Vulnerabilities in RED HAT
2,130 resultsVexday analysis
Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.
CVE-2026-15154MEDIUMGuardrails-detectors: guardrails-detectors: unauthenticated regular-expression denial of service (redos) via detector_params.regexEPSS 0.5%CVE-2026-32591MEDIUMMirror-registry: quay: server-side request forgery in proxy cache upstream registry configurationEPSS 0.5%CVE-2026-9792MEDIUMKeycloak: keycloak: security restriction bypass allows unauthorized ropc token acquisitionEPSS 0.5%CVE-2026-0992LOWLibxml2: libxml2: denial of service via crafted xml catalogsEPSS 0.5%CVE-2026-9705MEDIUMKeycloak: keycloak: attacker can re-enable and take over disabled clients via registration access tokenEPSS 0.5%CVE-2026-12382HIGHAap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofingEPSS 0.5%CVE-2026-58216MEDIUMSamba: kpasswd service: kpasswd packet that contains malformed asn.1 might cause the server to access 6 bytes of unallocated memory leading server to crashEPSS 0.5%CVE-2023-3745MEDIUMImagemagick: heap-buffer-overflow in pushcharpixel() in quantum-private.hEPSS 0.5%CVE-2026-74243MEDIUMQuay: unauthenticated secscan notification endpoint in quay when psk is unsetEPSS 0.5%CVE-2026-93576HIGHIo.netty/netty-codec-smtp: netty netty-codec-smtp — smtp command-name field is not crlf-validated (incomplete fix of cve-2025-59419)EPSS 0.5%CVE-2026-96276MEDIUMFlatpak: flatpak: arbitrary write in host context via flatpak build-initEPSS 0.5%CVE-2020-27792HIGHGhostscript: heap buffer over write vulnerability in ghostscript's lp8000_print_page() in gdevlp8k.cEPSS 0.5%CVE-2025-9640MEDIUMSamba: vfs_streams_xattr uninitialized memory write possibleEPSS 0.5%CVE-2025-12801MEDIUMNfs-utils: rpc.mountd in the nfs-utils privilege escalationEPSS 0.5%CVE-2026-1529HIGHOrg.keycloak.services.resources.organizations: keycloak: unauthorized organization registration via improper invitation token validationEPSS 0.5%CVE-2026-15561HIGHUndertow-core: oom via missing limits in chunked trailer in eap's undertowEPSS 0.5%CVE-2023-43786MEDIUMLibx11: stack exhaustion from infinite recursion in putsubimage()EPSS 0.5%CVE-2021-4472MEDIUMPython-mistralclient: mistral-dashboard: local file inclusion through the 'create workbook' featureEPSS 0.5%CVE-2026-18382MEDIUMProject-koku/koku-metrics-operator: koku-metrics-operator: service-account client credentials sent to user-controlled token_urlEPSS 0.5%CVE-2025-6020HIGHLinux-pam: linux-pam directory traversalEPSS 0.5%