Redhat
redhat
5,653 CVEs • 533 products
Products (533)
Click to collapseToggle
Products (533)
Click to collapse
CVEs (5,653)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Freedesktop Redhat2Enterprise Linux UdisksMar 25, 2026 Feb 25, 2026 N/A· v4 7.1 HIGH· v3 N/A· v2 A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instru...Show more |
2Gnome Redhat2Enterprise Linux LibsoupMar 23, 2026 Feb 13, 2026 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build confi...Show more |
2Keylime Redhat9Enterprise Linux Enterprise Linux EusEnterprise Linux For Arm 64+6 moreMar 5, 2026 Feb 6, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated client...Show more |
2Gnome Redhat2Enterprise Linux LibsoupMar 26, 2026 Feb 3, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malform...Show more |
1Redhat 1Open Security Issue Management Mar 10, 2026 Jan 29, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0 allows path traversal attacks via query parameters. |
2Gnome Redhat2Enterprise Linux LibsoupMar 25, 2026 Jan 28, 2026 N/A· v4 5.8 MEDIUM· v3 N/A· v2 A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remo...Show more |
2Gnome Redhat2Enterprise Linux LibsoupMar 25, 2026 Jan 28, 2026 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verb...Show more |
2Gnome Redhat2Enterprise Linux LibsoupMar 25, 2026 Jan 27, 2026 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input u...Show more |
1Redhat 8Build Of Apache Camel Data GridFuse+5 moreMar 18, 2026 Jan 7, 2026 N/A· v4 9.6 CRITICAL· v3 N/A· v2 A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result,...Show more |
2Nodemailer Redhat4Advanced Cluster Management For Kubernetes Ceph StorageDeveloper Hub+1 moreJan 8, 2026 Dec 18, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser. |
2Gnome Redhat3Enterprise Linux GlibOpenshiftJun 2, 2026 Dec 11, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious fil...Show more |
2Gnome Redhat2Enterprise Linux GlibJun 2, 2026 Dec 10, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when pr...Show more |
A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with d...Show more |
2Gnome Redhat29Ceph Storage Codeready Linux BuilderCodeready Linux Builder For Arm64+26 moreJun 2, 2026 Nov 26, 2025 N/A· v4 7.7 HIGH· v3 N/A· v2 A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable character...Show more |
Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument `x-amz-copy-source` to put an object and specifying an empty string as its content leads to the R...Show more |
1Redhat 8Build Of Apache Camel For Spring Boot Enterprise LinuxFuse+5 moreMar 18, 2026 Sep 2, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to indu...Show more |
A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Injection and unexpectedly send short unwanted e-mails. The email is limited to 64 characters (limited l...Show more |
1Redhat 2Enterprise Linux Openshift Container PlatformMay 19, 2026 Jul 28, 2025 N/A· v4 3.7 LOW· v3 N/A· v2 A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as...Show more |
A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-adm...Show more |
1Redhat 2Enterprise Linux Openshift Container PlatformAug 11, 2025 Jul 14, 2025 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code...Show more |