Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · redhat

redhat

· 268 Critical

Total CVEs

5,950

Critical

268

Products

540

Search All CVEs →

5,950

Products (540)

enterprise linux2,166 CVEsenterprise linux desktop1,947 CVEsenterprise linux server1,914 CVEsenterprise linux workstation1,850 CVEsenterprise linux server aus1,062 CVEsenterprise linux eus789 CVEsenterprise linux server tus770 CVEsenterprise linux server eus625 CVEsopenshift container platform306 CVEslinux252 CVEsjboss enterprise application platform243 CVEssatellite228 CVEsopenstack213 CVEsopenshift181 CVEsenterprise linux hpc node149 CVEssoftware collections137 CVEsvirtualization129 CVEsenterprise linux for ibm z systems114 CVEssingle sign-on110 CVEsenterprise linux for power little endian108 CVEskeycloak99 CVEsenterprise linux for power little endian eus95 CVEsenterprise linux for ibm z systems eus89 CVEsenterprise linux workstation supplementary86 CVEsvirtualization host84 CVEsenterprise linux server supplementary84 CVEsenterprise linux desktop supplementary84 CVEsenterprise linux hpc node eus83 CVEsenterprise linux server supplementary eus83 CVEsfedora core81 CVEslibvirt73 CVEsenterprise mrg73 CVEsenterprise linux for scientific computing71 CVEslinux advanced workstation71 CVEsansible tower64 CVEsenterprise linux server for power little endian update services for sap solutions63 CVEsenterprise linux kernel-based virtual machine57 CVEscloudforms48 CVEsenterprise linux aus46 CVEsenterprise linux for arm 6446 CVEsansible45 CVEsbuild of keycloak45 CVEsceph storage45 CVEsenterprise linux for power big endian45 CVEslinux workstation44 CVEslinux desktop44 CVEslinux server44 CVEsenterprise linux server update services for sap solutions43 CVEsenterprise linux for real time43 CVEscloudforms management engine42 CVEsjboss fuse42 CVEscodeready linux builder41 CVEsundertow40 CVEsopenstack platform39 CVEsenterprise virtualization37 CVEsenterprise linux for real time for nfv37 CVEshardened images37 CVEsenterprise linux for arm 64 eus37 CVEsjboss enterprise web server36 CVEsopenshift application runtimes33 CVEsdirectory server33 CVEsjboss core services33 CVEsstorage31 CVEsquay30 CVEsfuse29 CVEsenterprise linux update services for sap solutions27 CVEsfedora27 CVEsgluster storage26 CVEsansible automation platform25 CVEsansible engine25 CVEsjboss data grid25 CVEsjboss operations network24 CVEsprocess automation24 CVEsopenshift container platform for power23 CVEsjboss enterprise brms platform23 CVEsenterprise linux tus23 CVEsenterprise linux for real time for nfv tus22 CVEsjboss enterprise portal platform22 CVEsopenshift service mesh21 CVEsenterprise linux for real time tus21 CVEsbuild of quarkus21 CVEsdata grid21 CVEsjboss enterprise web platform21 CVEscodeready linux builder eus20 CVEsdecision manager20 CVEsintegration camel k20 CVEsenterprise linux for power big endian eus20 CVEscertificate system19 CVEsjboss enterprise application platform expansion pack19 CVEsenterprise virtualization manager19 CVEsjboss bpm suite18 CVEscodeready linux builder for ibm z systems eus18 CVEscodeready linux builder for arm64 eus18 CVEsresteasy18 CVEswildfly18 CVEsjboss enterprise soa platform17 CVEsopenshift container platform for linuxone17 CVEscodeready linux builder for power little endian eus17 CVEsjboss a-mq17 CVEsceph17 CVEscodeready linux builder for power little endian16 CVEscodeready linux builder for ibm z systems16 CVEsdeveloper tools15 CVEs389 directory server15 CVEsautomatic bug reporting tool14 CVEssatellite capsule14 CVEscloudforms 3.0 management engine13 CVEscodeready linux builder for arm6413 CVEsvirtualization manager13 CVEs3scale api management12 CVEsspacewalk12 CVEsadvanced cluster management for kubernetes12 CVEsenterprise linux server from rhui12 CVEssubscription asset manager11 CVEsopenshift container platform for ibm z10 CVEsicedtea-web10 CVEsnetwork satellite10 CVEsopenshift origin10 CVEsovirt-engine10 CVEsshim10 CVEsmrg realtime9 CVEscertification9 CVEsopenssl9 CVEsjboss middleware text-only advisories9 CVEsjboss wildfly application server9 CVEsansible inside9 CVEsansible developer9 CVEsspacewalk-java9 CVEsicedtea9 CVEsdescision manager9 CVEsenterprise linux hpc node supplementary9 CVEs3scale8 CVEsopenshift container platform ibm z systems8 CVEsopenshift container platform for arm648 CVEscodeready linux builder eus for power little endian eus8 CVEsjboss brms8 CVEsintegration camel quarkus8 CVEsintegration service registry7 CVEsdesktop7 CVEspagure7 CVEsconga7 CVEsenterprise linux compute node eus7 CVEsupdate infrastructure7 CVEsenterprise linux for ibm z systems eus s390x7 CVEsdogtag certificate system7 CVEsgluster storage server for on-premise7 CVEsjboss middleware6 CVEsenterprise linux resilient storage6 CVEsrichfaces6 CVEsamq6 CVEsjboss portal6 CVEstcpdump6 CVEswildfly core6 CVEsadvanced cluster security6 CVEsenterprise linux server supplementary aus6 CVEsicedtea66 CVEsbuild of apache camel for spring boot6 CVEsenterprise linux fast datapath5 CVEsautomation manager5 CVEsbuild of apache camel - hawtio5 CVEsceph storage mon5 CVEsceph storage osd5 CVEscodeready linux builder eus for power little endian5 CVEscodeready studio5 CVEsdiscovery5 CVEsedeploy5 CVEsenterprise linux atomic host5 CVEsenterprise linux eus compute node5 CVEsenterprise virtualization hypervisor5 CVEsetcd5 CVEsfreeipa5 CVEshibernate validator5 CVEsjboss application server5 CVEsjboss data virtualization5 CVEsjboss web server5 CVEslibnbd5 CVEsmirror registry for red hat openshift5 CVEsopenshift container platform for ibm linuxone5 CVEsopenshift developer tools and services5 CVEsopenstack for ibm power5 CVEsprocess automation manager5 CVEssatellite with embedded oracle5 CVEsopenshift data science4 CVEskvm4 CVEsopenshift virtualization4 CVEswildfly elytron4 CVEsspice-xpi4 CVEsstorage for public cloud4 CVEsevince4 CVEsnetwork satellite server4 CVEsjboss seam 2 framework4 CVEsjboss web framework kit4 CVEsmessaging realtime grid4 CVEsjbpm4 CVEsenterprise linux virtualization4 CVEsmigration toolkit for applications4 CVEskdebase4 CVEsenterprise linux server workstation4 CVEsopenshift serverless4 CVEsenterprise linux high availability4 CVEssingle sign on4 CVEsenterprise linux openstack platform4 CVEskexec-tools4 CVEsmobile application platform4 CVEsquickstart cloud installer4 CVEsopenshift data foundation3 CVEsrkt3 CVEsopenshift gitops3 CVEsmanageiq enterprise virtualization manager3 CVEsinterchange3 CVEsansible runner3 CVEsopenstack essex3 CVEsenterprise linux desktop workstation3 CVEsmod cluster3 CVEslinux powertools3 CVEsopenshift ai3 CVEsopenshift api for data protection3 CVEssos3 CVEsenterprise linux long life3 CVEsjboss enterprise application platform text-only advisories3 CVEs3scale api management platform3 CVEsvirtio-win3 CVEsservice interconnect3 CVEsintegration camel for spring boot3 CVEskdelibs3 CVEsjboss aerogear3 CVEscluster suite3 CVEsfast datapath3 CVEsdrools3 CVEsmigration toolkit for runtimes3 CVEsamq online3 CVEsstorage console3 CVEshornetq3 CVEsjboss fuse service works3 CVEsrhevm-reports3 CVEscman3 CVEsjboss community application server3 CVEsopenshift container storage3 CVEssubscription-manager3 CVEsamq broker3 CVEskernel3 CVEsjboss business rules management system3 CVEsopenstack-mistral3 CVEsenterprise linux for ibm z systems s390x3 CVEsjboss enterprise application platform continuous delivery3 CVEsenterprise linux ai2 CVEsfedora directory server2 CVEsvirtual desktop server manager2 CVEsjboss amq clients2 CVEsvirtualization for ibm power little endian2 CVEsopenshift dev spaces2 CVEsvirtualization server2 CVEsenterprise linux high availability eus2 CVEskernel-rt2 CVEscert-manager operator for red hat openshift2 CVEsenterprise linux for x86 64 eus2 CVEsenterprise linux server from rhui 62 CVEsenterprise linux for x86 642 CVEsenterprise linux server eus from rhui2 CVEsa-mq streams2 CVEsxnio2 CVEsopenshift distributed tracing2 CVEsdeveloper hub2 CVEsjboss communications platform2 CVEsopenshift pipelines2 CVEsdesktop workstation2 CVEsjboss core services httpd2 CVEsweb terminal2 CVEslha2 CVEswindows machine config operator2 CVEslibpng2 CVEsopenstack folsom2 CVEshivex2 CVEsjboss drools2 CVEsbuild of optaplanner2 CVEslibuser2 CVEsovirt-node2 CVEspackstack2 CVEsbodhi2 CVEscloudforms cloud engine2 CVEsenterprise linux for ibm z systems \(structure a\)2 CVEscloudforms 3.1 management engine2 CVEscloudforms 3.0.5 management engine2 CVEsqspice2 CVEscloudforms 3.0.4 management engine2 CVEslogging subsystem for red hat openshift2 CVEscygwin2 CVEsredhat package manager2 CVEsenterprise linux advanced virtualization eus2 CVEsicedtea72 CVEsluci2 CVEsrhn-client-tools2 CVEscoreos-installer2 CVEsapicast2 CVEsjboss enterprise web server text-only advisories2 CVEssatellite 5 managed db2 CVEsmigration toolkit2 CVEsansible collection2 CVEsmirror registry2 CVEsinstructlab2 CVEsenterprise virtualization host2 CVEsansible automation platform early access2 CVEscloudforms 3.0.3 management engine2 CVEscodeready linux builder for x86 64 eus2 CVEsenterprise linux advanced virtualization2 CVEsgluster storage management console2 CVEsnetwork proxy2 CVEsjboss remoting2 CVEscloudforms 3.0.2 management engine2 CVEsstorage native client2 CVEsstorage server2 CVEsstronghold2 CVEssysreport2 CVEssysstat2 CVEsjboss soa platform2 CVEsfedora 82 CVEstectonic2 CVEsnoobaa-operator2 CVEsjboss-ejb-client2 CVEsjboss-remoting2 CVEscloudforms 3.0.1 management engine2 CVEstuned2 CVEsopenshift update service1 CVEscairo1 CVEsbusiness-central1 CVEsopenstack-cinder1 CVEsopenstack-selinux1 CVEsxpaas1 CVEsopenstack foreman1 CVEsorigin-aggregated-logging1 CVEsbuild of apache camel1 CVEspackage manager1 CVEspam smb1 CVEspolicycoreutils1 CVEspolicykit1 CVEspre-execution environment1 CVEsbigmem kernel1 CVEsyum-rhn-plugin1 CVEsbeaker1 CVEsred hat developer hub1 CVEsredhat-upgrade-tool1 CVEsredhat directory server1 CVEsapplication stack1 CVEsrgmanager1 CVEsrhevm-dwh1 CVEsrhmask1 CVEsrhncfg1 CVEsrhnsd1 CVEsrhq mongo db drift server1 CVEsrsync1 CVEsrun once duration override operator1 CVEsansible galaxy1 CVEszanata1 CVEsself node remediation operator1 CVEssendmail1 CVEsservice telemetry framework1 CVEsservicemesh-operator1 CVEssetup1 CVEsansible automation platform text-only advisories1 CVEsslapi-nis1 CVEssmallrye config1 CVEssmallrye health1 CVEssoftware collection1 CVEssoteria1 CVEssource-to-image1 CVEsansible automation controller1 CVEsanalog real-time synthesizer1 CVEsspacewalk-web1 CVEsspice-activex1 CVEsstorage console node1 CVEsstorage management console1 CVEssupport for spring boot1 CVEssyndesis1 CVEssystem-config-firewall1 CVEssystem-config-printer1 CVEsai inference server1 CVEstemplate service broker operator1 CVEsthermostat1 CVEstmpwatch1 CVEstrusted artifact signer1 CVEstrusted profile analyzer1 CVEsuberfire1 CVEsaeolus conductor1 CVEsup2date1 CVEsadvanced workstation for the itanium processor1 CVEsvdsclient1 CVEsvirt-bootstrap1 CVEsvirt-manager1 CVEsvirtual desktop service manager1 CVEsadminutil1 CVEsvirtualization eus1 CVEsvirtualization host eus1 CVEsa-mq online1 CVEsenterprise linux load balancer1 CVEsenterprise linux for x86 64 update services for sap solutions1 CVEsenterprise linux resilient storage eus1 CVEsenterprise linux for x86 64 els1 CVEsenterprise linux server for ibm z systems1 CVEsenterprise linux server for power little endian1 CVEsenterprise linux for real time for nfv eus1 CVEsenterprise linux server for power little endian eus1 CVEsenterprise linux for real time eus1 CVEsenterprise linux server long life1 CVEsenterprise linux for power little endian els1 CVEsenterprise linux for ibm z systems els1 CVEsenterprise linux for ibm z systems 8 s390x1 CVEsenterprise linux supplementary1 CVEsenterprise linux for arm 64 els1 CVEsenterprise linux for arm64 eus1 CVEsenterprise linux worksation1 CVEsenterprise linux for arm64 els1 CVEsenterprise linux for arm641 CVEsenterprise linux els1 CVEsvscode-xml1 CVEsenterprise linux dekstop1 CVEsenterprise virtualization server1 CVEsvsftpd1 CVEsfabric8-kubernetes1 CVEsfabric8-maven1 CVEsenterprise linux computer node1 CVEsfedora coreos1 CVEsfeedhenry enterprise mobile application platform1 CVEsfence agents remediation operator1 CVEsfrysk1 CVEsgatekeeper1 CVEsgdk pixbuf1 CVEsgfs2-utils1 CVEsgluster-block1 CVEsgluster file system1 CVEsgluster storage server1 CVEsenterprise linux optional productivity applications1 CVEsgoogle cloud platform ansible collection1 CVEshal management console1 CVEsenterprise ipa1 CVEshawtjni1 CVEs dogtag certificate system1 CVEsenmasse1 CVEsdtach1 CVEsignition1 CVEsin-vehicle operating system1 CVEsinitscripts1 CVEsinsights-client1 CVEsintegration1 CVEsdocker community collection1 CVEsdocker1 CVEsdocbook utils1 CVEsdocbook stylesheets1 CVEsjboss a-mq streaming1 CVEsjboss a-mq streams1 CVEsjboss amq clients 21 CVEsdevice-mapper-multipath1 CVEsddskk-xemacs1 CVEsjboss data virtualization \& services1 CVEsdashbuilder1 CVEsdaredevil skk1 CVEsjboss enterprise data services platform1 CVEscryostat1 CVEsjboss enterprise service bus1 CVEscost management1 CVEscontainer development kit1 CVEscommunity network collection1 CVEsjboss fuse esb enterprise1 CVEsjboss keycloak1 CVEscommunity general collection1 CVEscommunity.general1 CVEsjboss overlord run time governance1 CVEscodeready linux builder for x86 641 CVEswildfly openssl1 CVEsjboss web services1 CVEsjboss weld1 CVEscodeready linux builder for eus1 CVEsjbossweb1 CVEsjbpm-designer1 CVEsjgroups1 CVEskdelibs devel1 CVEskdelibs sound1 CVEskdelibs sound devel1 CVEskernel doc1 CVEskernel source1 CVEskeycloak node.js adapter1 CVEskeycloak operator1 CVEskie-server1 CVEskie workbench1 CVEskroxylicious1 CVEskubeclient1 CVEskubernetes-client1 CVEslanguage support for java1 CVEslibrepo1 CVEslibreport1 CVEscluster project1 CVEslinux as31 CVEslinux as41 CVEslivecd-tools1 CVEslogging subsystem for red hat openshift for arm 641 CVEslogging subsystem for red hat openshift for ibm power little endian1 CVEslogging subsystem for red hat openshift for ibm z and linuxone1 CVEslouketo proxy1 CVEslv1 CVEslvm21 CVEsmachine-config-operator1 CVEsmachine deletion remediation operator1 CVEsmcstrans1 CVEsmigration toolkit for containers1 CVEsmigration toolkit for virtualization1 CVEswu ftpd1 CVEsmodulemd1 CVEsmrg management console1 CVEsmulticluster engine for kubernetes1 CVEsnetwork observability1 CVEsnetwork observability operator1 CVEsnetwork satelite server1 CVEsnetworkmanager1 CVEsnfs utils1 CVEsnode healthcheck operator1 CVEsnode maintenance operator1 CVEsoddjob1 CVEsopen iscsi1 CVEsopen security issue management1 CVEsopenshift-origin-node-util1 CVEsopenshift api management1 CVEsclair1 CVEsopenshift application runtimes text-only advisories1 CVEsopenshift assisted installer1 CVEsopenshift builder1 CVEscisco nx-os collection1 CVEsopenshift container platform assisted installer1 CVEscfme-gemset1 CVEsxerces1 CVEscertification for red hat enterprise linux1 CVEscertificate server1 CVEsceph storage for power1 CVEsopenshift installer1 CVEsopenshift logging1 CVEsopenshift machine-config-operator1 CVEsceph storage for ibm z systems1 CVEsopenshift osin1 CVEsopenshift router1 CVEsopenshift sandboxed containers1 CVEsopenshift secondary scheduler operator1 CVEsceph-iscsi-cli1 CVEs

Recent Vulnerabilities

View all 5,950
CVE-2026-59851HIGH 8.8

A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.

CVE-2026-59850MEDIUM 4.3

A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.

CVE-2026-59849LOW 3.1

A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service.

CVE-2026-59848MEDIUM 5.3

A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.

CVE-2026-59847MEDIUM 5.9

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.

CVE-2026-59846LOW 3.9

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.

CVE-2026-59845MEDIUM 5.3

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.

CVE-2026-59844MEDIUM 6.5

A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.

CVE-2026-59843MEDIUM 6.5

A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.

CVE-2026-59842LOW 3.7

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.

CVE-2026-15370MEDIUM 6.7

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.

CVE-2026-58016HIGH 7.5

A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.

CVE-2026-58015MEDIUM 5.9

A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.

CVE-2026-58014HIGH 7.3

A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.

CVE-2026-58013MEDIUM 6.5

A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.

CVE-2026-58012MEDIUM 6.5

A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.

CVE-2026-58011MEDIUM 6.5

A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.

CVE-2026-58010MEDIUM 6.5

A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.

CVE-2026-4629MEDIUM 6.5

A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role mapper into any client. This action allows the user to bypass existing scope restrictions and inject the `realm-admin` role into generated tokens, resulting in privilege escalation and full administrative access to the realm.

CVE-2026-14209MEDIUM 4.3

A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass security restrictions. When Fine-Grained Admin Permissions (FGAPv2) are enabled, an administrator who should only be able to search for users (but not view their full details) can use a specific "brute-force-user" endpoint to access a user's full profile. This includes sensitive information and security metadata. The issue occurs because the system fails to check if the administrator has the required "view" permission for that specific user when using this particular search path.

CVE-2026-13757MEDIUM 6.2

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

CVE-2026-13601HIGH 7.1

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.

CVE-2026-9800HIGH 8.1

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.

CVE-2026-53006CRITICAL 9.8

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching saddr and daddr before pskb_pull() is problematic since skb->head can change. Remove these temporary variables: - We only access &ipv6_hdr(skb)->saddr and &ipv6_hdr(skb)->daddr when net_dbg_ratelimited() is called in the slow path. - Avoid potential future misuse after pskb_pull() call.

CVE-2026-55655MEDIUM 5.0

A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.