Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Keylime Redhat9Enterprise Linux Enterprise Linux EusEnterprise Linux For Arm 64+6 moreJul 15, 2026 Feb 6, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated client...Show more |
2Gnome Redhat2Enterprise Linux LibsoupJun 17, 2026 Feb 3, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malform...Show more |
1Redhat 1Open Security Issue Management Jun 17, 2026 Jan 29, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0 allows path traversal attacks via query parameters. |
2Gnome Redhat2Enterprise Linux LibsoupJun 17, 2026 Jan 28, 2026 N/A· v4 5.8 MEDIUM· v3 N/A· v2 A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remo...Show more |
2Gnome Redhat2Enterprise Linux LibsoupJun 17, 2026 Jan 28, 2026 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verb...Show more |
2Gnome Redhat2Enterprise Linux LibsoupJun 17, 2026 Jan 27, 2026 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input u...Show more |
3Ibm RedhatXmlsoft7Aix Enterprise LinuxHardened Images+4 moreSep 1, 2026 Jan 15, 2026 N/A· v4 2.9 LOW· v3 N/A· v2 A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A re...Show more |
3Ibm RedhatXmlsoft7Aix Enterprise LinuxHardened Images+4 moreSep 1, 2026 Jan 15, 2026 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A re...Show more |
3Ibm RedhatXmlsoft7Aix Enterprise LinuxHardened Images+4 moreSep 1, 2026 Jan 15, 2026 N/A· v4 3.7 LOW· v3 N/A· v2 A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially c...Show more |
1Redhat 8Build Of Apache Camel Data GridFuse+5 moreSep 7, 2026 Jan 7, 2026 N/A· v4 9.6 CRITICAL· v3 N/A· v2 A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result,...Show more |
2Nodemailer Redhat4Advanced Cluster Management For Kubernetes Ceph StorageDeveloper Hub+1 moreJun 17, 2026 Dec 18, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser. |
2Gnome Redhat3Enterprise Linux GlibOpenshiftSep 1, 2026 Dec 11, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious fil...Show more |
2Gnome Redhat2Enterprise Linux GlibAug 25, 2026 Dec 10, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when pr...Show more |
A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with d...Show more |
2Gnome Redhat29Ceph Storage Codeready Linux BuilderCodeready Linux Builder For Arm64+26 moreAug 31, 2026 Nov 26, 2025 N/A· v4 7.7 HIGH· v3 N/A· v2 A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable character...Show more |
Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument `x-amz-copy-source` to put an object and specifying an empty string as its content leads to the R...Show more |
4Debian IbmRedhat+1 more11Aix Debian LinuxEnterprise Linux+8 moreJul 1, 2026 Oct 30, 2025 N/A· v4 7.3 HIGH· v3 N/A· v2 A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-af...Show more |
4Debian IbmRedhat+1 more11Aix Debian LinuxEnterprise Linux+8 moreJul 1, 2026 Oct 30, 2025 N/A· v4 7.3 HIGH· v3 N/A· v2 A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input...Show more |
1Redhat 8Build Of Apache Camel For Spring Boot Enterprise LinuxFuse+5 moreSep 4, 2026 Sep 2, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to indu...Show more |
A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Injection and unexpectedly send short unwanted e-mails. The email is limited to 64 characters (limited l...Show more |