Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-42271 KEVEPSS 83%
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints use…
Openshift Ai
1.83.7 / 2.25.8+
CRITICAL 9.8
CVE-2026-42010
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL ch…
Hardened Images
Mitigation only
CRITICAL 9.1
CVE-2026-34000
A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()…
Enterprise Linux
Mitigation only
CRITICAL 9.1
CVE-2026-34002
A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An a…
Enterprise Linux
Mitigation only
HIGH 7.4
CVE-2026-3833
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically fo…
Hardened Images
No fix yet
CRITICAL 9.1
CVE-2026-33845
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reass…
Openshift Container Platform
Mitigation only
MEDIUM 5.4
CVE-2026-7500
When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the ve…
Build Of Keycloak
Mitigation only
MEDIUM 5.5
CVE-2026-7163
A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allow…
Multicluster Engine For Kubernetes
Mitigation only
HIGH 7.5
CVE-2026-6732
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document …
Hardened Images
2.15.3 / 4.1.1.30+
MEDIUM 5.3
CVE-2026-2708
A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-…
Enterprise Linux
No fix yet
HIGH 8.8
CVE-2026-6859
A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace. This allows a r…
Instructlab
Mitigation only
HIGH 7.1
CVE-2026-6855
A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_…
Instructlab
Mitigation only
HIGH 8.1
CVE-2026-6848
A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot acc…
Quay
Mitigation only
HIGH 7.8
CVE-2026-6846
A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Form…
Hardened Images
after 2.46
MEDIUM 5.5
CVE-2026-6844
A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by prov…
Hardened Images
Mitigation only
MEDIUM 5.0
CVE-2026-6845
A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS…
Hardened Images
Mitigation only
MEDIUM 5.5
CVE-2026-6843
A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a nam…
Openshift Container Platform
Mitigation only
HIGH 7.8
CVE-2026-6384
A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to wri…
Enterprise Linux
Mitigation only
HIGH 7.1
CVE-2026-40917
A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS i…
Enterprise Linux
Mitigation only
MEDIUM 5.5
CVE-2026-40918
A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due …
Enterprise Linux
Mitigation only
MEDIUM 5.5
CVE-2026-40919
A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a speciall…
Enterprise Linux
Mitigation only
HIGH 7.8
CVE-2026-40915
A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted…
Enterprise Linux
Mitigation only
MEDIUM 5.5
CVE-2026-40916
A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of…
Enterprise Linux
Mitigation only
MEDIUM 5.5
CVE-2026-6245
A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to …
Openshift Container Platform
Mitigation only
HIGH 7.8
CVE-2026-1462
A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded durin…
Openshift Ai
2.25.7+
CRITICAL 9.9
CVE-2026-5483
A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows…
Openshift Ai
2.16.4 / 2.25.4+
HIGH 7.5
CVE-2026-1584
A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with…
Hardened Images
Mitigation only
HIGH 7.0
CVE-2026-4878
A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` func…
Openshift Container Platform
No fix yet
MEDIUM 5.5
CVE-2026-32591
A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy ca…
Mirror Registry For Red Hat Openshift
Mitigation only
HIGH 8.8
CVE-2026-32590
A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database u…
Mirror Registry For Red Hat Openshift
Mitigation only