Vulnerabilidades em Red Hat

2.067 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2024-0822HIGHOvirt: authentication bypassEPSS 0.7%CVE-2026-26157HIGHBusybox: busybox: arbitrary file overwrite and potential code execution via incomplete path sanitizationEPSS 0.7%CVE-2026-28367HIGHUndertow: undertow: request smuggling via `\r\r\r` as a header block terminatorEPSS 0.7%CVE-2026-15714MEDIUMLibsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary stringEPSS 0.7%CVE-2026-28368HIGHUndertow: undertow: request smuggling via inconsistent header parsingEPSS 0.7%CVE-2025-10725CRITICALOpenshift-ai: overly permissive clusterrole allows authenticated users to escalate privileges to cluster adminEPSS 0.7%CVE-2020-10727A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plainEPSS 0.7%CVE-2022-4132MEDIUMMemory leak on tls connectionsEPSS 0.7%CVE-2022-4245MEDIUMCodehaus-plexus: xml external entity (xxe) injectionEPSS 0.7%CVE-2023-2585LOWKeycloak: client access via device auth request spoofEPSS 0.7%CVE-2026-4111HIGHLibarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchiveEPSS 0.7%CVE-2024-4369MEDIUMCluster-image-registry-operator: exposes a secret via env variable in pod definition on azureEPSS 0.7%CVE-2023-7090MEDIUMSudo: improper handling of ipa_hostname leads to privilege mismanagementEPSS 0.7%CVE-2019-14866MEDIUMIn all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR arcEPSS 0.7%CVE-2025-13888CRITICALOpenshift-gitops-operator: openshift gitops: namespace admin cluster takeover via privileged jobsEPSS 0.7%CVE-2025-32907MEDIUMLibsoup: denial of service in server when client requests a large amount of overlapping ranges with range headerEPSS 0.7%CVE-2025-2559MEDIUMOrg.keycloak/keycloak-services: jwt token cache exhaustion leading to denial of service (dos) in keycloakEPSS 0.7%CVE-2017-7509LOWAn input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.20-1. If the certreqEPSS 0.7%CVE-2024-8768HIGHVllm: a completions api request with an empty prompt will crash the vllm api server.EPSS 0.7%CVE-2019-3891MEDIUMIt was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the CanEPSS 0.7%