |
| RHSA-2026:42692 | (RHSA-2026:42692) Important: evince security update | July 21, 2026 |
| RHSA-2026:42668 | (RHSA-2026:42668) Important: libtiff security update | July 21, 2026 |
| RHSA-2026:40768 | (RHSA-2026:40768) OpenShift Container Platform 4.22.6 bug fix and security update | July 21, 2026 |
| RHSA-2026:42644 | (RHSA-2026:42644) RHOAI 2.25.9 - Red Hat OpenShift AI | July 21, 2026 |
| RHSA-2026:40792 | (RHSA-2026:40792) OpenShift Container Platform 4.21.25 bug fix and security update | July 21, 2026 |
| RHSA-2026:42241 | (RHSA-2026:42241) Red Hat Hardened Images RPMs bug fix and enhancement update | July 21, 2026 |
| RHSA-2026:42555 | (RHSA-2026:42555) Important: postgresql:13 security update | July 21, 2026 |
| RHSA-2026:42552 | (RHSA-2026:42552) Important: kernel security, bug fix, and enhancement update | July 21, 2026 |
| RHSA-2026:42550 | (RHSA-2026:42550) Important: kernel-rt security, bug fix, and enhancement update | July 21, 2026 |
By the Year
In 2026 there have been 2191 vulnerabilities in Red Hat with an average score of 7.2 out of ten. Last year, in 2025 Red Hat had 1167 security vulnerabilities published. That is, 1024 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.65.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2191 | 7.24 |
| 2025 | 1167 | 6.59 |
| 2024 | 1688 | 6.57 |
| 2023 | 1206 | 6.75 |
| 2022 | 1362 | 6.97 |
| 2021 | 1123 | 6.61 |
| 2020 | 664 | 6.39 |
| 2019 | 772 | 6.98 |
| 2018 | 760 | 7.16 |
It may take a day or so for new Red Hat vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Red Hat Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-59846 | Jul 21, 2026 |
CVE-2026-59846: Shell Metacharacter Injection via %r ProxyCommand in libsshA flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior. |
|
| CVE-2026-16445 | Jul 21, 2026 |
Dracut DHCP Option Injection: Command Injection in initrd Network ModuleA flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot. |
And others... |
| CVE-2026-16461 | Jul 21, 2026 |
Buffer Overflow in rpcbind rpcinfo -s (rpcbdump)A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply are written into a fixed-size stack buffer without bounds checking. A user or administrator who runs `rpcinfo -s` against a malicious or compromised rpcbind endpoint could experience a crash or denial of service of the rpcinfo client. |
|
| CVE-2026-59844 | Jul 21, 2026 |
libssh SFTP Excessive Memory Allocation via SSH_FXP_READ (CVE-2026-59844)A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests. |
|
| CVE-2026-59845 | Jul 21, 2026 |
Local DoS via unchecked fork() in libssh ProxyCommandA flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service. |
|
| CVE-2026-59843 | Jul 21, 2026 |
DoS in Libssh: Zero Max Packet Size Loop in SSH_MSG_CHANNEL_OPENA flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service. |
|
| CVE-2026-59842 | Jul 21, 2026 |
libssh GSSAPI Key Exchange CVE-2026-59842: OOB Heap Read VulnerabilityA flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory. |
|
| CVE-2026-15370 | Jul 21, 2026 |
Unsafe SFTP Longname Buffer Overflow in libssh (CVE-2026-15370)A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server. |
|
| CVE-2026-15811 | Jul 21, 2026 |
kronosnet <=1.34 mem residual key leak, missing zerooutA vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this flaw to retrieve the active encryption key, allowing them to decrypt cluster network communications or inject malicious packets to cause severe high-availability cluster instability. |
|
| CVE-2026-15812 | Jul 21, 2026 |
kronosnet ACL Bypass via Unvalidated Link ID in Versions <=1.34A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP address) without network payload encryption, the validation architecture implicitly trusts the link ID provided within incoming data packets. A remote, unauthenticated attacker can exploit this lack of validation by spoofing a legitimate link ID inside crafted network frames. This allows the attacker to fully bypass the ACL framework and inject arbitrary data packets into the application layer, potentially leading to data corruption or service instabilities. |
|
| CVE-2026-15927 | Jul 21, 2026 |
Red Hat Quay SSRF via External Reference in Repo MirrorA flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror handlers which apply validate_external_registry_url(). A repository administrator can supply a crafted hostname that causes the Quay mirror worker to make requests via Skopeo to internal network services, cloud metadata endpoints, or other resources not intended to be reachable from the Quay application. |
|
| CVE-2026-64612 | Jul 20, 2026 |
Unprivileged DoS via malformed PNG in cups-filtersA flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job. |
|
| CVE-2026-12701 | Jul 20, 2026 |
Pulpcore Path Traversal in FilesystemExport Enables Arbitrary File WriteA path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../" anywhere in the path. An authenticated administrator can craft a relative_path containing embedded traversal sequences (e.g., "looking/normal/../../../../etc/shadow") that escapes the intended export directory during FilesystemExport operations. Because the file content is also user-controlled (uploaded artifact), this allows arbitrary file write to any location writable by the Pulp service user, potentially leading to service compromise or further system exploitation. |
And others... |
| CVE-2026-16277 | Jul 20, 2026 |
Stack buffer overflow in rpcbind's rpcinfo utilityA stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service. The highest threat from this vulnerability is to system availability. |
|
| CVE-2026-12080 | Jul 20, 2026 |
QEMU Guest Agent symlink exploit in guest-ssh-add-authorized-keys enables rootA flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race. Successful exploitation allows the attacker to gain ownership of arbitrary root-owned files or directories, leading to root access. This vulnerability requires an external management layer (e.g., libvirt) to trigger the affected code path. |
And others... |
| CVE-2026-15588 | Jul 20, 2026 |
GLib GDBus gdbusauth DoS via Input Length MisvalidationA denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang. |
And others... |
| CVE-2026-16254 | Jul 20, 2026 |
Claircore APK Scanner OOB Access CVE-2026-16254A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an out-of-bounds access that panics the scanner. If that panic is not recovered, the Clair indexer process can crash, leading to a denial of service. |
|
| CVE-2026-15813 | Jul 20, 2026 |
OOB Heap Corruption in KronosNet <=1.34 via Malformed PacketsA vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence numbers of incoming payload fragments. An attacker can exploit this lack of verification by transmitting malformed packets with corrupted sequence parameters. Under specific conditions, this forces the packet processing layer to parse data outside the designated bounds of the internal memory structures, causing an out-of-bounds memory access or heap corruption. This behavior can result in sudden application crashes or system instability. |
|
| CVE-2026-16242 | Jul 20, 2026 |
Konnectivity Proxy-Server: Unauthenticated Agent via Missing CA CertA flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic. |
And others... |
| CVE-2026-16118 | Jul 17, 2026 |
XDGMIME Heap Buffer Overflow via MIME Magic File (CVE-2026-16118)A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption. |
|
| CVE-2026-49852 | Jul 17, 2026 |
Python library joserfc - HMAC auth bug before 1.6.8joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attacker-forged HMAC-signed tokens when the caller-supplied verification key is the empty string or None, because HMACAlgorithm.sign and HMACAlgorithm.verify in src/joserfc/_rfc7518/jws_algs.py pass the output of OctKey.get_op_key(...) to hmac.new(...) and OctKey.import_key in src/joserfc/_rfc7518/oct_key.py only emits a SecurityWarning for keys shorter than 14 bytes without rejecting zero-length input. This issue is fixed in version 1.6.8. |
|
| CVE-2026-16104 | Jul 17, 2026 |
KeycloakServices auth endpoint leaks recaptcha keys via config VIEW onlyA flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive configuration values, such as reCAPTCHA secret keys, when they are requested by administrators with view-only permissions. This can lead to the exposure of third-party service credentials to unauthorized personnel or through administrative logs. |
And others... |
| CVE-2026-16103 | Jul 17, 2026 |
Brute-Force Token Redemption Loophole in Keycloak CIBA (keycloak-services)A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were omitted from the token redemption handler. This allows an attacker with valid client credentials to obtain access and refresh tokens for a user account that has been locked due to brute-force protection, provided the authentication request was started before the lockout occurred and was approved by the user. |
And others... |
| CVE-2026-16106 | Jul 17, 2026 |
Keycloak Admin API: RBAC Bypass Removing Composite RolesA flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker with limited administrative permissions can remove privileged roles they are not authorized to manage, leading to a loss of access for other users and administrators. |
And others... |
| CVE-2026-16108 | Jul 17, 2026 |
Keycloak Default-Group Disclosure via Delegated AdminA flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with realm-viewing permissions to see the names and identifiers of hidden default groups, even if they lack the specific permissions to view those groups. This can lead to the exposure of sensitive organizational structures or internal group names. |
And others... |
| CVE-2026-16093 | Jul 17, 2026 |
Bypass Keycloak Client Policies Signed JWT EnforcementKeycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met. This allows the attacker to authenticate using simpler methods like a client secret even when the administrator has mandated more secure, signed assertions. |
And others... |
| CVE-2026-63308 | Jul 17, 2026 |
Helm 4.2.3 Files.Lines OOB Crash DoSHelm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to trigger an index out of range panic by including zero-length byte slices in chart files. Attackers can include empty files in Helm charts to cause deterministic render failures across template, install, upgrade, lint, and SDK Engine.Render operations. |
|
| CVE-2026-16089 | Jul 17, 2026 |
Keycloak Services OAuth 2.0 Code Binding Flaw (Red Hat)A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be redeemed by their own client, potentially allowing them to obtain access tokens for a victim's identity. |
And others... |
| CVE-2026-16072 | Jul 17, 2026 |
Keycloak OrgMgmt API Bypass: Unauthorized Injection via Invitation LinkA flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application programming interface. By using this link, the administrator can create new user accounts and add them to the organization without having the required user management permissions or access to the invited email account. This allows an administrator to bypass security boundaries and add unauthorized members to an organization. |
And others... |
| CVE-2026-15943 | Jul 17, 2026 |
Keycloak keycloak-services: OIDC IDP Secret Leakage via Masked Client SecretA flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to improper validation, Keycloak reuses the existing real secret even if security-sensitive fields like the token URL have been changed, allowing an attacker to redirect and capture the secret. |
And others... |
| CVE-2026-15945 | Jul 16, 2026 |
Keycloak FGAP v2 Bypass: Delegated Admin Exposes Parent Group DataA flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration. |
And others... |
| CVE-2026-5674 | Jul 16, 2026 |
PipeWire Sandbox Escape via PulseAudio Compat LayerA flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system. |
|
| CVE-2026-48863 | Jul 16, 2026 |
libsolv PGP EdDSA Buffer Overflow (CVE-2026-48863)A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows. |
And others... |
| CVE-2026-1609 | Jul 16, 2026 |
Keycloak JWT grant bypass for disabled users due to missing validationA flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the users disabled status during JWT authorization grant processing. A remote attacker with low privileges can exploit this improper access control vulnerability by presenting a valid assertion token from an external identity provider to obtain a JWT for a disabled user. This allows unauthorized access to sensitive resources. |
|
| CVE-2026-3842 | Jul 16, 2026 |
QEMU OOB Write via cpu_physical_mem Map Length MismatchA flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond its allocated memory. This occurs when cpu_physical_memory_map() returns a shorter length than expected, leading to an out-of-bounds write. Successful exploitation could result in unauthorized access to guest memory or corruption of heap-allocated objects, potentially causing information disclosure, data integrity issues, or a denial of service. |
|
| CVE-2026-23538 | Jul 16, 2026 |
Feast Feature Server /ws/chat WS Auth Bypass Enables DOSA vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establish persistent WebSocket connections without any authentication. By opening a large number of simultaneous connections, an attacker can exhaust server resourcessuch as memory, CPU, and file descriptorsleading to a complete denial of service for legitimate users. |
|
| CVE-2026-12382 | Jul 15, 2026 |
RedHat AAP Gateway: Envoy Proxy Subject header bypass via non-mTLS routeA flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams. |
And others... |
| CVE-2026-15779 | Jul 15, 2026 |
Samba pam_winbind: chown / via mkhomedir Availability lossA flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this triggered not only by root, but by a non-root user holding a narrow sudo delegation to run commands as that account, causing ownership of / to change and resulting in severe denial of service (SSH, sudo, and package-manager failures). The change does not grant write access to / (which ships with restrictive 0555 permissions on RHEL), so the impact is availability loss rather than further privilege escalation. |
|
| CVE-2026-15809 | Jul 15, 2026 |
CRI-O Env Injection: Bypass CVE-2022-4318, Add /etc/passwd EntriesA flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable. |
|
| CVE-2026-14251 | Jul 15, 2026 |
OpenShift GitOps Argo CD ClusterRole Reconciliation Ownership Bypass (DoS)A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a denial of service. |
|
| CVE-2026-38753 | Jul 15, 2026 |
BusyBox v1.38 DoS via use-after-free in awk_sub (AWK)A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. |
|
| CVE-2026-38755 | Jul 15, 2026 |
BusyBox 1.38.0 Heap Overflow in evalcommand() Shell Enables DoSA heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. |
|
| CVE-2026-38752 | Jul 15, 2026 |
BusyBox AWK evaluate() stack overflow DoSA stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. |
|
| CVE-2026-38754 | Jul 15, 2026 |
Busybox 1.38.0 ash Shell Heap Overflow DoSA heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. |
|
| CVE-2026-15767 | Jul 14, 2026 |
libyuv Heap Buffer Overflow in Chrome Windows <150.0.7871.125Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High) |
|
| CVE-2026-53486 | Jul 14, 2026 |
decompress Node.js v<10.2.1 & 11.0.011.1.3 Path Traversal via Symlink/HardlinkThe decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits. This issue is fixed in @xhmikosr/decompress versions 10.2.1 and 11.1.3. |
|
| CVE-2026-15714 | Jul 14, 2026 |
libsoup OOB Read in multipart boundary parsingAn out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_multipart_input_stream_read_headers() function inside soup-multipart-input-stream.c, which does not adequately restrict or validate the size of incoming multipart boundary strings. When processing a crafted HTTP response containing a malformed or oversized boundary parameter, the internal stream reader reads past the allocated buffer bounds. A remote, unauthenticated attacker can exploit this behavior to cause a service denial (DoS) through application failure or potentially read fragments of unauthorized memory metadata. |
|
| CVE-2026-15713 | Jul 14, 2026 |
libsoup HTTP/2 Memory Leak Causing OOM DoS by Remote PeerA vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory context blocks under specific stream termination conditions, such as when an HTTP/2 connection encounters window exhaustion or explicit stream resets. A remote, unauthenticated attacker acting as a malicious network peer can trick the connection engine into allocating stream states that are subsequently leaked during cleanup. Over a sustained period, this flaw allows the remote attacker to consume the system's heap allocations incrementally, triggering a denial of service (DoS) through an ultimate Out-of-Memory (OOM) application crash. |
|
| CVE-2026-15711 | Jul 14, 2026 |
libsoup WebSocket Frame Length Validation DoSA vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a payload of 125 bytes or less. A remote, unauthenticated attacker can exploit this by sending a non-compliant, oversized control frame. Because the parser handles this protocol violation improperly instead of throwing an immediate connection termination error, it triggers a internal processing crash, resulting in a remote denial of service (DoS) for applications utilizing libsoup WebSockets. |
|
| CVE-2026-15709 | Jul 14, 2026 |
libsoup WebSocket permessage-deflate OOM DoS via decompression bombA flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compressed frame size via max_incoming_payload_size, it fails to track or limit memory allocation during decompression. A separate check for decompressed size (max_total_message_size) exists but executes only after inflation is complete, and it is entirely disabled by default for client connections. A remote, unauthenticated attacker can exploit this by sending a small, highly compressed payload (a decompression bomb), causing unbounded memory allocation that triggers an Out-of-Memory (OOM) crash and a Denial of Service (DoS). |
|