VYPR

Vendor CVEs

Red Hat

All CVEs

6,464 total · sorted by risk
  • CVE-2026-18212HigSep 16, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom DEFLATE compression and decompression helpers fail to release native zlib memory after use. An unauthenticated…

  • CVE-2026-88770MedSep 10, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue occurs because the token redemption process fails to check if a user account is currently locked due to brute-force protection. If an attacker has an active…

  • CVE-2026-87853HigSep 9, 2026
    risk 0.42cvss 7.5epss 0.00

    A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP…

  • CVE-2026-18355HigSep 7, 2026
    risk 0.42cvss 7.5epss 0.01

    A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an…

  • CVE-2026-86332MedSep 7, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any…

  • CVE-2026-82968MedSep 2, 2026
    risk 0.42cvss 6.4epss 0.00

    A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generated is not strictly bound to the specific upstream identity being verified. This…

  • CVE-2026-84470MedSep 1, 2026
    risk 0.42cvss 6.4epss 0.00

    A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard single-job launch path requires use-level…

  • CVE-2026-11873MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating…

  • CVE-2026-78701MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a connection to stall, leading to resource…

  • CVE-2026-73199MedAug 20, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending a malformed Lightweight Directory Access Protocol (LDAP) extended operation. By omitting the request value for the `JOIN_OID` in…

  • CVE-2026-66780MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters'…

  • CVE-2026-74243MedAug 14, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint. This allows the attacker to flood the notification queue and inject path…

  • CVE-2026-71846MedAug 12, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive privilege means that a compromise of the…

  • CVE-2026-64927MedAug 12, 2026
    risk 0.42cvss 6.4epss 0.00

    A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system (namespaces). By exploiting this, an…

  • CVE-2026-15565HigAug 11, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service attack without authentication and using only a…

  • CVE-2026-19391MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in…

  • CVE-2026-24330MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. This is achieved by leveraging WildFly libraries to craft a Java project that allows an HTTP POST request to…

  • CVE-2026-16456MedAug 10, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the `loadSecret` function. This function improperly reads the Secret namespace from user-controlled input without validation. This…

  • CVE-2026-18967MedAug 6, 2026
    risk 0.42cvss 6.4epss 0.00

    A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a…

  • CVE-2026-16100MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs,…

  • CVE-2026-18573MedAug 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements on confidential clients. Due…

  • CVE-2026-18572MedAug 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request…

  • CVE-2026-18208MedJul 31, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential client, configured to receive…

  • CVE-2026-18203MedJul 31, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify group membership. This allows a…

  • CVE-2026-18207MedJul 29, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a…

  • CVE-2026-16313HigJul 28, 2026
    risk 0.42cvss 7.6epss 0.00

    A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary…

  • CVE-2026-17059MedJul 24, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when…

  • CVE-2026-16445HigJul 21, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module.…

  • CVE-2026-59844MedJul 21, 2026
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.

  • CVE-2026-59843MedJul 21, 2026
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.

  • CVE-2026-62147MedJul 13, 2026
    risk 0.42cvss 6.5epss 0.00

    The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.

  • CVE-2026-15154MedJul 8, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detection API. This can cause…

  • CVE-2025-12799MedJul 7, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow, a server might be vulnerable to improper input handling.

  • CVE-2026-14324MedJul 1, 2026
    risk 0.42cvss 6.5epss 0.00

    RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.

  • CVE-2026-58016HigJun 30, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property`…

  • CVE-2026-4629MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role mapper into any client. This action allows the user to bypass existing scope restrictions and inject the `realm-admin` role into…

  • CVE-2026-12388MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is mapped to Keycloak users. An administrator with limited permissions to manage identity providers can exploit this flaw by creating…

  • CVE-2026-14164HigJun 30, 2026
    risk 0.42cvss 7.5epss 0.00

    A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can…

  • CVE-2026-13318MedJun 26, 2026
    risk 0.42cvss 6.4epss 0.00

    A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualMachineInstance (VMI), virt-api reads the target IP from vmi.Status.Interfaces[0].IP and passes it directly to net.Dial() without…

  • CVE-2026-12993MedJun 26, 2026
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. An attacker with artifact-write permission can upload XML documents with internal…

  • CVE-2026-9705MedJun 25, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled. This bypasses security controls,…

  • CVE-2026-13208MedJun 24, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from the request body without validating it against the connection's origin. Each virt-launcher pod…

  • CVE-2026-11820MedJun 23, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the Vonage/Nexmo SMS API by encoding API credentials (api_key and api_secret) into URL query parameters and sending them via GET requests. This causes credentials…

  • CVE-2023-54365HigJun 23, 2026
    risk 0.42cvss 7.5epss 0.01

    Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create…

  • CVE-2026-11884MedJun 10, 2026
    risk 0.42cvss 6.5epss 0.00

    A heap buffer overflow flaw was found in 389 Directory Server. When serializing objectclass definitions, the oc_superior (SUP) field length is omitted from buffer size calculations in read_schema_dse() and schema_oc_to_string(), but the field is still written via strcat(). An…

  • CVE-2026-11611MedJun 8, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service. Additional race conditions in plugin thread lifecycle can cause…

  • CVE-2026-7507HigMay 19, 2026
    risk 0.42cvss 7.5epss 0.01

    A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim into visiting a maliciously crafted link. By leveraging the…

  • CVE-2026-7307HigMay 19, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS)…

  • CVE-2026-42009HigMay 18, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate…

  • CVE-2026-33845HigApr 30, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of…

Page 46 of 130