Vulnerabilidades en RED HAT

2125 resultados
Análisis Vexday

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2026-93573MEDIUMIo.netty/netty-codec-http: netty split transfer-encoding fields bypass final-chunked validation and enable request smugglingEPSS 0.6%CVE-2026-10090CRITICALMulticluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscriptionEPSS 0.6%CVE-2026-93562MEDIUMIo.netty/netty-codec-http: netty: incomplete validation of malformed transfer-encoding allows http request smugglingEPSS 0.6%CVE-2026-9794MEDIUMKeycloak: keycloak: information disclosure via saml ecp endpointEPSS 0.6%CVE-2026-6266HIGHAap-controller: aap-gateway: account hijacking and unauthorized access via unverified email linkingEPSS 0.6%CVE-2025-6035MEDIUMGimp: gimp integer overflowEPSS 0.6%CVE-2023-4918HIGHPlaintext storage of user passwordEPSS 0.6%CVE-2020-14330MEDIUMAn Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content aEPSS 0.6%CVE-2025-46421MEDIUMLibsoup: information disclosure may leads libsoup client sends authorization header to a different host when being redirected by a serverEPSS 0.6%CVE-2025-5351MEDIUMLibssh: double free vulnerability in libssh key export functionsEPSS 0.6%CVE-2026-95508HIGHLibslirp: libslirp: heap buffer overflow in dhcpv6/tftp response builders on small interface mtuEPSS 0.6%CVE-2026-42011HIGHGnutls: gnutls: security bypass due to incorrect name constraint handlingEPSS 0.6%CVE-2026-37982MEDIUMKeycloak: org.keycloak.authentication: keycloak: unauthorized account takeover via webauthn token replayEPSS 0.6%CVE-2023-5455MEDIUMIpa: invalid csrf protectionEPSS 0.6%CVE-2024-5148HIGHGnome-remote-desktop: inadequate validation of session agents using d-bus methods may expose rdp tls certificateEPSS 0.6%CVE-2023-1672MEDIUMRace condition exists in the key generation and rotation functionalityEPSS 0.6%CVE-2026-9149MEDIUMLibsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv fileEPSS 0.6%CVE-2026-59848MEDIUMLibssh: libssh: denial of service via sftp responses with unknown request idsEPSS 0.6%CVE-2026-17107HIGHCluster-proxy: impersonation-header injection grants cluster-admin on every managed clusterEPSS 0.6%CVE-2026-59847MEDIUMLibssh: libssh: integrity downgrade via openssl aes-gcm tag verificationEPSS 0.6%