Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-44542

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-controlled path input is joined with a trusted base path prior to sanitization, allowing traversal sequences (e.g., ../) to escape the intended shared directory. As a result, an unauthenticated attacker possessing a valid public share hash with delete permissions enabled can delete arbitrary files outside the shared directory within the share owner’s configured storage scope. This a

PUBLISHED
Vendor
gtsteffaniak
Product
filebrowser
Provider severity
CRITICAL
Conflicts
0

CVE-2026-44541

Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.

PUBLISHED
Vendor
ethyca
Product
fides
Provider severity
HIGH
Conflicts
0

CVE-2026-4454

Use after free in Network in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
0

CVE-2026-4453

Integer overflow in Dawn in Google Chrome on Mac prior to 146.0.7680.153 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44523

Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JWT_SECRET configuration value. The application accepts any base64-decodable secret regardless of size, including secrets as short as 1 byte. This vulnerability is fixed in 0.19.4.

PUBLISHED
Vendor
enchant97
Product
note-mark
Provider severity
CRITICAL
Conflicts
1

CVE-2026-44522

Note Mark is an open-source note-taking application. From 0.13.0 to before 0.19.4, the Note Mark application allows authenticated users to upload assets to notes via POST /api/notes/{noteID}/assets, where the asset filename is provided through the X-Name HTTP request header. This value is stored directly in the database without any sanitization or validation - no path separator filtering, no directory traversal sequence rejection, and no use of filepath.Base() to strip directory components. The

PUBLISHED
Vendor
enchant97
Product
note-mark
Provider severity
HIGH
Conflicts
1

CVE-2026-44521

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolumeMySQL) allows any logged-in user, including users with read-only access to the affected volume, to inject SQL through a crafted target file hash. Successful exploitation can lead to unauthorized data disclosure and denial of service. This vulnerability only affects installations configured to use t

PUBLISHED
Vendor
Studio-42
Product
elFinder
Provider severity
HIGH
Conflicts
0

CVE-2026-44520

Docling-Graph turns documents into validated Pydantic objects, then builds a directed knowledge graph with explicit semantic relationships. Prior to 1.5.1, the URLInputHandler class in docling_graph/core/input/handlers.py makes HTTP requests to user-supplied URLs without validating whether the target resolves to a private, loopback, or link-local IP address. The URLValidator only checks for a valid scheme and non-empty netloc, performing no IP-level validation. Additionally, requests.head() was

PUBLISHED
Vendor
docling-project
Product
docling-graph
Provider severity
MEDIUM
Conflicts
1

CVE-2026-4452

Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
0

CVE-2026-44518

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT stateful signature verification code. When the verification function is called with a signature buffer shorter than the expected signature size for the given parameter set, the implementation does not validate the caller-supplied length and proceeds to read past the end of the buffer. The out-of-boun

PUBLISHED
Vendor
open-quantum-safe
Product
liboqs
Provider severity
MEDIUM
Conflicts
1

CVE-2026-44516

Valtimo is an open-source business process automation platform. From 12.4.0 to 12.33.0 and 13.26.0, the LoggingRestClientCustomizer in the web module automatically intercepts all outgoing HTTP calls made via Spring's RestClient and logs the full request body, response body, and response headers. When an error response is received, this information is included in the thrown HttpClientErrorException message, which is logged at ERROR level by Spring's default exception handling — regardless of the

PUBLISHED
Vendor
com.ritense.valtimo, valtimo-platform
Product
web, valtimo
Provider severity
HIGH
Conflicts
1

CVE-2026-44515

Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud News allows authenticated users to add feeds by providing a feed URL (via the web interface or the API). In affected versions, an authenticated attacker could provide a URL pointing to internal/private IP ranges or localhost, causing the Nextcloud server to perform server-side HTTP requests to attacker-controlled destinations, but not relaying the result. This enables blind SSRF, which can be used to scan or probe inter

PUBLISHED
Vendor
nextcloud
Product
news
Provider severity
LOW
Conflicts
0

CVE-2026-44514

Kubetail is a real-time logging dashboard for Kubernetes. Prior to 0.14.0, Kubetail's dashboard exposes WebSocket endpoints that did not adequately validate the Origin header on connection upgrade. A malicious web page visited by a user with an active Kubetail session could open a WebSocket to the user's dashboard and read their Kubernetes logs in real time. This is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability and affects both the desktop deployment (default http://localhost:7500) and

PUBLISHED
Vendor
kubetail-org, kubetail-org, kubetail-org
Product
github.com/kubetail-org/kubetail/modules/dashboard, github.com/kubetail-org/kubetail/modules/cli, kubetail
Provider severity
MEDIUM
Conflicts
1

CVE-2026-44513

A flaw was found in Diffusers, a library for pretrained diffusion models. A remote attacker could exploit a bypass in the `trust_remote_code` mechanism within the `DiffusionPipeline.from_pretrained` function. This vulnerability allows for arbitrary remote code execution, even when the user explicitly sets `trust_remote_code=False` or omits it. The issue stems from the security check being incorrectly placed, allowing malicious code to be loaded and executed by bypassing the intended security gat

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, huggingface, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat AI Inference Server, diffusers, Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat AI Inference Server, Red Hat AI Inference Server
Provider severity
HIGH
Conflicts
2

CVE-2026-44512

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0, onnx.version_converter.convert_version() can dereference a null pointer in Upsample_6_7::adapt_upsample_6_7() in onnx/version_converter/adapters/upsample_6_7.h when processing an untrusted model with an Upsample node that has zero inputs, causing an unrecoverable denial of service. This issue is fixed in version 1.22.0.

PUBLISHED
Vendor
onnx
Product
onnx
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44511

Katalyst Koi is a framework for building Rails admin functionality. Prior to 4.20.0 and 5.6.0, admin session cookies were not invalidated when an admin user logged out. An attacker with access to a valid admin session cookie could continue to access admin functionality after logout, until the cookie expired or session secrets were rotated. This vulnerability is fixed in 4.20.0 and 5.6.0.

PUBLISHED
Vendor
katalyst
Product
koi
Provider severity
HIGH
Conflicts
0

CVE-2026-4451

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 146.0.7680.153 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
0

CVE-2026-44505

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. network-libp2p handles kad get-record query progress in handle_dht_get (network-libp2p/src/swarm.rs). Prior to version 1.4.0, when a peer returns a FoundRecord, the code verifies the record via dht_verifier.verify(&record.record). On verifier error, handle_dht_get logs and returns early without completing the oneshot used by Network::dht_get, and without cleaning up per-query bookkeepi

PUBLISHED
Vendor
nimiq
Product
core-rs-albatross
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44504

Aegra is a drop-in replacement for LangSmith Deployments. Prior to 0.9.7, with multiple authenticated users on a shared instance are vulnerable to a cross-tenant IDOR. Any authenticated attacker, given another user's thread_id, can execute graph runs against the user's thread, read the user's full checkpoint state, and inject arbitrary messages into the user's conversation history. This vulnerability is fixed in 0.9.7.

PUBLISHED
Vendor
aegra
Product
aegra
Provider severity
HIGH
Conflicts
1

CVE-2026-44503

The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to strip sensitive HTTP headers when following 3xx redirects to a different host or scheme. Only the Authorization header is removed; Cookie, Proxy-Authorization, and all custom headers are forwarded to the redirect target.

PUBLISHED
Vendor
microsoft, microsoft, microsoft, microsoft, microsoft, microsoft
Product
Microsoft.Kiota.Abstractions, github.com/microsoft/kiota-http-go, microsoft-kiota-http, kiota-java, microsoft-kiota-abstractions, kiota-typescript
Provider severity
HIGH
Conflicts
1

CVE-2026-44502

Bugsink is a self-hosted error tracking tool. Prior to 2.1.3, Bugsink’s webhook URL validation could be (partially) bypassed because of a mismatch in URL parsing. The original validation logic parsed webhook URLs with Python’s urllib.parse.urlparse, then sent the request with requests.post. For malformed inputs involving backslashes and @, those components can disagree about where the authority ends and which hostname is the real target. A URL may therefore appear to target an allowlisted public

PUBLISHED
Vendor
bugsink
Product
bugsink
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44501

DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the OIDC callback flow, with no integrity protection (no HMAC, no encryption). This is a Deserialization of Untrusted Data vulnerability (CWE-502) affecting the GET /callback/oidc endpoint. Successful exploitation requires a valid user account in the configured OIDC identity provider This vulnerability

PUBLISHED
Vendor
datahub-project
Product
datahub
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44500

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version 6.0.0, several inbound deserialization paths in Zebra allocated buffers sized against generic transport or block-size ceilings before the tighter protocol or consensus limits were enforced. An unauthenticated or post-handshake peer could therefore force the node to preallocate and parse for orders of magnitude more data than the protocol intended,

PUBLISHED
Vendor
ZcashFoundation
Product
zebra
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4450

Out of bounds write in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
0

CVE-2026-44499

ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Zebra's block discovery pipeline allows an unauthenticated remote attacker to permanently halt all new block discovery on a targeted node. The attack exploits three independent weaknesses in the gossip, syncer, and download subsystems — all exercisable from a single TCP connection — to create a monotonically growing block deficit that never self-heals. This issue has been patche

PUBLISHED
Vendor
ZcashFoundation
Product
zebra
Provider severity
HIGH
Conflicts
0

CVE-2026-44498

ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, Zebra's block validator undercounts transparent signature operations against the 20000-sigop block limit (MAX_BLOCK_SIGOPS), allowing it to accept blocks that zcashd rejects with bad-blk-sigops. A miner who produces such a block can split the network: Zebra nodes follow the offending chain while zcashd nodes do not. This issue has been patched in version 4.4.0.

PUBLISHED
Vendor
ZcashFoundation
Product
zebra
Provider severity
CRITICAL
Conflicts
0

CVE-2026-44497

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 introduced a separate issue due to insufficient error handling of the case where the sighash type is invalid, during sighash computation. Instead of returning an error, the normal flow would resume, and the input sighash buffer would be left untouched. In scenarios where a previous signature validation could leave a valid sighash in the buffer, an inva

PUBLISHED
Vendor
ZcashFoundation
Product
zebra
Provider severity
CRITICAL
Conflicts
0

CVE-2026-44496

A flaw was found in Axios. A remote attacker, by influencing the XSRF cookie name in a browser environment, could cause the application to construct a regular expression that leads to excessive processing. This can result in a client-side Denial of Service (DoS), where the affected browser tab may freeze, impacting the availability of the application for the user.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, axios
Product
Red Hat Ansible Automation Platform 2, multicluster engine for Kubernetes 2.6, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Service Mesh 3.0, Red Hat Discovery 2, Cryostat 4, Red Hat build of Apicurio Registry 3, Red Hat Quay 3.12, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Quay 3.16, Red Hat OpenShift Dev Spaces 3.29, Red Hat OpenShift Virtualization 4, Red Hat OpenShift Service Mesh 3.0, Red Hat 3scale API Management Platform 2, Red Hat Fuse 7, Red Hat build of Apicurio Registry 3, Red Hat OpenShift Container Platform 4.2, Red Hat OpenShift Service Mesh 3.2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Service Mesh 3.2, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6, Red Hat OpenShift Service Mesh 3.3, Red Hat Ansible Automation Platform 2, Red Hat 3scale API Management Platform 2, Red Hat Data Grid 8.6.2, Red Hat OpenShift Container Platform 4.15, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Red Hat OpenShift Service Mesh 3.3, Red Hat build of Apache Camel for Spring Boot 4, Gatekeeper 3, Network Observability Operator, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3.1, Cryostat 4, Red Hat Advanced Cluster Management for Kubernetes 2.15, Red Hat Quay 3.9, Red Hat Migration Toolkit 1.8, Red Hat OpenShift Dev Spaces 3.29, Red Hat AMQ Broker 7, Red Hat OpenShift Container Platform 4.16, Red Hat 3scale API Management Platform 2, Self-service automation portal 2, Red Hat OpenShift Service Mesh 2.6, Network Observability Operator, Red Hat 3scale API Management Platform 2, Red Hat Build of Podman Desktop - Tech Preview, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Enterprise Linux AI (RHEL AI) 3, Network Observability Operator, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Container Platform 4.21, Red Hat OpenShift AI (RHOAI), Migration Toolkit for Applications 8, Red Hat Advanced Cluster Security for Kubernetes 4.10, multicluster engine for Kubernetes 2.8, Red Hat Developer Hub 1.10, Red Hat OpenShift Container Platform 4.19, OpenShift Service Mesh 3, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat OpenShift Service Mesh 2.6, Red Hat OpenShift AI (RHOAI), OpenShift Pipelines, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, multicluster engine for Kubernetes 2.9, Red Hat Advanced Cluster Security 4.9, Red Hat OpenShift Service Mesh 3.1, Red Hat Enterprise Linux 8, Red Hat build of Apache Camel - HawtIO 4, Migration Toolkit for Applications 8, OpenShift Pipelines, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Virtualization 4, Red Hat Ansible Automation Platform 2, Red Hat 3scale API Management Platform 2, multicluster engine for Kubernetes 2.1, Red Hat Developer Hub 1.9, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Trusted Profile Analyzer, Red Hat Trusted Artifact Signer 1.3, Red Hat Satellite 6, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3.15, Red Hat OpenShift Service Mesh 3.1, Red Hat Satellite 6, OpenShift Service Mesh 3, Red Hat Ansible Automation Platform 2.7, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4.14, Red Hat Advanced Cluster Management for Kubernetes 2.11, Red Hat Advanced Cluster Management for Kubernetes 2.14, Self-service automation portal 2, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, axios
Provider severity
HIGH
Conflicts
2

CVE-2026-44495

A flaw was found in Axios, a promise-based HTTP client. This vulnerability involves prototype pollution gadgets in the request configuration processing. If another vulnerability has already polluted the Object.prototype.transformResponse, affected Axios versions may incorrectly interpret this inherited value as part of the request configuration or as an option validator. Axios does not itself create the prototype pollution. Exploitability requires a separate prototype-pollution vulnerability or

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, axios, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Advanced Cluster Management for Kubernetes 2.15, Red Hat OpenShift AI (RHOAI), Red Hat Trusted Artifact Signer, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Management for Kubernetes 2.11, Red Hat build of Apicurio Registry 3, Red Hat 3scale API Management Platform 2, axios, Red Hat OpenShift Virtualization 4, Red Hat OpenShift Container Platform 4.21, Red Hat Quay 3.16, Red Hat Build of Podman Desktop - Tech Preview, Red Hat 3scale API Management Platform 2, Migration Toolkit for Applications 8, Self-service automation portal 2, Red Hat OpenShift Container Platform 4.15, multicluster engine for Kubernetes 2.9, Network Observability Operator, Red Hat build of Apache Camel - HawtIO 4, Red Hat Container Native Virtualization 4.14, Red Hat Data Grid 8.6.2, Red Hat Quay 3.12, Red Hat Advanced Cluster Security for Kubernetes 4.10, multicluster engine for Kubernetes 2.6, Red Hat Ansible Automation Platform 2.7, Red Hat OpenShift Dev Spaces, Red Hat OpenShift Service Mesh 2.6, OpenShift Service Mesh 3, multicluster engine for Kubernetes 2.8, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Service Mesh 3.0, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Security 4.9, Red Hat Trusted Profile Analyzer, Red Hat OpenShift Container Platform 4.21, Red Hat OpenShift Service Mesh 3.2, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat AMQ Broker 7, Red Hat Quay 3.1, Red Hat OpenShift Service Mesh 3.1, Red Hat OpenShift Container Platform 4.22, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 9, Red Hat Satellite 6, Red Hat build of Apicurio Registry 3, Network Observability Operator, Red Hat Migration Toolkit 1.8, Red Hat build of Apache Camel for Spring Boot 4, Red Hat OpenShift Container Platform 4, Red Hat 3scale API Management Platform 2, Red Hat OpenShift Dev Spaces 3.29, Red Hat OpenShift Service Mesh 3.3, Red Hat Quay 3.15, Red Hat OpenShift Service Mesh 3.1, Self-service automation portal 2, Red Hat OpenShift Service Mesh 3.2, Red Hat Ansible Automation Platform 2.6, Red Hat Ansible Automation Platform 2, Red Hat Satellite 6, Red Hat Ansible Automation Platform 2, Red Hat Quay 3.9, Red Hat Fuse 7, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Service Mesh 2.6, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Service Mesh 3.0, Red Hat OpenShift Container Platform 4.2, Red Hat Ansible Automation Platform 2, OpenShift Pipelines, multicluster engine for Kubernetes 2.1, Red Hat OpenShift Container Platform 4.16, Red Hat OpenShift AI (RHOAI), Gatekeeper 3, Red Hat OpenShift Container Platform 4.2, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Developer Hub 1.10, Red Hat 3scale API Management Platform 2, Migration Toolkit for Applications 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Container Native Virtualization 4.13, Cryostat 4, Red Hat OpenShift AI (RHOAI), OpenShift Pipelines, Red Hat 3scale API Management Platform 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat Developer Hub 1.9, Red Hat OpenShift Service Mesh 3.3, Network Observability Operator, Red Hat Satellite 6, OpenShift Service Mesh 3, Cryostat 4, Red Hat Discovery 2, Red Hat OpenShift Container Platform 4.14
Provider severity
HIGH
Conflicts
2

CVE-2026-44494

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack — intercepting, reading, and modifying all HTTP traffic including authentication credentials. The HTTP adapter at lib/adapters/http.js:670 reads config.proxy via standard property access, whic

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, axios, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Ansible Automation Platform 2, Network Observability Operator, Red Hat Ansible Automation Platform 2.7, Red Hat OpenShift Service Mesh 3.0, Red Hat Discovery 2, Red Hat 3scale API Management Platform 2, Red Hat OpenShift Container Platform 4.15, Red Hat Migration Toolkit 1.8, multicluster engine for Kubernetes 2.1, Red Hat OpenShift Container Platform 4.14, multicluster engine for Kubernetes 2.8, Migration Toolkit for Applications 8, Red Hat Enterprise Linux 8, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Fuse 7, Red Hat OpenShift Container Platform 4.21, Red Hat OpenShift Service Mesh 2.6, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Self-service automation portal 2, Red Hat OpenShift Virtualization 4, Migration Toolkit for Applications 8, Red Hat OpenShift Container Platform 4.19, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat OpenShift Service Mesh 3.2, Red Hat OpenShift Service Mesh 3.0, Red Hat OpenShift AI (RHOAI), Red Hat Developer Hub 1.9, Red Hat Satellite 6.19, Red Hat OpenShift Container Platform 4.2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat build of Apache Camel - HawtIO 4, Red Hat OpenShift Dev Spaces 3.29, Red Hat 3scale API Management Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift Service Mesh 3.1, Red Hat Ansible Automation Platform 2, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat Quay 3.12, multicluster engine for Kubernetes 2.6, Red Hat build of Apicurio Registry 3, Red Hat Advanced Cluster Security 4.9, Red Hat OpenShift Container Platform 4.16, Red Hat Satellite 6.19, Gatekeeper 3, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Management for Kubernetes 2.11, multicluster engine for Kubernetes 2.9, Red Hat OpenShift Container Platform 4.16, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat AMQ Broker 7, OpenShift Pipelines, Red Hat Advanced Cluster Security for Kubernetes 4.10, Network Observability Operator, Red Hat Ansible Automation Platform 2, OpenShift Pipelines, Red Hat OpenShift Service Mesh 3.2, Red Hat OpenShift Service Mesh 2.6, Red Hat Trusted Profile Analyzer, OpenShift Service Mesh 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat build of Apache Camel for Spring Boot 4, Red Hat Quay 3.15, Red Hat build of Apicurio Registry 3, Red Hat OpenShift Container Platform 4, Red Hat Container Native Virtualization 4.14, Red Hat OpenShift Dev Spaces 3.29, Self-service automation portal 2, OpenShift Service Mesh 3, Red Hat Advanced Cluster Management for Kubernetes 2.15, Red Hat Quay 3.1, Red Hat Quay 3.9, Red Hat OpenShift Service Mesh 3.3, Red Hat Build of Podman Desktop - Tech Preview, Red Hat Quay 3.16, Red Hat Data Grid 8.6.2, Red Hat OpenShift Container Platform 4.22, axios, Red Hat Ansible Automation Platform 2, Red Hat Developer Hub 1.10, Cryostat 4, Red Hat Container Native Virtualization 4.13, Network Observability Operator, Red Hat Satellite 6.19, Cryostat 4, Red Hat 3scale API Management Platform 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Container Platform 4.21, Red Hat 3scale API Management Platform 2, Red Hat OpenShift Service Mesh 3.3, Red Hat OpenShift Container Platform 4.2, Red Hat OpenShift Service Mesh 3.1, Red Hat Ansible Automation Platform 2.5 for RHEL 9
Provider severity
HIGH
Conflicts
2

CVE-2026-44492

A flaw was found in Axios, a promise-based HTTP client. This vulnerability occurs because Axios does not properly normalize IPv4-mapped IPv6 addresses. When a NO_PROXY setting is configured to block direct access to specific IPv4 addresses, an attacker can bypass this restriction by using the IPv4-mapped IPv6 form of the address in a request URL. This allows the request to be routed through the proxy, potentially exposing internal services or sensitive information that should otherwise be inacce

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, axios, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Build of Podman Desktop - Tech Preview, Red Hat OpenShift AI (RHOAI), Red Hat Container Native Virtualization 4.14, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Red Hat 3scale API Management Platform 2, Red Hat Quay 3.15, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat 3scale API Management Platform 2, Red Hat OpenShift Container Platform 4.19, Red Hat Discovery 2, OpenShift Pipelines, Red Hat build of Apicurio Registry 3, Red Hat Container Native Virtualization 4.13, Red Hat Migration Toolkit 1.8, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Developer Hub 1.10, Red Hat Advanced Cluster Management for Kubernetes 2.14, OpenShift Pipelines, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Gatekeeper 3, Red Hat build of Apicurio Registry 3, multicluster engine for Kubernetes 2.6, Red Hat OpenShift Service Mesh 3.3, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Developer Hub 1.9, Red Hat OpenShift Service Mesh 2.6, Red Hat build of Apache Camel - HawtIO 4, Red Hat OpenShift Dev Spaces 3.29, Red Hat Ansible Automation Platform 2.7, Red Hat Ansible Automation Platform 2, Red Hat Quay 3.1, Network Observability Operator, Network Observability Operator, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Advanced Cluster Management for Kubernetes 2.11, Red Hat OpenShift Container Platform 4.2, Red Hat Trusted Profile Analyzer, Red Hat OpenShift Container Platform 4.14, Self-service automation portal 2, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux 9, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Security 4.9, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat 3scale API Management Platform 2, Red Hat Ansible Automation Platform 2, multicluster engine for Kubernetes 2.8, Red Hat OpenShift AI (RHOAI), Cryostat 4, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat OpenShift Container Platform 4.16, multicluster engine for Kubernetes 2.1, Red Hat Trusted Artifact Signer 1.3, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat OpenShift Virtualization 4, Red Hat Ansible Automation Platform 2, Red Hat Satellite 6, Red Hat Fuse 7, Red Hat OpenShift Service Mesh 3.0, Red Hat OpenShift Service Mesh 3.0, multicluster engine for Kubernetes 2.9, Red Hat Ansible Automation Platform 2, Red Hat Quay 3.16, Red Hat OpenShift Service Mesh 3.2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4.15, Migration Toolkit for Applications 8, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4.21, Red Hat Quay 3.12, Red Hat Advanced Cluster Management for Kubernetes 2.15, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat OpenShift Dev Spaces 3.29, axios, Red Hat Quay 3.9, Cryostat 4, Red Hat OpenShift Service Mesh 3.1, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6, OpenShift Service Mesh 3, Red Hat OpenShift Service Mesh 3.1, Network Observability Operator, Self-service automation portal 2, Red Hat 3scale API Management Platform 2, Red Hat OpenShift Service Mesh 3.3, Red Hat Data Grid 8.6.2, Red Hat OpenShift Service Mesh 3.2, Red Hat OpenShift Service Mesh 2.6, OpenShift Service Mesh 3, Red Hat OpenShift AI (RHOAI), Migration Toolkit for Applications 8, Red Hat Satellite 6, Red Hat 3scale API Management Platform 2, Red Hat AMQ Broker 7
Provider severity
HIGH
Conflicts
2

CVE-2026-44490

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency in the same process (e.g. lodash _.merge / CVE-2018-16487), axios silently picks up the polluted values. (1) lib/utils.js line 406 builds merge()'s accumulator as result = {}, so result[targetKey] (line 414) walks Object.prototype and the polluted bucket's own keys are copied into the mer

PUBLISHED
Vendor
axios
Product
axios
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4449

Use after free in Blink in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
0

CVE-2026-44489

Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are still constructed as plain {} with Object.prototype in their chain. The setProxy() function at lib/adapters/http.js:209-223 reads proxy.username, proxy.password, and proxy.auth without hasOwnProperty checks. When Object.prototype.username is polluted, setProxy() constructs a Proxy-Authorization header with attacker-controlled credentials

PUBLISHED
Vendor
axios
Product
axios
Provider severity
LOW
Conflicts
1

CVE-2026-44488

A flaw was found in Axios, a promise-based HTTP client. When using the fetch adapter, Axios did not properly enforce configured request and response size limits. This vulnerability allows a remote attacker, through a malicious or compromised server, or by supplying a large data URL, to send or receive oversized data bodies. This can lead to resource exhaustion in server-side applications, resulting in a Denial of Service (DoS).

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, axios, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
OpenShift Pipelines, Red Hat Quay 3.12, Red Hat Quay 3.1, Red Hat Developer Hub 1.9, Red Hat Enterprise Linux 8, Red Hat Migration Toolkit 1.8, Red Hat AMQ Broker 7, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat build of Apache Camel for Spring Boot 4, axios, Red Hat Build of Podman Desktop - Tech Preview, OpenShift Service Mesh 3, Red Hat OpenShift AI (RHOAI), Red Hat 3scale API Management Platform 2, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Trusted Profile Analyzer, Red Hat OpenShift Virtualization 4, Self-service automation portal 2, Red Hat OpenShift Service Mesh 3.1, Red Hat Satellite 6.19, Red Hat OpenShift Virtualization 4, Network Observability Operator, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Dev Spaces 3.29, Red Hat OpenShift Service Mesh 3.2, Migration Toolkit for Applications 8, multicluster engine for Kubernetes 2.8, Red Hat Quay 3.16, Red Hat OpenShift Container Platform 4.2, Red Hat Ansible Automation Platform 2, Red Hat build of Apache Camel - HawtIO 4, Red Hat Ansible Automation Platform 2, Red Hat Trusted Artifact Signer 1.3, Red Hat Quay 3.15, Red Hat 3scale API Management Platform 2, Red Hat Data Grid 8.6.2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Security 4.9, Red Hat OpenShift Service Mesh 2.6, Red Hat OpenShift Container Platform 4.14, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat build of Apicurio Registry 3, Cryostat 4, Red Hat Ansible Automation Platform 2, Red Hat Developer Hub 1.10, Red Hat OpenShift Service Mesh 3.3, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat OpenShift Dev Spaces 3.29, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Container Platform 4.2, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Enterprise Linux AI (RHEL AI) 3, Network Observability Operator, Red Hat 3scale API Management Platform 2, Red Hat OpenShift Container Platform 4.22, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Gatekeeper 3, Red Hat OpenShift Service Mesh 3.0, Red Hat Satellite 6.19, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, OpenShift Service Mesh 3, Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift AI (RHOAI), multicluster engine for Kubernetes 2.6, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Service Mesh 3.1, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), OpenShift Pipelines, Red Hat OpenShift Service Mesh 2.6, Red Hat Advanced Cluster Management for Kubernetes 2.11, Red Hat Quay 3.9, Red Hat Enterprise Linux 8, multicluster engine for Kubernetes 2.1, Network Observability Operator, Red Hat OpenShift Container Platform 4.21, Self-service automation portal 2, Red Hat OpenShift Service Mesh 3.3, Red Hat OpenShift Container Platform 4.15, Red Hat OpenShift Container Platform 4.16, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat Advanced Cluster Security for Kubernetes 4.10, Cryostat 4, Red Hat OpenShift Service Mesh 3.0, Red Hat Fuse 7, Red Hat Satellite 6.19, Red Hat OpenShift AI (RHOAI), multicluster engine for Kubernetes 2.9, Red Hat build of Apicurio Registry 3, Red Hat Ansible Automation Platform 2.7, Red Hat OpenShift Container Platform 4.21, Red Hat OpenShift AI (RHOAI), Migration Toolkit for Applications 8, Red Hat OpenShift Service Mesh 3.2, Red Hat Discovery 2, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Management for Kubernetes 2.15
Provider severity
HIGH
Conflicts
2

CVE-2026-44487

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial HTTP request is sent through an authenticated HTTP proxy, redirects are followed, and the redirected URL is no longer proxied. Under affected redirect shapes, the final origin can receive the proxy credential that was in

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, axios, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
OpenShift Pipelines, OpenShift Pipelines, Cryostat 4, Red Hat Quay 3.1, Red Hat 3scale API Management Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3.16, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Container Platform 4.22, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Service Mesh 3.1, Red Hat OpenShift Container Platform 4.15, Migration Toolkit for Applications 8, Red Hat OpenShift Virtualization 4, Red Hat Ansible Automation Platform 2, Red Hat Developer Hub 1.10, Red Hat 3scale API Management Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat Satellite 6.19, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat Satellite 6.19, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4.16, Network Observability Operator, Red Hat Ansible Automation Platform 2, Red Hat Advanced Cluster Management for Kubernetes 2.11, Migration Toolkit for Applications 8, Red Hat OpenShift Container Platform 4.2, Red Hat OpenShift Service Mesh 3.3, OpenShift Service Mesh 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4.21, Gatekeeper 3, Red Hat 3scale API Management Platform 2, Red Hat build of Apache Camel for Spring Boot 4, Cryostat 4, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Dev Spaces 3.29, Red Hat OpenShift Service Mesh 3.2, Red Hat Quay 3.15, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Ansible Automation Platform 2.7, Red Hat Discovery 2, Red Hat Ansible Automation Platform 2.6, Red Hat Ansible Automation Platform 2, OpenShift Service Mesh 3, Red Hat OpenShift Dev Spaces 3.29, Red Hat OpenShift Service Mesh 2.6, Red Hat Enterprise Linux 9, Red Hat Satellite 6.19, Red Hat Quay 3.12, Red Hat Enterprise Linux 8, Red Hat Migration Toolkit 1.8, Red Hat OpenShift Service Mesh 3.1, multicluster engine for Kubernetes 2.6, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Service Mesh 2.6, Red Hat 3scale API Management Platform 2, Red Hat build of Apicurio Registry 3, Red Hat OpenShift AI (RHOAI), multicluster engine for Kubernetes 2.8, Red Hat OpenShift Service Mesh 3.3, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2.5 for RHEL 9, axios, Red Hat Advanced Cluster Security 4.9, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Container Platform 4.19, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Build of Podman Desktop - Tech Preview, Network Observability Operator, Red Hat Enterprise Linux 8, Red Hat OpenShift Service Mesh 3.2, Red Hat build of Apicurio Registry 3, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Fuse 7, Red Hat OpenShift Container Platform 4.14, Red Hat Trusted Artifact Signer 1.3, Red Hat Ansible Automation Platform 2, Red Hat Quay 3.9, Red Hat Trusted Profile Analyzer, Red Hat Advanced Cluster Management for Kubernetes 2.15, Red Hat OpenShift AI (RHOAI), Red Hat AMQ Broker 7, Red Hat OpenShift Service Mesh 3.0, Red Hat Data Grid 8.6.2, Red Hat 3scale API Management Platform 2, Red Hat OpenShift Container Platform 4.2, Red Hat build of Apache Camel - HawtIO 4, Red Hat OpenShift Service Mesh 3.0, Network Observability Operator, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), multicluster engine for Kubernetes 2.1, Red Hat Developer Hub 1.9, Red Hat Ansible Automation Platform 2, Self-service automation portal 2, multicluster engine for Kubernetes 2.9, Self-service automation portal 2, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat OpenShift Container Platform 4.21, Red Hat OpenShift Virtualization 4
Provider severity
HIGH
Conflicts
3

CVE-2026-44486

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorization header. If Axios then follows a redirect and the redirected request is no longer sent through that proxy, the stale Proxy-Authorization header can remain on the redirected request and be sent to the redirect target. T

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, axios, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
OpenShift Pipelines, multicluster engine for Kubernetes 2.9, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat build of Apicurio Registry 3, multicluster engine for Kubernetes 2.8, Red Hat OpenShift Service Mesh 2.6, Red Hat OpenShift Container Platform 4.14, Red Hat Ansible Automation Platform 2, axios, Red Hat OpenShift Virtualization 4, Gatekeeper 3, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Self-service automation portal 2, Red Hat OpenShift Dev Spaces 3.29, Red Hat Data Grid 8.6.2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Service Mesh 3.2, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat 3scale API Management Platform 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Service Mesh 3.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Virtualization 4, Red Hat Satellite 6, Red Hat Enterprise Linux 9, Red Hat Fuse 7, Red Hat Advanced Cluster Management for Kubernetes 2.11, Migration Toolkit for Applications 8, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Self-service automation portal 2, Red Hat OpenShift Container Platform 4.2, Red Hat AMQ Broker 7, Red Hat Advanced Cluster Security 4.9, Red Hat Satellite 6, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat build of Apicurio Registry 3, Red Hat Trusted Artifact Signer 1.3, Network Observability Operator, Network Observability Operator, Cryostat 4, Red Hat OpenShift Service Mesh 2.6, multicluster engine for Kubernetes 2.1, multicluster engine for Kubernetes 2.6, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6, Red Hat Ansible Automation Platform 2, Red Hat 3scale API Management Platform 2, Red Hat Developer Hub 1.9, Red Hat OpenShift Container Platform 4.19, Red Hat Enterprise Linux 8, Red Hat Quay 3.1, Red Hat Ansible Automation Platform 2.7, Red Hat OpenShift Dev Spaces 3.29, Migration Toolkit for Applications 8, Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4.16, Red Hat build of Apache Camel for Spring Boot 4, Red Hat OpenShift Service Mesh 3.2, Red Hat Trusted Profile Analyzer, Red Hat OpenShift Container Platform 4.15, Cryostat 4, Red Hat OpenShift AI (RHOAI), Red Hat Migration Toolkit 1.8, Red Hat Discovery 2, Red Hat OpenShift AI (RHOAI), Red Hat Build of Podman Desktop - Tech Preview, Red Hat Quay 3.16, Red Hat build of Apache Camel - HawtIO 4, Red Hat OpenShift Service Mesh 3.3, Red Hat Developer Hub 1.10, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Service Mesh 3.0, Red Hat Advanced Cluster Management for Kubernetes 2.15, Red Hat Ansible Automation Platform 2, Network Observability Operator, Red Hat Quay 3.15, Red Hat Enterprise Linux AI (RHEL AI) 3, OpenShift Service Mesh 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Service Mesh 3.0, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat OpenShift Container Platform 4.21, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat OpenShift AI (RHOAI), Red Hat 3scale API Management Platform 2, OpenShift Service Mesh 3, Red Hat OpenShift Service Mesh 3.1, Red Hat Quay 3.12, Red Hat 3scale API Management Platform 2, Red Hat OpenShift Service Mesh 3.3, Red Hat Quay 3.9, OpenShift Pipelines, Red Hat 3scale API Management Platform 2
Provider severity
HIGH
Conflicts
2

CVE-2026-44484

A flaw was found in PyTorch Lightning. This deep learning framework introduced functionality that could be leveraged as a credential harvesting mechanism. A remote attacker could exploit this to obtain sensitive user credentials, leading to significant information disclosure and potential further system compromise.

PUBLISHED
Vendor
Lightning-AI, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
pytorch-lightning, Red Hat AI Inference Server, Red Hat AI Inference Server, Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3
Provider severity
CRITICAL
Conflicts
3

CVE-2026-44483

RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6.0.4 and 7.0.2, setPath in @rvf/set-get (used by @rvf/core to flatten incoming form data into a nested object) does not block the keys __proto__, constructor, or prototype when walking a path. Because field names in submitted form data are passed directly to setPath via preprocessFormData (and through parseFormData / validate), an attacker who can submit a form to a Remix / Rea

PUBLISHED
Vendor
airjp73, @rvf
Product
rvf, set-get
Provider severity
HIGH
Conflicts
1

CVE-2026-44482

soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an HTML payload executed locally in the Electron app. This means attacker-controlled SoundCloud track metadata can lead to local command execution on the user's machine. The application exposes a preload API (window.soundcloudAPI.sendTrackUpdate) to the remote SoundCloud page. Track metadata from SoundCloud is trusted and forwarded through IPC into th

PUBLISHED
Vendor
richardhbtz
Product
soundcloud-rpc
Provider severity
CRITICAL
Conflicts
1

CVE-2026-4448

Heap buffer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
0

CVE-2026-44479

Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI runs in non-interactive mode (--non-interactive or auto-detected AI agent), commands that cannot complete autonomously emit JSON payloads with suggested follow-up commands. If the user authenticated via --token or -t on the command line, the token value is included verbatim in those suggestions. The plaintext token may be captured in CI/CD logs, agent transcripts, or other automa

PUBLISHED
Vendor
vercel
Product
vercel
Provider severity
MEDIUM
Conflicts
1

CVE-2026-44478

hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboarding/config endpoint by checking onboardingCompleted and canReRunOnboarding before allowing config overwrites. However, GET /v1/onboarding/config still leaks all infrastructure secrets in plaintext to unauthenticated users when the ONBOARDING_RECOVERY_TOKEN stored in the database is an empty string. This vulnerability is fixed in 2026.4.0.

PUBLISHED
Vendor
hoppscotch
Product
hoppscotch
Provider severity
HIGH
Conflicts
1

CVE-2026-44477

A flaw was found in CloudNativePG's metrics exporter. The issue arises because the metrics exporter connected to PostgreSQL using a highly privileged account and did not properly restrict privileges during monitoring operations. A low-privileged database user could exploit this behavior through crafted monitoring queries or PostgreSQL object resolution manipulation to regain PostgreSQL superuser privileges and potentially execute arbitrary operating system commands as the postgres user inside th

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, cloudnative-pg, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Openshift Data Foundation 4, Red Hat Openshift Data Foundation 4, Red Hat Openshift Data Foundation 4, Red Hat Openshift Data Foundation 4, cloudnative-pg, Red Hat Openshift Data Foundation 4, Red Hat Openshift Data Foundation 4, Red Hat Openshift Data Foundation 4, Red Hat Openshift Data Foundation 4
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-44475

Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against its locally stored values. A malicious gNB can overwrite Ella Core's stored UE security capabilities for any UE with arbitrary values by sending a single crafted PathSwitchRequest. This vulnerability is fixed in 1.10.0.

PUBLISHED
Vendor
ellanetworks
Product
core
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44474

Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core didn't enforce security rules on concurrent running of security procedures defined in TS 33.501 §6.9.5.1 — it could send a NAS Security Mode Command while an N2 handover was still pending (and vice versa). Concurrent Security Mode Command and N2 handover produce a KgNB mismatch between the UE and target gNB, causing the handover to fail. Requires a stalled gNB + re-registration race to trigger. This vulnerability is

PUBLISHED
Vendor
ellanetworks
Product
core
Provider severity
LOW
Conflicts
0

CVE-2026-44473

Ella Core is a 5G core designed for private networks. Prior to 1.10.0, a radio with a valid NG Setup can send a forged PDUSessionResourceSetupResponse carrying any UE's AMF-UE-NGAP-ID. Ella Core does not verify the message arrived on the SCTP association bound to that UE's logical NG-connection, then creates a GTP tunnel towards that radio. This vulnerability is fixed in 1.10.0.

PUBLISHED
Vendor
ellanetworks
Product
core
Provider severity
HIGH
Conflicts
1

CVE-2026-44471

gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, when checked out with gitoxide, permit writing an attacker-controlled symlink into any existing directory the user has write access to. During checkout, all symlink index entries are deferred and created after regular files using a single shared gix_worktree::Stack. Internally, this uses a gix_fs::Stack. gix_fs::Stack::make_relative_path_current() caches validated path prefixes:

PUBLISHED
Vendor
GitoxideLabs
Product
gitoxide
Provider severity
HIGH
Conflicts
0

CVE-2026-44470

The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. Prior to 1.3834.0, the CoworkVMService component in Claude Desktop for Windows ran as SYSTEM and did not validate whether the VM bundle directory was a real directory or an NTFS directory junction before creating files within it. A local non-elevated user could replace the user-writable VM bundle directory with a directory junction pointing to an attacker-chosen location, cau

PUBLISHED
Vendor
anthropics
Product
claude-code
Provider severity
HIGH
Conflicts
1

CVE-2026-4447

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
1