Vulnerabilities in RED HAT
2,125 resultsVexday analysis
Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.
CVE-2026-28369HIGHUndertow: undertow: request smuggling via malformed http request headersEPSS 0.9%CVE-2024-1139HIGHCluster-monitoring-operator: credentials leakEPSS 0.9%CVE-2023-6681MEDIUMJwcrypto: denail of service via specifically crafted jweEPSS 0.9%CVE-2026-15709HIGHSoupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of serviceEPSS 0.9%CVE-2026-4111HIGHLibarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchiveEPSS 0.9%CVE-2023-2974MEDIUMQuarkus-core: tls protocol configured with quarkus.http.ssl.protocols is not enforced, client can enforce weaker supported tls protocolEPSS 0.9%CVE-2019-10207MEDIUMA flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attackEPSS 0.9%CVE-2026-5367HIGHOvn: ovn: information disclosure via crafted dhcpv6 packetsEPSS 0.9%CVE-2025-4969MEDIUMLibsoup: off-by-one out-of-bounds read in find_boundary() in soup-multipart.cEPSS 0.9%CVE-2024-0914MEDIUMOpencryptoki: timing side-channel in handling of rsa pkcs#1 v1.5 padded ciphertexts (marvin)EPSS 0.9%CVE-2020-1741MEDIUMA flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed originEPSS 0.9%CVE-2026-56211HIGHLibaom: libaom: remote code execution via svc layer context handling with attacker-controlled framesEPSS 0.9%CVE-2019-3889MEDIUMA reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprisEPSS 0.9%CVE-2025-5449MEDIUMLibssh: integer overflow in libssh sftp server packet length validation leading to denial of serviceEPSS 0.9%CVE-2026-73268CRITICALCluster-curator-controller: cluster-curator-controller: spec.install.overridejob allows arbitrary job spec injectionEPSS 0.9%CVE-2026-0603HIGHOrg.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injectionEPSS 0.9%CVE-2025-23368HIGHOrg.wildfly.core:wildfly-elytron-integration: wildfly elytron brute force attack via cliEPSS 0.9%CVE-2023-5557HIGHTracker-miners: sandbox escapeEPSS 0.9%CVE-2026-7307HIGHKeycloak: keycloak: denial of service via specially crafted saml inputEPSS 0.9%CVE-2026-93491HIGHIo.netty/netty-codec-http: netty: denial of service via unbounded httpservercodec http/1.1 pipeline queueEPSS 0.9%