Red Hat Red Hat Linux OS and other open source products

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Red Hat product.

RSS Feeds for Red Hat security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Red Hat products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Red Hat Sorted by Most Security Vulnerabilities since 2018

Red Hat Enterprise Linux (RHEL)2526 vulnerabilities

Red Hat Enterprise Linux Server1534 vulnerabilities
RedHat Enterprise Linux (RHEL) Server. Includes software bundeled with RHEL server.

Red Hat Enterprise Linux Workstation1504 vulnerabilities
RedHat Enterprise Linux (RHEL) Workstation. Includes software bundled with RHEL Workstation.

Red Hat Enterprise Linux Desktop1493 vulnerabilities
RedHat Enterprise Linux (RHEL) Desktop. Includes software bundled with RHEL desktop

Red Hat Enterprise Linux Eus1042 vulnerabilities

Red Hat Openshift542 vulnerabilities

Red Hat Rhel Eus504 vulnerabilities

Red Hat Rhel E4s405 vulnerabilities

Red Hat Rhel Tus360 vulnerabilities

Red Hat Rhel Aus359 vulnerabilities

Red Hat Satellite355 vulnerabilities

Red Hat Openshift Ai295 vulnerabilities

Red Hat Rhel Eus Long Life274 vulnerabilities

Red Hat Openstack274 vulnerabilities

Red Hat Rhel Els263 vulnerabilities

Red Hat Hummingbird242 vulnerabilities

Red Hat Jboss Fuse203 vulnerabilities

Red Hat Rhivos199 vulnerabilities

Red Hat Jbosseapxp181 vulnerabilities

Red Hat Build Keycloak178 vulnerabilities

Red Hat Jboss Data Grid159 vulnerabilities

Red Hat Enterprise Linux Ai151 vulnerabilities

Red Hat Openshift Devspaces149 vulnerabilities

Red Hat Quay139 vulnerabilities

Red Hat Single Sign On128 vulnerabilities

Red Hat Software Collections123 vulnerabilities

Red Hat Keycloak123 vulnerabilities

Red Hat Rhdh123 vulnerabilities

Red Hat Cryostat119 vulnerabilities

Red Hat Virtualization115 vulnerabilities

Red Hat Acm112 vulnerabilities

Red Hat Discovery105 vulnerabilities

Red Hat Single Sign On95 vulnerabilities

Red Hat Openshift Pipelines93 vulnerabilities

Red Hat Ai Inference Server93 vulnerabilities

Red Hat Ceph Storage92 vulnerabilities

Red Hat Apache Camel Hawtio91 vulnerabilities

Red Hat Amq Streams84 vulnerabilities

Red Hat Service Mesh82 vulnerabilities

Red Hat Multicluster Engine81 vulnerabilities

Red Hat Camel Spring Boot80 vulnerabilities

Red Hat Logging80 vulnerabilities

Red Hat Amq Broker76 vulnerabilities

Red Hat Ansible Portal76 vulnerabilities

Red Hat Serverless74 vulnerabilities

Red Hat Openshift Lightspeed73 vulnerabilities

Red Hat Ansible Tower69 vulnerabilities

Red Hat Kafka66 vulnerabilities

Red Hat Openshift Gitops65 vulnerabilities

Red Hat Quarkus63 vulnerabilities

Red Hat Rhui62 vulnerabilities

Red Hat 3scale Amp61 vulnerabilities

Red Hat Podman Desktop58 vulnerabilities

Red Hat Apicurio Registry55 vulnerabilities

Red Hat Libvirt55 vulnerabilities

Red Hat Camel Quarkus54 vulnerabilities

Red Hat Service Registry54 vulnerabilities

Red Hat Virtualization Host53 vulnerabilities

Red Hat Rhmt53 vulnerabilities

Red Hat Multicluster Globalhub50 vulnerabilities

Red Hat Network Observ Optr50 vulnerabilities

Red Hat Satellite Capsule48 vulnerabilities

Red Hat Jboss Core Services44 vulnerabilities

Red Hat Ansible42 vulnerabilities

Red Hat Http Server42 vulnerabilities

Red Hat Enterprise Linux Aus41 vulnerabilities

Red Hat Undertow40 vulnerabilities
Java HTTP Server and Servlet Container

Red Hat Gatekeeper40 vulnerabilities

Red Hat Ocp Tools39 vulnerabilities

Recent Red Hat Security Advisories

Advisory Title Published
RHSA-2026:35454 (RHSA-2026:35454) Red Hat Hardened Images RPMs Security Update July 3, 2026
RHSA-2026:35272 (RHSA-2026:35272) Red Hat Hardened Images RPMs bug fix and enhancement update July 3, 2026
RHSA-2026:35387 (RHSA-2026:35387) Red Hat Hardened Images RPMs bug fix and enhancement update July 3, 2026
RHSA-2026:35111 (RHSA-2026:35111) Red Hat Hardened Images RPMs Security Update July 2, 2026
RHSA-2026:34975 (RHSA-2026:34975) Red Hat Hardened Images RPMs bug fix and enhancement update July 2, 2026
RHSA-2026:29863 (RHSA-2026:29863) Important: OpenShift Container Platform 4.19.36 bug fix and security update July 2, 2026
RHSA-2026:35016 (RHSA-2026:35016) Red Hat Hardened Images RPMs Security Update July 2, 2026
RHSA-2026:34927 (RHSA-2026:34927) Important: kernel security update July 2, 2026
RHSA-2026:34924 (RHSA-2026:34924) Red Hat Hardened Images RPMs Security Update July 2, 2026
RHSA-2026:34911 (RHSA-2026:34911) Important: kernel security, bug fix, and enhancement update July 2, 2026

By the Year

In 2026 there have been 1952 vulnerabilities in Red Hat with an average score of 7.3 out of ten. Last year, in 2025 Red Hat had 1157 security vulnerabilities published. That is, 795 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.71.




Year Vulnerabilities Average Score
2026 1952 7.29
2025 1157 6.58
2024 1686 6.57
2023 1206 6.75
2022 1362 6.97
2021 1123 6.62
2020 664 6.39
2019 772 6.98
2018 760 7.16

It may take a day or so for new Red Hat vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Red Hat Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-58379 Jul 03, 2026
GIMP PSP Parser Heap Overflow Arbitrary Code Execution A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerability occurs because the software incorrectly calculates buffer sizes when processing low bit-depth images, leading to an overwrite of adjacent memory.
Enterprise Linux (RHEL)
CVE-2026-14615 Jul 03, 2026
Admin Permission Leak in Keycloak FGAP v2 A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to view details of child groups they are not authorized to access directly, including group names, paths, and custom attributes.
Build Keycloak
CVE-2026-14614 Jul 03, 2026
Keycloak ClientResource Permission Bypass via FGAP v2 A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see or manage. As a result, an attacker could inject unauthorized data or permissions into the security tokens issued to end-users, potentially tricking other applications into granting higher levels of access than intended.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-14613 Jul 03, 2026
Keycloak FGAP v2: Admin RLS Bypass Exposes Hidden Groups A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a specific "role" can also see a list of all groups assigned to that role. The system fails to check if the administrator has permission to see those specific groups. This could allow a restricted administrator to discover "hidden" groups and see their details, such as internal names and custom settings, which might contain sensitive deployment information.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-14612 Jul 03, 2026
Off-by-One in FreeIPA ipa-otpd OAuth2 Handler OOB Memory Access Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device authorization handler can cause out-of-bounds memory access when processing an oversized response from a configured external OAuth2/OIDC Identity Provider. An attacker who controls or can man-in-the-middle the IdP endpoint may be able to trigger ipa-otpd to write or read one byte past the end of a fixed-size buffer. Exploitation requires FreeIPA to be configured with an external IdP, attacker control or MITM of that IdP, and a user to initiate the OAuth2 device authorization flow. The most likely impact is limited denial of service affecting the ipa-otpd daemon.
Enterprise Linux (RHEL)
CVE-2026-14544 Jul 03, 2026
Integer Overflow in HP HPLIP hpcups Remote Priv Escalation A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. This can occur through an integer overflow in the hpcups processing path when handling specially crafted print data.
Enterprise Linux (RHEL)
CVE-2026-58381 Jul 02, 2026
GIMP PSP File Parser Double-Free Vulnerability A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution.
Enterprise Linux (RHEL)
CVE-2026-38969 Jul 02, 2026
WEBrick 1.9.2 Request Smuggling via Content-Length Reparse ruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state, enabling request smuggling.
CVE-2026-47262 Jul 01, 2026
containerd DoS via faulty image load causing OOM kill (v<1.7.33,2.0.10,2.1.9) containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2.
CVE-2026-46680 Jul 01, 2026
containerd RunAsNonRoot Bypass via Large UID (v1.7.32/2.0.9/2.2.4/2.3.1) containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.
CVE-2026-14330 Jul 01, 2026
PulseAudio Unbounded alloca() Calls in Protocol Server Multiple unbounded alloca() calls in the PulseAudio protocol server.
Enterprise Linux (RHEL)
CVE-2026-14324 Jul 01, 2026
RAOP Module Accepts Unbounded ContentLength Values (CVE202614324) RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
Enterprise Linux (RHEL)
CVE-2026-5138 Jul 01, 2026
Auth Bypass in Foreman's Taxonomy Controller Exposing CrossTenant Data A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information disclosure vulnerability. This flaw occurs because the taxonomy_scope controller method does not properly validate organization and location IDs from nested request parameters, bypassing existing authorization checks. This allows the user to leak sensitive infrastructure metadata, including subnet topology, IP ranges, gateways, DNS servers, and VLAN IDs, from organizations and locations they are not authorized to access.
Satellite
Satellite Capsule
Satellite Maintenance
And others...
CVE-2026-5135 Jul 01, 2026
Foreman Host Retarget Bypass via Broken Access Control A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. This is achieved by modifying the match field through nested host attributes, effectively bypassing authorisation checks. The consequence is the potential for unauthorised modification of managed host configurations across different organisational and location boundaries.
Satellite
Satellite Capsule
Satellite Maintenance
And others...
CVE-2026-5142 Jul 01, 2026
Foreman SSH Key Leak via View_Keypairs Permission A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.
Satellite
Satellite Capsule
Satellite Maintenance
And others...
CVE-2026-23537 Jul 01, 2026
Unauthenticated FS Write via /save-document in Feast Feature Server A vulnerability has been identified in the Feast Feature Servers `/save-document` endpoint that allows an unauthenticated remote attacker to write arbitrary JSON files to the server's filesystem. Although the system attempts to restrict file locations, these protections can be bypassed, enabling an attacker to overwrite vital application configurations or startup scripts. Because this flaw requires no credentials or special privileges, any attacker with network access to the server can potentially compromise the integrity of the system. This could lead to unauthorized system modifications, denial of service through disk exhaustion, or potential remote code execution.
Openshift Ai
CVE-2026-5136 Jul 01, 2026
Foreman Usergroup Role Escalation via Improper Permission Validation A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and then add themselves as a member. Successful exploitation of this vulnerability leads to full privilege escalation, granting the attacker administrator-level access.
Satellite
Satellite Capsule
Satellite Maintenance
And others...
CVE-2026-14258 Jul 01, 2026
dhcpcd ND Router Advertisement Zero-Length Option DoS A flaw was found in dhcpcd's IPv6 Neighbor Discovery Router Advertisement processing. A specially crafted IPv6 Router Advertisement containing a zero-length Neighbor Discovery option can bypass validation during packet storage and later be reparsed without adequate validation, causing the parser to enter a non-advancing loop. Successful exploitation may result in excessive CPU consumption, leading to a denial of service.
Enterprise Linux (RHEL)
CVE-2026-53488 Jul 01, 2026
CRI Label Injection in containerd 1.7.x/2.0-2.3 (1.7.33/2.3.2) containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
CVE-2026-58016 Jun 30, 2026
GLib g_dbus_node_info_new_for_xml uint overflow OOB read DoS A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested within other elements like <method>, <signal>, <property> or <arg>. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-58015 Jun 30, 2026
GLib D-Bus DBUS_COOKIE_SHA1 Auth: CookieCtx Path Traversal CVE-2026-58015 A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-58014 Jun 30, 2026
GLib g_key_file Off-By-One Array Index Bug Causing OOB Access A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-58013 Jun 30, 2026
GLib Buffer Over-Read in giochannel.c Minor Info Disclosure & DoS A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-58012 Jun 30, 2026
GLib g_regex_replace over-read via G_REGEX_RAW causing info leak & DoS A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-58011 Jun 30, 2026
Out-of-bounds read in GLib g_date_time_get_ymd A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-58010 Jun 30, 2026
GLib Off-by-One in gvs_tuple_is_normal leads to 1byte OOB Read A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-12388 Jun 30, 2026
Privilege Escalation in Keycloak via Hardcoded Role Mapper A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is mapped to Keycloak users. An administrator with limited permissions to manage identity providers can exploit this flaw by creating a "Hardcoded Role" mapper that assigns high-level administrative roles (like realm-admin) to themselves or others. This allows a restricted administrator to bypass security checks and gain full control over the entire realm.
Build Keycloak
CVE-2026-4629 Jun 30, 2026
Keycloak Privilege Escalation via Role Mapper Injection A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role mapper into any client. This action allows the user to bypass existing scope restrictions and inject the `realm-admin` role into generated tokens, resulting in privilege escalation and full administrative access to the realm.
Build Keycloak
CVE-2026-14209 Jun 30, 2026
Keycloak Admin UI: FGAP bypass via brute-force-user endpoint A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass security restrictions. When Fine-Grained Admin Permissions (FGAPv2) are enabled, an administrator who should only be able to search for users (but not view their full details) can use a specific "brute-force-user" endpoint to access a user's full profile. This includes sensitive information and security metadata. The issue occurs because the system fails to check if the administrator has the required "view" permission for that specific user when using this particular search path.
Build Keycloak
Jbosseapxp
CVE-2026-13316 Jun 30, 2026
Foreman SSRF via http_proxies_controller to Cloud Metadata A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.
Satellite
CVE-2026-13149 Jun 30, 2026
brace-expansion npm <=5.0.6 DoS via exponential brace groups brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.
CVE-2026-12610 Jun 30, 2026
SSSD PAM Responder UAF Crash via YubiKey Manipulation DOS & Possible Priv Esc A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-14164 Jun 30, 2026
Double-Free in libarchive RAR5 Reader A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-55957 Jun 29, 2026
Apache Tomcat JNDIRealm GSSAPI Auth Bypass (11.0.4) Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.5, 10.1.37 or 9.0.101, which fixes the issue.
CVE-2026-55956 Jun 29, 2026
Apache Tomcat 11.0.22 Improper Auth: Default Servlet Ignores Constraints Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.
CVE-2026-55955 Jun 29, 2026
Apache Tomcat Replay Auth via EncryptionInterceptor v8.5-11.x Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119, which fixes the issue.
CVE-2026-55276 Jun 29, 2026
Apache Tomcat 11.0.22: Incorrect Control Flow Log Issue Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119 which fixes the issue.
CVE-2026-53404 Jun 29, 2026
Apache Tomcat Rewrite Valve OR Logic Bypass 8.5.100 Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.
CVE-2026-50229 Jun 29, 2026
Apache Tomcat (<=11.0.22) Basic XSS in Number Guess Example - CVE-2026-50229 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.
CVE-2026-13757 Jun 29, 2026
Stack Exhaustion in p11-kit via Nested CKA Template Recursion A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-12912 Jun 29, 2026
Heap-based Buffer Overflow in libtiff PixarLog Decoder A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-13676 Jun 29, 2026
fast-uri <=3.1.2/4.0.0 Unicode IDN Canonicalization Bug fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) before passing the same URL to Node's URL or fetch can be bypassed when the two implementations resolve the same input to different hosts. Patches: upgrade to fast-uri 3.1.3 for the 3.x line or 4.0.1 for the 4.x line. Workarounds: enforce host policy using the same URL parser used for the actual request, or reject non-ASCII hosts before policy checks.
Confidential Compute Attestation
Cryostat
Migration Toolkit Applications
And others...
CVE-2026-11979 Jun 29, 2026
Stack Overflow in libxml2 xmlcatalog --shell mode libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process. This issue has been fixed in the commit c2e233fc. NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.
CVE-2026-54371 Jun 29, 2026
Local Priv Escalation via Symlink Traversal in attr <2.6.0 Getfattr/Setfattr attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-54370 Jun 29, 2026
acl before 2.4.0 Local Priv Esc via TOCTOU Symlink Race acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.
CVE-2026-54369 Jun 29, 2026
Linux ACL pre-2.4.0 Symlink Traversal in acl_get_file() & others - Priv Esc acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-12856 Jun 29, 2026
Arbitrary CMD Exec via JavaDoc Hover in VSCode Java Ext (CVE-2026-12856) A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers, allowing a malicious Java file to include hidden commands. If a user clicks a specially crafted link within a JavaDoc hover popup, an attacker can execute arbitrary VS Code commands, which can lead to full system compromise in trusted workspaces.
Openshift Devspaces
CVE-2026-41991 Jun 29, 2026
GNU gzip gzexe TOCTOU File Overwrite via Symlink GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the users PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can precreate the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a timeofcheck to timeofuse (TOCTOU) condition that allows arbitrary file overwrite. This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269
CVE-2026-13601 Jun 29, 2026
Yelp yelp-xsl CSP Permissiveness Lets Flatpak Bypass Sandbox A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
Enterprise Linux (RHEL)
CVE-2026-13595 Jun 29, 2026
Heap UAF in util-linux libblkid during nested probing A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.