Red Hat Red Hat Linux OS and other open source products

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Red Hat product.

RSS Feeds for Red Hat security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Red Hat products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Red Hat Sorted by Most Security Vulnerabilities since 2018

Red Hat Enterprise Linux (RHEL)2626 vulnerabilities

Red Hat Enterprise Linux Server1534 vulnerabilities
RedHat Enterprise Linux (RHEL) Server. Includes software bundeled with RHEL server.

Red Hat Enterprise Linux Workstation1504 vulnerabilities
RedHat Enterprise Linux (RHEL) Workstation. Includes software bundled with RHEL Workstation.

Red Hat Enterprise Linux Desktop1493 vulnerabilities
RedHat Enterprise Linux (RHEL) Desktop. Includes software bundled with RHEL desktop

Red Hat Enterprise Linux Eus1108 vulnerabilities

Red Hat Openshift584 vulnerabilities

Red Hat Rhel Eus560 vulnerabilities

Red Hat Rhel E4s461 vulnerabilities

Red Hat Rhel Tus413 vulnerabilities

Red Hat Rhel Aus410 vulnerabilities

Red Hat Satellite360 vulnerabilities

Red Hat Rhel Eus Long Life325 vulnerabilities

Red Hat Rhel Els317 vulnerabilities

Red Hat Openshift Ai305 vulnerabilities

Red Hat Openstack276 vulnerabilities

Red Hat Hummingbird267 vulnerabilities

Red Hat Jbosseapxp213 vulnerabilities

Red Hat Build Keycloak207 vulnerabilities

Red Hat Jboss Fuse203 vulnerabilities

Red Hat Rhivos199 vulnerabilities

Red Hat Jboss Data Grid188 vulnerabilities

Red Hat Single Sign On159 vulnerabilities

Red Hat Enterprise Linux Ai154 vulnerabilities

Red Hat Openshift Devspaces150 vulnerabilities

Red Hat Quay144 vulnerabilities

Red Hat Rhdh123 vulnerabilities

Red Hat Keycloak123 vulnerabilities

Red Hat Software Collections123 vulnerabilities

Red Hat Cryostat119 vulnerabilities

Red Hat Acm117 vulnerabilities

Red Hat Virtualization115 vulnerabilities

Red Hat Discovery111 vulnerabilities

Red Hat Ai Inference Server104 vulnerabilities

Red Hat Single Sign On95 vulnerabilities

Red Hat Openshift Pipelines93 vulnerabilities

Red Hat Ceph Storage92 vulnerabilities

Red Hat Apache Camel Hawtio91 vulnerabilities

Red Hat Multicluster Engine86 vulnerabilities

Red Hat Amq Streams84 vulnerabilities

Red Hat Service Mesh84 vulnerabilities

Red Hat Logging81 vulnerabilities

Red Hat Camel Spring Boot80 vulnerabilities

Red Hat Amq Broker77 vulnerabilities

Red Hat Ansible Portal77 vulnerabilities

Red Hat Rhui74 vulnerabilities

Red Hat Openshift Lightspeed74 vulnerabilities

Red Hat Serverless74 vulnerabilities

Red Hat Ansible Tower69 vulnerabilities

Red Hat Openshift Gitops67 vulnerabilities

Red Hat Kafka66 vulnerabilities

Red Hat Quarkus63 vulnerabilities

Red Hat 3scale Amp61 vulnerabilities

Red Hat Podman Desktop58 vulnerabilities

Red Hat Apicurio Registry55 vulnerabilities

Red Hat Libvirt55 vulnerabilities

Red Hat Camel Quarkus54 vulnerabilities

Red Hat Service Registry54 vulnerabilities

Red Hat Rhmt54 vulnerabilities

Red Hat Virtualization Host53 vulnerabilities

Red Hat Multicluster Globalhub50 vulnerabilities

Red Hat Network Observ Optr50 vulnerabilities

Red Hat Satellite Capsule49 vulnerabilities

Red Hat Directory Server45 vulnerabilities

Red Hat Jboss Core Services44 vulnerabilities

Red Hat Http Server42 vulnerabilities

Red Hat Ansible42 vulnerabilities

Red Hat Enterprise Linux Aus41 vulnerabilities

Red Hat Gatekeeper40 vulnerabilities

Recent Red Hat Security Advisories

Advisory Title Published
RHSA-2026:49927 (RHSA-2026:49927) Moderate: fence-agents security update August 4, 2026
RHSA-2026:49922 (RHSA-2026:49922) Important: thunderbird security update August 4, 2026
RHSA-2026:49921 (RHSA-2026:49921) Important: thunderbird security update August 4, 2026
RHSA-2026:49914 (RHSA-2026:49914) Low: php8.4 security, bug fix, and enhancement update August 4, 2026
RHSA-2026:49911 (RHSA-2026:49911) Important: fence-agents security update August 4, 2026
RHSA-2026:49910 (RHSA-2026:49910) Moderate: systemd security, bug fix, and enhancement update August 4, 2026
RHSA-2026:49909 (RHSA-2026:49909) Important: libpq security update August 4, 2026
RHSA-2026:49908 (RHSA-2026:49908) Important: libpq security update August 4, 2026
RHSA-2026:49871 (RHSA-2026:49871) Moderate: kernel security, bug fix, and enhancement update August 4, 2026
RHSA-2026:49857 (RHSA-2026:49857) Moderate: kernel security, bug fix, and enhancement update August 4, 2026

By the Year

In 2026 there have been 2483 vulnerabilities in Red Hat with an average score of 7.2 out of ten. Last year, in 2025 Red Hat had 1168 security vulnerabilities published. That is, 1315 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.36.




Year Vulnerabilities Average Score
2026 2483 7.20
2025 1168 6.85
2024 1690 6.63
2023 1206 6.75
2022 1362 6.96
2021 1123 6.61
2020 664 6.39
2019 772 6.98
2018 760 7.16

It may take a day or so for new Red Hat vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Red Hat Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-18739 Aug 04, 2026
popt Off-by-One Vulnerability Allows Local Exec A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-68744 Aug 04, 2026
Red Hat SSSD NSS Preallocation Leak Exposes Heap Data A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.
Enterprise Linux (RHEL)
Openshift
CVE-2026-18569 Aug 04, 2026
Keycloak Backchannel Logout Flaw: SIGOmitted OIDC Logout A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to skip signature validation. In this specific setup, the system incorrectly accepts logout requests that have no cryptographic signature. An attacker who knows certain technical details about a user's session can use this flaw to force that user to be logged out, potentially disrupting their work.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-42169 Aug 04, 2026
GIMP APNG/DDS Loader Heap Buffer Overflow A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in the DDS plug-in due to a BPP mismatch in the `load_layer()` function. Both vulnerabilities can be triggered by opening a specially crafted image file, potentially leading to code execution.
Enterprise Linux (RHEL)
CVE-2026-17614 Aug 04, 2026
Path Traversal in WildFly Domain Mode via Slave-DC Protocol A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getConfigurationFile() methods in wildfly-core/deployment-repository do not validate that the resolved file path remains within the configured repository or configuration root directories. A remote attacker who has obtained the slave host controller secret or compromised a slave host controller can supply a crafted relative path containing directory traversal sequences (e.g., ../../etc/passwd) via the slave-DC wire protocol, causing the Domain Controller to resolve and serve arbitrary files readable by the DC process. This leads to unauthorized disclosure of sensitive information such as configuration files, keystores, and system credentials.
Jboss Enterprise Application Platform
Jbosseapxp
Red Hat Single Sign On
And others...
CVE-2026-18477 Aug 03, 2026
TOCTOU in GNU tar incremental dumpdir rename A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflowsincluding extracting into a newly created directory without using the -P option do not mitigate the issue.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-18651 Aug 03, 2026
389 Directory Server Auth Bypass via SASL PLAIN & Account Lock Defect A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted. A client that supplies valid credentials for an account that has been administratively locked can continue to use the same connection with that account's privileges, defeating account lock as an access-revocation control.
Directory Server
Enterprise Linux (RHEL)
CVE-2026-18508 Aug 03, 2026
GNU tar Hardlink Extraction Path Traversal via --one-top-level A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-68742 Aug 03, 2026
SSSD NSS Responder OOB Read via GETHOSTBYADDR Causing DoS A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.
Enterprise Linux (RHEL)
Openshift
CVE-2026-6695 Aug 03, 2026
GIMP PAA decode_lzss Heap OOB RCE A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer. This could lead to heap metadata corruption and potentially enable the attacker to execute arbitrary code on the affected system.
Enterprise Linux (RHEL)
CVE-2026-6694 Aug 03, 2026
GIMP file-png Plugin Stack Overflow via Malicious APNG tRNS Chunk A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to crash and resulting in a Denial of Service (DoS) for the user.
Enterprise Linux (RHEL)
CVE-2026-18573 Aug 02, 2026
Keycloak Services Bypass of Client Policies via Confidential Client Update A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements on confidential clients. Due to improper evaluation of the client state during an update operation, an attacker with client management permissions can bypass these security policies by first creating a public client and then updating it to a confidential client with weaker authentication. This can result in the persistence of clients that do not comply with the intended security hardening of the realm.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-18572 Aug 02, 2026
Keycloak Time Policy Bypass via Fake Time Claims Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-18571 Aug 02, 2026
Keycloak: FGAP V2 Allows Unauthorized User Group Additions A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-18570 Aug 02, 2026
Red Hat Keycloak FullScopeDisabled Executor Bypass A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executor only validates the fullScopeAllowed field when it is explicitly provided in a request. By omitting this field, a delegated user can bypass the policy, resulting in a client created with full scope access. This allows the client to obtain tokens with unauthorized role mappings.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-67318 Aug 01, 2026
Axios 1.13.0 HTTP/2 maxBodyLength Bypass in Node HTTP Adapter axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent with httpVersion: 2. Because Node's HTTP/2 request API does not honor the maxBodyLength option and axios's byte-counting stream wrapper is gated on maxRedirects === 0, an attacker who controls a stream passed to axios can cause the application to transmit outbound data exceeding the configured finite maxBodyLength. Impact is limited to resource consumption and policy bypass (excess egress, upstream quota consumption, limited availability); it does not enable code execution, credential disclosure, or request-destination control. Calls using the default maxBodyLength: -1 and browser adapters are not affected.
CVE-2026-67316 Aug 01, 2026
Axios Prototype Pollution; fixed in 1.18.0 & 0.33.0 axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method aliases (axios.get(), axios.delete(), axios.head(), axios.options()), inherited data is read via (config || {}).data before config normalization, causing an attacker-controlled body to be sent on requests that did not set one. Additional low-level paths, only reachable when calling exported adapters/helpers (e.g. lib/adapters/http.js, unsafe/helpers/resolveConfig.js) directly with plain configs and no own proxy or paramsSerializer, can inherit polluted proxy values (routing requests through an attacker-controlled proxy) or paramsSerializer values (attacker-controlled URL serialization). These low-level gadgets do not reproduce through normal high-level axios calls on 1.15.2+. The issue is fixed in axios 1.18.0 and 0.33.0.
CVE-2026-67315 Aug 01, 2026
Axios 1.15-1.17 Loopback 0.0.0.0 Proxy Bypass axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.
CVE-2026-67317 Aug 01, 2026
CVE-2026-67317: axios <1.18.0 bypass maxBodyLength via unknown stream size axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.
CVE-2026-67314 Aug 01, 2026
Axios auth prototype pollution in HTTP adapter (v1.15.2-1.17.9) axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js). When an application is already affected by a separate prototype-pollution primitive and makes an axios request with an own auth object that omits the username and/or password properties, axios reads the inherited Object.prototype.username and Object.prototype.password values and uses them to construct an outbound 'Authorization: Basic ...' header. axios itself does not pollute prototypes. The practical impact is outbound request tampering: an attacker who controls the polluted prototype values can inject attacker-chosen Basic auth credentials or replace an existing Authorization header. Credential disclosure is only possible under additional application-specific conditions.
CVE-2026-67313 Aug 01, 2026
Uncontrolled Recursion in Axios 0.28.0+ formDataToJSON Leading to RangeError axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brackets to exhaust the JavaScript call stack and trigger RangeError, causing request failure or process termination in applications that do not handle the exception.
CVE-2026-18141 Jul 31, 2026
Unauthenticated mTLS Bypass & Event Injection in Ansible EDA aap-gateway A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The system also inadvertently discloses the expected certificate subject in error messages, which simplifies the attack. This vulnerability allows an attacker to inject arbitrary events into EDA, potentially triggering automated workflows.
Ansible Automation Platform
CVE-2026-18446 Jul 31, 2026
fast-uri <=4.1.2: Backslash URL Parsing Breaks Host Validation (SSRF) fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward slash) is parsed with no authority and folds into the path. Node's native WHATWG URL parser instead treats a backslash as interchangeable with a forward slash for special schemes, so the two parsers extract different hosts from the same input. Applications that use fast-uri to enforce host based policy such as allowlists, SSRF filtering, or redirect validation before passing the same URL into Node's URL or fetch consumers can be steered to an unintended host. Upgrade to fast-uri 4.1.2, 3.1.5, or 2.4.4.
CVE-2026-18358 Jul 31, 2026
Red Hat GNOME-Remote-Desktop RDP Connection Throttle Bypass A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations until timeout, exhausting resources and preventing legitimate users from establishing RDP sessions. This issue does not affect the upstream version.
Enterprise Linux (RHEL)
CVE-2026-11770 Jul 31, 2026
389 DS LDAP Filter Injection via CleanAllRUV Replication Status-Check A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.
Directory Server
Enterprise Linux (RHEL)
CVE-2026-15722 Jul 31, 2026
389 DS LDAP: Stack Buffer Overflow in get_ruvelement_from_berval A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.
Directory Server
Enterprise Linux (RHEL)
CVE-2026-10079 Jul 31, 2026
RHACS Deployment Metadata Bypass via openshift.io Label A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the workload as having empty UID, name and labels and namespace "default". This bypasses deploy-time policy detection and enforcement visibility, prevents correct persistence in Central and breaks violation reporting and compliance correlation for the affected deployment.
Advanced Cluster Security
CVE-2026-18209 Jul 31, 2026
Keycloak keycloak-services OIDC Param Poll. Reroute Enables Session Fix A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a redirect URL and ignores the fragment portion. When a client is configured with a wildcard redirect URI, an attacker can use this to inject duplicate security parameters into the login response. If a client application is not configured correctly, it might trust the attacker's injected data instead of the real security information from Keycloak, leading to session fixation or account confusion.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-18206 Jul 31, 2026
Keycloak keycloak-services Hostname Validation Flaw Enables Unauth Client Mod A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a wildcard domain (like *.example.com) to restrict which hosts can register or update clients. Due to improper validation, the system accepts any hostname that ends with the specified domain suffix, even if it is not a legitimate subdomain. An attacker who can control the reverse DNS of their connection can bypass these host-based restrictions, potentially allowing unauthorized client modifications.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-18203 Jul 31, 2026
Keycloak GPI Prefix Check IDOR Enables Admin Access A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify group membership. This allows a user who belongs to a different group with a similar starting name to bypass security checks and gain unauthorized access to administrative functions or protected resources.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-18214 Jul 31, 2026
Keycloak Token Exchange Bypass: Domain Restriction Lapse Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloak token, does not check these domain restrictions. This means an attacker with a valid Google account from a different domain could bypass the security check and gain access to the Keycloak realm.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-18211 Jul 31, 2026
Keycloak secure-client-uris flaw bypasses redirect URI security A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security requirements on client configurations, such as requiring encrypted connections for redirect URIs. Due to an improper check that only looks at the start of a web address rather than properly verifying the host, an attacker can bypass these security restrictions by using a specially crafted domain name. This could allow an attacker to intercept sensitive authentication codes over unencrypted connections.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-18208 Jul 31, 2026
Unauthorized OIDC Introspection Exposure in Keycloak Services A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential client, configured to receive signed JWT introspection responses, attempts to introspect a token issued for a different audience. Although the endpoint correctly identifies the token as inactive for that client, it still returns the full set of token claims within a signed JWT field. This allows an unauthorized client to bypass audience-based restrictions and access sensitive information contained in the token.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-16105 Jul 31, 2026
Keycloak RoleContainerResource Authorization Bypass in Admin REST API A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm permissions to remove essential child roles from built-in admin roles, potentially disrupting administrative functions within a realm.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-18215 Jul 31, 2026
Keycloak Token Exchange Bypass Ignoring Org Restriction Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an attacker with a valid Microsoft token from a completely different organization could gain access to the Keycloak realm, potentially accessing sensitive data or performing unauthorized actions.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-18217 Jul 31, 2026
Keycloak SAML Wildcard URL Injection (CVE-2026-18217) A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect binding. If a client is configured with a wildcard redirect URL, an attacker can craft a request that includes malicious parameters. When a user authenticates, Keycloak appends its legitimate response to the attacker's parameters. This can cause some service providers to process the attacker's data instead of the real login information, potentially leading to a user being logged into the wrong account.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-18218 Jul 31, 2026
TokenManager revocation bypass in Keycloak A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm already has an older, non-zero revocation policy in place. This issue can allow previously issued tokens to remain valid for refreshing sessions and accessing user information even after an administrator has attempted to invalidate them.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-18157 Jul 31, 2026
Yggdrasil-WP Manager: Argument Injection in APT Backend Allows Root RCE A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the attacker to fully compromise the system's integrity, confidentiality, and availability.
Enterprise Linux (RHEL)
CVE-2026-68563 Jul 30, 2026
Leapp Collection: Insecure PG Backup Archive Permissions Leak Info A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a PostgreSQL data backup archive is created with insecure permissions. This allows a local non-root user on the managed node to read sensitive archived PostgreSQL data, leading to information disclosure.
Enterprise Linux (RHEL)
CVE-2026-68562 Jul 30, 2026
RedHat Ansible Leapp Report Manipulation Exposes Controller Files A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy them to the managed node. This vulnerability leads to information disclosure, potentially exposing sensitive controller-side data such as private keys or credentials.
Enterprise Linux (RHEL)
CVE-2026-58216 Jul 30, 2026
Samba KDC kpasswd OOB Read in ASN.1 Authenticated DoS An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service. When processing malformed ASN.1-encoded Kerberos password change request, Samba server miscalculates the structure size and attempts to read up to six bytes beyond the end of the allocated buffer. While this out-of-bounds read typically results in a harmless decryption failure, if the read hits unmapped memory, it causes the KDC process to crash. An authenticated attacker can send a specially crafted kpasswd request containing malformed ASN.1 data to trigger the out-of-bounds read, which may cause the KDC process to terminate, resulting in a denial of service.
Enterprise Linux (RHEL)
Openshift
CVE-2026-58222 Jul 30, 2026
LDAP Filter Injection & PrivEsc in Samba AD DC A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied attribute names and executes the resulting internal database search in a trusted context, bypassing normal Access Control List (ACL) enforcement. An authenticated low-privilege domain user can exploit these flaws to disclose confidential Active Directory attributes that would normally be inaccessible. The disclosed information may be leveraged to derive sensitive authentication material, potentially leading to privilege escalation and complete domain compromise. For example: In deployments configured with Group Managed Service Accounts (gMSAs), an attacker can extract the "msKds-RootKeyData" attribute and derive gMSA passwords offline, potentially leading to complete domain compromise if privileged gMSAs are present.
Enterprise Linux (RHEL)
Openshift
CVE-2026-16308 Jul 30, 2026
IBM Quarkus REST DoS via Unbounded MIME Header Accum (3.27,3.33) IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.
CVE-2026-58218 Jul 30, 2026
Samba DNS TKEY Cache DoS via Unauth Reg A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service.
Enterprise Linux (RHEL)
Openshift
CVE-2026-18382 Jul 30, 2026
koku-metrics-operator CR Leak Red Hat SSO Secrets via User-Defined OAuth URL A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authentication.type is set to service-account, the operator sends the tenant's Red Hat SSO client_id and client_secret to this user-controlled URL, allowing the attacker to obtain the credentials.
Cost Management
CVE-2026-18378 Jul 30, 2026
Red Hat koku-metrics-operator Exposes Pull-Secret via User-Controlled Upload URL A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent to this user-controlled URL, allowing the attacker to obtain the token.
Cost Management
CVE-2026-18381 Jul 30, 2026
CVE-2026-18381: koku-metrics-operator URL Injection Leaks K8s SA Token A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token.
Cost Management
CVE-2026-18369 Jul 30, 2026
Dogtag PKI ACME Responder SSRF via IP literals & redirects A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME account holder can exploit this to perform server-side request forgery (SSRF), making the Dogtag server send HTTP GET requests to internal network services. With the InMemory database backend, the response body of internal targets is disclosed to the attacker through the ACME challenge error.
Certificate System
Enterprise Linux (RHEL)
CVE-2026-58040 Jul 30, 2026
Node.js HTTPS Agent TLS Session Reuse Skips Hostname Verification An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
CVE-2026-56850 Jul 30, 2026
Node.js HTTPS Agent PFX Key Collision Enables mTLS Identity Reuse A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.