| gstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsing CVE-2026-73434 | Severity medium |
| gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux FUJIFILM strd parsing leading to out-of-bounds read/write CVE-2026-73433 | Severity medium |
| ipa: FreeIPA: Unauthenticated DoS in `/ipa/i18n_messages` via Unbounded Request Body Read CVE-2026-73198 | Severity high |
| ipa: FreeIPA: Unauthenticated DoS in `/ipa/migration/migration.py` via Unbounded Request Body Read CVE-2026-73197 | Severity high |
| libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return CVE-2026-71227 | Severity medium |
| libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi's one-shot AIO path CVE-2026-71226 | Severity high |
| libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries CVE-2026-71225 | Severity medium |
| gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk CVE-2026-71224 | Severity medium |
| gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing CVE-2026-71222 | Severity medium |
| gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemeta CVE-2026-71221 | Severity high |
| gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_edit CVE-2026-71220 | Severity high |
| gfs2-utils: gfs2-utils: stack overflow via alloca(1<<di_depth) in hash table traversal CVE-2026-71219 | Severity medium |
| gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted FITS images CVE-2026-66758 | Severity high |
| libssh: libssh: denial of service via automatic certificate authentication loop CVE-2026-59849 | Severity high |
| libssh: libssh: information disclosure via short GSSAPI Curve25519 public key CVE-2026-59842 | Severity medium |
| gimp: GIMP: Arbitrary code execution in PSD plugin due to unsigned underflow CVE-2026-59090 | Severity critical |
| gimp: gimp: Integer overflow in read_RLE_channel() CVE-2026-58384 | Severity high |
| gimp: gimp: Double-free in read_layer_block() CVE-2026-58381 | Severity high |
| gimp: gimp: Stack buffer overflow in pnmscanner_gettoken() CVE-2026-58380 | Severity high |
| samba: CTDB fails to do integrity checking of received packets CVE-2026-58224 | Severity medium |
| glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" CVE-2026-58016 | Severity critical |
| glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive CVE-2026-58015 | Severity high |
| glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" CVE-2026-58014 | Severity high |
| glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" CVE-2026-58013 | Severity high |
| glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() CVE-2026-58012 | Severity high |
| glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime CVE-2026-58011 | Severity high |
| glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() CVE-2026-58010 | Severity high |
| openssh: Heap out-of-bounds read in Red Hat Enterprise Linux versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel… CVE-2026-55654 | Severity low |
| abrt: unsanitized systemd journal content written to dump directory files enables content injection CVE-2026-54231 | Severity medium |
| abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites CVE-2026-54230 | Severity high |
| kernel: ipv6: fix possible UAF in icmpv6_rcv() CVE-2026-53006 | Severity critical |
| kernel: netfilter: conntrack: remove sprintf usage CVE-2026-53002 | Severity critical |
| kernel: netfilter: nat: use kfree_rcu to release ops CVE-2026-53000 | Severity high |
| libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data CVE-2026-48864 | Severity high |
| Kludex Starlette HTTP Request/Response Smuggling Vulnerability CVE-2026-48710 | Severity medium Exploited yes |
| openshift/router: openshift/router: mTLS client certificate spoofing via unstripped X-SSL-Client headers on HTTP frontend CVE-2026-46579 | Severity high |
| axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-44495 | Severity high |
| mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() CVE-2026-44172 | Severity critical |
| openshift/router: openshift/router: cloud metadata SSRF via FQDN-typed EndpointSlice bypasses destination validation CVE-2026-42965 | Severity high |
| gimp: GIMP APNG loader heap-buffer-overflow when fcTL width exceeds IHDR width (file-png.c) CVE-2026-42169 | Severity high |
| nginx: NGINX: Arbitrary code execution or Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers CVE-2026-42055 | Severity high |
| gnutls: gnutls: Authentication Bypass via NUL Character in Username CVE-2026-42010 | Severity critical |
| gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability CVE-2026-42009 | Severity high |
| Apache Tomcat Missing Encryption of Sensitive Data Vulnerability CVE-2026-34486 | Severity high Exploited yes |
| gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment CVE-2026-33845 | Severity critical |
| mirror-registry: quay: server-side request forgery in proxy cache upstream registry configuration CVE-2026-32591 | Severity high |
| mirror-registry: quay: insecure direct object reference in BlobUpload CVE-2026-32589 | Severity high |
| undertow: Undertow: Request Smuggling via Malformed HTTP Request Headers CVE-2026-28369 | Severity critical |
| undertow: Undertow: Request smuggling via inconsistent header parsing CVE-2026-28368 | Severity critical |
| undertow: Undertow: Request smuggling via `\r\r\r` as a header block terminator CVE-2026-28367 | Severity critical |
| rsyslog: A configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash… CVE-2026-19654 | Severity high |
| libdm: lvm2: libdm: Denial of Service via uncontrolled recursion in config parser CVE-2026-19617 | Severity medium |
| freeipa: ipa: FreeIPA: trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes CVE-2026-19550 | Severity high |
| keycloak-services: keycloak-services: Client access-type policy condition bypass during client update CVE-2026-18573 | Severity medium |
| keycloak-services: keycloak-services: UMA claim token can override authorization time-policy evaluation attributes CVE-2026-18572 | Severity medium |
| keycloak-services: keycloak-services: FGAP V2 group assignment bypass during user creation CVE-2026-18571 | Severity high |
| keycloak-services: keycloak-services: Full-scope-disabled client policy validation bypass via omitted fullScopeAllowed CVE-2026-18570 | Severity medium |
| tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite CVE-2026-18508 | Severity medium |
| tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape CVE-2026-18477 | Severity medium |
| keycloak-services: keycloak-services: Client not-before revocation ignored when realm not-before is older but nonzero CVE-2026-18218 | Severity medium |
| keycloak-services: keycloak-services: Microsoft external access-token exchange bypasses configured tenant CVE-2026-18215 | Severity high |
| keycloak-services: keycloak-services: Google external access-token exchange bypasses hosted-domain restriction CVE-2026-18214 | Severity high |
| keycloak-services: keycloak-services: OIDC redirect_uri fragment bypass in HTTP parameter pollution check CVE-2026-18209 | Severity medium |
| keycloak-services: keycloak-services: Generic identity-provider creation can bind brokers to organizations without manage-organizations CVE-2026-18201 | Severity medium |
| keycloak-services: keycloak-services: Information disclosure via role-users endpoint bypasses per-user view filter CVE-2026-17059 | Severity medium |
| keycloak-services: keycloak-services: Realm default-group reads disclose hidden groups under FGAP v2 CVE-2026-16108 | Severity medium |
| keycloak-services: keycloak-services: Incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged… CVE-2026-16106 | Severity medium |
| keycloak-services: keycloak-services: Missing per-role authorization on RoleContainerResource composite endpoints CVE-2026-16105 | Severity medium |
| keycloak-services: keycloak-services: Authenticator config endpoint exposes raw reCAPTCHA secrets to view-only admins CVE-2026-16104 | Severity medium |
| keycloak-services: keycloak-services: Required signed-JWT assertion policy can be bypassed with unsigned assertion headers CVE-2026-16093 | Severity medium |
| keycloak-services: keycloak-services: Authorization codes can be retargeted to another client session CVE-2026-16089 | Severity medium |
| keycloak-services: keycloak-services: Organization invitation link exposure allows unauthorized member creation CVE-2026-16072 | Severity medium |
| keycloak-services: keycloak-services: Group hierarchy search discloses hidden parent groups under FGAP v2 CVE-2026-15945 | Severity medium |
| libssh: libssh: stack buffer overflow in SFTP server longname construction CVE-2026-15370 | Severity high |
| guardrails-detectors: guardrails-detectors: Unauthenticated Regular-Expression Denial of Service (ReDoS) via detector_params.regex CVE-2026-15154 | Severity medium |
| p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing CVE-2026-13757 | Severity medium |
| kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level VM… CVE-2026-13201 | Severity high |
| ipa: Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore CVE-2026-13097 | Severity high |
| FreeIPA: idm: ipa: FreeIPA: Obtaining TGS with impersonating cname through trust relationships CVE-2026-11861 | Severity high |
| keycloak-policy-enforcer: Keycloak Policy Enforcer: Authorization bypass via incorrect URI comparison CVE-2026-9800 | Severity high |
| keycloak: Keycloak: Privilege escalation via Time-of-Check to Time-of-Use (TOCTOU) vulnerability CVE-2026-9796 | Severity medium |
| org.keycloak/keycloak-services: Session fixation in OIDC login flow that can lead to account takeover CVE-2026-7507 | Severity high |
| keycloak: Keycloak: Denial of Service via specially crafted SAML input CVE-2026-7307 | Severity high |
| gimp: GIMP: Arbitrary code execution or denial of service via buffer overflow in GIF image processing CVE-2026-6384 | Severity high |
| tar: tar: Hidden file injection via crafted archives CVE-2026-5704 | Severity medium |
| libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing CVE-2026-5121 | Severity high |
| firewalld: firewalld: Local unprivileged user can modify firewall state due to D-Bus setter mis-authorization CVE-2026-4948 | Severity medium |
| polkit: Polkit: Denial of Service via unbounded input processing through standard input CVE-2026-4897 | Severity medium |
| libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() CVE-2026-4878 | Severity high |
| libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing CVE-2026-4775 | Severity high |
| keycloak: Keycloak: Denial of Service via excessive processing of OpenID Connect scope parameters CVE-2026-4634 | Severity high |
| libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing CVE-2026-4424 | Severity high |
| samba: Remote Code Execution in SAMR CVE-2026-4408 | Severity critical |
| gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison CVE-2026-3833 | Severity high |
| gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response CVE-2026-3832 | Severity low |
| samba: group policy certificate enrollment uses http:// without validation CVE-2026-3012 | Severity high |
| org.keycloak/keycloak-services: Improper Enforcement of Disabled Identity Provider in IdentityBrokerService (Authentication Bypass) CVE-2026-3009 | Severity high |
| keycloak: Keycloak: Denial of Service due to excessive SAMLRequest decompression CVE-2026-2575 | Severity medium |
| mirror-registry: quay: quay: Server-Side Request Forgery via log export functionality CVE-2026-2377 | Severity high |
| samba: vfs_worm does not block directory modification CVE-2026-2340 | Severity medium |