Red Hat Red Hat Linux OS and other open source products

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Red Hat product.

RSS Feeds for Red Hat security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Red Hat products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Red Hat Sorted by Most Security Vulnerabilities since 2018

Red Hat Enterprise Linux (RHEL)2742 vulnerabilities

Red Hat Enterprise Linux Server1534 vulnerabilities
RedHat Enterprise Linux (RHEL) Server. Includes software bundeled with RHEL server.

Red Hat Enterprise Linux Workstation1504 vulnerabilities
RedHat Enterprise Linux (RHEL) Workstation. Includes software bundled with RHEL Workstation.

Red Hat Enterprise Linux Desktop1493 vulnerabilities
RedHat Enterprise Linux (RHEL) Desktop. Includes software bundled with RHEL desktop

Red Hat Enterprise Linux Eus1142 vulnerabilities

Red Hat Openshift619 vulnerabilities

Red Hat Rhel Eus605 vulnerabilities

Red Hat Rhel E4s510 vulnerabilities

Red Hat Rhel Tus445 vulnerabilities

Red Hat Rhel Aus431 vulnerabilities

Red Hat Satellite369 vulnerabilities

Red Hat Rhel Eus Long Life348 vulnerabilities

Red Hat Rhel Els338 vulnerabilities

Red Hat Openshift Ai328 vulnerabilities

Red Hat Hummingbird293 vulnerabilities

Red Hat Openstack280 vulnerabilities

Red Hat Jbosseapxp241 vulnerabilities

Red Hat Build Keycloak223 vulnerabilities

Red Hat Jboss Fuse212 vulnerabilities

Red Hat Jboss Data Grid199 vulnerabilities

Red Hat Rhivos199 vulnerabilities

Red Hat Single Sign On181 vulnerabilities

Red Hat Acm156 vulnerabilities

Red Hat Enterprise Linux Ai155 vulnerabilities

Red Hat Quay154 vulnerabilities

Red Hat Openshift Devspaces154 vulnerabilities

Red Hat Rhdh126 vulnerabilities

Red Hat Discovery125 vulnerabilities

Red Hat Keycloak123 vulnerabilities

Red Hat Software Collections123 vulnerabilities

Red Hat Cryostat120 vulnerabilities

Red Hat Virtualization115 vulnerabilities

Red Hat Ai Inference Server105 vulnerabilities

Red Hat Kafka104 vulnerabilities

Red Hat Ceph Storage96 vulnerabilities

Red Hat Multicluster Engine96 vulnerabilities

Red Hat Single Sign On95 vulnerabilities

Red Hat Openshift Pipelines95 vulnerabilities

Red Hat Apache Camel Hawtio93 vulnerabilities

Red Hat Logging91 vulnerabilities

Red Hat Rhui89 vulnerabilities

Red Hat Camel Spring Boot87 vulnerabilities

Red Hat Amq Streams84 vulnerabilities

Red Hat Service Mesh84 vulnerabilities

Red Hat Amq Broker78 vulnerabilities

Red Hat Ansible Portal77 vulnerabilities

Red Hat Openshift Lightspeed75 vulnerabilities

Red Hat Serverless75 vulnerabilities

Red Hat Http Server72 vulnerabilities

Red Hat Ansible Tower69 vulnerabilities

Red Hat Openshift Gitops68 vulnerabilities

Red Hat Quarkus67 vulnerabilities

Red Hat 3scale Amp62 vulnerabilities

Red Hat Camel Quarkus58 vulnerabilities

Red Hat Podman Desktop58 vulnerabilities

Red Hat Apicurio Registry57 vulnerabilities

Red Hat Rhmt56 vulnerabilities

Red Hat Libvirt55 vulnerabilities

Red Hat Multicluster Globalhub54 vulnerabilities

Red Hat Service Registry54 vulnerabilities

Red Hat Virtualization Host53 vulnerabilities

Red Hat Satellite Capsule53 vulnerabilities

Red Hat Network Observ Optr51 vulnerabilities

Red Hat Directory Server48 vulnerabilities

Red Hat Jboss Core Services48 vulnerabilities

Red Hat Insights Proxy44 vulnerabilities

Red Hat Ansible42 vulnerabilities

Red Hat Enterprise Linux Aus41 vulnerabilities

Recent Red Hat Security Advisories

Advisory Title Published
RHSA-2026:62555 (RHSA-2026:62555) Important: Red Hat build of Quarkus 3.33.3.SP1 release and security update September 3, 2026
RHSA-2026:62515 (RHSA-2026:62515) Important: Red Hat build of Quarkus 3.27.5.SP1 release and security update September 3, 2026
RHSA-2026:59831 (RHSA-2026:59831) Important: OpenShift Container Platform 4.12.97 bug fix and security update September 3, 2026
RHSA-2026:63136 (RHSA-2026:63136) Important: grafana-pcp security update September 3, 2026
RHSA-2026:63134 (RHSA-2026:63134) Important: osbuild-composer security update September 3, 2026
RHSA-2026:60019 (RHSA-2026:60019) Important: OpenShift Container Platform 4.17.57 bug fix and security update September 3, 2026
RHSA-2026:63130 (RHSA-2026:63130) Important: rhc security update September 3, 2026
RHSA-2026:63124 (RHSA-2026:63124) Important: grafana-pcp security update September 3, 2026
RHSA-2026:63117 (RHSA-2026:63117) Important: python3.12 security update September 3, 2026
RHSA-2026:63024 (RHSA-2026:63024) Important: python3.12 security update September 3, 2026

By the Year

In 2026 there have been 3074 vulnerabilities in Red Hat with an average score of 7.2 out of ten. Last year, in 2025 Red Hat had 1175 security vulnerabilities published. That is, 1899 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.34.




Year Vulnerabilities Average Score
2026 3074 7.20
2025 1175 6.85
2024 1693 6.82
2023 1207 6.74
2022 1362 6.96
2021 1123 6.61
2020 664 6.39
2019 772 6.98
2018 760 7.16

It may take a day or so for new Red Hat vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Red Hat Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-84185 Sep 03, 2026
jwcrypto General JWS Verification Bypass via Key ID Misidentification A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a coding error, the library fails to correctly identify the specific key ID (kid) and may instead accept a signature made by any valid key in the set. This can allow an attacker with a valid key to bypass authorization checks in applications that rely on the key ID to identify specific tenants or users.
Ansible Automation Platform
Enterprise Linux (RHEL)
Openshift Ai
And others...
CVE-2026-71224 Sep 03, 2026
Stack Overflow in gfs2-utils Metadata Walk via untrusted inode height A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata without bounds validation, causing stack exhaustion and a denial of service when processing crafted GFS2 filesystem images.
Enterprise Linux (RHEL)
CVE-2026-71222 Sep 03, 2026
Red Hat GFS2-Utils Heap OOB Read in ea_num_ptrs A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory contents or cause a crash when processing crafted GFS2 filesystem images.
Enterprise Linux (RHEL)
CVE-2026-71221 Sep 03, 2026
Stack OOB Write in RedHat gfs2-utils savemeta Arbitrary Code Execution A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.
Enterprise Linux (RHEL)
CVE-2026-71220 Sep 03, 2026
Stack OOB Write in gfs2-utils (Red Hat) A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.
Enterprise Linux (RHEL)
CVE-2026-71219 Sep 03, 2026
Stack Overflow in gfs2-utils via di_depth overflow DoS A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 filesystem image with a large di_depth value causes stack exhaustion and a denial of service when processed by fsck.gfs2, gfs2_edit, or savemeta.
Enterprise Linux (RHEL)
CVE-2026-85150 Sep 03, 2026
GStreamer RTSP Digest Auth NULL Deref DoS A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.
Enterprise Linux (RHEL)
CVE-2026-66786 Sep 02, 2026
Submariner RCE via unvalidated CRD CableName in cert-auth mode A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdown hooks, leading to remote code execution as root on the gateway node.
Acm
CVE-2026-84838 Sep 02, 2026
RedHat RPM rpmuncompress Command Injection via Unescaped Filename A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow invokes rpmuncompress on the malicious file, leading to high impact on the confidentiality, integrity, and availability of data accessible to the invoking user.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-84837 Sep 02, 2026
Command Injection in rpmbuild via Path Manipulation A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-78409 Sep 02, 2026
Linux Kernel 6.15+ X-mount.subdir Symlink Traversal Local PrivEsc The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-78410 Sep 02, 2026
util-linux Local Privilege Escalation via Redirected Restricted Bind Mount A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-78408 Sep 02, 2026
CVE-2026-78408: nsenter --join-cgroup root-FD leak allows cgroup migration The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-53683 Sep 02, 2026
Red Hat Password_Reset Unvalidated Redirect reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.
Enterprise Linux (RHEL)
CVE-2026-14957 Sep 02, 2026
Libreswan FIPS X.509 Cert Public Key Extraction Null Assertion DoS In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with no CA certificates loaded in the NSS database are not vulnerable.
CVE-2026-82968 Sep 02, 2026
Keycloak first-broker-login flow allows social ID hijacking A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generated is not strictly bound to the specific upstream identity being verified. This allows an attacker with a different account on the same social provider to intercept the process and link their own account to the victim's local profile, gaining unauthorized access.
Build Keycloak
Red Hat Single Sign On
CVE-2026-84470 Sep 01, 2026
Ansible Automation Platform Bulk Job Launch API Permission Bypass A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard single-job launch path requires use-level permission on the same field. A principal that holds read (but not use) permission on an instance group -- for example the built-in read-only System Auditor role -- together with execute permission on a job template can launch bulk jobs onto instance groups they are not authorized to use, bypassing execution-placement isolation.
Ansible Automation Platform
CVE-2026-49329 Sep 01, 2026
OpenShift OAuth Server DoS via Crafted Accept-Language Header A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcceptLanguage() without input validation. A bypass of the CVE-2022-32149 mitigation exists: the upstream guard counts only '-' characters but the internal BCP 47 scanner aliases '_' to '-' after the guard check. An unauthenticated attacker can send a crafted Accept-Language header using '_' separators to trigger quadratic-time parsing, consuming excessive CPU and denying authentication to all cluster users.
Openshift
CVE-2026-84270 Sep 01, 2026
GVFS MTP Backend DoS via unchecked memcpy A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, do_read() in gvfsbackendmtp.c trusts the data length returned by the device without limiting it to the original size requested by the client. If a malicious MTP device responds with more bytes than requested, this unrestricted length is passed directly to memcpy(). This causes the operation to read memory outside the intended boundaries. This allows an attacker who plugs in a malicious MTP device to cause a segmentation fault when a file is read and crash the gvfsd-mtp process, resulting in a denial of service.
Enterprise Linux (RHEL)
CVE-2026-84269 Sep 01, 2026
gvfs AFP backend heap overflow causing DoS A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the intended boundaries. This issue allows a malicious server to overflow a heap buffer and crash the gvfsd-afp process, resulting in a denial of service.
Enterprise Linux (RHEL)
CVE-2026-84267 Sep 01, 2026
GVFS SFTP Backend Buffer Uninitialized Leak Enables ASLR Bypass A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the function does not verify that the buffer is completely filled, leaving the remainder of the buffer containing uninitialized heap contents. If the server sends a short FXP_HANDLE reply, these uninitialized bytes are taken as the file handle. The client will then echo these uninitialized bytes back to the server on all subsequent requests using that handle. With a length of 128 bytes, this issue allows the malicious server to deterministically read uninitialized heap memory from the gvfsd-sftp process, leaking its heap base and the load address of the libgio library, resulting in a deterministic defeat of Address Space Layout Randomization (ASLR).
Enterprise Linux (RHEL)
CVE-2026-84232 Sep 01, 2026
Stored XSS via HTML/SVG in pulpcore content serving A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for .html files, image/svg+xml for .svg files) and without a Content-Disposition: attachment header when using local filesystem storage. An authenticated user or attacker with content upload permissions can upload a specially crafted HTML or SVG file containing JavaScript, which executes in the browser of any user who visits the file URL, resulting in stored cross-site scripting (XSS) in the context of the host application.
Ansible Automation Platform
Satellite
Rhui
And others...
CVE-2026-84268 Sep 01, 2026
GVFS SFTP Backend Buffer Overflow in read_reply() A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution.
Enterprise Linux (RHEL)
CVE-2026-84233 Sep 01, 2026
Local Command Execution via Macro Expansion in rpm's rpmuncompress A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-84218 Sep 01, 2026
SSRF via JMXServiceURL bypass in Jolokia JSR-160 proxy A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `target.url` value from a Jolokia POST request and passes it to `JMXServiceURL` and `JMXConnectorFactory` for establishing the remote JMX connection. The existing denylist only rejects URLs matching `service:jmx:rmi:///jndi/ldap:.*`, which can be bypassed using alternative valid JMX service URL forms, including `ldaps://` schemes or LDAP URLs with a non-empty JMX host component. These URLs are accepted as valid `JMXServiceURL` objects and can cause the Jolokia agent JVM to perform a JNDI lookup against an attacker-controlled LDAP endpoint. This can result in server-side request forgery (SSRF), forwarding of supplied JMX credentials to the remote endpoint, and potentially remote code execution depending on the classes and configuration available in the target JVM.
Camel Quarkus
Camel Spring Boot
Jboss Fuse
And others...
CVE-2026-53682 Sep 01, 2026
Red Hat Unauth Query of Security Domain Hosts via /ca/rest API An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.
Certificate System
Enterprise Linux (RHEL)
CVE-2026-11873 Sep 01, 2026
Red Hat Dogtag CA Log Amplification via Unauth Stacktrace Leak An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating a log-amplification resource exhaustion vector (disk growth and I/O contention) without requiring authentication.
Enterprise Linux (RHEL)
Certificate System
CVE-2026-18743 Sep 01, 2026
popt ConfigFileToString Realloc Heap Corruption (CVE-2026-18743) A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-83596 Aug 31, 2026
WebKitGTK Memory Corruption via Malicious Web Content A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
Enterprise Linux (RHEL)
CVE-2026-13732 Aug 31, 2026
GDB STABS Debug Format Parser Buffer Overflow in read_member_functions A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++ classes. The bug causes the destructor entries to remain in the main function list while the list length counter is decremented, resulting in an out-of-bounds write when the function list is copied to its final allocated array. An attacker can craft an ELF binary with malicious .stab and .stabstr sections that triggers this out-of-bounds write when a user opens the file in GDB and performs any symbol-inspection operation such as setting a breakpoint. The inferior process does not need to be executed. Under controlled conditions, this was demonstrated to achieve execution of arbitrary commands within the GDB process.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-17615 Aug 31, 2026
XXE in RESTEasy SourceProvider Enables Remote File Read A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitive file contents in the HTTP response. This is due to the SourceProvider.writeTo() method creating a SAXParser without disabling external entity resolution, leading to an XML External Entity (XXE) vulnerability.
Camel Quarkus
Apicurio Registry
Debezium
And others...
CVE-2026-76763 Aug 31, 2026
Unauth Remote DoS via BigInteger Coercion in SmallRye GraphQL A flaw was found in SmallRye GraphQL. The number scalar coercion for BigInteger does not properly validate the magnitude of float or string inputs. An unauthenticated remote attacker can exploit this by sending a GraphQL query containing a large exponent float literal. This can lead to the allocation of extremely large BigInteger objects, causing CPU exhaustion or an OutOfMemoryError, resulting in a denial of service.
Quarkus
CVE-2026-12894 Aug 31, 2026
Qute RefResolver bypass allows code exec in Quarkus A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue exists in the component responsible for looking up data values (ReflectionValueResolver), which fails to properly block access to sensitive Java internal functions when processing certain data types like Enums. An attacker who can provide or influence the template text can exploit this bypass to take control of the server by executing unauthorized commands.
Camel Quarkus
Quarkus
Jbosseapxp
And others...
CVE-2026-81624 Aug 31, 2026
Undertow WebSocket Config Overflow Allows Memory Exhaustion Remote DOS Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being unlimited. This allows a remote attacker to send large amounts of data or maintain connections indefinitely, potentially crashing the server by exhausting its memory or other resources.
Camel Spring Boot
Enterprise Linux (RHEL)
Jboss Fuse
And others...
CVE-2026-82343 Aug 28, 2026
GIMP file-psd plugin heap OOB read/stack OOB access CVE-2026-82343 A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not properly validate the channel-count parameter. This incorrect validation leads to improper memory bounds checking, resulting in both a heap out-of-bounds read and a stack out-of-bounds access. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of memory contents.
Enterprise Linux (RHEL)
CVE-2026-82330 Aug 28, 2026
GIMP file-pvr VQ Decoder OOB Heap Read DoS/Info Disclosure A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.
Enterprise Linux (RHEL)
CVE-2026-82328 Aug 28, 2026
GIMP file-ico Plugin Heap OOB Read in ICO Processing A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.
Enterprise Linux (RHEL)
CVE-2026-82327 Aug 28, 2026
OOB Write in libsolv .solv Cache Rewrite Causing DoS A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's compressed filelist data without validating that they fall within the expected range. A corrupted or specially crafted .solv cache file (for example, one left in a torn state after an unclean system shutdown) can cause an out-of-bounds memory write when a tool such as dnf, yum, or zypper next processes it. Successful exploitation is expected to result in a crash of the affected tool (denial of service); it is not expected to allow arbitrary code execution because the out-of-bounds write always stores a fixed, non-attacker-controlled value.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-82324 Aug 28, 2026
GIMP IFF/ILBM Plugin Heap OOB Read via HAM Row Size A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles cases where the number of color planes (nPlanes) is zero. This causes a row size mismatch that bypasses memory bounds checking, resulting in heap out-of-bounds reads. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.
Enterprise Linux (RHEL)
CVE-2026-18393 Aug 28, 2026
FFmpeg TDSC Cursor Heap Overflow in tdsc_load_cursor() A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when processing crafted TDSC cursor data. A remote attacker could exploit this by supplying a specially crafted video file, potentially leading to a denial of service or arbitrary code execution.
Enterprise Linux Ai
Openshift Ai
CVE-2026-80179 Aug 27, 2026
jwcrypto JWE Deserialization Memory Overrun DoS A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memory, leading to a MemoryError. This issue results in a denial of service (DoS) for services that process untrusted JWE values.
Ansible Automation Platform
Enterprise Linux (RHEL)
Openshift Ai
And others...
CVE-2026-81893 Aug 27, 2026
gdk-pixbuf 2.26.4+ OOB Write via Malformed JPEG ICC Profile A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image. Affected version >= 2.26.4
Enterprise Linux (RHEL)
CVE-2026-5680 Aug 27, 2026
Undertow WebSocket DoS via PerMessageDeflate Buffer Doubling A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.
Camel Spring Boot
Apache Camel Hawtio
Jboss Data Grid
And others...
CVE-2026-78002 Aug 27, 2026
rsyslog RainerScript replace() Heap Overflow (DoS) A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful exploitation can lead to a denial of service (DoS) for the affected system.
Enterprise Linux (RHEL)
CVE-2026-81668 Aug 27, 2026
Katello API Auth Bypass: Unauthorized Cross-Org Content View Filter Access A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the parent Content View Filter. An authenticated, low-privileged user with Content View permissions in one organization may be able to access and modify filter rules belonging to a Content View Filter in another organization by supplying that filter's identifier. This can result in unauthorized disclosure of filter-rule information and unauthorized changes to unpublished Content View filter configuration.
Satellite
CVE-2026-81658 Aug 27, 2026
Foreman: Unauthorized Disclosure via Audited Template Revision Endpoint A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving an audited template revision. An authenticated, low privileged user with a template-related permission, such as view_ptables, can obtain historical template contents belonging to another organization or location by supplying the corresponding audit ID. This can result in unauthorized disclosure of historical template contents, which may contain sensitive configuration information, credentials, or other secrets. The REST API revision endpoints correctly restrict this lookup.
Satellite
CVE-2026-80158 Aug 26, 2026
Unlogged Kerberos Bind Password Leak via Ansible ipa_getkeytab A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log, unlike the sibling password parameter in the same module. As a consequence, the supplied IPA/LDAP bind password is recorded in cleartext in the managed host's system journal/syslog (the module's "Invoked with" record), is included in the module's return values and verbose (-v) output, and is displayed in Automation Controller / AWX job output. The password is additionally passed on the command line to the ipa-getkeytab helper (as --bindpw <value>), exposing it in the process list to local users while the command runs. An attacker able to read these logs, job output, or the process table can obtain the directory bind credential, potentially compromising the accounts and objects that credential can access.
Ceph Storage
Openstack
CVE-2026-79902 Aug 26, 2026
Unbounded VLA stack allocation in GIMP's Seattle FilmWorks plugin A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without integer overflow checks, causing an unbounded stack allocation. This issue leads to an application crash, resulting in a denial of service.
Enterprise Linux (RHEL)
CVE-2026-79654 Aug 26, 2026
Katello CVH API Auth Bypass: Unauthorized Org Access A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history of a Content View belonging to another organization by supplying its identifier to the affected API endpoint. This can result in unauthorized disclosure of Content View lifecycle information, including publication and promotion events, associated users, and timestamps.
Satellite
CVE-2026-80185 Aug 25, 2026
BlueZ sdp-xml.c Type Confusion in RegisterProfile() leads to Local DoS BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.
Enterprise Linux (RHEL)
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.