Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-42593

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoffice/convert, chromium/convert/url, chromium/convert/html, and chromium/convert/markdown accept stampSource=pdf + stampExpression=/path and watermarkSource=pdf + watermarkExpression=/path from anonymous callers. The dedicated stamp/watermark routes require an uploaded file when the source type is image or pdf; these six routes only overwrite the expression when a file is uploade

PUBLISHED
Vendor
gotenberg
Product
gotenberg
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42592

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, FilterOutboundURL resolves the hostname, checks the resolved IPs against the private-address deny-list, and returns only the error. It discards the resolved addresses. Chromium later performs its own DNS resolution when it navigates to the URL. An attacker who controls DNS for a hostname with a short TTL returns a public IP on the first query (Gotenberg allows) and a private IP on the second query (Chromium connects to t

PUBLISHED
Vendor
gotenberg
Product
gotenberg
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42591

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/libreoffice/convert) passes uploaded documents directly to LibreOffice without inspecting their content. LibreOffice then fetches any embedded external URLs on its own, completely bypassing the SSRF filters. This vulnerability is fixed in 8.32.0.

PUBLISHED
Vendor
gotenberg
Product
gotenberg
Provider severity
HIGH
Conflicts
0

CVE-2026-42590

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.30.0, The ExifTool metadata write blocklist in Gotenberg can be bypassed using ExifTool's group-prefix syntax, enabling arbitrary file rename, move, hardlink, and symlink creation on the server. ExifTool supports group-prefix syntax where File:FileName is processed identically to FileName -- the prefix is stripped by SetNewValue in Writer.pl before tag matching. The safeKeyPattern regex (^[a-zA-Z0-9\-_.:]+$) allows colons, so

PUBLISHED
Vendor
gotenberg
Product
gotenberg
Provider severity
HIGH
Conflicts
0

CVE-2026-4259

The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PUBLISHED
Vendor
Unknown
Product
ultimate-woocommerce-auction-pro
Provider severity
HIGH
Conflicts
1

CVE-2026-42589

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON metadata object and passes its keys directly to ExifTool via the go-exiftool library. No validation is performed on key characters. A \n embedded in a JSON key splits the ExifTool stdin stream into a new argument line, allowing an attacker to inject arbitrary ExifTool flags — including -if, which evaluates Perl expressions. This achieves unauthenti

PUBLISHED
Vendor
gotenberg
Product
gotenberg
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42588

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String). An authenticated attacker can invoke these operations with a crafted discovery

PUBLISHED
Vendor
Apache Software Foundation, Apache Software Foundation, Apache Software Foundation
Product
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ
Provider severity
HIGH
Conflicts
2

CVE-2026-42587

A flaw was found in Netty. A remote attacker can bypass the configured decompression limit in the HttpContentDecompressor by sending a specially crafted compressed payload using Brotli (br), Zstandard (zstd), or Snappy content encodings. This can lead to unbounded memory allocation, resulting in an out-of-memory Denial of Service (DoS) for the affected system.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, io.netty, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, netty, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, io.netty, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Satellite 6, Red Hat build of Quarkus 3.33.2, Red Hat build of Debezium 3, Red Hat build of Apicurio Registry 2, streams for Apache Kafka 3, Red Hat Process Automation 7, netty-codec-http, Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16, Cryostat 4, Red Hat build of Quarkus 3.27.4, Red Hat Data Grid 8.6.2, Red Hat Satellite 6, Red Hat Fuse 7, Red Hat Build of Keycloak, Red Hat Build of Keycloak, Cryostat 4 on RHEL 9, Red Hat OpenShift Dev Spaces 3.28, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Dev Spaces 3.28, OpenShift Serverless, Red Hat Single Sign-On 7, Red Hat Build of Keycloak, Red Hat Build of Keycloak, Red Hat JBoss Enterprise Application Platform 8, Red Hat OpenShift Dev Spaces 3.29, Red Hat OpenShift AI (RHOAI), Red Hat build of OptaPlanner 8, Red Hat Build of Keycloak, streams for Apache Kafka 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), netty, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Cryostat 4 on RHEL 9, Red Hat OpenShift AI 2.25, Red Hat build of Debezium 3, Red Hat AMQ Broker 7, OpenShift Serverless, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat JBoss Enterprise Application Platform 7, Red Hat build of Apicurio Registry 3, OpenShift Serverless, Red Hat Process Automation 7, streams for Apache Kafka 3, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat Build of Keycloak, Streams for Apache Kafka 2.9.4, Red Hat Fuse 7, netty-codec-http2, Red Hat build of Apicurio Registry 2, Red Hat AMQ Broker 7, OpenShift Serverless, Red Hat build of Apache Camel 4 for Quarkus 3, OpenShift Serverless, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Single Sign-On 7, Red Hat AMQ Clients, Cryostat 4 on RHEL 9, OpenShift Serverless, OpenShift Serverless, Red Hat JBoss Enterprise Application Platform Expansion Pack, OpenShift Serverless, Red Hat build of Apicurio Registry 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat JBoss Enterprise Application Platform 7, OpenShift Serverless, OpenShift Serverless, Red Hat build of OptaPlanner 8, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Spaces 3.28
Provider severity
HIGH
Conflicts
2

CVE-2026-42586

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses.

PUBLISHED
Vendor
io.netty, netty
Product
netty-codec-redis, netty
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42585

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

PUBLISHED
Vendor
io.netty, netty
Product
netty-codec-http, netty
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42584

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, io.netty, Red Hat, Red Hat, Red Hat, Red Hat, netty, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift Dev Spaces 3.28, Red Hat OpenShift Dev Spaces 3.28, Red Hat Process Automation 7, Red Hat OpenShift AI (RHOAI), Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16, OpenShift Serverless, Red Hat Satellite 6, Red Hat JBoss Enterprise Application Platform 8, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat build of Apicurio Registry 3, Red Hat Build of Keycloak, streams for Apache Kafka 3, Red Hat build of Apicurio Registry 2, Cryostat 4 on RHEL 9, Red Hat Build of Keycloak, OpenShift Serverless, Red Hat OpenShift Dev Spaces 3.29, Red Hat OpenShift AI (RHOAI), Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat AMQ Clients, Red Hat Build of Keycloak, Red Hat build of OptaPlanner 8, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Build of Keycloak, Red Hat Fuse 7, Red Hat OpenShift AI (RHOAI), OpenShift Serverless, Red Hat OpenShift Dev Spaces 3.28, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat build of Quarkus 3.33.2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat build of Quarkus 3.27.4, Red Hat OpenShift AI 2.25, OpenShift Serverless, Red Hat OpenShift AI (RHOAI), OpenShift Serverless, netty-codec-http, Red Hat OpenShift AI (RHOAI), OpenShift Serverless, OpenShift Serverless, Red Hat OpenShift AI (RHOAI), netty, Red Hat Single Sign-On 7, OpenShift Serverless, OpenShift Serverless, Red Hat build of Debezium 3, Red Hat Build of Keycloak, streams for Apache Kafka 2, Red Hat OpenShift AI (RHOAI), Red Hat Data Grid 8, Red Hat Satellite 6, Cryostat 4 on RHEL 9, Red Hat JBoss Enterprise Application Platform 7, Red Hat AMQ Broker 7, OpenShift Serverless
Provider severity
HIGH
Conflicts
2

CVE-2026-42583

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

PUBLISHED
Vendor
io.netty, io.netty, netty
Product
netty-codec-compression, netty-codec, netty
Provider severity
HIGH
Conflicts
2

CVE-2026-42582

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[

PUBLISHED
Vendor
netty, io.netty
Product
netty, netty-codec-http3
Provider severity
HIGH
Conflicts
2

CVE-2026-42581

A flaw was found in Netty's HttpObjectDecoder. A remote attacker can exploit this by sending a specially crafted HTTP/1.0 request that includes both `Transfer-Encoding: chunked` and `Content-Length` headers. While Netty correctly strips the conflicting `Content-Length` header for HTTP/1.1 messages, this guard is absent for HTTP/1.0. This can lead to HTTP request smuggling, where downstream proxies or handlers may misinterpret message boundaries, potentially allowing an attacker to bypass securit

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, netty, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat JBoss Enterprise Application Platform 7, OpenShift Serverless, Red Hat Fuse 7, Cryostat 4 on RHEL 9, Red Hat OpenShift Dev Spaces 3.28, OpenShift Serverless, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Process Automation 7, Red Hat AMQ Clients, Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Red Hat AMQ Broker 7, Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16, Red Hat build of Quarkus 3.33.2, Red Hat OpenShift AI (RHOAI), Red Hat Build of Keycloak, Red Hat OpenShift Dev Spaces 3.28, Red Hat OpenShift AI (RHOAI), OpenShift Serverless, streams for Apache Kafka 3, Red Hat build of Quarkus 3.27.4, OpenShift Serverless, OpenShift Serverless, Red Hat Enterprise Linux AI (RHEL AI) 3, streams for Apache Kafka 2, OpenShift Serverless, Red Hat OpenShift AI (RHOAI), Red Hat Build of Keycloak, Red Hat build of OptaPlanner 8, Red Hat OpenShift AI 2.25, Red Hat JBoss Enterprise Application Platform 8, Red Hat Build of Keycloak, Red Hat build of Apicurio Registry 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), OpenShift Serverless, Red Hat build of Apicurio Registry 2, Red Hat OpenShift AI (RHOAI), OpenShift Serverless, netty, Red Hat Build of Keycloak, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6, OpenShift Serverless, Red Hat Single Sign-On 7, OpenShift Serverless, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Debezium 3, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat OpenShift Dev Spaces 3.29, Red Hat Build of Keycloak, Red Hat Satellite 6, Red Hat OpenShift Dev Spaces 3.28, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Data Grid 8
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-42580

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

PUBLISHED
Vendor
netty, io.netty
Product
netty, netty-codec-http
Provider severity
MEDIUM
Conflicts
2

CVE-2026-4258

Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover a victim's ECDH private key by sending crafted off-curve public keys and observing ECDH outputs. The dhJavaEc() function directly returns the raw x-coordinate of the scalar multiplication result (no hashing), providing a plaintext oracle without requiring any decryption feedback.

PUBLISHED
Vendor
n/a, n/a
Product
sjcl, org.webjars.npm:sjcl
Provider severity
HIGH
Conflicts
3

CVE-2026-42579

A flaw was found in Netty. Netty's DNS (Domain Name System) codec does not properly enforce domain name constraints as defined in RFC 1035 during both encoding and decoding processes. This vulnerability allows a remote attacker to exploit the decoder using malicious DNS responses or exploit the encoder through user-influenced hostnames, leading to a high integrity impact on the affected system.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, netty, Red Hat, Red Hat, Red Hat
Product
Red Hat Build of Keycloak, Cryostat 4 on RHEL 9, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat OpenShift Dev Spaces 3.28, Red Hat build of OptaPlanner 8, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Spaces 3.29, Red Hat OpenShift AI (RHOAI), Red Hat Build of Keycloak, Red Hat build of Apicurio Registry 3, OpenShift Serverless, OpenShift Serverless, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat Data Grid 8, Red Hat Fuse 7, streams for Apache Kafka 2, Red Hat build of Quarkus 3.27.4, Red Hat build of Debezium 3, Red Hat OpenShift Dev Spaces 3.28, Cryostat 4 on RHEL 9, Red Hat OpenShift AI (RHOAI), Red Hat build of Quarkus 3.33.2, OpenShift Serverless, streams for Apache Kafka 3, Red Hat Process Automation 7, OpenShift Serverless, Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16, Red Hat OpenShift AI (RHOAI), OpenShift Serverless, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), OpenShift Serverless, Red Hat JBoss Enterprise Application Platform 7, Red Hat OpenShift Dev Spaces 3.28, Red Hat Enterprise Linux AI (RHEL AI) 3, OpenShift Serverless, Red Hat Build of Keycloak, Red Hat OpenShift AI (RHOAI), Red Hat Build of Keycloak, Red Hat JBoss Enterprise Application Platform 8, OpenShift Serverless, OpenShift Serverless, Cryostat 4 on RHEL 9, Red Hat build of Apicurio Registry 2, Red Hat Single Sign-On 7, Red Hat Build of Keycloak, netty, Red Hat OpenShift AI (RHOAI), OpenShift Serverless, Red Hat OpenShift AI (RHOAI)
Provider severity
HIGH
Conflicts
2

CVE-2026-42578

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers int

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, netty, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
streams for Apache Kafka 2, OpenShift Serverless, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.25, Red Hat Build of Keycloak, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6, netty, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat AMQ Clients, Red Hat AMQ Broker 7, Red Hat Process Automation 7, Red Hat Data Grid 8, Red Hat Build of Keycloak, Red Hat build of Apicurio Registry 2, Red Hat Single Sign-On 7, OpenShift Serverless, Red Hat OpenShift AI (RHOAI), Red Hat build of Debezium 3, Red Hat Fuse 7, Red Hat Satellite 6, Red Hat build of Quarkus 3.33.2, Cryostat 4 on RHEL 9, OpenShift Serverless, Red Hat JBoss Enterprise Application Platform 7, OpenShift Serverless, Cryostat 4 on RHEL 9, Red Hat OpenShift Dev Spaces 3.28, OpenShift Serverless, OpenShift Serverless, Red Hat Build of Keycloak, Red Hat OpenShift Dev Spaces 3.28, Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16, Red Hat Build of Keycloak, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat build of Quarkus 3.27.4, Red Hat Build of Keycloak, Cryostat 4 on RHEL 9, OpenShift Serverless, OpenShift Serverless, Red Hat build of Apicurio Registry 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Spaces 3.28, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat JBoss Enterprise Application Platform 8, Red Hat Enterprise Linux AI (RHEL AI) 3, streams for Apache Kafka 3, Red Hat OpenShift AI (RHOAI), OpenShift Serverless, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of OptaPlanner 8, OpenShift Serverless, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Spaces 3.29
Provider severity
HIGH, LOW
Conflicts
3

CVE-2026-42577

Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll transport fails to detect and close TCP connections that receive a RST after being half-closed, leading to stale channels that are never cleaned up and, in some code paths, a 100% CPU busy-loop in the event loop thread. This vulnerability is fixed in 4.2.13.Final.

PUBLISHED
Vendor
netty
Product
netty
Provider severity
HIGH
Conflicts
0

CVE-2026-42576

apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, DiscoverKeys in pkg/apk/apk/implementation.go unconditionally type-asserts JWKS keys as *rsa.PublicKey without checking the key type. If a repository JWKS endpoint returns a non-RSA key (e.g. EC), the unchecked assertion panics and crashes apko. This affects any workflow that initializes the APK database and fetches repository keys. This issue has been patched in version 1.2.7.

PUBLISHED
Vendor
chainguard-dev
Product
apko
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42575

apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, apko verifies the signature on APKINDEX.tar.gz but never compares individually downloaded .apk packages against the checksum recorded in the signed index. The checksum is parsed and available via ChecksumString(), and the downloaded package control hash is computed, but the two values are never compared in getPackageImpl(). Mismatched packages are silently accepted. An attacker who can su

PUBLISHED
Vendor
chainguard-dev
Product
apko
Provider severity
HIGH
Conflicts
1

CVE-2026-42574

apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before version 1.2.5, a crafted .apk could install a TypeSymlink tar entry whose target pointed outside the build root, and a subsequent directory-creation or file-write entry in the same or later archive could traverse that symlink to reach host paths the build user could write to. This issue has been patched in version 1.2.5.

PUBLISHED
Vendor
chainguard-dev
Product
apko
Provider severity
HIGH
Conflicts
1

CVE-2026-42573

Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks. This issue has been patched in version 5.55.7.

PUBLISHED
Vendor
Red Hat, sveltejs
Product
Red Hat Build of Podman Desktop, svelte
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-42572

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.83.39, a missing authorization directive on the GET /api/v1/stable/dags/tasks endpoint caused Hatchet's tenant-membership check to be skipped for this route. A user authenticated to any tenant on the same Hatchet instance could query the endpoint with another tenant's UUID and a DAG UUID belonging to that tenant, and receive task metadata for that DAG. This vulnerability is fixed in 0.

PUBLISHED
Vendor
hatchet-dev
Product
hatchet
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42571

Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to before 7.23.3, and 7.24.0 to before 7.24.2, there is a a privilege escalation vulnerability affecting Pelican's Web User Interface (WebUI). This attack allows any user authenticated to the WebUI via OAuth to gain admin privileges under certain configurations. This issue has been patched in versions 7.21.5, 7.22.3, 7.23.3, and 7.24.2.

PUBLISHED
Vendor
PelicanPlatform
Product
pelican
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42570

A flaw was found in devalue, a JavaScript library used for serializing values. Due to quirks in some JavaScript engines, the `devalue.parse` function could be exploited by a remote attacker when deserializing specially crafted sparse arrays. This could lead to excessive memory consumption, resulting in a Denial of Service (DoS) for the affected system.

PUBLISHED
Vendor
Red Hat, sveltejs, Red Hat
Product
Red Hat Trusted Artifact Signer 1.4, devalue, Red Hat Build of Podman Desktop
Provider severity
HIGH
Conflicts
2

CVE-2026-4257

The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. This is due to the plugin using the Twig `Twig_Loader_String` template engine without sandboxing, combined with the `cfsPreFill` prefill functionality that allows unauthenticated users to inject arbitrary Twig expressions into form field values via GET parameters. This makes it possible for unauthenticated a

PUBLISHED
Vendor
supsysticcom
Product
Contact Form by Supsystic
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42569

phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access to a legacy import feature. This issue has been patched in version 7.0.6.

PUBLISHED
Vendor
phpvms
Product
phpvms
Provider severity
CRITICAL
Conflicts
1

CVE-2026-42568

Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username parameter is inserted directly into the LDAP filter without proper RFC 4515 escaping. Versions 5.13.0 and 5.12.7 patch the issue.

PUBLISHED
Vendor
yamcs
Product
yamcs
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42567

Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the Svelte runtime can take exponential time to test in <svelte:element this={tag}></svelte:element>. This issue has been patched in version 5.55.7.

PUBLISHED
Vendor
sveltejs
Product
svelte
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42566

Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a malformed character encoding can render other radios unusable over BLE when managed through the iOS app. The malformed name does not need to be maliciously crafted — it can arise from ordinary buffer truncation and has been observed occurring naturally in the wild. At least one code path could place a null terminator in the middle of a multibyte seque

PUBLISHED
Vendor
meshtastic
Product
firmware
Provider severity
HIGH
Conflicts
0

CVE-2026-42565

@workos/authkit-session is a toolkit for building WorkOS AuthKit framework integrations. Prior to 0.5.1, an open redirect vulnerability exists in AuthService.handleCallback due to insufficient validation of the returnPathname value derived from the OAuth state parameter. The state parameter is round-tripped through the identity provider (IdP) and can be influenced by an attacker. The handleCallback function decodes and returns returnPathname without enforcing restrictions on origin or scheme. As

PUBLISHED
Vendor
workos
Product
authkit-session
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42564

jotty·page is a self-hosted app for your checklists and notes. Prior to 1.22.0, an unauthenticated path traversal vulnerability exists in /api/app-icons/[filename]. The filename route parameter is joined into a filesystem path without traversal/boundary validation, allowing file reads outside data/uploads/app-icons/. This vulnerability is fixed in 1.22.0.

PUBLISHED
Vendor
fccview
Product
jotty
Provider severity
HIGH
Conflicts
1

CVE-2026-42563

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, Dulwich's `ProcessMergeDriver` substitutes the file path (from the git tree, controllable by an attacker via a malicious branch) into the merge driver command via the `%P` placeholder and executes it with `subprocess.run(..., shell=True)`. An attacker who can cause a victim to merge an untrusted branch can achieve arbitrary command execution by crafting malicious

PUBLISHED
Vendor
jelmer
Product
dulwich
Provider severity
HIGH
Conflicts
0

CVE-2026-42562

Plainpad is a self hosted note taking app. Prior to version 1.1.1, Plainpad allows a low-privilege authenticated user to self-escalate to administrator by submitting admin=true in PUT /api.php/v1/users/{id}. The endpoint directly persists the admin attribute from user input, and the escalated account can immediately access admin-only routes. This issue has been patched in version 1.1.1.

PUBLISHED
Vendor
alextselegidis
Product
plainpad
Provider severity
HIGH
Conflicts
0

CVE-2026-42561

A flaw was found in python-multipart. A remote attacker can exploit this denial of service (DoS) vulnerability by sending a specially crafted request with an excessive number of part headers or a single very large header value during multipart/form-data parsing. This can lead to excessive CPU utilization, resulting in a denial of service for the affected system.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Kludex, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Migration Toolkit for Applications 8.2, Red Hat OpenShift AI (RHOAI), python-multipart, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Satellite 6, Red Hat Ansible Automation Platform 2.7, Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6, Red Hat Satellite 6, Red Hat Ansible Automation Platform 2.7, Exploit Intelligence, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Ansible Automation Platform 2.6, Red Hat Satellite 6.17, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat AI Inference Server, OpenShift Lightspeed, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.3, Red Hat Satellite 6, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI), OpenShift Lightspeed
Provider severity
HIGH
Conflicts
2

CVE-2026-42560

auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1.2, the Patreon OAuth provider maps every authenticated Patreon account to the same local user.ID, instead of deriving a unique ID from the Patreon account returned by Patreon. In practice, this means all Patreon-authenticated users of an application using this library are collapsed into a single local identity. Any application that trusts token.User.ID as the stable account ke

PUBLISHED
Vendor
go-pkgz
Product
auth
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4256

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology Inc. PassGate allows LDAP Injection. This issue affects PassGate: through 30042026.

PUBLISHED
Vendor
PEAKUP Technology Inc.
Product
PassGate
Provider severity
HIGH
Conflicts
0

CVE-2026-42559

RMCP is an official Rust SDK for the Model Context Protocol. Prior to version 1.4.0, the rmcp crate's Streamable HTTP server transport (crates/rmcp/src/transport/streamable_http_server/) did not validate the incoming Host header. This allowed a malicious public website, via a DNS rebinding attack, to send authenticated requests to an MCP server running on the victim's loopback or private-network interface. This vulnerability is fixed in 1.4.0.

PUBLISHED
Vendor
modelcontextprotocol
Product
rust-sdk
Provider severity
HIGH
Conflicts
1

CVE-2026-42558

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.2, a vulnerability chain consisting of Stored XSS and Iframe Sandbox escape in the Xibo CMS allows users with DataSet permissions to use the Data Connector functionality to craft messages which escape the sandbox and facilitate XSS. Exploitation of the vulnerability is possible on behalf of an authorized user who has both of the following privileges, which are no

PUBLISHED
Vendor
xibosignage
Product
xibo-cms
Provider severity
HIGH
Conflicts
1

CVE-2026-42557

A flaw was found in jupyterlab. This vulnerability allows a remote attacker to achieve arbitrary code execution by presenting a user with a specially crafted notebook containing a deceptive button in its pre-saved HTML cell output. When the user clicks this button, the CommandLinker component executes arbitrary JupyterLab commands without sufficient validation, leading to the execution of unauthorized code.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, jupyter, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, jupyterlab
Product
Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), notebook, Red Hat Migration Toolkit for Applications 8.2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), jupyterlab
Provider severity
HIGH
Conflicts
3

CVE-2026-42556

Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in post content by tampering their own save request and send the public preview link /p/<postId>?share=true to another user. The preview page renders that stored HTML with dangerouslySetInnerHTML on the main application origin. This issue has been patched in version 2.21.7.

PUBLISHED
Vendor
gitroomhq
Product
postiz-app
Provider severity
HIGH
Conflicts
0

CVE-2026-42555

Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32.0, com.ritense.valtimo:case from 13.0.0 to before 13.23.0, and com.ritense.valtimo:contract from 13.4.0 to before 13.23.0 evaluate Spring Expression Language (SpEL) expressions from user-supplied input using StandardEvaluationContext, which provides unrestricted access to Java types and methods. An authenticated user with the ADMIN role can achieve Remote Code Execution and cr

PUBLISHED
Vendor
valtimo-platform, com.ritense.valtimo, com.ritense.valtimo, com.ritense.valtimo
Product
valtimo, contract, case, document
Provider severity
CRITICAL
Conflicts
1

CVE-2026-42554

Fiber is a web framework for Go. Prior to 2.52.12 and 3.1.0, Cross-Site Scripting vulnerability in Go Fiber allows a remote attacker to inject arbitrary HTML/JavaScript by supplying Accept: text/html on any request whose handler passes attacker-influenced data to the AutoFormat() feature. The developer opts into content negotiation by calling AutoFormat(), but does not opt into raw HTML emission for a particular request; Fiber chooses that branch from attacker-controlled Accept. The html branch

PUBLISHED
Vendor
gofiber
Product
fiber
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42553

Cinny is a Matrix client. Prior to 4.10.3, A remote authenticated attacker who shares a room with a victim and has permissions to create room emotes (for example in a DM) can cause the victim's client to send their Matrix access token to an attacker-controlled server. This occurs when the victim opens the emoji or sticker picker for the room containing a malicious emote pack. This is caused by an incorrect fallback in EmojiBoard that uses untrusted pack.meta.avatar (user-controlled) without conv

PUBLISHED
Vendor
cinnyapp
Product
cinny
Provider severity
HIGH
Conflicts
0

CVE-2026-42552

Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the default error handler Engine::_error() writes the full exception message, exception code, and stack trace (including absolute filesystem paths) directly into the HTTP 500 response, with no debug gating. Production deployments leak internal paths, any secret interpolated into an exception message, and full module structure — giving attackers primitives for chaining other weaknesses (LFI, path traversal). This vulnerability is f

PUBLISHED
Vendor
flightphp
Product
core
Provider severity
HIGH
Conflicts
0

CVE-2026-42551

Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Request::getMethod() unconditionally honors the X-HTTP-Method-Override header and the $_REQUEST['_method'] parameter on any HTTP verb (including safe verbs such as GET), with no opt-in and no whitelist of permitted target methods. A GET request can silently become a DELETE or PUT, enabling CSRF escalation against destructive endpoints, bypass of middleware gated on unsafe verbs, and cache poisoning between CDN and origin. This vul

PUBLISHED
Vendor
flightphp
Product
core
Provider severity
HIGH
Conflicts
0

CVE-2026-42550

Flight is an extensible micro-framework for PHP. Prior to 3.18.1, SimplePdo::insert(), SimplePdo::update(), and SimplePdo::delete() build SQL statements by concatenating the $table argument and the keys of the $data array directly into the query, with no identifier quoting and no validation. When an application forwards user-controlled data shapes to these helpers — a common and documented pattern, e.g. $db->insert('users', $request->data->getData()) — an attacker can inject arbitrary SQL by cra

PUBLISHED
Vendor
flightphp
Product
core
Provider severity
HIGH
Conflicts
0

CVE-2026-4255

A DLL search order hijacking vulnerability in Thermalright TR-VISION HOME on Windows (64-bit) allows a local attacker to escalate privileges via DLL side-loading. The application loads certain dynamic-link library (DLL) dependencies using the default Windows search order, which includes directories that may be writable by non-privileged users.\n\n\n\nBecause these directories can be modified by unprivileged users, an attacker can place a malicious DLL with the same name as a legitimate dependenc

PUBLISHED
Vendor
thermalright
Product
TR-VISION HOME
Provider severity
HIGH
Conflicts
0

CVE-2026-42549

Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the make:controller CLI command calls mkdir(..., recursive: true) on a path built from the user-supplied controller name, before Nette's class-name validation runs. The class-file write is correctly rejected by Nette when the name contains /, but the recursive directory creation side effect is already committed — including directories located outside the project root through ../ traversal. This vulnerability is fixed in 3.18.1.

PUBLISHED
Vendor
flightphp
Product
core
Provider severity
MEDIUM
Conflicts
0