Skip to main content

Vendor archive

redhat CVEs

Beta · best-effort

5,981 CVEs tagged to vendor redhat666 Critical, 2,011 High, 2,837 Medium, 467 Low, 0 Unrated.

CVE-2025-57847

Published Apr 8, 2026

A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permis…

CVSS 6.4 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2025-14821

Published Apr 7, 2026

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host info…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-4740

Published Apr 7, 2026

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewa…

CVSS 8.2 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-5673

Published Apr 6, 2026

A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() f…

CVSS 5.6 · Medium
evidence mentions
3
Buzz score
29.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-37977

Published Apr 6, 2026

A flaw was found in Keycloak. A remote attacker can exploit a Cross-Origin Resource Sharing (CORS) header injection vulnerability in Keycloak's User-Managed Access (UMA) token end…

CVSS 3.7 · Low
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2026-3184

Published Apr 3, 2026

A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before set…

CVSS 3.7 · Low
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-4636

Published Apr 2, 2026

A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resour…

CVSS 8.1 · High
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2026-4634

Published Apr 2, 2026

A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to th…

CVSS 7.5 · High
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2026-4325

Published Apr 2, 2026

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an attacker to delete arb…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2026-4282

Published Apr 2, 2026

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attack…

CVSS 7.4 · High
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2026-3872

Published Apr 2, 2026

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers…

CVSS 7.3 · High
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2026-5165

Published Mar 30, 2026

A flaw was found in virtio-win, specifically within the VirtIO Block (BLK) device. When the device undergoes a reset, it fails to properly manage memory, resulting in a use-after-…

CVSS 6.7 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-5164

Published Mar 30, 2026

A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap request. A local user could ex…

CVSS 6.7 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-5119

Published Mar 30, 2026

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNEC…

CVSS 5.9 · Medium
evidence mentions
18
Buzz score
45.9
Vendor/product tagsBeta · best-effort

CVE-2026-28369

Published Mar 27, 2026

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping…

CVSS 8.7 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-28368

Published Mar 27, 2026

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to…

CVSS 8.7 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-28367

Published Mar 27, 2026

A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certai…

CVSS 8.7 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-4948

Published Mar 27, 2026

A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicyS…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort
Showing 176-200 of 5,981 CVEsPage 8 of 240