Vulnerabilidades em RED HAT
2.125 resultadosAnálise Vexday
Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.
CVE-2026-93569HIGHIo.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated to http/2 :authority, overriding the request-target authorityEPSS 0.7%CVE-2026-15218HIGHModels-as-a-service: red hat openshift ai: maas-api and maas-controller serviceaccounts with excessive permissions lead to privilege escalationEPSS 0.7%CVE-2020-10727—A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plainEPSS 0.7%CVE-2019-3872MEDIUMIt was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x anEPSS 0.7%CVE-2022-4132MEDIUMMemory leak on tls connectionsEPSS 0.7%CVE-2025-2559MEDIUMOrg.keycloak/keycloak-services: jwt token cache exhaustion leading to denial of service (dos) in keycloakEPSS 0.7%CVE-2026-71475MEDIUMInsights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url pathEPSS 0.7%CVE-2022-4245MEDIUMCodehaus-plexus: xml external entity (xxe) injectionEPSS 0.7%CVE-2023-2585LOWKeycloak: client access via device auth request spoofEPSS 0.7%CVE-2025-13888CRITICALOpenshift-gitops-operator: openshift gitops: namespace admin cluster takeover via privileged jobsEPSS 0.7%CVE-2026-66792CRITICALMulticloud-operators-subscription: multicloud-operators-subscription: isclusteradmin() trusts user-settable annotations on managed clustersEPSS 0.7%CVE-2026-14450CRITICALMaas-billing: maas api: privilege escalation via forged http headers due to missing authenticationEPSS 0.7%CVE-2024-4369MEDIUMCluster-image-registry-operator: exposes a secret via env variable in pod definition on azureEPSS 0.7%CVE-2023-7090MEDIUMSudo: improper handling of ipa_hostname leads to privilege mismanagementEPSS 0.7%CVE-2019-14866MEDIUMIn all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR arcEPSS 0.7%CVE-2024-8447MEDIUMNarayana: deadlock via multiple join requests sent to lra coordinatorEPSS 0.7%CVE-2025-32907MEDIUMLibsoup: denial of service in server when client requests a large amount of overlapping ranges with range headerEPSS 0.7%CVE-2026-11774HIGH389-ds-base: 389-ds-base: integer overflow in sasl packet length bypasses size limit leading to heap buffer overflowEPSS 0.7%CVE-2024-8768HIGHVllm: a completions api request with an empty prompt will crash the vllm api server.EPSS 0.7%CVE-2019-3891MEDIUMIt was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the CanEPSS 0.7%