Vulnerabilidades em Red Hat

2.122 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2026-76139HIGHAcm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@master with full build credentialsEPSS 0.4%CVE-2025-32910MEDIUMLibsoup: null pointer deference on libsoup via /auth/soup-auth-digest.c through "soup_auth_digest_authenticate" on client when server omits the "realm" parameter in an unauthorized response with digest authenticationEPSS 0.4%CVE-2025-32912MEDIUMLibsoup: null pointer dereference in client when server omits the "nonce" parameter in an unauthorized response with digest authenticationEPSS 0.4%CVE-2026-5142MEDIUMForeman: foreman: cross-tenant private ssh key disclosure via taxonomy scoping bypassEPSS 0.4%CVE-2024-3567MEDIUMQemu-kvm: net: assertion failure in update_sctp_checksum()EPSS 0.4%CVE-2025-26597HIGHXorg: xwayland: buffer overflow in xkbchangetypesofkey()EPSS 0.4%CVE-2026-18611HIGHData-science-pipelines-operator: dspo: cryptographically weak secret generation (math/rand) for db and s3 credentialsEPSS 0.4%CVE-2026-15416HIGHArgo-cd: argo cd unauthenticated remote code execution in repo-server via generatemanifest grpc endpointEPSS 0.4%CVE-2026-0968LOWLibssh: libssh: denial of service due to malformed sftp messageEPSS 0.4%CVE-2023-32251LOWKernel: ksmbd brute force delay bypass via asynchronous requestsEPSS 0.4%CVE-2026-6859HIGHInstructlab: instructlab: arbitrary code execution due to hardcoded `trust_remote_code=true`EPSS 0.4%CVE-2026-0988LOWGlib: glib: denial of service via integer overflow in g_buffered_input_stream_peek()EPSS 0.4%CVE-2026-3872HIGHKeycloak: keycloak: information disclosure due to redirect_uri validation bypassEPSS 0.4%CVE-2026-37982MEDIUMKeycloak: org.keycloak.authentication: keycloak: unauthorized account takeover via webauthn token replayEPSS 0.4%CVE-2026-85234HIGHTftp: tftp-hpa: denial of service due to out-of-bounds read/write in remap engineEPSS 0.4%CVE-2025-13467MEDIUMOrg.keycloak.storage.ldap: keycloak: deserialization of untrusted data in ldap user federationEPSS 0.4%CVE-2019-3864MEDIUMA vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameteEPSS 0.4%CVE-2025-3501HIGHOrg.keycloak.protocol.services: keycloak hostname verificationEPSS 0.4%CVE-2025-5914HIGHLibarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.cEPSS 0.4%CVE-2026-15574HIGHVllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header and full chat payloads logged at hard-coded debug defaultEPSS 0.4%