Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-39851

Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange() mutation was revealing the existence of user-provided email addresses in error messages. This vulnerability is fixed in 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118.

PUBLISHED
Vendor
saleor
Product
saleor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39850

Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method View::renderPhpFile() that leads to Local File Inclusion. The function calls extract($_params_, EXTR_OVERWRITE) before the require statement that loads the view file. As a result, a caller-controlled _file_ key in the $params array overwrites the internal local variable specifying which file to include, potentially enabling RCE if an attacker can write PHP files through a separa

PUBLISHED
Vendor
yiisoft
Product
yii2
Provider severity
HIGH
Conflicts
1

CVE-2026-3985

The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' parameter in all versions up to, and including, 1.6.9. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the `has_checkout_consent()` method. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used

PUBLISHED
Vendor
constantcontact
Product
Creative Mail – Easier WordPress & WooCommerce Email Marketing
Provider severity
HIGH
Conflicts
0

CVE-2026-39849

Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1, the `dns.interface` configuration field in Pi-hole FTL accepted newline characters without validation, allowing an attacker to inject arbitrary directives into the generated dnsmasq configuration file. On installations with no admin password set (the default for many deployments), the configuration API is fully accessible without credentials, allowing a network-adjacent attack

PUBLISHED
Vendor
pi-hole
Product
FTL
Provider severity
HIGH
Conflicts
0

CVE-2026-39848

Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed through GET requests without CSRF protection. A remote attacker can cause a logged-in administrator's browser to request /apps/action.php?action=stop&name=<container> or /apps/action.php?action=start&name=<container>, which starts or stops the target container. This vulnerability is fixed in 1.1.0.

PUBLISHED
Vendor
10ij
Product
dockyard
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39847

Emmett is a full-stack Python web framework designed with simplicity. From 2.5.0 to before 2.8.1, the RSGI static handler for Emmett's internal assets (/__emmett__ paths) is vulnerable to path traversal attacks. An attacker can use ../ sequences (eg /__emmett__/../rsgi/handlers.py) to read arbitrary files outside the assets directory. This vulnerability is fixed in 2.8.1.

PUBLISHED
Vendor
emmett-framework
Product
emmett
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39846

SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption content is stored without safe escaping and later unescaped into rendered HTML, creating a stored XSS sink. Because the desktop renderer runs with nodeIntegration enabled and contextIsolation disabled, attacker-controlled JavaScript executes with access to Node.js APIs. In practice,

PUBLISHED
Vendor
siyuan-note
Product
siyuan
Provider severity
CRITICAL
Conflicts
1

CVE-2026-39845

Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable the webhook add-on as a workaround.

PUBLISHED
Vendor
WeblateOrg
Product
weblate
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39844

NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path separators, an attacker can bypass this sanitization on Windows by using backslashes (\) in the upload filename. Applications that construct file paths using file.name (a pattern demonstrated in NiceGUI's bundled examples) are vulnerable to arbitrary file write on Windows. This vulnerability is fixed in 3.10.0.

PUBLISHED
Vendor
zauberzeug
Product
nicegui
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39843

Plane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw is incomplete which could lead to the same full read Server-Side Request Forgery when a normal html page contains a link tag with an href that redirects to a private IP address is supplied to Add link by an authenticated attacker with low privileges. Redirects for the main page URL are validated, but not the favicon fetch path. fetch_and_encode_favicon() still uses requests.get

PUBLISHED
Vendor
makeplane
Product
plane
Provider severity
HIGH
Conflicts
0

CVE-2026-39842

OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine that allow arbitrary code execution on the server. The JavaScript rules engine executes user-supplied scripts via Nashorn's ScriptEngine.eval() without sandboxing, class filtering, or access restrictions, and the authorization check in RulesResourceImpl only restricts Groovy rules to superusers while leaving JavaScript rules unrestricted for any u

PUBLISHED
Vendor
openremote
Product
openremote
Provider severity
CRITICAL
Conflicts
1

CVE-2026-39841

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.

PUBLISHED
Vendor
Wikimedia Foundation
Product
Mediawiki - Cargo Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39840

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows XSS Targeting Non-Script Elements.This issue affects Mediawiki - Cargo Extension: before 3.8.7.

PUBLISHED
Vendor
Wikimedia Foundation
Product
Mediawiki - Cargo Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3984

A weakness has been identified in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This vulnerability affects unknown code of the file save_up_athlete.php. This manipulation of the argument a_name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
Campcodes
Product
Division Regional Athletic Meet Game Result Matrix System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-39839

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.

PUBLISHED
Vendor
Wikimedia Foundation
Product
Mediawiki - Cargo Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39838

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation MediaWiki - ProofreadPage Extension allows XSS Targeting Non-Script Elements. The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.

PUBLISHED
Vendor
Wikimedia Foundation
Product
MediaWiki - ProofreadPage Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39837

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in WikiWorks Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.

PUBLISHED
Vendor
Wikimedia Foundation
Product
Mediawiki - Cargo Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39836

The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).

PUBLISHED
Vendor
Go standard library
Product
net
Provider severity
HIGH
Conflicts
0

CVE-2026-39835

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, golang.org/x/crypto, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Multicluster Engine for Kubernetes, Red Hat OpenShift GitOps, Red Hat Advanced Cluster Security for Kubernetes 4.11, Red Hat OpenShift GitOps, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.22, Red Hat Quay 3.1, Red Hat Advanced Cluster Security for Kubernetes 4.11, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift GitOps, cert-manager Operator for Red Hat OpenShift, Multicluster Engine for Kubernetes, Red Hat Trusted Artifact Signer 1.4, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat Edge Manager 1.1, Red Hat OpenShift Builds 1.7.3, Red Hat Edge Manager 1.1, Red Hat Advanced Cluster Security 4.9, Red Hat Edge Manager 1.1, Red Hat Enterprise Linux 10, Red Hat Advanced Cluster Security 4.9, Red Hat OpenShift Container Platform 4, multicluster engine for Kubernetes 2.1, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Builds 1.7.3, Red Hat OpenShift Builds 1.7.3, Red Hat Trusted Artifact Signer 1.4, Multicluster Engine for Kubernetes, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Security Profiles Operator, Red Hat Advanced Cluster Security for Kubernetes 4.11, Red Hat Edge Manager 1.0, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.3, Red Hat Openshift Data Foundation 4.22, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenShift GitOps, Red Hat Trusted Artifact Signer, Zero Trust Workload Identity Manager - Tech Preview, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Multicluster Engine for Kubernetes, Red Hat Enterprise Linux 10, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift on AWS, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, Red Hat OpenShift GitOps, Red Hat OpenShift Container Platform 4, OpenShift Serverless, multicluster engine for Kubernetes 2.6, Red Hat Ceph Storage 9, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer, Red Hat Advanced Cluster Security 4.9, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift GitOps, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Builds 1.7.3, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.0, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat OpenStack Platform 16.2, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Security 4.9, Red Hat OpenShift Container Platform 4, multicluster engine for Kubernetes 2.8, Red Hat OpenShift Container Platform 4, Security Profiles Operator, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Dev Workspaces Operator, Red Hat OpenStack Platform 17.1, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat Advanced Cluster Security for Kubernetes 4.11, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 17.1, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, Red Hat Openshift Data Foundation 4.22, RHEM 1.1 for RHEL 9, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Zero Trust Workload Identity Manager - Tech Preview, Red Hat OpenStack Platform 18.0, Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux 8, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, RHEM 1.0 for RHEL 9, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Confidential Compute Attestation, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift GitOps, External Secrets Operator for Red Hat OpenShift, Red Hat Advanced Cluster Security for Kubernetes 4.11, OpenShift API for Data Protection, Red Hat Edge Manager 1.0, Red Hat Quay 3.12, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Builds 1.8.1, Red Hat OpenStack Platform 16.2, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, OpenShift Serverless, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, OpenShift API for Data Protection, Red Hat Quay 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.3, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Dev Spaces, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Builds 1.8.1, Red Hat Trusted Artifact Signer 1.3, Red Hat Advanced Cluster Security for Kubernetes 4.10, Confidential Compute Attestation, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat OpenShift Builds 1.8.1, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Security 4.9, Red Hat Edge Manager 1.1, Zero Trust Workload Identity Manager - Tech Preview, Red Hat Edge Manager 1.1, Red Hat OpenShift Builds 1.8.1, Zero Trust Workload Identity Manager, Red Hat OpenShift AI (RHOAI), Red Hat Edge Manager 1.1, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, Red Hat Edge Manager 1.0, Red Hat Edge Manager 1.1, Red Hat OpenShift Builds 1.7.3, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat Trusted Artifact Signer, Red Hat Advanced Cluster Security 4.9, Red Hat OpenShift Builds 1.8.1, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.1, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Virtualization 4, Red Hat Advanced Cluster Security for Kubernetes 4.11, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, Red Hat Trusted Artifact Signer 1.4, Red Hat Edge Manager 1.1, Red Hat Trusted Artifact Signer 1.4, Red Hat Edge Manager 1.1, Red Hat OpenShift Builds 1.7.3, Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift for Windows Containers, Red Hat OpenShift Container Platform 4, Red Hat Quay 3.15, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.4, Red Hat Openshift Data Foundation 4.22, Red Hat Trusted Artifact Signer 1.4, Red Hat Edge Manager 1.0, Red Hat Trusted Artifact Signer 1.4, Red Hat Edge Manager 1.1, RHEM 1.1 for RHEL 10, Red Hat OpenShift Builds 1.8.1, Zero Trust Workload Identity Manager, Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat OpenShift AI (RHOAI), Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.3, Red Hat Trusted Artifact Signer 1.3, Red Hat Trusted Artifact Signer 1.3, Red Hat Edge Manager 1.0, OpenShift API for Data Protection 1.6, OpenShift Pipelines, Red Hat OpenShift Container Platform 4, golang.org/x/crypto/ssh, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Dev Workspaces Operator, Assisted Installer for Red Hat OpenShift Container Platform 2, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift for Windows Containers, Red Hat OpenShift Container Platform 4, Red Hat OpenShift GitOps, Red Hat OpenStack Platform 17.1, Red Hat Openshift Data Foundation 4.22, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenStack Platform 16.2, Red Hat OpenShift Container Platform 4, cert-manager Operator for Red Hat OpenShift, Red Hat Advanced Cluster Security for Kubernetes 4.11, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat OpenShift AI (RHOAI), Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift Builds 1.8.1, Confidential Compute Attestation, Cryostat 4 on RHEL 9, Red Hat OpenShift Container Platform 4, Red Hat OpenShift GitOps, Red Hat Quay 3.16, Red Hat Trusted Artifact Signer 1.4, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift GitOps, Zero Trust Workload Identity Manager, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat Quay 3.9, Red Hat OpenShift Container Platform 4
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-39834

When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty packets without making progress. The size comparison now uses int64 to prevent truncation.

PUBLISHED
Vendor
golang.org/x/crypto
Product
golang.org/x/crypto/ssh
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39833

The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested.

PUBLISHED
Vendor
golang.org/x/crypto
Product
golang.org/x/crypto/ssh/agent
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39832

A flaw was found in golang.org/x/crypto/ssh/agent. When a key was added to a remote agent, security restrictions, known as constraint extensions, were not properly processed during the request. This allowed these restrictions to be silently removed when keys were forwarded, leading to the unrestricted use of the key on the remote host. This vulnerability could enable an attacker to bypass intended security controls and perform unauthorized actions.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, golang.org/x/crypto, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Trusted Artifact Signer 1.4, Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Builds 1.7.1, Red Hat OpenShift GitOps, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift GitOps, Red Hat OpenShift Builds 1.7.1, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift GitOps, Red Hat OpenShift GitOps, Red Hat Edge Manager 1.0, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Builds 1.8.1, Red Hat Enterprise Linux 9, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Builds 1.8.1, Red Hat Edge Manager 1.0, Red Hat OpenStack Platform 17.1, Red Hat OpenShift Container Platform 4, Assisted Installer for Red Hat OpenShift Container Platform 2, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4, Red Hat Quay 3.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 8, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.22, Red Hat Ceph Storage 9, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat OpenShift AI (RHOAI), Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.0, Red Hat OpenShift GitOps, Red Hat OpenShift Builds 1.8.1, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, Red Hat OpenShift Builds 1.8.1, Red Hat OpenShift Builds 1.8.1, Red Hat Edge Manager 1.1, Red Hat Quay 3.9, OpenShift API for Data Protection 1.6, Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat Quay 3.12, Red Hat OpenShift Container Platform 4, OpenShift Serverless, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenStack Platform 17.1, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Builds 1.7.1, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Builds 1.7.1, RHEM 1.1 for RHEL 10, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, OpenShift Serverless, Red Hat Edge Manager 1.0, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Builds 1.7.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift GitOps, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift GitOps, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, RHEM 1.1 for RHEL 9, Red Hat OpenStack Platform 17.1, Red Hat OpenShift GitOps, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.1, OpenShift Pipelines, Red Hat OpenStack Platform 18.0, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Advanced Cluster Security 4, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, Red Hat OpenShift Dev Workspaces Operator, Red Hat Advanced Cluster Management for Kubernetes 2, Multicluster Engine for Kubernetes, Red Hat Advanced Cluster Security 4, Red Hat Advanced Cluster Security 4.9, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Builds 1.8.1, Red Hat OpenStack Platform 16.2, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, External Secrets Operator for Red Hat OpenShift, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.0, Red Hat Edge Manager 1.1, Red Hat Trusted Artifact Signer 1.3, Red Hat Edge Manager 1.1, RHEM 1.0 for RHEL 9, Red Hat Edge Manager 1.1, Red Hat OpenShift Dev Workspaces Operator, Red Hat Edge Manager 1.1, Red Hat OpenStack Platform 16.2, Red Hat OpenShift Builds 1.8.1, golang.org/x/crypto/ssh/agent, Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.0, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Builds 1.7.1, Red Hat Advanced Cluster Security 4.9, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Virtualization 4, Red Hat Edge Manager 1.0, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.0, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat Quay 3.15, Red Hat Quay 3, Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.1, Red Hat OpenStack Platform 16.2, Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 16.2, Red Hat OpenShift GitOps, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux 10, Red Hat Edge Manager 1.1, Red Hat Advanced Cluster Security 4.9, Red Hat Quay 3.16, Red Hat Advanced Cluster Security 4, Red Hat Edge Manager 1.1, Red Hat OpenShift GitOps
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-39831

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

PUBLISHED
Vendor
golang.org/x/crypto
Product
golang.org/x/crypto/ssh
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39830

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, golang.org/x/crypto, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, Red Hat OpenShift Dev Spaces, Red Hat Trusted Artifact Signer 1.4, Red Hat Edge Manager 1.0, Red Hat Edge Manager 1.1, Red Hat OpenShift GitOps, Red Hat OpenShift Container Platform 4, OpenShift Serverless, Red Hat OpenShift GitOps, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Confidential Compute Attestation, Red Hat Advanced Cluster Security 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Builds 1.7.1, Red Hat Enterprise Linux 10, Red Hat OpenShift Virtualization 4, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Builds 1.7.1, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat OpenShift GitOps, Zero Trust Workload Identity Manager - Tech Preview, Red Hat Trusted Artifact Signer, Red Hat Advanced Cluster Security 4, Red Hat Openshift Data Foundation 4.22, DevWorkspace Operator 0.42, Red Hat Openshift Data Foundation 4.22, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Virtualization 4, Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, cert-manager Operator for Red Hat OpenShift, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenStack Platform 17.1, Red Hat OpenShift GitOps, Zero Trust Workload Identity Manager, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, External Secrets Operator for Red Hat OpenShift, Red Hat Edge Manager 1.1, Zero Trust Workload Identity Manager, Red Hat OpenStack Platform 18.0, Red Hat Enterprise Linux 10, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Builds 1.7.1, Red Hat Openshift Data Foundation 4.22, OpenShift API for Data Protection, Red Hat OpenShift Builds 1.7.1, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Security Profiles Operator, Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 16.2, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, OpenShift API for Data Protection, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.1, Red Hat OpenStack Platform 16.2, multicluster engine for Kubernetes 2.1, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat OpenShift GitOps, Red Hat Edge Manager 1.0, Red Hat OpenShift AI 3.3, Red Hat Advanced Cluster Security 4.9, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Assisted Installer for Red Hat OpenShift Container Platform 2, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Virtualization 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Builds 1.7.1, Red Hat Trusted Artifact Signer 1.4, Zero Trust Workload Identity Manager - Tech Preview, Red Hat Enterprise Linux 10, Red Hat Edge Manager 1.0, Red Hat OpenShift Builds 1.8.1, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, RHEM 1.0 for RHEL 9, Red Hat Edge Manager 1.1, Red Hat OpenShift Builds 1.8.1, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift GitOps, Red Hat OpenShift Container Platform 4, Red Hat Quay 3.9, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Virtualization 4, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4, RHEM 1.1 for RHEL 9, Red Hat OpenShift Virtualization 4, Red Hat OpenShift Container Platform 4, Red Hat Quay 3.16, Red Hat OpenShift GitOps, Red Hat Edge Manager 1.0, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, multicluster engine for Kubernetes 2.8, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Trusted Artifact Signer 1.4, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift for Windows Containers, Red Hat OpenShift on AWS, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift Container Platform 4, Red Hat OpenShift GitOps, Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.1, golang.org/x/crypto/ssh, Red Hat Edge Manager 1.1, Red Hat OpenStack Platform 16.2, Red Hat OpenShift GitOps, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat Edge Manager 1.1, Red Hat OpenShift Virtualization 4, cert-manager Operator for Red Hat OpenShift, Red Hat OpenShift GitOps, Red Hat OpenShift Container Platform 4, Red Hat Quay 3.1, Confidential Compute Attestation, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Security Profiles Operator, Red Hat Trusted Artifact Signer 1.3, Red Hat Trusted Artifact Signer, Red Hat Trusted Artifact Signer 1.4, OpenShift Pipelines, Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 18.0, RHEM 1.1 for RHEL 10, Red Hat OpenStack Platform 17.1, Red Hat OpenShift Container Platform 4, Cryostat 4 on RHEL 9, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Virtualization 4, Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift Builds 1.7.1, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Builds 1.8.1, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift Virtualization 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 8, Red Hat OpenShift Virtualization 4, Red Hat Edge Manager 1.1, DevWorkspace Operator 0.42, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Builds 1.8.1, OpenShift Serverless, Red Hat OpenShift Builds 1.8.1, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.4, Red Hat Quay 3.15, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4, Confidential Compute Attestation, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift AI (RHOAI), Red Hat Ceph Storage 9, Red Hat Edge Manager 1.0, OpenShift API for Data Protection 1.6, Zero Trust Workload Identity Manager - Tech Preview, Red Hat Advanced Cluster Security 4.9, OpenShift API for Data Protection, Red Hat Openshift Data Foundation 4, Red Hat Trusted Artifact Signer 1.4, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.22, Red Hat Trusted Artifact Signer 1.4, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.22, Red Hat Quay 3, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenStack Platform 17.1, OpenShift API for Data Protection, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Security 4, Red Hat OpenShift Container Platform 4, Zero Trust Workload Identity Manager, Red Hat Advanced Cluster Security for Kubernetes 4.11, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat Trusted Artifact Signer, Red Hat OpenShift Builds 1.8.1, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift Builds 1.8.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.0, Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 16.2, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.0, Red Hat OpenShift Container Platform 4, Red Hat Quay 3.12, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift for Windows Containers
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-3983

A security flaw has been discovered in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This affects an unknown part of the file save-games.php. The manipulation of the argument game_name results in cross site scripting. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

PUBLISHED
Vendor
Campcodes
Product
Division Regional Athletic Meet Game Result Matrix System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-39829

The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, golang.org/x/crypto, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.4, golang.org/x/crypto/ssh, Red Hat Openshift Data Foundation 4, Red Hat Openshift Data Foundation 4.22, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Zero Trust Workload Identity Manager, Red Hat Edge Manager 1.0, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, External Secrets Operator for Red Hat OpenShift, Red Hat OpenShift Container Platform 4, cert-manager Operator for Red Hat OpenShift, Red Hat OpenShift Virtualization 4, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 16.2, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Builds 1.7.1, Red Hat Quay 3.1, Red Hat Advanced Cluster Security 4, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, OpenShift Serverless, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift GitOps, OpenShift API for Data Protection, Red Hat OpenShift Builds 1.7.1, Red Hat Edge Manager 1.1, Red Hat Trusted Artifact Signer 1.3, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, Assisted Installer for Red Hat OpenShift Container Platform 2, cert-manager Operator for Red Hat OpenShift, Red Hat Enterprise Linux 9, Confidential Compute Attestation, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.0, OpenShift API for Data Protection, Red Hat Openshift Data Foundation 4.22, multicluster engine for Kubernetes 2.1, Red Hat OpenShift Container Platform 4, Confidential Compute Attestation, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Builds 1.8.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 16.2, Zero Trust Workload Identity Manager - Tech Preview, Red Hat Edge Manager 1.1, Red Hat Trusted Artifact Signer 1.4, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Confidential Compute Attestation, Red Hat OpenShift GitOps, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Builds 1.8.1, Red Hat OpenShift Virtualization 4, multicluster engine for Kubernetes 2.6, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat OpenStack Platform 17.1, Red Hat Trusted Artifact Signer 1.4, Security Profiles Operator, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift GitOps, Red Hat Edge Manager 1.1, Red Hat Enterprise Linux 10, Red Hat Trusted Artifact Signer 1.4, Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux 10, Red Hat Edge Manager 1.1, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, multicluster engine for Kubernetes 2.8, Red Hat OpenShift Virtualization 4, Multicluster Engine for Kubernetes, Red Hat OpenShift on AWS, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.22, Red Hat OpenStack Platform 17.1, OpenShift API for Data Protection, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Container Platform 4, multicluster engine for Kubernetes 2.6, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, multicluster engine for Kubernetes 2.8, Red Hat Advanced Cluster Security 4.9, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift for Windows Containers, Red Hat Enterprise Linux 10, Red Hat Trusted Artifact Signer 1.3, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat Openshift Data Foundation 4.22, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift GitOps, Red Hat OpenShift Builds 1.7.1, Red Hat OpenShift AI (RHOAI), Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Builds 1.8.1, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenStack Platform 16.2, Red Hat OpenShift GitOps, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Builds 1.8.1, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Virtualization 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.4, Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux 10, Red Hat Trusted Artifact Signer 1.3, RHEM 1.0 for RHEL 9, Red Hat Edge Manager 1.1, Red Hat Advanced Cluster Security for Kubernetes 4.11, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift for Windows Containers, Red Hat Quay 3.12, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Builds 1.8.1, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift Virtualization 4, Red Hat Enterprise Linux 9, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, Red Hat OpenShift Virtualization 4, Red Hat Advanced Cluster Security 4.9, OpenShift API for Data Protection, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Builds 1.7.1, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, multicluster engine for Kubernetes 2.1, Red Hat Edge Manager 1.0, Red Hat Edge Manager 1.1, Red Hat OpenShift Builds 1.7.1, Red Hat Quay 3.9, Red Hat Trusted Artifact Signer 1.3, Red Hat Edge Manager 1.1, Red Hat OpenShift Builds 1.8.1, Red Hat Trusted Artifact Signer 1.3, Red Hat Trusted Artifact Signer, Red Hat Trusted Artifact Signer 1.3, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Advanced Cluster Management for Kubernetes 2.15, Security Profiles Operator, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat OpenShift Dev Spaces 3.29, Red Hat Ceph Storage 9, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Security 4.9, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Virtualization 4, Red Hat Edge Manager 1.1, Red Hat OpenShift AI (RHOAI), Red Hat OpenStack Platform 18.0, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Virtualization 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Container Platform 4, Red Hat Quay 3.16, Red Hat OpenShift Container Platform 4, Zero Trust Workload Identity Manager - Tech Preview, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, OpenShift API for Data Protection 1.6, Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.0, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift GitOps, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.0, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, DevWorkspace Operator 0.42, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Builds 1.7.1, Red Hat OpenStack Platform 18.0, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift GitOps, DevWorkspace Operator 0.42, OpenShift Pipelines, Red Hat Openshift Data Foundation 4.22, Zero Trust Workload Identity Manager, Red Hat OpenShift Virtualization 4, Red Hat Trusted Artifact Signer, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, Red Hat Openshift Data Foundation 4, Zero Trust Workload Identity Manager, Red Hat OpenStack Platform 16.2, Red Hat Advanced Cluster Security 4, multicluster engine for Kubernetes 2.9, OpenShift Serverless, Red Hat Openshift Data Foundation 4.22, Red Hat OpenStack Platform 17.1, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Container Platform 4, Zero Trust Workload Identity Manager - Tech Preview, Red Hat OpenShift Container Platform 4, Cryostat 4 on RHEL 9, Red Hat OpenShift GitOps, Red Hat Edge Manager 1.1, RHEM 1.1 for RHEL 10, Red Hat OpenShift Builds 1.8.1, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.22, RHEM 1.1 for RHEL 9, Red Hat OpenShift GitOps, Red Hat OpenShift Container Platform 4, Red Hat Quay 3.15, Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat OpenShift GitOps, Red Hat Quay 3, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Edge Manager 1.0, Red Hat OpenShift Container Platform 4
Provider severity
HIGH
Conflicts
2

CVE-2026-39828

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, golang.org/x/crypto, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Edge Manager 1.0, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Quay 3.9, Red Hat Edge Manager 1.1, Red Hat Trusted Artifact Signer 1.3, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat Trusted Artifact Signer 1.4, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift Virtualization 4, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift Builds 1.8.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift for Windows Containers, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux 10, Red Hat OpenShift Virtualization 4, External Secrets Operator for Red Hat OpenShift, Red Hat OpenShift GitOps, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat Trusted Artifact Signer 1.4, Confidential Compute Attestation, Red Hat Enterprise Linux 9, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, Security Profiles Operator, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.0, Red Hat Advanced Cluster Security 4, Red Hat Edge Manager 1.1, Red Hat OpenShift Virtualization 4, Red Hat Advanced Cluster Security 4.9, Red Hat Edge Manager 1.0, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, Red Hat OpenShift GitOps, Red Hat Edge Manager 1.1, Red Hat OpenShift GitOps, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Builds 1.7.1, Red Hat Trusted Artifact Signer 1.3, Zero Trust Workload Identity Manager, Red Hat Quay 3.15, Red Hat Edge Manager 1.0, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Builds 1.8.1, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Zero Trust Workload Identity Manager - Tech Preview, Red Hat Trusted Artifact Signer 1.4, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Builds 1.8.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Builds 1.8.1, Red Hat OpenStack Platform 17.1, Red Hat Advanced Cluster Management for Kubernetes 2.15, Red Hat Openshift Data Foundation 4.22, Cryostat 4 on RHEL 9, Red Hat Trusted Artifact Signer, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Zero Trust Workload Identity Manager, Red Hat Openshift Data Foundation 4, Red Hat Trusted Artifact Signer 1.4, Red Hat Openshift Data Foundation 4.22, Assisted Installer for Red Hat OpenShift Container Platform 2, Security Profiles Operator, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat OpenStack Platform 18.0, Red Hat Edge Manager 1.1, Red Hat Trusted Artifact Signer 1.4, Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Security 4, Red Hat Trusted Artifact Signer 1.4, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat OpenShift Virtualization 4, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.22, Red Hat OpenStack Platform 16.2, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Security 4.9, Red Hat OpenShift Container Platform 4, OpenShift API for Data Protection, Red Hat Quay 3.1, Red Hat OpenShift Virtualization 4, Red Hat Trusted Artifact Signer 1.4, RHEM 1.1 for RHEL 10, Red Hat Edge Manager 1.1, Red Hat OpenShift GitOps, Red Hat OpenShift Virtualization 4, Red Hat OpenShift for Windows Containers, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 17.1, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat OpenStack Platform 16.2, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, DevWorkspace Operator 0.42, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, golang.org/x/crypto/ssh, multicluster engine for Kubernetes 2.8, OpenShift Serverless, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.1, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, Red Hat Trusted Artifact Signer, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift Container Platform 4, Red Hat OpenShift GitOps, Red Hat OpenShift GitOps, Red Hat OpenShift AI (RHOAI), Red Hat Edge Manager 1.1, RHEM 1.1 for RHEL 9, Red Hat Trusted Artifact Signer 1.4, Red Hat Edge Manager 1.0, Red Hat Advanced Cluster Security 4.9, Red Hat OpenStack Platform 18.0, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Dev Spaces, Red Hat OpenStack Platform 16.2, multicluster engine for Kubernetes 2.1, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4, Red Hat OpenShift Builds 1.7.1, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Ceph Storage 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Virtualization 4, Red Hat OpenShift Container Platform 4, OpenShift API for Data Protection, Multicluster Engine for Kubernetes, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat OpenShift Builds 1.7.1, cert-manager Operator for Red Hat OpenShift, Red Hat Trusted Artifact Signer 1.3, Zero Trust Workload Identity Manager, Red Hat Edge Manager 1.0, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, OpenShift Pipelines, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Builds 1.7.1, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, OpenShift Serverless, Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux 10, multicluster engine for Kubernetes 2.6, Red Hat Edge Manager 1.1, DevWorkspace Operator 0.42, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 17.1, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift GitOps, Red Hat Quay 3.12, RHEM 1.0 for RHEL 9, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, cert-manager Operator for Red Hat OpenShift, Red Hat Quay 3.16, Red Hat Advanced Cluster Security for Kubernetes 4.11, Red Hat Edge Manager 1.1, Red Hat Enterprise Linux 10, multicluster engine for Kubernetes 2.6, Red Hat Advanced Cluster Security 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat OpenShift AI (RHOAI), Zero Trust Workload Identity Manager - Tech Preview, Red Hat OpenShift Builds 1.7.1, multicluster engine for Kubernetes 2.6, Red Hat OpenShift GitOps, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift Builds 1.8.1, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Quay 3, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.4, Multicluster Engine for Kubernetes, Red Hat OpenShift on AWS, Red Hat OpenShift Container Platform 4, OpenShift API for Data Protection 1.6, Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux 8, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Red Hat OpenShift Builds 1.7.1, Red Hat OpenShift Container Platform 4, Confidential Compute Attestation, Red Hat OpenShift Virtualization 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift GitOps, Red Hat OpenShift Builds 1.8.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Builds 1.8.1, Red Hat OpenStack Platform 16.2, Red Hat OpenShift Container Platform 4, Confidential Compute Attestation, Zero Trust Workload Identity Manager - Tech Preview, Red Hat OpenShift Container Platform 4, Red Hat OpenShift GitOps, Red Hat OpenShift Virtualization 4, Red Hat Edge Manager 1.1
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-39827

An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released for garbage collection.

PUBLISHED
Vendor
golang.org/x/crypto
Product
golang.org/x/crypto/ssh
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39826

If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block.

PUBLISHED
Vendor
Go standard library
Product
html/template
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39825

ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a que

PUBLISHED
Vendor
Go standard library
Product
net/http/httputil
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39824

NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.

PUBLISHED
Vendor
golang.org/x/sys
Product
golang.org/x/sys/windows
Provider severity
LOW
Conflicts
1

CVE-2026-39823

CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS.

PUBLISHED
Vendor
Go standard library
Product
html/template
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39822

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

PUBLISHED
Vendor
Go standard library
Product
os
Provider severity
HIGH
Conflicts
1

CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to U

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, golang.org/x/net, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9, Red Hat Ansible Automation Platform 2.6 for RHEL 10, Red Hat Enterprise Linux 8, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Builds 1.8.1, Red Hat OpenShift AI (RHOAI), Cluster Observability Operator 1.5.0, Red Hat OpenShift distributed tracing 3.10.0, Red Hat OpenShift Container Platform 4, Multiarch Tuning Operator, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux 10, External Secrets Operator for Red Hat OpenShift, Red Hat multicluster global hub 1.4.2, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Enterprise Linux 9, Red Hat OpenShift distributed tracing 3.10.0, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Enterprise Linux 10, Red Hat OpenShift for Windows Containers, Red Hat OpenShift Container Platform 4, Fence Agents Remediation Operator, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift distributed tracing 3.10.0, Cryostat 4, OpenShift Serverless, Gatekeeper 3, Red Hat OpenShift distributed tracing 3.10.0, Confidential Compute Attestation, Red Hat OpenShift Cluster Manager CLI, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat OpenStack Platform 16.2, Red Hat OpenShift AI (RHOAI), Red Hat OpenStack Platform 16.2, RHEM 1.1 for RHEL 10, Red Hat Enterprise Linux AI 3.4, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat OpenShift distributed tracing 3.10.0, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Enterprise Linux 8, Red Hat Quay 3.1, Network Observability Operator, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 17.1, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Edge Manager 1.0, multicluster engine for Kubernetes 2.6, Red Hat OpenShift GitOps 1.2, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Advanced Cluster Management for Kubernetes 2, Logging Subsystem for Red Hat OpenShift 6.4, Red Hat OpenShift distributed tracing 3.10.0, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 10, Red Hat OpenShift on AWS, Zero Trust Workload Identity Manager, Node HealthCheck Operator, Logical Volume Manager Storage, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Multicluster Engine for Kubernetes, Red Hat Enterprise Linux 10, Red Hat Edge Manager 1.1, Red Hat Ceph Storage 5, Red Hat OpenShift AI (RHOAI), Red Hat Ceph Storage 8, Red Hat Satellite 6.17 for RHEL 9, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux 10, Red Hat Hardened Images, Red Hat OpenStack Platform 17.1, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 7, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), golang.org/x/net/idna, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3.15, Red Hat Service Interconnect 1, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Service Mesh 3.3, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat OpenShift Builds 1.7.1, Red Hat Enterprise Linux 8, Compliance Operator, Red Hat Enterprise Linux 10, Multicluster Engine for Kubernetes, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Security Profiles Operator, Red Hat OpenStack Platform 18.0, Red Hat Ansible Automation Platform 2.7, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Enterprise Linux 8, Red Hat OpenShift AI 2.25, Red Hat Openshift Data Foundation 4.22, multicluster engine for Kubernetes 2.6, Cluster Observability Operator 1.5.0, Red Hat Satellite 6, OpenShift API for Data Protection 1.6, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, multicluster engine for Kubernetes 2.8, RHEM 1.0 for RHEL 9, Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux AI 3.4, Multicluster Engine for Kubernetes, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, OpenShift Serverless, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI 3.4, Red Hat OpenStack Platform 17.1, multicluster engine for Kubernetes 2.8, Red Hat Ansible Automation Platform 2, Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux 10, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Satellite 6.16 for RHEL 9, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Openshift Data Foundation 4.22, Cluster Observability Operator 1.5.0, Red Hat Enterprise Linux 10, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Service Mesh 2.6, Red Hat OpenShift AI (RHOAI), Multicluster Engine for Kubernetes, Red Hat Enterprise Linux 9, Red Hat Connectivity Link 1, Red Hat Enterprise Linux 9, Multicluster Engine for Kubernetes, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.7 for RHEL 10, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 8, Red Hat Certification Program for Red Hat Enterprise Linux 9, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI 3.4, Red Hat Quay 3.16, Logical Volume Manager Storage, Red Hat OpenStack Platform 16.2, Red Hat Satellite 6.18 for RHEL 9, Red Hat Enterprise Linux 8, Red Hat Advanced Cluster Management for Kubernetes 2, Machine Deletion Remediation Operator, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Enterprise Linux 8, Red Hat OpenShift AI 2.25, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat OpenShift Container Platform 4, Red Hat Ceph Storage 6, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Builds 1.7.1, Multicluster Engine for Kubernetes, OpenShift API for Data Protection, Red Hat Satellite 6.19 for RHEL 9, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat OpenShift Service Mesh 3.2, Node HealthCheck Operator, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat OpenStack Platform 18.0, Red Hat OpenShift AI (RHOAI), Logical Volume Manager Storage, Node HealthCheck Operator, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift GitOps 1.19, Red Hat OpenShift Virtualization 4, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Power monitoring for Red Hat OpenShift, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift distributed tracing 3.10.0, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3.12, Red Hat Advanced Cluster Security for Kubernetes 4.11, Red Hat OpenShift AI (RHOAI), Multicluster Global Hub 1.5.4, Red Hat Openshift Data Foundation 4.22, Red Hat Advanced Cluster Management for Kubernetes 2.13, OpenShift Pipelines, Multicluster Engine for Kubernetes, Multicluster Engine for Kubernetes, Red Hat Enterprise Linux AI 3.4, Red Hat OpenShift AI (RHOAI), Multicluster Engine for Kubernetes, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift AI (RHOAI), Cluster Observability Operator 1.5.0, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Service Mesh 3.0, OpenShift Pipelines, Confidential Compute Attestation, Red Hat OpenShift AI (RHOAI), Red Hat Web Terminal 1.15, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, RHEM 1.1 for RHEL 9, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat OpenShift Container Platform 4, Red Hat Lightspeed for Runtimes Operator, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Red Hat Web Terminal 1.12, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Multicluster Engine for Kubernetes, Red Hat OpenShift AI (RHOAI), Red Hat OpenStack Platform 17.1, Red Hat Service Interconnect 2, Red Hat Enterprise Linux 10, Red Hat OpenShift Virtualization 4, Red Hat Web Terminal 1.13, Red Hat OpenShift Service Mesh 3.1, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Enterprise Linux 9, Red Hat Openshift Data Foundation 4.22, OpenShift Serverless, Red Hat Enterprise Linux 9, Red Hat Ansible Automation Platform 2, Red Hat 3scale API Management Platform 2, Red Hat OpenShift AI 2.25, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.22, Multicluster Engine for Kubernetes, Red Hat Trusted Artifact Signer 1.4, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Web Terminal 1.16, Red Hat Openshift Data Foundation 4.22, Red Hat Ansible Automation Platform 2.7 for RHEL 9, Red Hat OpenShift AI (RHOAI), Red Hat Hardened Images, Red Hat Enterprise Linux 7, Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux 9, Deployment Validation Operator, Zero Trust Workload Identity Manager - Tech Preview, Red Hat Advanced Cluster Management for Kubernetes 2.13, streams for Apache Kafka 3, Red Hat OpenShift Container Platform 4, Red Hat Ceph Storage 9, Red Hat Enterprise Linux 7, Red Hat OpenShift AI (RHOAI), OpenShift API for Data Protection, Red Hat Enterprise Linux AI 3.4, Red Hat Advanced Cluster Management for Kubernetes 2, Assisted Installer for Red Hat OpenShift Container Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Cluster Observability Operator 1.5.0, Red Hat Openshift Data Foundation 4.22, Red Hat Advanced Cluster Management for Kubernetes 2.13, Cluster Observability Operator 1.5.0, Cluster Observability Operator 1.5.0, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Multicluster Engine for Kubernetes, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Enterprise Linux AI 3.4, Red Hat Enterprise Linux 10, Red Hat Advanced Cluster Management for Kubernetes 2.13, multicluster engine for Kubernetes 2.8, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Dev Spaces 3.29, multicluster engine for Kubernetes 2.8, Multicluster Engine for Kubernetes, Red Hat OpenShift AI (RHOAI), Multicluster Engine for Kubernetes, Red Hat Web Terminal 1.11, Red Hat multicluster global hub 1.6.0, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, Red Hat Satellite 6.16 for RHEL 8, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Openshift Data Foundation 4.22, Red Hat Satellite 6, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Advanced Cluster Security 4.9, OpenShift Serverless, Red Hat Developer Hub, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4.22, Cluster Observability Operator 1.5.0, Red Hat Advanced Cluster Management for Kubernetes 2.13, Multicluster Engine for Kubernetes, Red Hat Quay 3.9, cert-manager Operator for Red Hat OpenShift, Red Hat Migration Toolkit 1.8, Logging Subsystem for Red Hat OpenShift 6.2, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Builds 1.8.1, Red Hat OpenShift Container Platform 4, OpenShift Developer Tools and Services, Red Hat OpenShift AI (RHOAI), Cluster Observability Operator 1.5.0, Multicluster Global Hub 1.7.0, File Integrity Operator, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Enterprise Linux 10, Red Hat Advanced Cluster Management for Kubernetes 2, DevWorkspace Operator 0.42, Red Hat Enterprise Linux 8, Red Hat Migration Toolkit for Applications 8.2, multicluster engine for Kubernetes 2.9, Red Hat OpenShift Container Platform 4, Red Hat Web Terminal 1.14, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Advanced Cluster Management for Kubernetes 2, Multicluster Engine for Kubernetes, Red Hat Ansible Automation Platform 2, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, OpenShift Lightspeed, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, multicluster engine for Kubernetes 2.6, Red Hat OpenShift Container Platform 4
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-39820

A flaw was found in the `net/mail` package of the Go programming language. An attacker could provide specially crafted inputs to the `ParseAddress`, `ParseAddressList`, or `ParseDate` functions. This could lead to excessive consumption of CPU and memory resources, resulting in a Denial of Service (DoS) for applications processing these inputs.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Go standard library, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
OpenShift Service Mesh 3, Logging for Red Hat OpenShift 6.2, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.25, Red Hat OpenShift Dev Workspaces Operator, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Red Hat Ceph Storage 6, Red Hat OpenShift Service Mesh 3.0, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Container Platform 4, Red Hat Ceph Storage 5, Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, Multicluster Engine for Kubernetes, Logical Volume Manager Storage, Red Hat OpenShift Virtualization 4, Red Hat Enterprise Linux 9, Red Hat OpenShift Service Mesh 3.3, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat OpenShift distributed tracing 3, Red Hat OpenShift AI (RHOAI), OpenShift Lightspeed, Red Hat Quay 3.1, Zero Trust Workload Identity Manager, Red Hat OpenShift AI (RHOAI), Red Hat Certification Program for Red Hat Enterprise Linux 9, Red Hat OpenStack Platform 17.1, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Migration Toolkit for Applications 8.2, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 8, OpenShift API for Data Protection, Zero Trust Workload Identity Manager - Tech Preview, Red Hat Trusted Artifact Signer, Logging Subsystem for Red Hat OpenShift 6.4, Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, OpenShift Pipelines, Red Hat Quay 3.16, Assisted Installer for Red Hat OpenShift Container Platform 2, Confidential Compute Attestation, Red Hat OpenShift AI (RHOAI), net/mail, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4, Red Hat Lightspeed for Runtimes Operator, OpenShift Service Mesh 2, Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4, Red Hat Ansible Automation Platform 2, Logical Volume Manager Storage, Red Hat OpenShift Service Mesh 3.0, Red Hat OpenShift Dev Spaces, Red Hat OpenShift Service Mesh 3.0, Red Hat OpenShift AI (RHOAI), Multicluster Engine for Kubernetes, Red Hat OpenShift Service Mesh 3.3, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat Edge Manager 1, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat OpenShift Dev Spaces, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Virtualization 4, Red Hat OpenShift Service Mesh 3.1, Red Hat OpenShift Virtualization 4, Red Hat Enterprise Linux 9, Red Hat Openshift Data Foundation 4, cert-manager Operator for Red Hat OpenShift, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat OpenShift Service Mesh 3.2, Red Hat Enterprise Linux 10, OpenShift Service Mesh 2, Confidential Compute Attestation, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Red Hat OpenStack Platform 16.2, Red Hat OpenShift Container Platform 4, OpenShift Developer Tools and Services, OpenShift API for Data Protection 1.6, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1, Red Hat Developer Hub 1.9, Power monitoring for Red Hat OpenShift, Red Hat Enterprise Linux 10, Red Hat OpenShift for Windows Containers, Multicluster Engine for Kubernetes, Red Hat Openshift Data Foundation 4, Red Hat OpenShift Service Mesh 3.2, Red Hat OpenShift AI (RHOAI), Cryostat 4, Red Hat Ceph Storage 9, Red Hat Service Interconnect 2, Red Hat OpenShift Service Mesh 3.3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Quay 3.12, Red Hat Enterprise Linux 8, Multicluster Global Hub, Red Hat Advanced Cluster Security 4.9, Multiarch Tuning Operator, Red Hat OpenShift Service Mesh 3.1, Network Observability Operator, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3.9, Red Hat Quay 3.15, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, External Secrets Operator for Red Hat OpenShift, Red Hat Enterprise Linux 10, Red Hat OpenShift Virtualization 4, Red Hat OpenShift Service Mesh 3.3, Red Hat Enterprise Linux 10, Multicluster Global Hub, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, Red Hat OpenShift AI (RHOAI), Red Hat Hardened Images, Red Hat OpenShift GitOps, Confidential Compute Attestation, Red Hat Migration Toolkit 1.8, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Cluster Manager CLI, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Logical Volume Manager Storage, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat OpenShift Service Mesh 3.0, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Service Mesh 3.2, Red Hat Openshift Data Foundation 4, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4, Red Hat Enterprise Linux 10, Multicluster Engine for Kubernetes, Red Hat Service Interconnect 1, Red Hat OpenShift GitOps, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat Developer Hub 1.10, Red Hat Enterprise Linux 8, Red Hat OpenShift Service Mesh 3.2, Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, File Integrity Operator, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Security Profiles Operator, Custom Metric Autoscaler operator for Red Hat Openshift, Red Hat Satellite 6, Multicluster Engine for Kubernetes, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Multicluster Engine for Kubernetes, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Hardened Images, Multicluster Engine for Kubernetes, Multicluster Engine for Kubernetes, Red Hat Enterprise Linux 9, Red Hat Openshift Data Foundation 4, Red Hat OpenShift AI (RHOAI), Multicluster Engine for Kubernetes, Gatekeeper 3, Red Hat OpenShift Service Mesh 3.1, Red Hat Trusted Artifact Signer 1.4, OpenShift Serverless, Red Hat OpenShift Service Mesh 3.1, Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 18.0, Red Hat Quay 3, Red Hat Advanced Cluster Security for Kubernetes 4.10
Provider severity
HIGH
Conflicts
2

CVE-2026-3982

A vulnerability was determined in itsourcecode University Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_result.php. Executing a manipulation of the argument vr can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
itsourcecode
Product
University Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-39819

The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.

PUBLISHED
Vendor
Go toolchain
Product
cmd/go
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39817

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.

PUBLISHED
Vendor
Go toolchain
Product
cmd/go
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39816

The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The TinkerpopClientService supports configuration of ByteCode Submission for the Script Submission Type, enabling Groovy Script execution in the service prior to submitting the query. The missing Restricted annotation allows users without the Execute Code Permission to configure the Service in installations that use fine-gra

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache NiFi
Provider severity
HIGH
Conflicts
0

CVE-2026-39815

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending crafted HTTP requests

PUBLISHED
Vendor
Fortinet
Product
FortiDDoS-F
Provider severity
HIGH
Conflicts
0

CVE-2026-39814

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiWeb 7.2.7 through 7.2.12, FortiWeb 7.0.10 through 7.0.12 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

PUBLISHED
Vendor
Fortinet
Product
FortiWeb
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39813

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.

PUBLISHED
Vendor
Fortinet, Fortinet
Product
FortiSandbox, FortiSandbox Cloud
Provider severity
CRITICAL
Conflicts
1

CVE-2026-39812

A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox PaaS 5.0.0 through 5.0.5, FortiSandbox PaaS 4.4.0 through 4.4.8, FortiSandbox PaaS 4.2 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>

PUBLISHED
Vendor
Fortinet, Fortinet
Product
FortiSandbox PaaS, FortiSandbox
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39811

A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to denial of service via <insert attack vector here>

PUBLISHED
Vendor
Fortinet
Product
FortiWeb
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39810

A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via decrypting database dump.

PUBLISHED
Vendor
Fortinet
Product
FortiClientEMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3981

A vulnerability was found in itsourcecode Online Doctor Appointment System 1.0. Affected is an unknown function of the file /admin/doctor_action.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

PUBLISHED
Vendor
itsourcecode
Product
Online Doctor Appointment System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-39809

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEMS 7.0 all versions may allow attacker to execute unauthorized code or commands via sending crafted requests

PUBLISHED
Vendor
Fortinet
Product
FortiClientEMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39808

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

PUBLISHEDCISA KEV
Vendor
Fortinet, Fortinet
Product
FortiSandbox, FortiSandbox PaaS
Provider severity
CRITICAL
Conflicts
1

CVE-2026-39807

Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel bandit allows unauthenticated transport-state spoofing on plaintext HTTP connections. 'Elixir.Bandit.Pipeline':determine_scheme/2 in lib/bandit/pipeline.ex returns the client-supplied URI scheme verbatim, ignoring the transport's secure? flag. HTTP/1.1 absolute-form request targets (e.g. GET https://victim/path HTTP/1.1) and the HTTP/2 :scheme pseudo-header are both attacker-controlled strings that flow through this fu

PUBLISHED
Vendor
mtrudel, mtrudel
Product
bandit, bandit
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39806

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote denial of service via worker process exhaustion. 'Elixir.Bandit.HTTP1.Socket':do_read_chunked_data!/5 in lib/bandit/http1/socket.ex terminates only when the last-chunk line 0\r\n is followed immediately by the empty trailer line \r\n. RFC 9112 §7.1.2 permits zero or more trailer fields between them. When trailers are present, none of the match clauses fit: the catch-all arm compu

PUBLISHED
Vendor
mtrudel, mtrudel
Product
bandit, bandit
Provider severity
HIGH
Conflicts
1