Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-40983

In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.

PUBLISHED
Vendor
Red Hat, Red Hat, Spring, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Build of Apache Camel 4.18 for Quarkus 3.33, Red Hat Fuse 7, Micrometer, streams for Apache Kafka 3, Red Hat AMQ Clients, Red Hat Build of Keycloak, Red Hat Satellite 6, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Data Grid 8.6.2, Red Hat OpenShift Dev Spaces, Red Hat AMQ Broker 7, Red Hat Build of Keycloak, Red Hat OpenShift Dev Spaces, Red Hat Build of Keycloak, Red Hat build of Apicurio Registry 3, Red Hat build of Apache Camel - HawtIO 4, Red Hat Build of Keycloak, Red Hat build of Quarkus, Red Hat Build of Keycloak, Red Hat Build of Keycloak, Red Hat build of Apache Camel for Spring Boot 4, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6, Red Hat Build of Keycloak, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat OpenShift Dev Spaces, Red Hat build of Debezium 3, streams for Apache Kafka 2
Provider severity
HIGH
Conflicts
2

CVE-2026-40982

A flaw was found in Spring Cloud Config. A remote attacker can exploit a directory traversal vulnerability by sending a specially crafted URL to the spring-cloud-config-server module. This allows the attacker to access arbitrary text and binary files on the system.

PUBLISHED
Vendor
Spring, Red Hat, Red Hat
Product
Spring Cloud Config, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Enterprise Linux 8
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-40981

When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 t

PUBLISHED
Vendor
Red Hat, Spring, Red Hat
Product
Red Hat Enterprise Linux 8, Spring Cloud Config, Red Hat JBoss Enterprise Application Platform Expansion Pack
Provider severity
HIGH
Conflicts
2

CVE-2026-40980

In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayoutTextStripper`. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)

PUBLISHED
Vendor
Spring
Product
Spring AI
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40979

In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)

PUBLISHED
Vendor
Spring
Product
Spring AI
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40978

SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)

PUBLISHED
Vendor
Spring
Product
Spring AI
Provider severity
HIGH
Conflicts
0

CVE-2026-40977

When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is started. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); PID file / symlink behavior (`ApplicationPidFileWriter`). Versions that are no longer supported are also affected per vendor advisory.

PUBLISHED
Vendor
Spring
Product
Spring Boot
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40976

In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable. Affected: Spring Boot 4.0.0–4.0.5; upgrade

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Spring, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat build of Apache Camel - HawtIO 4, Red Hat OpenShift Dev Spaces, Red Hat Enterprise Linux 8, Red Hat AMQ Clients, Red Hat AMQ Broker 7, Red Hat Fuse 7, Red Hat Enterprise Linux 9, Spring Boot, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform 8, Red Hat AMQ Broker 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat build of Apache Camel - HawtIO 4, Red Hat JBoss Enterprise Application Platform 7, Red Hat OpenShift Dev Spaces, Red Hat JBoss Enterprise Application Platform 8, Red Hat build of OptaPlanner 8, Red Hat Data Grid 8, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apache Camel for Spring Boot 4, Red Hat JBoss Enterprise Application Platform 7, Red Hat Fuse 7, Red Hat Single Sign-On 7, Red Hat Process Automation 7
Provider severity
CRITICAL
Conflicts
2

CVE-2026-40975

Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); random value property source / weak PRNG for secrets. Versions that are no longer supported are also affected per vendor

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Spring, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14, Red Hat Fuse 7, Red Hat Enterprise Linux 8, Red Hat AMQ Clients, Red Hat JBoss Enterprise Application Platform 7, Red Hat OpenShift Dev Spaces 3.28, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat AMQ Broker 7, Red Hat OpenShift Dev Spaces 3.28, Red Hat JBoss Enterprise Application Platform 8, Spring Boot, HawtIO HawtIO 4.4.0, Red Hat Data Grid 8.6.1, Red Hat Single Sign-On 7, Red Hat Enterprise Linux 9, Red Hat Process Automation 7, Red Hat build of OptaPlanner 8
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-40974

Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); Cassandra SSL auto-configuration. Versions that are no longer supported are also affected per vendor advisory.

PUBLISHED
Vendor
Spring
Product
Spring Boot
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40973

A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across application restarts, this may allow the attacker to read session information and hijack authenticated users or deploy a gadget chain and execute code as the application's user. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–

PUBLISHED
Vendor
Spring
Product
Spring Boot
Provider severity
HIGH
Conflicts
0

CVE-2026-40972

An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution in the remote application. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); DevTools remote se

PUBLISHED
Vendor
Spring
Product
Spring Boot
Provider severity
HIGH
Conflicts
0

CVE-2026-40971

When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor advisory.

PUBLISHED
Vendor
Spring
Product
Spring Boot
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40970

When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

PUBLISHED
Vendor
Spring
Product
Spring Boot
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40969

The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure, which may be useful for further attacks. Affected versions: Spring gRPC: 1.0.0 - 1.0.2 (fixed in 1.0.3). Older, unsupported versions are also affected.

PUBLISHED
Vendor
Spring
Product
Spring gRPC
Provider severity
LOW
Conflicts
0

CVE-2026-40968

When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited by a subsequent unauthenticated request on the same thread. This may allow the subsequent user to gain escalated permissions. Affected versions: Spring gRPC: 1.0.0 - 1.0.2 (fixed in 1.0.3). Older, unsupported versions are also affected.

PUBLISHED
Vendor
Spring
Product
Spring gRPC
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40967

In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are not properly escaped, leading to the ability to alter the query. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)

PUBLISHED
Vendor
Spring
Product
Spring AI
Provider severity
HIGH
Conflicts
0

CVE-2026-40966

In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conversationId. Only applications that use VectorStoreChatMemoryAdvisor and pass user-supplied input as a conversationId are affected.

PUBLISHED
Vendor
VMware
Product
Spring AI
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40965

Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed through the public /token_keys endpoint. This endpoint is designed to provide public key material for JWT token verification but incorrectly exposes private key components for EC keys. The vulnerability affects deployments using EC keys for JWT token signing. The vulnerability does not affect RSA key co

PUBLISHED
Vendor
Cloud Foundry Foundation, Cloud Foundry Foundation
Product
uaa_release, CF Deployment
Provider severity
CRITICAL
Conflicts
2

CVE-2026-40964

Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for every application and platform component via minting a JWT that the cf-auth-proxy accepts as a valid logs.admin token. Affected versions: - log-cache_release: all versions through v3.2.6 (inclusive); fixed in v3.2.7 or later - CF Deployment: all versions through v55.?.0 (inclusive); fixed in v55.?.0 or later (bundles log-c

PUBLISHED
Vendor
Cloud Foundry Foundation, Cloud Foundry Foundation
Product
log-cache_release, CF Deployment
Provider severity
HIGH
Conflicts
1

CVE-2026-40963

The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking whether the caller had read permission on those linked Dags. An authenticated UI/API user authorized for one Dag could enumerate linked Dag IDs and dependency metadata for other Dags they were not authorized to read. Affects deployments that rely on per-Dag read scoping to keep Dag dependency topology private across teams. Users are advised to upgrade to `apache-airflow` 3.2.2

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow
Provider severity
LOW
Conflicts
0

CVE-2026-40962

FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.

PUBLISHED
Vendor
FFmpeg
Product
FFmpeg
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40961

A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe_url` check, enabling redirection from a trusted Airflow domain to an attacker-controlled origin. Users are advised to upgrade to `apache-airflow` 3.2.2 or later. As a defense-in-depth mitigation, deployment operators can place Airflow behind a reverse proxy that strips off-domain `next=` query parameters before they reach the login endpoint.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow
Provider severity
HIGH
Conflicts
0

CVE-2026-40960

Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure environment or HTTP API, and also receive access to it.

PUBLISHED
Vendor
Luanti
Product
Luanti
Provider severity
HIGH
Conflicts
0

CVE-2026-4096

IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking

PUBLISHED
Vendor
IBM
Product
DevOps Plan
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40959

Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.

PUBLISHED
Vendor
Luanti
Product
Luanti
Provider severity
CRITICAL
Conflicts
0

CVE-2026-40958

CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.

PUBLISHED
Vendor
Absolute Security
Product
Secure Access
Provider severity
LOW
Conflicts
0

CVE-2026-40957

o   CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator.

PUBLISHED
Vendor
Absolute Security
Product
Secure Access
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40956

CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can cause a small amount of random memory to leak.

PUBLISHED
Vendor
Absolute Security
Product
Secure Access
Provider severity
LOW
Conflicts
0

CVE-2026-40955

CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.

PUBLISHED
Vendor
Absolute Security
Product
Secure Access
Provider severity
LOW
Conflicts
0

CVE-2026-40954

CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client

PUBLISHED
Vendor
Absolute Security
Product
Secure Access
Provider severity
LOW
Conflicts
0

CVE-2026-40953

CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can create a denial of service attack against the client over which they have control.

PUBLISHED
Vendor
Absolute Security
Product
Secure Access
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40952

CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a non-default location.

PUBLISHED
Vendor
Absolute Security
Product
Secure Access
Provider severity
HIGH
Conflicts
0

CVE-2026-40951

CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and trigger a denial of service.

PUBLISHED
Vendor
Absolute Software
Product
Secure Access
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40950

CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a specially crafted message to the server and cause a denial of service

PUBLISHED
Vendor
Absolute Software
Product
Secure Access
Provider severity
HIGH
Conflicts
0

CVE-2026-40949

CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to trigger a denial of service.

PUBLISHED
Vendor
Absolute Software
Product
Secure Access
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40948

The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login / login-callback flow, and did not use PKCE. An attacker with a Keycloak account in the same realm could deliver a crafted callback URL to a victim's browser and cause the victim to be logged into the attacker's Airflow session (login-CSRF / session fixation), where any credentials the victim subsequently stored in Airflow Connections would be harve

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow Providers Keycloak
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40947

Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search path.

PUBLISHED
Vendor
Yubico, Yubico, Yubico
Product
python-fido2, libfido2, yubikey-manager
Provider severity
LOW
Conflicts
1

CVE-2026-40946

Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets SkipClientIDCheck: true in the go-oidc verifier configuration, disabling the standard audience (aud) claim validation at the library level. This allows tokens issued for unrelated services by the same OIDC issuer to be accepted by Oxia. This vulnerability is fixed in 0.16.2.

PUBLISHED
Vendor
oxia-db
Product
oxia
Provider severity
CRITICAL
Conflicts
0

CVE-2026-40945

Oxia is a metadata store and coordination system. Prior to 0.16.2, when OIDC authentication fails, the full bearer token is logged at DEBUG level in plaintext. If debug logging is enabled in production, JWT tokens are exposed in application logs and any connected log aggregation system. This vulnerability is fixed in 0.16.2.

PUBLISHED
Vendor
oxia-db
Product
oxia
Provider severity
HIGH
Conflicts
0

CVE-2026-40944

Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configuration only parses the first PEM block from CA certificate files. When a CA bundle contains multiple certificates (e.g., intermediate + root CA), only the first certificate is loaded. This silently breaks certificate chain validation for mTLS. This vulnerability is fixed in 0.16.2.

PUBLISHED
Vendor
oxia-db
Product
oxia
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40943

Oxia is a metadata store and coordination system. Prior to 0.16.2, a race condition between session heartbeat processing and session closure can cause the server to panic with send on closed channel. The heartbeat() method uses a blocking channel send while holding a mutex, and under specific timing with concurrent close() calls, this can lead to either a deadlock (channel buffer full) or a panic (send on closed channel after TOCTOU gap in KeepAlive). This vulnerability is fixed in 0.16.2.

PUBLISHED
Vendor
oxia-db
Product
oxia
Provider severity
HIGH
Conflicts
0

CVE-2026-40942

The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, The OIDC JWKS and Metadata Document caches used an inverted time comparison (isBefore instead of isAfter), causing the cache to never return cached values. Every incoming request triggered a fresh HTTP fetch of the OIDC Metadata Document and JWKS keys from the OIDC provider. The OIDC token cache for the FHIR client connections used an inverted time comparison (isB

PUBLISHED
Vendor
dev.dsf, datasharingframework, dev.dsf
Product
dsf-bpe-server, dsf, dsf-bpe-process-api-v2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-40941

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31.

PUBLISHED
Vendor
Cacti
Product
cacti
Provider severity
HIGH
Conflicts
0

CVE-2026-4094

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete the entire multi-currency configuration by visiting any wp-admin page with the `woocs_reset` parameter appended. Additionally, because no nonce is verified, this is also e

PUBLISHED
Vendor
realmag777
Product
FOX – Currency Switcher Professional for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-40939

The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, OIDC-authenticated sessions had no configured maximum inactivity timeout. Sessions persisted indefinitely after login, even after the OIDC access token expired. This vulnerability is fixed in 2.1.0.

PUBLISHED
Vendor
datasharingframework, dev.dsf, dev.dsf, dev.dsf
Product
dsf, dsf-fhir-server, dsf-bpe-server, dsf-common-jetty
Provider severity
MEDIUM
Conflicts
1

CVE-2026-40938

A flaw was found in Tekton Pipelines, a system for declaring continuous integration/continuous delivery (CI/CD) pipelines. An authenticated user, able to submit `ResolutionRequest` objects, can exploit a vulnerability by injecting malicious commands into the git resolver's revision parameter. This allows for the execution of unauthorized programs on the resolver pod. Successful exploitation can lead to the exfiltration of all cluster-wide secrets, resulting in significant information disclosure.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, tektoncd, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
OpenShift Pipelines, Red Hat OpenShift Builds 1.8.1, OpenShift Pipelines, OpenShift Pipelines, OpenShift Pipelines, Red Hat OpenShift Builds 1.7.3, OpenShift Pipelines, OpenShift Pipelines, Red Hat OpenShift Builds 1.8.1, OpenShift Pipelines, OpenShift Pipelines, OpenShift Pipelines, Red Hat OpenShift Builds 1.8.1, OpenShift Pipelines, Red Hat OpenShift Builds 1.8.1, OpenShift Pipelines, OpenShift Pipelines, pipeline, OpenShift Pipelines, OpenShift Pipelines, OpenShift Pipelines, Red Hat OpenShift Builds 1.7.3, OpenShift Pipelines, Red Hat OpenShift Pipelines 1.21, OpenShift Pipelines, OpenShift Pipelines, OpenShift Pipelines, OpenShift Pipelines, OpenShift Pipelines, Red Hat OpenShift Builds 1.7.3, Red Hat OpenShift Builds 1.7.3, OpenShift Pipelines, Red Hat OpenShift Pipelines 1.21, OpenShift Pipelines, OpenShift Pipelines, OpenShift Pipelines, Red Hat OpenShift Builds 1.7.3, OpenShift Pipelines, OpenShift Pipelines, OpenShift Pipelines, OpenShift Serverless, Red Hat OpenShift AI (RHOAI), OpenShift Pipelines, OpenShift Pipelines, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Virtualization 4, Red Hat OpenShift Builds 1.7.3, Red Hat OpenShift AI (RHOAI), OpenShift Pipelines, Red Hat OpenShift Virtualization 4, OpenShift Pipelines, OpenShift Pipelines, Red Hat OpenShift Virtualization 4, OpenShift Pipelines, Red Hat OpenShift Builds 1.7.3, OpenShift Pipelines, OpenShift Pipelines, OpenShift Pipelines, OpenShift Pipelines, Red Hat OpenShift Virtualization 4, OpenShift Pipelines, OpenShift Pipelines, OpenShift Pipelines, OpenShift Pipelines, OpenShift Pipelines, OpenShift Pipelines, OpenShift Pipelines, Red Hat OpenShift Pipelines 1.21, Red Hat Trusted Artifact Signer, OpenShift Pipelines, OpenShift Pipelines, OpenShift Pipelines, OpenShift Serverless, Red Hat OpenShift Builds 1.8.1, OpenShift Pipelines, OpenShift Lightspeed, Red Hat OpenShift Builds 1.8.1, OpenShift Pipelines, Red Hat OpenShift AI (RHOAI), OpenShift Pipelines, OpenShift Pipelines, Red Hat OpenShift AI (RHOAI), OpenShift Pipelines
Provider severity
HIGH
Conflicts
3

CVE-2026-40937

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-alpha.94, all four notification target admin API endpoints in `rustfs/src/admin/handlers/event.rs` use a `check_permissions` helper that validates authentication only (access key + session token), without performing any admin-action authorization via `validate_admin_request`. Every other admin handler in the codebase correctly calls `validate_admin_request` with a specific `AdminAction`. This is the only admin handler fi

PUBLISHED
Vendor
rustfs
Product
rustfs
Provider severity
HIGH
Conflicts
0

CVE-2026-40935

WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` accepts the CAPTCHA length (`ql`) directly from the query string with no clamping or sanitization, letting any unauthenticated client force the server to generate a 1-character CAPTCHA word. Combined with a case-insensitive `strcasecmp` comparison over a ~33-character alphabet and the fact that failed validations do NOT consume the stored session token, an attacker can trivially brute-force the CAP

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40934

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at ~/.local/share/jupyter/runtime/jupyter_cookie_secret and is never rotated when a user changes their password. After a password reset and server restart, any previously issued authentication cookie remains cryptographically valid because the signing key has not changed. An attacker who has captured a session cookie through any

PUBLISHED
Vendor
jupyter-server
Product
jupyter_server
Provider severity
HIGH
Conflicts
0