Red Hat Red Hat Linux OS and other open source products

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Red Hat product.

RSS Feeds for Red Hat security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Red Hat products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Red Hat Sorted by Most Security Vulnerabilities since 2018

Red Hat Enterprise Linux (RHEL)2817 vulnerabilities

Red Hat Enterprise Linux Server1534 vulnerabilities
RedHat Enterprise Linux (RHEL) Server. Includes software bundeled with RHEL server.

Red Hat Enterprise Linux Workstation1504 vulnerabilities
RedHat Enterprise Linux (RHEL) Workstation. Includes software bundled with RHEL Workstation.

Red Hat Enterprise Linux Desktop1493 vulnerabilities
RedHat Enterprise Linux (RHEL) Desktop. Includes software bundled with RHEL desktop

Red Hat Enterprise Linux Eus1180 vulnerabilities

Red Hat Openshift647 vulnerabilities

Red Hat Rhel Eus639 vulnerabilities

Red Hat Rhel E4s544 vulnerabilities

Red Hat Rhel Tus474 vulnerabilities

Red Hat Rhel Aus458 vulnerabilities

Red Hat Satellite376 vulnerabilities

Red Hat Rhel Eus Long Life375 vulnerabilities

Red Hat Rhel Els359 vulnerabilities

Red Hat Openshift Ai332 vulnerabilities

Red Hat Hummingbird321 vulnerabilities

Red Hat Openstack287 vulnerabilities

Red Hat Build Keycloak258 vulnerabilities

Red Hat Jbosseapxp248 vulnerabilities

Red Hat Jboss Fuse240 vulnerabilities

Red Hat Single Sign On222 vulnerabilities

Red Hat Jboss Data Grid215 vulnerabilities

Red Hat Rhivos199 vulnerabilities

Red Hat Openshift Devspaces161 vulnerabilities

Red Hat Acm159 vulnerabilities

Red Hat Quay158 vulnerabilities

Red Hat Enterprise Linux Ai157 vulnerabilities

Red Hat Rhdh128 vulnerabilities

Red Hat Discovery125 vulnerabilities

Red Hat Software Collections123 vulnerabilities

Red Hat Keycloak123 vulnerabilities

Red Hat Cryostat121 vulnerabilities

Red Hat Virtualization115 vulnerabilities

Red Hat Camel Spring Boot111 vulnerabilities

Red Hat Ai Inference Server106 vulnerabilities

Red Hat Kafka104 vulnerabilities

Red Hat Apache Camel Hawtio99 vulnerabilities

Red Hat Ceph Storage99 vulnerabilities

Red Hat Rhui96 vulnerabilities

Red Hat Multicluster Engine96 vulnerabilities

Red Hat Openshift Pipelines95 vulnerabilities

Red Hat Single Sign On95 vulnerabilities

Red Hat Amq Broker94 vulnerabilities

Red Hat Logging92 vulnerabilities

Red Hat Quarkus89 vulnerabilities

Red Hat Amq Streams85 vulnerabilities

Red Hat Service Mesh84 vulnerabilities

Red Hat Camel Quarkus79 vulnerabilities

Red Hat Ansible Portal77 vulnerabilities

Red Hat Apicurio Registry77 vulnerabilities

Red Hat Serverless76 vulnerabilities

Red Hat Openshift Lightspeed75 vulnerabilities

Red Hat Http Server72 vulnerabilities

Red Hat Ansible Tower69 vulnerabilities

Red Hat Openshift Gitops68 vulnerabilities

Red Hat 3scale Amp63 vulnerabilities

Red Hat Podman Desktop58 vulnerabilities

Red Hat Rhmt56 vulnerabilities

Red Hat Satellite Capsule56 vulnerabilities

Red Hat Debezium55 vulnerabilities

Red Hat Libvirt55 vulnerabilities

Red Hat Multicluster Globalhub54 vulnerabilities

Red Hat Service Registry54 vulnerabilities

Red Hat Directory Server53 vulnerabilities

Red Hat Virtualization Host53 vulnerabilities

Red Hat Network Observ Optr51 vulnerabilities

Red Hat Jboss Core Services48 vulnerabilities

Red Hat Insights Proxy44 vulnerabilities

Red Hat Ansible42 vulnerabilities

Red Hat Satellite Utils42 vulnerabilities

Recent Red Hat Security Advisories

Advisory Title Published
RHSA-2026:69719 (RHSA-2026:69719) Important: mod_auth_openidc security update September 22, 2026
RHSA-2026:69718 (RHSA-2026:69718) Important: mod_auth_openidc security update September 22, 2026
RHSA-2026:69716 (RHSA-2026:69716) Important: mod_auth_openidc security update September 22, 2026
RHSA-2026:69715 (RHSA-2026:69715) Important: mod_auth_openidc security update September 22, 2026
RHSA-2026:69713 (RHSA-2026:69713) Important: mod_auth_openidc:2.3 security update September 22, 2026
RHSA-2026:69712 (RHSA-2026:69712) Important: mod_auth_openidc:2.3 security update September 22, 2026
RHSA-2026:69698 (RHSA-2026:69698) Important: postgresql:15 security update September 21, 2026
RHSA-2026:69655 (RHSA-2026:69655) Moderate: libxml2 security, bug fix, and enhancement update September 21, 2026
RHSA-2026:69609 (RHSA-2026:69609) Important: openexr security update September 21, 2026
RHSA-2026:69553 (RHSA-2026:69553) Low: libarchive security update September 21, 2026

By the Year

In 2026 there have been 3510 vulnerabilities in Red Hat with an average score of 7.2 out of ten. Last year, in 2025 Red Hat had 1179 security vulnerabilities published. That is, 2331 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.38.




Year Vulnerabilities Average Score
2026 3510 7.24
2025 1179 6.86
2024 1695 6.82
2023 1207 6.75
2022 1362 6.96
2021 1123 6.61
2020 664 6.39
2019 772 6.98
2018 760 7.16

It may take a day or so for new Red Hat vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Red Hat Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-93433 Sep 21, 2026
libstoragemgmt SCSI VPD 0x80 Buffer Overflow in _sg_parse_vpd_80() A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specially crafted SCSI (Small Computer System Interface) Vital Product Data (VPD) page 0x80 data. This malformed data, specifically an untrusted page length field, can lead to a stack buffer overflow in the `_sg_parse_vpd_80()` function during serial number parsing. Successful exploitation could result in a denial of service by crashing or destabilizing the process querying the serial number.
Enterprise Linux (RHEL)
CVE-2026-92382 Sep 21, 2026
USBREDIR OOB Write via usbredirhost_iso_packet() (ISO OUT stream) An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer permanently unsubmitted, defeating the bounds check in usbredirhost_iso_packet() and allowing a usbredir peer to write past the end of the packet descriptor array on every subsequent isochronous packet.
Enterprise Linux (RHEL)
CVE-2026-94449 Sep 21, 2026
SmallRye Fault Tolerance memory leak causing resource exhaustion A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices. The issue occurs when using the ApplyGuard or ApplyFaultTolerance annotations, where the library fails to release internal tracking objects after each request. This causes a steady increase in memory usage that eventually leads to the application slowing down and crashing due to lack of memory.
Exploit Intelligence
Camel Quarkus
Apicurio Registry
And others...
CVE-2026-94184 Sep 21, 2026
A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure or process termination under memory hardening. Affects v5.0.8 through v6.6.6.
Enterprise Linux (RHEL)
CVE-2026-80110 Sep 21, 2026
A flaw was found in pki-core A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to override a more specific literal-mapped permission when both match. In the CA's profile-management REST API this allows a request to POST /v2/profiles/raw -- intended to require Administrator-level profiles.create permission -- to instead be authorized under the lower-privileged profiles.approve permission held by the default Certificate Manager Agents group. The highest threat from this vulnerability is to confidentiality and integrity of the certificate authority's issuance policy.
Certificate System
Enterprise Linux (RHEL)
CVE-2026-75939 Sep 21, 2026
A flaw was found in openshift/oc-mirror A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating network traffic to the signature endpoint, could exploit this to craft a PGP message with a valid Red Hat release key ID but a forged signature. This enables the `oc-mirror` tool to accept and mirror a malicious release payload into a disconnected registry, potentially compromising the integrity of software deployments.
Openshift
CVE-2026-94368 Sep 21, 2026
NooBaa Core SigV4 Header Injection via Unsigned x-amz- Header A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when the service processes S3 presigned URLs using Signature Version 4 (SigV4). Due to improper validation, the service fails to reject requests containing unsigned x-amz- headers, instead simply dropping them from the signature calculation. This allows an attacker who possesses a valid presigned PUT URL to add an unsigned x-amz-copy-source header, effectively converting a simple upload into a CopyObject operation. This can lead to unauthorized access and copying of any data the original signer is permitted to reach across the entire storage system.
Openshift Data Foundation
CVE-2026-92574 Sep 21, 2026
CRI-O Privilege Escalation via Malicious Checkpoint Restore (before 1.34) A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the destination configuration. This can allow execution with elevated privileges across the container security boundary. Affected upstream supported versions are CRI-O 1.34 and later. Downstream Red Hat products are affected from OCP 4.17 onward. Fixes have been applied to supported branches but are not yet released. Exploitation requires permission to create a pod from a malicious checkpoint image and checkpoint restore functionality to be available.
Confidential Compute Attestation
Enterprise Linux (RHEL)
Openshift
And others...
CVE-2026-15801 Sep 21, 2026
CRIO chkrestore metadata flaw enabling host FS ops A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow a user with sufficient privileges to perform unintended operations on the host filesystem. Successful exploitation requires that container checkpoint and restore functionality is enabled, which is not the default configuration. An attacker must also be able to trigger restoration of a container from untrusted checkpoint content.
Openshift
CVE-2026-94218 Sep 21, 2026
Keycloak Auth Session Flaw: 2FA Bypass via Session Restart Link A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a stronger authentication flow, such as mandatory two-factor authentication (2FA) setup, through a client policy. A user can bypass this requirement by manually visiting a specific session restart web link during the login process. This action clears the internal markers that track the required security steps, allowing the user to log in with only a password and gain access without completing the mandated 2FA setup.
Build Keycloak
Red Hat Single Sign On
CVE-2026-94217 Sep 21, 2026
Keycloak UMA Permission Ticket Merging (CVE-2026-94217) A flaw was found in the User-Managed Access (UMA) implementation of Keycloak. The issue occurs in the authorization token endpoint when processing permission tickets. If two different users own resources with the same name, the system incorrectly merges the permissions from both resources when one user requests an authorization token. This allows an attacker to gain access scopes on a victim's resource that were never intended to be shared.
Build Keycloak
Red Hat Single Sign On
CVE-2026-94215 Sep 21, 2026
Keycloak Admin REST API Privilege Escalation via Realm Validation Bypass A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses a per-request in-memory cache to resolve clients by their unique identifier without verifying if the client belongs to the realm specified in the request path. This allows an administrator with limited privileges to read or modify sensitive client configurations in the master realm by accessing them through a realm they control. Successful exploitation could lead to the exposure of client credentials or the redirection of administrative login attempts to malicious sites.
Build Keycloak
Red Hat Single Sign On
CVE-2026-94213 Sep 21, 2026
Keycloak Auth Services: Admin Bypass Reveals Full User Profiles A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue occurs in the policy evaluation endpoint, which is used by administrators to test how access policies apply to specific users. Due to missing authorization checks, a delegated administrator with limited viewing privileges can access the full profile and role information of any user in the realm, even if they are not permitted to view user details. This could lead to the exposure of sensitive information such as email addresses and assigned security roles.
Build Keycloak
Red Hat Single Sign On
CVE-2026-94001 Sep 19, 2026
Keycloak Admin REST API DeleteCred PrivEsc for Delegated Admin A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials does not correctly check for fine-grained reset-password permissions. This allows a delegated administrator, who should be restricted from resetting passwords, to delete a user's password credentials, resulting in the user being unable to log in.
Build Keycloak
Red Hat Single Sign On
CVE-2026-94000 Sep 19, 2026
Privilege Escalation via Keycloak Admin REST Group-Membership API A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges before allowing a user to be added. This allows a delegated administrator with limited permissions to add themselves to a high-privilege group, potentially gaining full control over the entire realm.
Build Keycloak
Red Hat Single Sign On
CVE-2026-93999 Sep 19, 2026
Keycloak OIDC Token Refresh Bypass for Disabled Clients A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh process when the server restores requested audiences from stored client IDs. Keycloak fails to verify if the target audience client is still enabled before issuing a new access token. This allows an application with an existing refresh token to continue obtaining valid access tokens for a disabled client, potentially bypassing administrative access controls for resource servers that rely on offline JWT validation.
Build Keycloak
Red Hat Single Sign On
CVE-2026-75885 Sep 18, 2026
OpenShift Console Unauth devfile API SSRF/DoS A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial responses to the attacker. Additionally, by sending repeated large requests without a specified content length, an attacker can cause unbounded memory growth, leading to a Denial of Service (DoS).
Openshift
CVE-2026-93562 Sep 18, 2026
Netty HTTP/1 Decoder Request Smuggling via Malformed Transfer-Encoding A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending specially crafted HTTP requests, an attacker can inject arbitrary HTTP requests, potentially bypassing security controls or accessing unauthorized resources.
Amq Broker
Amq Clients
Camel Quarkus
And others...
CVE-2026-93574 Sep 18, 2026
Netty netty-codec-http HTTP Smuggling via Chunk-Size Post-Digit Whitespace A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/1.1 chunk-size token that includes post-digit whitespace. This incorrect parsing of the chunk size can lead to HTTP request smuggling. This allows an attacker to bypass security controls or access unauthorized resources in proxy/backend deployments.
Amq Broker
Amq Clients
Camel Quarkus
And others...
CVE-2026-91202 Sep 18, 2026
cockpit-files symlink exploitation: lowpriv local user can change file ownership A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged "Paste as owner" function. This allows for arbitrary file ownership changes outside the intended pasted directory, leading to a compromise of data integrity. In some cases, this could also lead to reduced confidentiality if the new ownership grants unauthorized read access. Exploitation requires user interaction to select a non-original owner during the paste operation.
Enterprise Linux (RHEL)
CVE-2026-91203 Sep 18, 2026
Red Hat Cockpit-files Symlink Race Local Privilege Escalation A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By manipulating directory entries and winning this race, the attacker can redirect these operations to unintended files. This could lead to unauthorized changes in file ownership and permissions on arbitrary files, potentially compromising system integrity and availability by altering system or application states or rendering services unusable.
Enterprise Linux (RHEL)
CVE-2026-91205 Sep 18, 2026
Unprivileged Race Condition in cockpit-files Enables Symlink Attack A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable parent directory, the attacker can replace a newly created directory with a symbolic link (symlink) before the ownership change operation (chown) is applied. This allows the attacker to redirect the ownership change to an arbitrary file, potentially leading to information disclosure or unauthorized modification of sensitive files.
Enterprise Linux (RHEL)
CVE-2026-92768 Sep 18, 2026
cockpitmachines CLI Arg Disclosure: VM Credentials Leaked A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-line arguments during VM creation or installation. The cockpit-machines component passes password values directly on the command line, making them visible to other local users on systems where process arguments are not restricted. Successful exploitation leads to information disclosure, potentially compromising VM access.
Enterprise Linux (RHEL)
CVE-2026-92747 Sep 18, 2026
Local Inspection Disclosure in cockpit-machines install_machine JSON A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This occurs when the `install_machine.py` script passes these credentials as a JSON command-line argument during VM creation or installation. The exposure is limited to the period when the installation workflow is active and depends on host process-visibility policies.
Enterprise Linux (RHEL)
CVE-2026-92745 Sep 18, 2026
Local Process Metadata Disclosure in cockpit-machines via RHSM Offline Token Leak A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is passed as a command-line argument to a helper script during the token validation process. Successful exploitation could lead to the compromise of confidentiality, as the exposed token can be used to request access tokens.
Enterprise Linux (RHEL)
CVE-2026-93432 Sep 18, 2026
RedHat Quarkus Qute XSS via Unescaped eval Sub-Template A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's content type information. This bypasses standard escaping mechanisms, allowing untrusted data to be output as raw, unescaped text. This vulnerability can lead to Cross-Site Scripting (XSS) and JSON Injection, potentially allowing a remote attacker to execute arbitrary code in a user's browser or manipulate data.
Exploit Intelligence
Camel Quarkus
Apicurio Registry
And others...
CVE-2026-91142 Sep 18, 2026
Cockpit ILP32 Integer Overflow Enables Unauthorized lastlog Access A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A low-privileged authenticated user with a specially provisioned large User ID (UID) can cause the computed offset to wrap around. This allows the user to perform unauthorized reads and writes to other users' `lastlog` records, potentially disclosing or altering sensitive login accounting information.
Enterprise Linux (RHEL)
Openshift Devspaces
CVE-2026-91147 Sep 18, 2026
Red Hat cockpit-ws Remote Unauthenticated DoS via URL-Root Prefix A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is made to the exact URL-root prefix without a trailing slash, `cockpit-ws` can terminate unexpectedly. This issue leads to the unavailability of the Cockpit web service.
Enterprise Linux (RHEL)
Openshift Devspaces
CVE-2026-91149 Sep 18, 2026
RedHat Cockpit DoS via Unbounded Thread Creation (CVE-2026-91149) A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded number of detached threads, consuming system resources such as memory and file descriptors. The primary consequence is a denial of service (DoS), leading to degradation or complete unavailability of the Cockpit service for legitimate users.
Enterprise Linux (RHEL)
Openshift Devspaces
CVE-2026-93579 Sep 18, 2026
Netty HTTP/2 Header Field Injection Vulnerability (CVE-2026-93579) A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage Return, into HTTP/2 header field values due to insufficient validation. When these values cross an HTTP/2 to HTTP/1.1 translation boundary, they can be exploited for request smuggling, header injection, or response splitting. This could lead to unauthorized access, data manipulation, or other security bypasses.
Amq Broker
Camel Quarkus
Camel Spring Boot
And others...
CVE-2026-93685 Sep 18, 2026
RedHat Multicluster Observability Addon: Auth Bypass on Debug Endpoint A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details, after completing a basic encrypted connection. This vulnerability does not enable direct remote code execution.
Acm
CVE-2026-93573 Sep 18, 2026
Netty Transfer-Encoding Field Split Bypass Enables Request Smuggling A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing a non-final transfer coding like `gzip` or `deflate`. This bypass can lead to HTTP request smuggling, enabling attackers to bypass security controls, desynchronize request processing, or cause requests to be processed in an unintended context.
Amq Broker
Amq Clients
Camel Quarkus
And others...
CVE-2026-93568 Sep 18, 2026
Red Hat: HTTP/2/3 EXT CONNECT Downgrade in Apache HTTPd A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. Netty's HTTP-object conversion path incorrectly processes these requests as regular HTTP/1.1 CONNECT requests, leading to a loss of critical protocol and path information. This misinterpretation can allow attackers to bypass security policies, such as routing or authorization logic, in applications that rely on Netty for HTTP/2 or HTTP/3 communication, resulting in integrity loss.
Amq Broker
Camel Quarkus
Camel Spring Boot
And others...
CVE-2026-93576 Sep 18, 2026
Netty netty-codec-smtp SMTP cmd-name not CRLF-validated Vulnerability A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-name field. A remote attacker, if an application routes untrusted input into this field, can embed CR/LF characters to inject arbitrary SMTP commands. This can lead to SMTP command smuggling, allowing for unauthorized email relay or spoofing of sender/recipient addresses. While the impact is significant, the real-world exploitability is considered lower as applications typically do not place user-controlled data in the command-name field.
Camel Spring Boot
Jboss Fuse
Jboss Enterprise Application Platform
And others...
CVE-2026-85511 Sep 18, 2026
EAP Elytron Token-Realm OAuth2 Introspection URL Encoding Flaw A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.
Jboss Enterprise Application Platform
Jbosseapxp
CVE-2026-93569 Sep 18, 2026
Netty HTTP/1HTTP/2 Host Header Conflict Allows Unauthorized Access A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, Netty incorrectly prioritizes the Host header for the HTTP/2 :authority field, discarding the original request-target authority. This inconsistency can allow an attacker to bypass security controls in Netty-based proxies or gateways, potentially leading to unauthorized access, cache poisoning, or misrouting of requests.
Amq Broker
Camel Quarkus
Camel Spring Boot
And others...
CVE-2026-93567 Sep 18, 2026
Netty HTTP/2 CONNECT Host Header Exploit Bypass Tunnel Allow-List A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONNECT authority-form request-target for the tunnel authority. A remote attacker can exploit this by supplying a different Host header, leading to a malformed HTTP/2 CONNECT request. This can bypass security controls such as tunnel allow-lists or egress policies, resulting in integrity loss.
Amq Broker
Camel Quarkus
Camel Spring Boot
And others...
CVE-2026-93676 Sep 18, 2026
xdg-dbus-proxy D-Bus Broadcast Filter Bypass Enables Flatpak Signal Intercept xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to unauthorized applications.
Enterprise Linux (RHEL)
CVE-2026-93566 Sep 18, 2026
Netty HTTP Request Smuggling via Chunk-Size Line Bypass A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to inject arbitrary HTTP requests. This vulnerability can lead to HTTP request smuggling, potentially resulting in information disclosure or other unauthorized actions.
Amq Broker
Amq Clients
Camel Quarkus
And others...
CVE-2026-10832 Sep 18, 2026
WildFly Elytron ASN1 DERDecoder DoS via Excessive Memory Allocation A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability by sending a specially crafted DER (Distinguished Encoding Rules) payload. The decoder attempts to allocate excessive memory based on an inflated length value without proper validation, leading to Java Virtual Machine (JVM) memory exhaustion. This results in a remote Denial of Service (DoS) for services that process untrusted DER/ASN.1 input, including SASL (Simple Authentication and Security Layer) authentication mechanisms and X.500 certificate principal parsing paths.
Cryostat
Camel Quarkus
Apache Camel Hawtio
And others...
CVE-2026-93565 Sep 18, 2026
Netty RtspDecoder Method-Token Smuggling via RTSP Request A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens in Real-Time Streaming Protocol (RTSP) requests. A remote attacker can exploit this by sending a specially crafted RTSP request, leading to method-token smuggling. This vulnerability allows an attacker to bypass method-based access controls and can also be used to launder malicious requests through Netty-based RTSP proxies, making them appear legitimate to backend systems.
Amq Broker
Amq Clients
Camel Quarkus
And others...
CVE-2026-93653 Sep 18, 2026
DenialofService in Poppler Splash via tilingpattern overflow A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to compute an attacker-controlled repeat count that drives an excessively long loop in the pattern-fill scanline routine, without a corresponding memory allocation. An attacker could exploit this by supplying a malicious PDF to an application that renders it via Poppler's Splash backend, causing the rendering process to consume 100% CPU for an attacker-controlled, extended duration.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-93564 Sep 18, 2026
Netty HAProxy PROXY-v2 RefCnt Leak: Remote DoS A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to send specially crafted PROXY-protocol v2 headers. This can lead to memory exhaustion, resulting in a Denial of Service (DoS) for the affected system.
Amq Broker
Camel Quarkus
Camel Spring Boot
And others...
CVE-2026-93558 Sep 18, 2026
Netty WebSocketServerExtensionHandler DoS via HTTP/1.1 Pipelining Queue Overflow A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the application can respond. This leads to an unbounded growth of a per-connection queue, consuming excessive memory. Eventually, this can cause the Java Virtual Machine (JVM) to exhaust its heap, resulting in a Denial of Service (DoS) for the affected server.
Amq Broker
Amq Clients
Camel Quarkus
And others...
CVE-2026-93560 Sep 18, 2026
Netty STOMP codec int truncation can cause DoS A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the maximum integer value. This integer truncation vulnerability could lead to an infinite decode loop, causing a Denial of Service (DoS) by exhausting memory and CPU resources.
Camel Spring Boot
Jboss Fuse
Jboss Enterprise Application Platform
And others...
CVE-2026-93492 Sep 18, 2026
Netty HpackEncoder DoS via oversized SETTINGS MAX_HEADER_TABLE_SIZE A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. This causes the HpackEncoder to store an excessive number of unique headers, leading to increased CPU usage and memory consumption, ultimately resulting in a Denial of Service (DoS).
Amq Broker
Camel Quarkus
Camel Spring Boot
And others...
CVE-2026-93491 Sep 18, 2026
Netty HttpServerCodec DoS via HTTP/1.1 pipelining (before 4.2) A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without limit, leading to unbounded heap memory consumption and a denial of service due to memory exhaustion.
Amq Broker
Amq Clients
Camel Quarkus
And others...
CVE-2026-93488 Sep 18, 2026
Netty SpdySessionHandler Unbounded Streams DoS A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no API to change it. A remote peer can open a SPDY connection and send a large number of SYN_STREAM frames with FLAG_FIN=0, causing unbounded heap and direct memory allocation that can lead to JVM OutOfMemoryError and a denial of service.
Amq Broker
Amq Clients
Camel Quarkus
And others...
CVE-2026-93563 Sep 18, 2026
MemEx DoS via Unbounded Multi-line Response in SmtpResponseDecoder (Apache MINA) A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP server, could exploit this by sending a specially crafted, unbounded multi-line SMTP response without a terminator. This vulnerability leads to unbounded memory accumulation within the client's Java Virtual Machine (JVM) heap, causing an `OutOfMemoryError` and a denial of service (DoS) due to a process crash.
Camel Spring Boot
Jboss Fuse
Jboss Enterprise Application Platform
And others...
CVE-2026-81627 Sep 18, 2026
Privilege Escalation via VAPIC Alias Overflow in QEMU A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM window. A privileged guest user on a Q35/KVM machine can position this alias over locked SMRAM, bypassing chipset D_LCK protection and injecting code into System Management Mode memory.
Enterprise Linux (RHEL)
Enterprise Linux Nvidia
Openshift
And others...
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.