| libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return CVE-2026-71227 | Severity medium |
| libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi's one-shot AIO path CVE-2026-71226 | Severity high |
| libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries CVE-2026-71225 | Severity medium |
| libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data CVE-2026-48864 | Severity high |
| openshift/router: openshift/router: mTLS client certificate spoofing via unstripped X-SSL-Client headers on HTTP frontend CVE-2026-46579 | Severity high |
| axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-44495 | Severity high |
| openshift/router: openshift/router: cloud metadata SSRF via FQDN-typed EndpointSlice bypasses destination validation CVE-2026-42965 | Severity high |
| gnutls: gnutls: Authentication Bypass via NUL Character in Username CVE-2026-42010 | Severity critical |
| gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability CVE-2026-42009 | Severity high |
| gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment CVE-2026-33845 | Severity critical |
| libdm: lvm2: libdm: Denial of Service via uncontrolled recursion in config parser CVE-2026-19617 | Severity medium |
| tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite CVE-2026-18508 | Severity medium |
| tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape CVE-2026-18477 | Severity medium |
| p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing CVE-2026-13757 | Severity medium |
| libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing CVE-2026-5121 | Severity high |
| polkit: Polkit: Denial of Service via unbounded input processing through standard input CVE-2026-4897 | Severity medium |
| libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() CVE-2026-4878 | Severity high |
| libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing CVE-2026-4424 | Severity high |
| samba: Remote Code Execution in SAMR CVE-2026-4408 | Severity critical |
| gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison CVE-2026-3833 | Severity high |
| gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response CVE-2026-3832 | Severity low |
| samba: group policy certificate enrollment uses http:// without validation CVE-2026-3012 | Severity high |
| samba: vfs_worm does not block directory modification CVE-2026-2340 | Severity medium |
| samba: Missing access check on reparse point operations CVE-2026-1933 | Severity high |
| ose-cluster-ingress-operator: Remote Code Execution Through HAProxy Configuration Injection CVE-2026-1784 | Severity high |
| libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling CVE-2025-6170 | Severity low |
| libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 CVE-2025-6021 | Severity high |
| libarchive: Double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c CVE-2025-5914 | Severity high |
| rsync: Info Leak via Uninitialized Stack Contents CVE-2024-12085 | Severity high |
| A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a… CVE-2024-1635 | Severity high |
| An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of… CVE-2023-6563 | Severity high |
| A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A… CVE-2023-6291 | Severity high |
| A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This… CVE-2023-6134 | Severity medium |