Vulnerability index

Browse CVEs

812 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Hardened Images HIGH 7.4
CVE-2026-3833

A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically fo…

No fix yet
Fix from $1,950 2026-04-30
Openshift Container Platform CRITICAL 9.1
CVE-2026-33845

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reass…

Mitigation only
Fix from $2,300 2026-04-30
Build Of Keycloak MEDIUM 5.4
CVE-2026-7500

When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the ve…

Mitigation only
Fix from $1,600 2026-04-30
Multicluster Engine For Kubernetes MEDIUM 5.5
CVE-2026-7163

A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allow…

Mitigation only
Fix from $1,600 2026-04-30
Enterprise Linux MEDIUM 5.3
CVE-2026-2708

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-…

No fix yet
Fix from $1,600 2026-04-23
Instructlab HIGH 8.8
CVE-2026-6859

A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace. This allows a r…

Mitigation only
Fix from $1,950 2026-04-22
Instructlab HIGH 7.1
CVE-2026-6855

A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_…

Mitigation only
Fix from $1,950 2026-04-22
Quay HIGH 8.1
CVE-2026-6848

A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot acc…

Mitigation only
Fix from $1,950 2026-04-22
Hardened Images MEDIUM 5.5
CVE-2026-6844

A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by prov…

Mitigation only
Fix from $1,600 2026-04-22
Hardened Images MEDIUM 5.0
CVE-2026-6845

A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS…

Mitigation only
Fix from $1,600 2026-04-22
Openshift Container Platform MEDIUM 5.5
CVE-2026-6843

A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a nam…

Mitigation only
Fix from $1,600 2026-04-22
Enterprise Linux HIGH 7.8
CVE-2026-6384

A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to wri…

Mitigation only
Fix from $1,950 2026-04-15
Enterprise Linux HIGH 7.1
CVE-2026-40917

A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS i…

Mitigation only
Fix from $1,950 2026-04-15
Enterprise Linux MEDIUM 5.5
CVE-2026-40918

A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due …

Mitigation only
Fix from $1,600 2026-04-15
Enterprise Linux MEDIUM 5.5
CVE-2026-40919

A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a speciall…

Mitigation only
Fix from $1,600 2026-04-15
Enterprise Linux HIGH 7.8
CVE-2026-40915

A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted…

Mitigation only
Fix from $1,950 2026-04-15
Enterprise Linux MEDIUM 5.5
CVE-2026-40916

A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of…

Mitigation only
Fix from $1,600 2026-04-15
Openshift Container Platform MEDIUM 5.5
CVE-2026-6245

A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to …

Mitigation only
Fix from $1,600 2026-04-15
Hardened Images HIGH 7.5
CVE-2026-1584

A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with…

Mitigation only
Fix from $1,950 2026-04-09
Openshift Container Platform HIGH 7.0
CVE-2026-4878

A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` func…

No fix yet
Fix from $1,950 2026-04-09
Mirror Registry For Red Hat Openshift MEDIUM 5.5
CVE-2026-32591

A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy ca…

Mitigation only
Fix from $1,600 2026-04-08
Mirror Registry For Red Hat Openshift HIGH 8.8
CVE-2026-32590

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database u…

Mitigation only
Fix from $1,950 2026-04-08
Mirror Registry For Red Hat Openshift HIGH 7.4
CVE-2026-32589

A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can inter…

Mitigation only
Fix from $1,950 2026-04-08
Mirror Registry For Red Hat Openshift MEDIUM 6.5
CVE-2026-2377

A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to …

Mitigation only
Fix from $1,600 2026-04-08
Mirror Registry For Red Hat Openshift MEDIUM 5.3
CVE-2025-14243

A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and ema…

Mitigation only
Fix from $1,600 2026-04-08
Web Terminal MEDIUM 6.4
CVE-2025-57853

A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd file being created with group-w…

Mitigation only
Fix from $1,600 2026-04-08
Openshift Update Service MEDIUM 6.4
CVE-2025-57854

A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being c…

Mitigation only
Fix from $1,600 2026-04-08
Process Automation Manager MEDIUM 6.4
CVE-2025-58713

A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems from the /etc/passwd file bein…

Mitigation only
Fix from $1,600 2026-04-08
Advanced Cluster Management For Kubernetes MEDIUM 6.7
CVE-2025-57851

A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems from the /etc/passwd file bein…

Mitigation only
Fix from $1,600 2026-04-08
Hardened Images MEDIUM 5.5
CVE-2026-5745

A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_te…

Mitigation only
Fix from $1,600 2026-04-07