Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-42548

Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Flight::jsonp() concatenates the ?jsonp= query parameter directly into an application/javascript response body without validating that the value is a legal JavaScript identifier. An attacker can inject arbitrary JavaScript that executes in the response origin, enabling reflected cross-site scripting. This vulnerability is fixed in 3.18.1.

PUBLISHED
Vendor
flightphp
Product
core
Provider severity
HIGH
Conflicts
0

CVE-2026-42547

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. In versions prior to 2.4.28, users can create alerts for customers that are not assigned to them. This can be abused to falsely attribute fake alerts to customers. In combination with Cross-Site Scripting, this can also be used to exfiltrate alerts from other customers. Version 2.4.28 contains a patch.

PUBLISHED
Vendor
dfir-iris
Product
iris-web
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42546

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.3.0 and prior to version 4.11.0, a resource leak exists in OP-TEE’s shared memory cleanup logic because the function `cleanup_shm_refs()` in `core/tee/entry_std.c` fails to apply a required bitmask (`OPTEE_MSG_ATTR_TYPE_MASK`) to parameter attributes. When processing non-contiguous memory parameters from a normal-

PUBLISHED
Vendor
OP-TEE
Product
optee_os
Provider severity
LOW
Conflicts
0

CVE-2026-42545

Granian is a Rust HTTP server for Python applications. From 0.2.0 to 2.7.4, Granian aborts a worker process if a WSGI application returns an invalid HTTP response header name or value. The WSGI response conversion path uses .unwrap() on both the header name and header value constructors, so malformed output from the application becomes a process abort instead of a handled error. This vulnerability is fixed in 2.7.4.

PUBLISHED
Vendor
emmett-framework
Product
granian
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42544

Granian is a Rust HTTP server for Python applications. From 1.2.0 to 2.7.4, Granian aborts a worker process when an unauthenticated client sends a WebSocket upgrade request whose Sec-WebSocket-Protocol header contains non-ASCII bytes. The crash happens in Granian's WebSocket scope construction path, before the ASGI application is invoked. This vulnerability is fixed in 2.7.4.

PUBLISHED
Vendor
emmett-framework
Product
granian
Provider severity
HIGH
Conflicts
1

CVE-2026-42543

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 are vulnerable to a cross-site request forgery attack, because they use the HTTP method `GET` to change state on the server. Version 2.4.28 contains a patch.

PUBLISHED
Vendor
dfir-iris
Product
iris-web
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42542

TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash the taosd server process by sending a single crafted RPC packet. No credentials or prior session state are required. Version 3.4.1.6 fixes the issue.

PUBLISHED
Vendor
taosdata
Product
TDengine
Provider severity
HIGH
Conflicts
0

CVE-2026-42541

Kubewarden is a policy engine for Kubernetes. Prior to , An attacker with privileged AdmissionPolicy or AdmissionPolicyGroup create permissions (which isn't the default) can craft a policy that makes use of the can_i host callback. The callback issues a SubjectAccessReview (SAR) requests to enumerate RBAC permissions of any user or service account across the cluster. can_i does not perform that check to enforce the context-aware allow-list and forwards the request directly to the callback handle

PUBLISHED
Vendor
kubewarden
Product
kubewarden-controller
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42540

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 allow a user to alter values in the database via manipulated API requests. Version 2.4.28 contains a patch.

PUBLISHED
Vendor
dfir-iris
Product
iris-web
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4254

A weakness has been identified in Tenda AC8 up to 16.03.50.11. This vulnerability affects the function doSystemCmd of the file /goform/SysToolChangePwd of the component HTTP Endpoint. This manipulation of the argument local_2c causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
Tenda
Product
AC8
Provider severity
CRITICAL
Conflicts
2

CVE-2026-42539

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 return sensitive data to the user which are not required for the client’s operation. Version 2.4.28 contains a patch.

PUBLISHED
Vendor
dfir-iris
Product
iris-web
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42538

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 do not properly validate uploaded files. The application can therefore be misused to host phishing pages, amongst other things. This also creates another instance of a Cross-Site Scripting (XSS) vulnerability. Version 2.4.28 contains a patch.

PUBLISHED
Vendor
dfir-iris
Product
iris-web
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42536

A flaw was found in Apache HTTP Server, specifically within the mod_xml2enc module. This heap-based buffer overflow vulnerability can be triggered when processing untrusted content through the xml2StartParse function. A remote attacker could potentially exploit this to cause a denial of service, information disclosure, or possibly arbitrary code execution.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Apache Software Foundation, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 8, Red Hat Hardened Images, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10.0 Extended Update Support, Apache HTTP Server, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10
Provider severity
HIGH
Conflicts
2

CVE-2026-42535

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache HTTP Server
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42534

A flaw was found in Unbound. An adversary who can query a vulnerable Unbound instance and control a slow or malicious domain name server can exploit a vulnerability in the jostle logic. This flaw allows retransmitted queries to renew the age of slow-running queries, preventing them from being identified as aged and replaced. This can degrade Unbound's resolution performance, potentially leading to a denial of resolution service through coordinated attacks.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, NLnet Labs
Product
Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 6, Red Hat Hardened Images, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Unbound
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-42533

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a he

PUBLISHED
Vendor
F5, F5
Product
NGINX Plus, NGINX Open Source
Provider severity
CRITICAL, HIGH
Conflicts
2

CVE-2026-42530

A flaw was found in the ngx_http_v3_module module of NGINX. When NGINX is configured to use the HTTP/3 QUIC module, an attacker can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream and cause a use-after-free issue, potentially allowing code execution or a denial of service by forcing the process to restart.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, F5, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 10, Red Hat Lightspeed proxy 1, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Hardened Images, NGINX Open Source, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-4253

A security flaw has been discovered in Tenda AC8 16.03.50.11. This affects the function route_set_user_policy_rule of the file /cgi-bin/UploadCfg of the component Web Interface. The manipulation of the argument wans.policy.list1 results in os command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

PUBLISHED
Vendor
Tenda
Product
AC8
Provider severity
MEDIUM
Conflicts
2

CVE-2026-42527

Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.**;javax.**;org.apache.camel.**;!*', or the no-'javax.**' variant in the aggregation-repository components) uses a recursive 'java.**' glob that admits classes whose hashCode/equals/readObject methods perform network I/O, notably java.net.URL and java.net.InetAddress. When an attacker can deliver

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Camel
Provider severity
HIGH
Conflicts
0

CVE-2026-42526

In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0, the team-scoping logic could resolve a `conn_id` containing a `/` (e.g. `"my_team/conn"`) to the same path as another team's team-scoped secret when the caller had no team context. A privileged caller without team context could therefore retrieve another team's secret by crafting a colliding `conn_id`. Fixed in 9.28.0 by switching the team-scope separator to `--` and rejectin

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow Amazon provider
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42525

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Microsoft Entra ID (previously Azure AD) Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42524

Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins HTML Publisher Plugin
Provider severity
HIGH
Conflicts
0

CVE-2026-42523

Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall/Read permission.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins GitHub Plugin
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42522

A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacker-specified GitHub App credentials.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins GitHub Branch Source Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42521

Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in configuration when deserializing inheritance strategies, without restricting the classes that can be instantiated, allowing attackers with Item/Configure permission to instantiate arbitrary types, which may lead to information disclosure or other impacts depending on the classes available on the classpath.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Matrix Authorization Strategy Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42520

Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Credentials Binding Plugin
Provider severity
HIGH
Conflicts
0

CVE-2026-4252

A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The manipulation leads to reliance on ip address for authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
Tenda
Product
AC8
Provider severity
CRITICAL
Conflicts
2

CVE-2026-42519

A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1 and earlier allows attackers with Overall/Read permission to enumerate pending and approved Script Security classpaths.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Script Security Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42518

This vulnerability exists in e-Sushrut due to disclosure of sensitive information and hardcoded AES encryption keys in client-side JavaScript. An unauthenticated remote attacker could exploit this vulnerability by accessing the client-side code to extract sensitive information and cryptographic keys. Successful exploitation of this vulnerability could lead to exposure of sensitive data and compromise of cryptographic protections on the targeted system.

PUBLISHED
Vendor
CDAC-Noida
Product
e-Sushrut, Hospital Management Information System (HMIS)
Provider severity
HIGH
Conflicts
0

CVE-2026-42517

This vulnerability exists in e-Sushrut due to the use of reversible Base64 encoding for protecting sensitive data. An authenticated attacker could exploit this vulnerability by decoding and manipulating Base64-encoded parameters in the request URL to gain unauthorized access to sensitive information on the targeted system.

PUBLISHED
Vendor
CDAC-Noida
Product
e-Sushrut, Hospital Management Information System (HMIS)
Provider severity
HIGH
Conflicts
0

CVE-2026-42516

This vulnerability exists in e-Sushrut due to improper authorization checks during resource access. An authenticated attacker could exploit this vulnerability by manipulating encoded parameters in the request URL to gain unauthorized access to patient accounts on the targeted system.

PUBLISHED
Vendor
CDAC-Noida
Product
e-Sushrut, Hospital Management Information System (HMIS)
Provider severity
HIGH
Conflicts
0

CVE-2026-42515

This vulnerability exists in e-Sushrut due to improper access control in resource access validation. An authenticated attacker could exploit this vulnerability by manipulating parameter in the API request URL to gain unauthorized access to sensitive information of patients on the targeted system.

PUBLISHED
Vendor
CDAC-Noida
Product
e-Sushrut, Hospital Management Information System (HMIS)
Provider severity
HIGH
Conflicts
0

CVE-2026-42514

This vulnerability exists in e-Sushrut due to exposure of OTPs in plaintext within API responses. A remote attacker could exploit this vulnerability by intercepting API responses containing valid OTPs. Successful exploitation of this vulnerability could allow an attacker to impersonate the target user and gain unauthorized access to user accounts on the targeted system.

PUBLISHED
Vendor
CDAC-Noida
Product
e-Sushrut, Hospital Management Information System (HMIS)
Provider severity
HIGH
Conflicts
0

CVE-2026-42513

This vulnerability exists in e-Sushrut due to improper authentication logic that relies on client-side response parameters to determine authentication status. A remote attacker could exploit this vulnerability by intercepting and modifying the server response. Successful exploitation of this vulnerability could allow the attacker to bypass authentication and gain unauthorized access to user accounts on the targeted system.

PUBLISHED
Vendor
CDAC-Noida
Product
e-Sushrut, Hospital Management Information System (HMIS)
Provider severity
HIGH
Conflicts
0

CVE-2026-42512

As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the array incorrectly calculates its new size when requesting memory, resulting in a heap buffer overrun. A specially crafted packet can cause dhclient to overrun its buffer of environment entries. This can result in a crash, but it may be possible to leverage this bug to achieve remote code execution.

PUBLISHED
Vendor
FreeBSD
Product
FreeBSD
Provider severity
HIGH
Conflicts
0

CVE-2026-42511

The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subsequently re-parsed by dhclient, e.g., after a system restart, an attacker-controlled field from the lease is passed to dhclient-script(8), which evaluates it. A rogue DHCP server may be able to execute arbirary code as root on a system running dhclient.

PUBLISHED
Vendor
FreeBSD
Product
FreeBSD
Provider severity
HIGH
Conflicts
0

CVE-2026-42510

OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.

PUBLISHED
Vendor
OpenStack
Product
Ironic
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4251

A vulnerability was determined in CityData CityChat up to 0.12.6 on Android. Affected by this vulnerability is an unknown functionality of the file resources/assets/flutter_assets/assets/credentials.json of the component ai.citydata.citychat. Executing a manipulation can lead to unprotected storage of credentials. The attack requires local access. A high complexity level is associated with this attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be u

PUBLISHED
Vendor
CityData
Product
CityChat
Provider severity
LOW
Conflicts
2

CVE-2026-42509

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 through 10.8.0. Users are recommended to upgrade to version 10.9.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Wicket
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42508

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, golang.org/x/crypto, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux CodeReady Linux Builder (v. 10), OpenShift API for Data Protection 1.6, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Advanced Cluster Security for Kubernetes 4.10, multicluster engine for Kubernetes 2.8, Red Hat Quay 3.15, OpenShift API for Data Protection, RHEM 1.1 for RHEL 9, Red Hat Ceph Storage 9, Red Hat OpenShift Builds 1.8.1, Red Hat OpenShift Container Platform 4, OpenShift Serverless, Red Hat Quay 3.9, Red Hat Trusted Artifact Signer 1.4, Red Hat Edge Manager 1.0, Red Hat Quay 3, Red Hat Enterprise Linux 9, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenStack Platform 17.1, Assisted Installer for Red Hat OpenShift Container Platform 2, Red Hat Hardened Images, Red Hat Quay 3.12, Red Hat OpenStack Platform 16.2, RHEM 1.0 for RHEL 9, Red Hat Openshift Data Foundation 4.22, RHEM 1.1 for RHEL 10, Red Hat Advanced Cluster Security 4.9, Red Hat Enterprise Linux 9, Red Hat OpenShift Builds 1.7.3, External Secrets Operator for Red Hat OpenShift, Red Hat Quay 3.1, Red Hat Enterprise Linux 8, Red Hat Quay 3.16, Red Hat Enterprise Linux AppStream (v. 9), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, DevWorkspace Operator 0.42, Red Hat Enterprise Linux AppStream (v. 10), Red Hat OpenShift GitOps, Red Hat Advanced Cluster Management for Kubernetes 2.11, Red Hat Edge Manager 1.1, Red Hat OpenStack Platform 18.0, golang.org/x/crypto/ssh/knownhosts, Red Hat Enterprise Linux 10, multicluster engine for Kubernetes 2.1, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux AppStream (v. 8)
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-42507

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.

PUBLISHED
Vendor
Go standard library
Product
net/textproto
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42506

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

PUBLISHED
Vendor
golang.org/x/net
Product
golang.org/x/net/html
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42505

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

PUBLISHED
Vendor
Go standard library
Product
crypto/tls
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42504

Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

PUBLISHED
Vendor
Go standard library
Product
mime
Provider severity
HIGH
Conflicts
1

CVE-2026-42503

gopls by default communicates via pipe. However, -port and -listen flags are supported as means of debugging. If -listen is given a value without an explicit host (e.g. :8080), or -port is used, gopls will listen on 0.0.0.0.  As a result, users might inadvertently cause gopls to bind 0.0.0.0. This can allow a malicious party on the same network to execute code arbitrarily via gopls.

PUBLISHED
Vendor
golang.org/x/tools
Product
golang.org/x/tools/gopls
Provider severity
HIGH
Conflicts
0

CVE-2026-42502

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

PUBLISHED
Vendor
golang.org/x/net
Product
golang.org/x/net/html
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42501

A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently installed toolchain (due to the GOTOOLCHAIN environment variable, or a go.work or go.mod with a toolchain

PUBLISHED
Vendor
Go toolchain
Product
cmd/go
Provider severity
HIGH
Conflicts
1

CVE-2026-42500

Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image.

PUBLISHED
Vendor
golang.org/x/image
Product
golang.org/x/image/bmp
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4250

A vulnerability was found in Albert Sağlık Hizmetleri ve Ticaret Albert Health up to 1.7.3 on Android. Affected is an unknown function of the file resources/assets/service-account.json of the component Google Cloud Service Account Key Handler. Performing a manipulation results in unprotected storage of credentials. The attack requires a local approach. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been made public and could be used. The v

PUBLISHED
Vendor
Albert Sağlık Hizmetleri ve Ticaret
Product
Albert Health
Provider severity
LOW
Conflicts
2

CVE-2026-42499

Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Go standard library, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 10, OpenShift Service Mesh 3, Multicluster Engine for Kubernetes, Red Hat Openshift Data Foundation 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Ansible Automation Platform 2, OpenShift Service Mesh 2, Red Hat OpenShift Cluster Manager CLI, Red Hat Enterprise Linux 9, Zero Trust Workload Identity Manager - Tech Preview, Multicluster Engine for Kubernetes, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4, Multicluster Global Hub, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat Satellite 6, Red Hat OpenShift GitOps, Red Hat OpenShift Container Platform 4, Red Hat Migration Toolkit for Applications 8.2, Red Hat Advanced Cluster Security for Kubernetes 4.10, Multiarch Tuning Operator, OpenShift API for Data Protection, Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, Red Hat Certification Program for Red Hat Enterprise Linux 9, Multicluster Engine for Kubernetes, Multicluster Engine for Kubernetes, Red Hat Enterprise Linux 10, cert-manager Operator for Red Hat OpenShift, Red Hat Enterprise Linux 10, Red Hat OpenShift Service Mesh 3.1, Red Hat OpenShift AI (RHOAI), Multicluster Engine for Kubernetes, Gatekeeper 3, Cryostat 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, Red Hat OpenShift Service Mesh 3.3, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Multicluster Engine for Kubernetes, Red Hat Hardened Images, File Integrity Operator, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat OpenShift Service Mesh 3.2, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat OpenShift Service Mesh 3.1, Red Hat OpenShift distributed tracing 3, Logical Volume Manager Storage, Red Hat Enterprise Linux 10, Red Hat OpenShift Service Mesh 3.0, Red Hat Openshift Data Foundation 4, Red Hat OpenShift Service Mesh 3.3, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 9, Red Hat OpenShift Virtualization 4, Red Hat Enterprise Linux 8, Multicluster Engine for Kubernetes, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Service Mesh 3.0, Red Hat OpenShift Service Mesh 3.2, Red Hat OpenShift Container Platform 4, Red Hat Ceph Storage 5, Red Hat OpenShift Container Platform 4, Red Hat Developer Hub 1.10, Red Hat OpenShift AI (RHOAI), Logical Volume Manager Storage, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Logical Volume Manager Storage, Red Hat Migration Toolkit 1.8, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 17.1, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift for Windows Containers, Red Hat Enterprise Linux 10, OpenShift Developer Tools and Services, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat Ceph Storage 6, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3.15, Multicluster Engine for Kubernetes, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Virtualization 4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Workspaces Operator, Multicluster Engine for Kubernetes, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Service Mesh 3.3, Red Hat Openshift Data Foundation 4, OpenShift Service Mesh 2, Red Hat OpenShift GitOps, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Lightspeed for Runtimes Operator, Red Hat Hardened Images, Red Hat Enterprise Linux 9, Assisted Installer for Red Hat OpenShift Container Platform 2, Red Hat Openshift Data Foundation 4, Red Hat Developer Hub 1.9, Red Hat OpenShift Service Mesh 3.1, Red Hat Service Interconnect 2, Confidential Compute Attestation, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Logging for Red Hat OpenShift 6.2, Red Hat OpenShift AI 2.25, Confidential Compute Attestation, Red Hat Quay 3.12, Red Hat OpenShift Dev Spaces, Logging Subsystem for Red Hat OpenShift 6.4, Red Hat Openshift Data Foundation 4, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Multicluster Global Hub, External Secrets Operator for Red Hat OpenShift, Red Hat OpenShift AI (RHOAI), Red Hat OpenStack Platform 18.0, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Enterprise Linux 8, Red Hat OpenShift Service Mesh 3.3, Custom Metric Autoscaler operator for Red Hat Openshift, Red Hat OpenShift Virtualization 4, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Service Mesh 3.2, Red Hat OpenShift Virtualization 4, OpenShift Serverless, Red Hat OpenShift AI (RHOAI), OpenShift API for Data Protection 1.6, Red Hat Service Interconnect 1, Red Hat Trusted Artifact Signer 1.4, Red Hat Advanced Cluster Security 4.9, Red Hat OpenShift Service Mesh 3.2, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 8, Multicluster Engine for Kubernetes, Red Hat OpenStack Platform 16.2, Red Hat Enterprise Linux 9, Red Hat Advanced Cluster Management for Kubernetes 2, net/mail, Red Hat Edge Manager 1, Security Profiles Operator, Red Hat OpenShift AI (RHOAI), Red Hat Trusted Artifact Signer, Red Hat Enterprise Linux 10, Red Hat OpenShift Service Mesh 3.0, Red Hat Quay 3, Red Hat OpenShift AI (RHOAI), Network Observability Operator, Red Hat Edge Manager 1, OpenShift Pipelines, Zero Trust Workload Identity Manager, OpenShift Lightspeed, Power monitoring for Red Hat OpenShift, Red Hat OpenShift Service Mesh 3.1, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Spaces, Red Hat OpenShift Service Mesh 3.0, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Quay 3.9, Red Hat OpenShift Container Platform 4, Red Hat Quay 3.16, Red Hat OpenShift Container Platform 4, Red Hat Quay 3.1, Red Hat Ceph Storage 9, Confidential Compute Attestation
Provider severity
HIGH
Conflicts
2