Red Hat Red Hat Linux OS and other open source products

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Red Hat product.

RSS Feeds for Red Hat security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Red Hat products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Red Hat Sorted by Most Security Vulnerabilities since 2018

Red Hat Enterprise Linux (RHEL)2640 vulnerabilities

Red Hat Enterprise Linux Server1534 vulnerabilities
RedHat Enterprise Linux (RHEL) Server. Includes software bundeled with RHEL server.

Red Hat Enterprise Linux Workstation1504 vulnerabilities
RedHat Enterprise Linux (RHEL) Workstation. Includes software bundled with RHEL Workstation.

Red Hat Enterprise Linux Desktop1493 vulnerabilities
RedHat Enterprise Linux (RHEL) Desktop. Includes software bundled with RHEL desktop

Red Hat Enterprise Linux Eus1115 vulnerabilities

Red Hat Openshift593 vulnerabilities

Red Hat Rhel Eus564 vulnerabilities

Red Hat Rhel E4s467 vulnerabilities

Red Hat Rhel Tus422 vulnerabilities

Red Hat Rhel Aus414 vulnerabilities

Red Hat Satellite361 vulnerabilities

Red Hat Rhel Eus Long Life329 vulnerabilities

Red Hat Rhel Els320 vulnerabilities

Red Hat Openshift Ai305 vulnerabilities

Red Hat Openstack277 vulnerabilities

Red Hat Hummingbird275 vulnerabilities

Red Hat Jbosseapxp220 vulnerabilities

Red Hat Build Keycloak216 vulnerabilities

Red Hat Jboss Fuse203 vulnerabilities

Red Hat Rhivos199 vulnerabilities

Red Hat Jboss Data Grid194 vulnerabilities

Red Hat Single Sign On166 vulnerabilities

Red Hat Enterprise Linux Ai154 vulnerabilities

Red Hat Openshift Devspaces151 vulnerabilities

Red Hat Quay145 vulnerabilities

Red Hat Rhdh124 vulnerabilities

Red Hat Software Collections123 vulnerabilities

Red Hat Keycloak123 vulnerabilities

Red Hat Cryostat120 vulnerabilities

Red Hat Acm118 vulnerabilities

Red Hat Virtualization115 vulnerabilities

Red Hat Discovery111 vulnerabilities

Red Hat Ai Inference Server104 vulnerabilities

Red Hat Single Sign On95 vulnerabilities

Red Hat Openshift Pipelines94 vulnerabilities

Red Hat Ceph Storage93 vulnerabilities

Red Hat Apache Camel Hawtio91 vulnerabilities

Red Hat Multicluster Engine87 vulnerabilities

Red Hat Service Mesh84 vulnerabilities

Red Hat Amq Streams84 vulnerabilities

Red Hat Logging82 vulnerabilities

Red Hat Camel Spring Boot81 vulnerabilities

Red Hat Amq Broker77 vulnerabilities

Red Hat Ansible Portal77 vulnerabilities

Red Hat Openshift Lightspeed75 vulnerabilities

Red Hat Serverless75 vulnerabilities

Red Hat Rhui74 vulnerabilities

Red Hat Ansible Tower69 vulnerabilities

Red Hat Openshift Gitops68 vulnerabilities

Red Hat Kafka66 vulnerabilities

Red Hat Quarkus63 vulnerabilities

Red Hat 3scale Amp62 vulnerabilities

Red Hat Podman Desktop58 vulnerabilities

Red Hat Apicurio Registry56 vulnerabilities

Red Hat Rhmt55 vulnerabilities

Red Hat Libvirt55 vulnerabilities

Red Hat Camel Quarkus54 vulnerabilities

Red Hat Service Registry54 vulnerabilities

Red Hat Virtualization Host53 vulnerabilities

Red Hat Satellite Capsule51 vulnerabilities

Red Hat Network Observ Optr51 vulnerabilities

Red Hat Multicluster Globalhub51 vulnerabilities

Red Hat Directory Server45 vulnerabilities

Red Hat Jboss Core Services44 vulnerabilities

Red Hat Http Server42 vulnerabilities

Red Hat Ansible42 vulnerabilities

Red Hat Gatekeeper41 vulnerabilities

Red Hat Enterprise Linux Aus41 vulnerabilities

Recent Red Hat Security Advisories

Advisory Title Published
RHSA-2026:51436 (RHSA-2026:51436) Important: postfix security update August 6, 2026
RHSA-2026:51368 (RHSA-2026:51368) Important: libyang security update August 6, 2026
RHSA-2026:51357 (RHSA-2026:51357) satellite/iop-vulnerability-engine-rhel9 container image available as a Technology Preview August 6, 2026
RHSA-2026:51356 (RHSA-2026:51356) General availability of the satellite/iop-advisor-backend-rhel9 container image August 6, 2026
RHSA-2026:51351 (RHSA-2026:51351) Important: libyang security update August 6, 2026
RHSA-2026:51349 (RHSA-2026:51349) General availability of the satellite/iop-host-inventory-frontend-rhel9 container image August 6, 2026
RHSA-2026:51348 (RHSA-2026:51348) Technical preview of the satellite/iop-vulnerability-frontend-rhel9 container image August 6, 2026
RHSA-2026:51347 (RHSA-2026:51347) General availability of the satellite/iop-host-inventory-rhel9 container image August 6, 2026
RHSA-2026:51342 (RHSA-2026:51342) General availability of the satellite/iop-advisor-frontend-rhel9 container image August 6, 2026
RHSA-2026:51341 (RHSA-2026:51341) Technical preview of the satellite/iop-vmaas-rhel9 container image August 6, 2026

By the Year

In 2026 there have been 2531 vulnerabilities in Red Hat with an average score of 7.2 out of ten. Last year, in 2025 Red Hat had 1168 security vulnerabilities published. That is, 1363 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.34.




Year Vulnerabilities Average Score
2026 2531 7.19
2025 1168 6.85
2024 1690 6.81
2023 1206 6.75
2022 1362 6.96
2021 1123 6.61
2020 664 6.39
2019 772 6.98
2018 760 7.16

It may take a day or so for new Red Hat vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Red Hat Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-15816 Aug 07, 2026
dracut initramfs cmd injection via unquoted DHCP ROOT_PATH A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.
Enterprise Linux (RHEL)
Hummingbird
Openshift
CVE-2026-18938 Aug 07, 2026
p11-kit RPC Integer Overflow Causing DoS on 32bit Linux A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-19079 Aug 07, 2026
policycoreutils fixfiles TOCTOU race changes SELinux labels A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate and relabel unlabeled files under /tmp and other directories. A local attacker could exploit a race window between the file discovery and the label change operation by swapping directory components with symlinks, causing chcon to follow the symlink and modify SELinux labels on arbitrary system files. This could undermine SELinux mandatory access control protections on critical files such as /etc/shadow.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-7867 Aug 06, 2026
Priv. Escalation via as-user Auth Bypass in udisks2 Mount() A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.
Enterprise Linux (RHEL)
CVE-2026-18649 Aug 06, 2026
GStreamer gst-plugins-good rtph264/265 depayloader buffer DoS A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.
Enterprise Linux (RHEL)
CVE-2026-18967 Aug 06, 2026
SAML Broker One-Time Use (OTU) Bypass in Keycloak A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it multiple times. Successful exploitation could allow an attacker to hijack a user's session and gain unauthorized access to the system as that user.
Build Keycloak
Jbosseapxp
Red Hat Single Sign On
And others...
CVE-2026-18839 Aug 05, 2026
popt Integer Underflow in Help Formatting Causes DOS An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-44605 Aug 05, 2026
RPM Package Manager heap buf. overflow leads to DoS A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.
Hummingbird
Enterprise Linux (RHEL)
CVE-2026-15572 Aug 05, 2026
Keycloak DCR Allowed Proto Mapper Flaw Enables Admin Escalation A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker with client registration privileges can exploit this by first registering an allowed mapper type with a malicious configuration and then swapping it for a restricted, high-privilege mapper type (such as one that hardcodes administrative roles). This allows the attacker to gain full administrative access to the Keycloak realm.
Build Keycloak
CVE-2026-16442 Aug 05, 2026
Keycloak SAML Broker SSO Bypass via IdP Account Linking A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-49331 Aug 05, 2026
Auth Skip Regex Injection in OpenShift/OAuth-Proxy (Identity Header Forgery) A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identity headers (X-Forwarded-User, X-Forwarded-Email, X-Forwarded-Access-Token) to the upstream application without stripping them. An unauthenticated attacker can inject forged identity headers on whitelisted paths.
Openshift
CVE-2026-16100 Aug 05, 2026
Keycloak Prometheus Metric Label DoS via Memory Exhaustion A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-16071 Aug 05, 2026
LDAP DN Boundary Bypass in Keycloak LDAP Storage Provider A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the system allows lookups for users located outside the configured search boundary, leading to the disclosure of account information from unauthorized parts of the directory and unintended importing of those users into local storage.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-16102 Aug 05, 2026
Keycloak DCR Path Validation Flaw Enables Privilege Escalation A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-15573 Aug 05, 2026
Keycloak PathMatcher URINormalization Auth Bypass A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-16443 Aug 05, 2026
Red Hat Keycloak Services SAML Meta Import flaw: Signature Bypass A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-71227 Aug 05, 2026
DoS via Reused AIO Handle in libkcapi's _kcapi_aio_read_all() A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-71226 Aug 05, 2026
Mem Corruption via Uncanceled AIO on Err: libkcapi One-Shot AIO Leakage Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-71225 Aug 05, 2026
IV Reuse in libkcapi large payload encryption causes confidentiality breach A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit this by making an application that uses libkcapi process specially crafted large inputs. This can lead to a significant weakening of data confidentiality, as the repeated IV use can expose relationships in encrypted plaintext, and may also affect data integrity by causing incorrect cryptographic processing.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-10090 Aug 05, 2026
ACM app-subscription controller allows cluster-admin escalation via Helm charts A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscription resource referencing it. The app-subscription controller fetches and applies the Helm chart contents with its own elevated authority, without verifying whether the subscription creator holds the "open-cluster-management:subscription-admin" role and without restricting applied resources to the subscription namespace. This allows the attacker to include cluster-scoped resources in the Helm chart, such as a ClusterRoleBinding granting the attacker's ServiceAccount the "cluster-admin" ClusterRole. Successful exploitation results in full cluster-admin privilege escalation. This contradicts the ACM documentation which states that non-subscription-admin users should have resources deployed into the subscription namespace only.
Acm
CVE-2026-10059 Aug 05, 2026
Privilege Escalation via Namespaced ClusterCurator in MCE A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.
Multicluster Engine
CVE-2026-18103 Aug 04, 2026
Red Hat DHCP OMAPI Buffer Overflow via InfiniBand MAC -> Persistent DoS A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Programming Interface) port, especially if not secured with TSIG (Transaction Signature) key authentication, could send a specially crafted lease creation request. This request, containing an overly long InfiniBand MAC address, triggers a buffer overflow in the `print_hw_addr()` function. Successful exploitation leads to a persistent denial of service (DoS), causing the `dhcpd` service to crash and preventing it from restarting without manual intervention.
Enterprise Linux (RHEL)
CVE-2026-68743 Aug 04, 2026
SSSD Local OOB Read via Unvalidated Auth Token A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.
Enterprise Linux (RHEL)
Openshift
CVE-2026-70368 Aug 04, 2026
Stunnel s_vlog OOB stack read via oversized log message A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with network access to a stunnel service can send protocol inputs that trigger a log message longer than 1024 bytes, leading to an out-of-bounds stack read and a potential crash. In certain corner cases, the same vulnerability could be used to replace a series of trailing "\n" characters with "\0".
Enterprise Linux (RHEL)
CVE-2026-70367 Aug 04, 2026
Stunnel 5.79 SSRF Bypass via IPv6 -> Localhost via SOCKS Proxy A Server-Side Request Forgery (SSRF) bypass vulnerability exists in stunnel 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses (e.g., ::ffff:127.0.0.1) or unspecified addresses ("0.0.0.0", "::"), enabling access to loopback-only services on the "stunnel" host that should not be network-reachable.
Enterprise Linux (RHEL)
CVE-2026-18739 Aug 04, 2026
popt Off-by-One Vulnerability Allows Local Exec A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-68744 Aug 04, 2026
Red Hat SSSD NSS Preallocation Leak Exposes Heap Data A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.
Enterprise Linux (RHEL)
Openshift
CVE-2026-18569 Aug 04, 2026
Keycloak Backchannel Logout Flaw: SIGOmitted OIDC Logout A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to skip signature validation. In this specific setup, the system incorrectly accepts logout requests that have no cryptographic signature. An attacker who knows certain technical details about a user's session can use this flaw to force that user to be logged out, potentially disrupting their work.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-42169 Aug 04, 2026
GIMP APNG/DDS Loader Heap Buffer Overflow A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in the DDS plug-in due to a BPP mismatch in the `load_layer()` function. Both vulnerabilities can be triggered by opening a specially crafted image file, potentially leading to code execution.
Enterprise Linux (RHEL)
CVE-2026-17614 Aug 04, 2026
Path Traversal in WildFly Domain Mode via Slave-DC Protocol A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getConfigurationFile() methods in wildfly-core/deployment-repository do not validate that the resolved file path remains within the configured repository or configuration root directories. A remote attacker who has obtained the slave host controller secret or compromised a slave host controller can supply a crafted relative path containing directory traversal sequences (e.g., ../../etc/passwd) via the slave-DC wire protocol, causing the Domain Controller to resolve and serve arbitrary files readable by the DC process. This leads to unauthorized disclosure of sensitive information such as configuration files, keystores, and system credentials.
Jboss Enterprise Application Platform
Jbosseapxp
Red Hat Single Sign On
And others...
CVE-2026-69198 Aug 03, 2026
ip-address JS 10.1.1-10.2.1 IP Classifier Mask Bypass ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's own subnet mask is shorter than the reference range's mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as /0 suppresses classification entirely: isLoopback(), isPrivate(), isLinkLocal(), isCGNAT(), isMulticast(), isUnspecified(), isBroadcast(), isULA(), and getType() all report an internal address as unremarkable, while correctForm() and address still return the real internal target. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, may therefore treat an internal target as external and allow the request. The underlying bit comparison is correct, and mask(n) already returns the first n bits of the full parsed address independently of subnetMask; the defect is solely that the containment guard sits in the classification path. This issue is fixed in version 10.2.2.
CVE-2026-69192 Aug 03, 2026
CVE-2026-69192: IP-Address <10.3.1 Octet Parsing Mismatch Exploits SSRF ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. new Address4('012.0.0.1') reports correctForm() of 12.0.0.1 and isPrivate() of false, but fetch('http://012.0.0.1/') connects to 10.0.0.1. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, will classify an internal target as external and allow the request. The defect is in the parse gate rather than in any one classifier, so every consumer of Address4 inherits it: isPrivate(), isLoopback(), isLinkLocal(), isCGNAT(), isInSubnet(), isHostInSubnet(), and correctForm() are all computed from the mis-decoded octets. This issue is fixed in version 10.3.1.
CVE-2026-69153 Aug 03, 2026
PostCSS 8.5.18: SourceMap Leakage via PreviousMap.loadFile() PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting maps sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.
CVE-2026-69152 Aug 03, 2026
Brace-Expansion JS Library DoS via expand() <1.1.18,2.1.4,3.0.6,5.0.9 The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.
CVE-2026-18477 Aug 03, 2026
TOCTOU in GNU tar incremental dumpdir rename A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflowsincluding extracting into a newly created directory without using the -P option do not mitigate the issue.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-18651 Aug 03, 2026
389 Directory Server Auth Bypass via SASL PLAIN & Account Lock Defect A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted. A client that supplies valid credentials for an account that has been administratively locked can continue to use the same connection with that account's privileges, defeating account lock as an access-revocation control.
Directory Server
Enterprise Linux (RHEL)
CVE-2026-18508 Aug 03, 2026
GNU tar Hardlink Extraction Path Traversal via --one-top-level A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-68742 Aug 03, 2026
SSSD NSS Responder OOB Read via GETHOSTBYADDR Causing DoS A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.
Enterprise Linux (RHEL)
Openshift
CVE-2026-6695 Aug 03, 2026
GIMP PAA decode_lzss Heap OOB RCE A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer. This could lead to heap metadata corruption and potentially enable the attacker to execute arbitrary code on the affected system.
Enterprise Linux (RHEL)
CVE-2026-6694 Aug 03, 2026
GIMP file-png Plugin Stack Overflow via Malicious APNG tRNS Chunk A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to crash and resulting in a Denial of Service (DoS) for the user.
Enterprise Linux (RHEL)
CVE-2026-18573 Aug 02, 2026
Keycloak Services Bypass of Client Policies via Confidential Client Update A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements on confidential clients. Due to improper evaluation of the client state during an update operation, an attacker with client management permissions can bypass these security policies by first creating a public client and then updating it to a confidential client with weaker authentication. This can result in the persistence of clients that do not comply with the intended security hardening of the realm.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-18572 Aug 02, 2026
Keycloak Time Policy Bypass via Fake Time Claims Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-18571 Aug 02, 2026
Keycloak: FGAP V2 Allows Unauthorized User Group Additions A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-18570 Aug 02, 2026
Red Hat Keycloak FullScopeDisabled Executor Bypass A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executor only validates the fullScopeAllowed field when it is explicitly provided in a request. By omitting this field, a delegated user can bypass the policy, resulting in a client created with full scope access. This allows the client to obtain tokens with unauthorized role mappings.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-67318 Aug 01, 2026
Axios 1.13.0 HTTP/2 maxBodyLength Bypass in Node HTTP Adapter axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent with httpVersion: 2. Because Node's HTTP/2 request API does not honor the maxBodyLength option and axios's byte-counting stream wrapper is gated on maxRedirects === 0, an attacker who controls a stream passed to axios can cause the application to transmit outbound data exceeding the configured finite maxBodyLength. Impact is limited to resource consumption and policy bypass (excess egress, upstream quota consumption, limited availability); it does not enable code execution, credential disclosure, or request-destination control. Calls using the default maxBodyLength: -1 and browser adapters are not affected.
CVE-2026-67316 Aug 01, 2026
Axios Prototype Pollution; fixed in 1.18.0 & 0.33.0 axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method aliases (axios.get(), axios.delete(), axios.head(), axios.options()), inherited data is read via (config || {}).data before config normalization, causing an attacker-controlled body to be sent on requests that did not set one. Additional low-level paths, only reachable when calling exported adapters/helpers (e.g. lib/adapters/http.js, unsafe/helpers/resolveConfig.js) directly with plain configs and no own proxy or paramsSerializer, can inherit polluted proxy values (routing requests through an attacker-controlled proxy) or paramsSerializer values (attacker-controlled URL serialization). These low-level gadgets do not reproduce through normal high-level axios calls on 1.15.2+. The issue is fixed in axios 1.18.0 and 0.33.0.
CVE-2026-67315 Aug 01, 2026
Axios 1.15-1.17 Loopback 0.0.0.0 Proxy Bypass axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.
CVE-2026-67317 Aug 01, 2026
CVE-2026-67317: axios <1.18.0 bypass maxBodyLength via unknown stream size axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.
CVE-2026-67314 Aug 01, 2026
Axios auth prototype pollution in HTTP adapter (v1.15.2-1.17.9) axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js). When an application is already affected by a separate prototype-pollution primitive and makes an axios request with an own auth object that omits the username and/or password properties, axios reads the inherited Object.prototype.username and Object.prototype.password values and uses them to construct an outbound 'Authorization: Basic ...' header. axios itself does not pollute prototypes. The practical impact is outbound request tampering: an attacker who controls the polluted prototype values can inject attacker-chosen Basic auth credentials or replace an existing Authorization header. Credential disclosure is only possible under additional application-specific conditions.
CVE-2026-67313 Aug 01, 2026
Uncontrolled Recursion in Axios 0.28.0+ formDataToJSON Leading to RangeError axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brackets to exhaust the JavaScript call stack and trigger RangeError, causing request failure or process termination in applications that do not handle the exception.
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.