Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-3383

A weakness has been identified in ChaiScript up to 6.1.0. This affects the function chaiscript::Boxed_Number::go of the file include/chaiscript/dispatchkit/boxed_number.hpp. Executing a manipulation can lead to divide by zero. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
n/a
Product
ChaiScript
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-33829

Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2016, Windows Server 2025, Windows Server 2012 R2, Windows 11 Version 24H2, Windows 10 Version 1607, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2022, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 25H2, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows 11 version 26H1, Windows Server 2025 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33828

Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows Server 2019, Windows 11 version 23H2, Windows Server 2022, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 23H2, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows Server 2016, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-33827

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows Server 2022, Windows Server 2012 R2, Windows 11 version 26H1, Windows Server 2012, Windows 10 Version 1809, Windows Server 2012 (Server Core installation), Windows Server 2016, Windows 10 Version 1607, Windows Server 2025, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019, Windows 11 version 22H3, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows 11 Version 23H2
Provider severity
HIGH
Conflicts
1

CVE-2026-33826

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2019, Windows Server 2012 R2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012 R2 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-33825

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

PUBLISHEDCISA KEV
Vendor
Microsoft
Product
Microsoft Defender Antimalware Platform
Provider severity
HIGH
Conflicts
0

CVE-2026-33824

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows Server 2022, Windows 11 version 26H1, Windows 10 Version 21H2, Windows Server 2019, Windows 11 Version 23H2, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows Server 2016, Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 version 22H3, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows 11 Version 24H2
Provider severity
CRITICAL
Conflicts
1

CVE-2026-33823

Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Teams
Provider severity
CRITICAL
Conflicts
0

CVE-2026-33822

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2024, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33821

Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Dynamics 365
Provider severity
HIGH
Conflicts
0

CVE-2026-3382

A security flaw has been discovered in ChaiScript up to 6.1.0. The impacted element is the function chaiscript::Boxed_Number::get_as of the file include/chaiscript/dispatchkit/boxed_number.hpp. Performing a manipulation results in memory corruption. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
n/a
Product
ChaiScript
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2026-33819

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Bing
Provider severity
CRITICAL
Conflicts
0

CVE-2026-33816

Memory-safety vulnerability in github.com/jackc/pgx/v5.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, github.com/jackc/pgx/v5, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Edge Manager 1.1, Red Hat Quay 3, Red Hat Edge Manager 1.1, Multicluster Global Hub, Custom Metric Autoscaler 2.19, Red Hat 3scale API Management Platform 2, Red Hat Openshift Data Foundation 4.2, Red Hat Advanced Cluster Security 4, Multicluster Global Hub, RHEM 1.1 for RHEL 9, Red Hat Openshift Data Foundation 4.2, Cryostat 4 on RHEL 9, Red Hat Advanced Cluster Security 4, Multicluster Global Hub, Red Hat Edge Manager 1, Red Hat Openshift Data Foundation 4.2, Red Hat 3scale API Management Platform 2, Red Hat Openshift Data Foundation 4.2, Multicluster Global Hub, Red Hat Edge Manager 1.1, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.2, Red Hat Advanced Cluster Security 4.9, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.2, Red Hat Advanced Cluster Security 4.8, Red Hat Edge Manager 1.1, Multicluster Global Hub 1.3.4, Multicluster Global Hub, Red Hat Advanced Cluster Security 4.9, Multicluster Global Hub, Red Hat Trusted Artifact Signer, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.2, Red Hat Edge Manager 1.1, Custom Metric Autoscaler operator for Red Hat Openshift, Red Hat Edge Manager 1, Red Hat Trusted Artifact Signer 1.3, Multicluster Global Hub 1.3.4, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.2, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat Edge Manager 1.1, Red Hat OpenShift AI (RHOAI), github.com/jackc/pgx/v5/pgproto3, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.2, Red Hat Enterprise Linux 10, Zero Trust Workload Identity Manager - Tech Preview, Red Hat Advanced Cluster Security 4.8, RHEM 1.0 for RHEL 9, Custom Metric Autoscaler 2.19, Red Hat Edge Manager 1.1, Zero Trust Workload Identity Manager - Tech Preview, Red Hat Openshift Data Foundation 4.2, Red Hat OpenShift AI (RHOAI), Red Hat Hardened Images, Multicluster Global Hub, RHEM 1.1 for RHEL 10, Red Hat Edge Manager 1, Red Hat Edge Manager 1.1, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.2, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Zero Trust Workload Identity Manager, Red Hat Trusted Artifact Signer, Multicluster Global Hub, Multicluster Engine for Kubernetes, Red Hat Trusted Artifact Signer 1.3, Multicluster Global Hub 1.7.1, Red Hat Trusted Artifact Signer 1.3, Multicluster Global Hub, Red Hat Openshift Data Foundation 4.2, Multicluster Global Hub, Red Hat Edge Manager 1.1, Custom Metric Autoscaler operator for Red Hat Openshift, Red Hat 3scale API Management Platform 2, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.2, Red Hat Advanced Cluster Management for Kubernetes 2.15, Red Hat Edge Manager 1, Red Hat Advanced Cluster Security 4, Red Hat Openshift Data Foundation 4.2, Red Hat Advanced Cluster Management for Kubernetes 2.16, Red Hat Edge Manager 1, Red Hat Edge Manager 1, Multicluster Global Hub, Multicluster Global Hub, Red Hat Openshift Data Foundation 4.2, Red Hat Trusted Artifact Signer 1.3, Zero Trust Workload Identity Manager - Tech Preview, Red Hat Advanced Cluster Security 4.8, Multicluster Global Hub, Custom Metric Autoscaler 2.19, Multicluster Global Hub 1.3.4, Red Hat Hardened Images, Red Hat Trusted Artifact Signer 1.3, Red Hat Advanced Cluster Security 4.9, Red Hat Openshift Data Foundation 4.2, Multicluster Global Hub, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1, Custom Metric Autoscaler 2.19, Red Hat Openshift Data Foundation 4.2, Red Hat Trusted Artifact Signer, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Custom Metric Autoscaler operator for Red Hat Openshift, Red Hat Trusted Artifact Signer, Zero Trust Workload Identity Manager, Red Hat Edge Manager 1, Red Hat Openshift Data Foundation 4.2, Red Hat Trusted Artifact Signer, Red Hat Openshift Data Foundation 4.2, Multicluster Global Hub, Multicluster Global Hub, OpenShift Pipelines, Multicluster Global Hub, Red Hat Edge Manager 1, Red Hat Edge Manager 1.1, Red Hat OpenShift Pipelines 1.21, Zero Trust Workload Identity Manager, Red Hat OpenShift AI (RHOAI), Red Hat Trusted Artifact Signer 1.3
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-33815

A flaw was found in github.com/jackc/pgx. This memory-safety vulnerability could potentially lead to unexpected behavior or system instability.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, github.com/jackc/pgx/v5, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Trusted Artifact Signer, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat Trusted Artifact Signer 1.3, Red Hat Openshift Data Foundation 4.2, Red Hat Edge Manager 1, Red Hat Hardened Images, github.com/jackc/pgx/v5/pgproto3, Red Hat Openshift Data Foundation 4.2, Zero Trust Workload Identity Manager, Multicluster Global Hub, Red Hat 3scale API Management Platform 2, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.2, Custom Metric Autoscaler 2.19, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.2, Multicluster Global Hub, Red Hat Advanced Cluster Security 4, Red Hat Advanced Cluster Security 4, Red Hat Openshift Data Foundation 4.2, Red Hat Edge Manager 1, Multicluster Global Hub, Red Hat Advanced Cluster Management for Kubernetes 2.16, Multicluster Global Hub, Red Hat Openshift Data Foundation 4.2, Multicluster Global Hub, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Multicluster Global Hub, Multicluster Global Hub, Red Hat Trusted Artifact Signer, Multicluster Global Hub, Zero Trust Workload Identity Manager, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift AI (RHOAI), Zero Trust Workload Identity Manager, Multicluster Global Hub 1.3.4, Red Hat Openshift Data Foundation 4.2, Red Hat Trusted Artifact Signer, Red Hat Enterprise Linux 10, Red Hat Edge Manager 1, Red Hat Advanced Cluster Security 4, Red Hat Advanced Cluster Security 4.9, Red Hat Openshift Data Foundation 4.2, Multicluster Global Hub 1.3.4, Zero Trust Workload Identity Manager - Tech Preview, Red Hat Quay 3, Zero Trust Workload Identity Manager - Tech Preview, Red Hat Trusted Artifact Signer 1.3, Red Hat Trusted Artifact Signer, Red Hat Openshift Data Foundation 4.2, Red Hat Advanced Cluster Security 4.9, Red Hat 3scale API Management Platform 2, Red Hat Edge Manager 1, Red Hat Openshift Data Foundation 4.2, Multicluster Global Hub, Multicluster Global Hub, Red Hat Edge Manager 1, OpenShift Pipelines, Multicluster Global Hub 1.3.4, Multicluster Global Hub, Red Hat Openshift Data Foundation 4.2, Red Hat Advanced Cluster Security 4.9, Custom Metric Autoscaler operator for Red Hat Openshift, Multicluster Engine for Kubernetes, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.2, Custom Metric Autoscaler 2.19, Red Hat Openshift Data Foundation 4.2, Red Hat Advanced Cluster Security 4.8, Multicluster Global Hub, Multicluster Global Hub, Red Hat Openshift Data Foundation 4.2, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat Trusted Artifact Signer, OpenShift Pipelines, Red Hat Openshift Data Foundation 4.2, Zero Trust Workload Identity Manager - Tech Preview, Red Hat Advanced Cluster Security 4.8, RHEM 1.1 for RHEL 9, Red Hat Openshift Data Foundation 4.2, Multicluster Global Hub 1.7.1, Red Hat Openshift Data Foundation 4.2, Multicluster Global Hub, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat Edge Manager 1, Red Hat Advanced Cluster Security 4.8, Red Hat OpenShift AI (RHOAI), Red Hat Edge Manager 1, Red Hat Openshift Data Foundation 4.2, Custom Metric Autoscaler operator for Red Hat Openshift, Red Hat Hardened Images, Red Hat 3scale API Management Platform 2, Multicluster Global Hub, Red Hat Edge Manager 1, Red Hat Trusted Artifact Signer 1.3, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.2, Multicluster Global Hub, Red Hat Edge Manager 1, Cryostat 4 on RHEL 9, Red Hat Trusted Artifact Signer 1.3, Red Hat Trusted Artifact Signer 1.3, Multicluster Global Hub, Custom Metric Autoscaler 2.19, Custom Metric Autoscaler 2.19, RHEM 1.1 for RHEL 10, Custom Metric Autoscaler operator for Red Hat Openshift, Red Hat Edge Manager 1, Red Hat Advanced Cluster Management for Kubernetes 2.15, RHEM 1.0 for RHEL 9, Red Hat Openshift Data Foundation 4.2
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-33814

A flaw was found in the HTTP/2 protocol implementation within the Go standard library (golang.org/x/net and net/http/internal/http2). A remote attacker can exploit this vulnerability by sending a specially crafted HTTP/2 SETTINGS frame with the SETTINGS_MAX_FRAME_SIZE parameter set to zero. This malicious frame causes the transport layer to enter an infinite loop of writing CONTINUATION frames, leading to resource exhaustion and a Denial of Service (DoS) condition.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, golang.org/x/net, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Go standard library, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift Service Mesh 3.0, Cluster Observability Operator 1.5.0, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Red Hat OpenShift Service Mesh 3.3, OpenShift API for Data Protection 1.6, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift AI (RHOAI), Cluster Observability Operator 1.5.0, Red Hat OpenShift Service Mesh 3.3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Service Mesh 3.1, Red Hat Openshift Data Foundation 4.22, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Service Mesh 3.0, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Multicluster Engine for Kubernetes, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Service Mesh 3.1, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Cluster Observability Operator 1.5.0, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Service Mesh 3.2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Service Mesh 3.3, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Cluster Observability Operator 1.5.0, Multicluster Engine for Kubernetes, Multicluster Engine for Kubernetes, Red Hat OpenShift Service Mesh 3.0, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Service Mesh 3.1, Multicluster Engine for Kubernetes, Multicluster Engine for Kubernetes, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, OpenShift Service Mesh 2, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Service Mesh 3.2, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Management for Kubernetes 2, Multicluster Engine for Kubernetes, Red Hat OpenShift Service Mesh 3.1, Multicluster Engine for Kubernetes, Red Hat Openshift Data Foundation 4.22, Red Hat Hardened Images, Red Hat OpenShift Service Mesh 3.3, Red Hat OpenShift AI (RHOAI), golang.org/x/net/http2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift AI (RHOAI), Multicluster Engine for Kubernetes, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Management for Kubernetes 2, Cluster Observability Operator 1.5.0, Red Hat OpenShift Service Mesh 3.0, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, net/http, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Multicluster Engine for Kubernetes, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift AI (RHOAI), Cluster Observability Operator 1.5.0, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat OpenShift Virtualization 4, Red Hat OpenShift AI (RHOAI), Cluster Observability Operator 1.5.0, Red Hat Hardened Images, Red Hat OpenShift AI 2.25, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift AI (RHOAI), Cluster Observability Operator 1.5.0, Red Hat OpenShift Service Mesh 3.2, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Service Mesh 3.2, Multicluster Engine for Kubernetes, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Cluster Observability Operator 1.5.0, Red Hat OpenShift AI (RHOAI)
Provider severity
HIGH
Conflicts
2

CVE-2026-33813

Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.

PUBLISHED
Vendor
golang.org/x/image
Product
golang.org/x/image/webp
Provider severity
HIGH
Conflicts
0

CVE-2026-33812

Parsing a malicious font file can cause excessive memory allocation.

PUBLISHED
Vendor
golang.org/x/image
Product
golang.org/x/image/font/sfnt
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33811

A flaw was found in the `net` package of Go (golang), specifically when using the `LookupCNAME` function with the `cgo` DNS resolver. A remote attacker could exploit this by providing a very long Canonical Name (CNAME) response. This can trigger a double-free of C memory, leading to a crash and a Denial of Service (DoS) for the affected application.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Go standard library, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Service Interconnect 1, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Multicluster Global Hub 1.7.1, Multicluster Engine for Kubernetes, Red Hat 3scale API Management Platform 2, Node HealthCheck Operator, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat Web Terminal 1.12, Red Hat OpenShift Virtualization 4, Red Hat Migration Toolkit for Applications 8.2, Security Profiles Operator, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenStack Platform 16.2, Red Hat OpenShift for Windows Containers, Red Hat OpenShift Virtualization 4, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Node HealthCheck Operator, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Logical Volume Manager Storage, Red Hat Hardened Images, Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat OpenShift AI 2.25, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Service Mesh 3.1, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Fence Agents Remediation Operator, Red Hat Web Terminal 1.13, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), OpenShift Serverless, Red Hat Enterprise Linux 10, Red Hat Satellite 6.16 for RHEL 9, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6.18 for RHEL 9, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Web Terminal 1.14, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 7, Red Hat Migration Toolkit 1.8, multicluster engine for Kubernetes 2.6, Red Hat OpenShift Dev Spaces, net, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), RHEM 1.0 for RHEL 9, RHEM 1.1 for RHEL 9, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, External Secrets Operator for Red Hat OpenShift, Multiarch Tuning Operator, Red Hat Advanced Cluster Security for Kubernetes 4.11, mirror registry for Red Hat OpenShift, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Enterprise Linux 10, Red Hat OpenStack Platform 17.1, Machine Deletion Remediation Operator, Red Hat OpenShift Cluster Manager CLI, Node HealthCheck Operator, Compliance Operator, Red Hat Ansible Automation Platform 2, Red Hat OpenStack Platform 16.2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Builds 1.7.3, Red Hat Connectivity Link 1, Red Hat OpenShift Virtualization 4, multicluster engine for Kubernetes 2.1, Red Hat Advanced Cluster Security for Kubernetes 4.10, Multicluster Global Hub, Red Hat Enterprise Linux 10, Multicluster Engine for Kubernetes, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat Ceph Storage 6, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat OpenStack Services on OpenShift 18.0, Red Hat AMQ Clients, Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), Cryostat 4 on RHEL 9, Red Hat OpenShift AI (RHOAI), Assisted Installer for Red Hat OpenShift Container Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Multicluster Engine for Kubernetes, Red Hat OpenShift Service Mesh 3.3, Red Hat Enterprise Linux 8, mirror registry for Red Hat OpenShift 2, Red Hat Hardened Images, Red Hat OpenShift Service Mesh 3.3, Red Hat Quay 3, Red Hat OpenShift Container Platform 4, multicluster engine for Kubernetes 2.8, Red Hat OpenShift Service Mesh 3.0, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Multicluster Engine for Kubernetes, Red Hat OpenShift Service Mesh 3.1, Red Hat OpenShift Service Mesh 3.2, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ansible Automation Platform 2, Red Hat Satellite 6, Red Hat Ansible Automation Platform 2, Red Hat AMQ Clients, Red Hat OpenShift Service Mesh 3.1, Red Hat Satellite 6.17 for RHEL 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift GitOps 1.19, Network Observability Operator, Red Hat OpenShift AI (RHOAI), Confidential Compute Attestation, Confidential Compute Attestation, Red Hat OpenShift Service Mesh 3.3, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4, Red Hat Enterprise Linux 9, Red Hat Service Interconnect 1, Red Hat Ansible Automation Platform 2, Red Hat OpenStack Platform 17.1, Red Hat Quay 3, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), OpenShift Pipelines, Red Hat multicluster global hub 1.6.0, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat OpenStack Platform 17.1, RHEM 1.1 for RHEL 10, Red Hat OpenStack Platform 17.1, Red Hat build of Apicurio Registry 2, Deployment Validation Operator, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat Edge Manager 1.1, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Virtualization 4, Red Hat Ansible Automation Platform 2, Red Hat Service Interconnect 2, Multicluster Engine for Kubernetes, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Ansible Automation Platform 2.6 for RHEL 10, Multicluster Engine for Kubernetes, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Certification Program for Red Hat Enterprise Linux 9, OpenShift Lightspeed, Red Hat multicluster global hub 1.4.4, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, OpenShift Serverless, Service Telemetry Framework 1.5, Red Hat Enterprise Linux 9, Red Hat Edge Manager 1.0, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Enterprise Linux 9, Red Hat OpenShift GitOps 1.2, Logical Volume Manager Storage, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Red Hat OpenShift on AWS, OpenShift Source-to-Image (S2I), Red Hat OpenShift distributed tracing 3, Red Hat Ceph Storage 5, Red Hat OpenShift Service Mesh 3.2, Red Hat Openshift Data Foundation 4, Custom Metric Autoscaler operator for Red Hat Openshift, Zero Trust Workload Identity Manager, Red Hat Enterprise Linux 9, Multicluster Global Hub 1.5.4, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Multicluster Engine for Kubernetes, Confidential Compute Attestation, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Web Terminal 1.16, Red Hat OpenShift Dev Workspaces Operator, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, OpenShift Service Mesh 2, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Trusted Artifact Signer 1.4, streams for Apache Kafka 3, Red Hat OpenShift Service Mesh 3.1, OpenShift Developer Tools and Services, Red Hat Ceph Storage 9, Red Hat Enterprise Linux 10, Red Hat OpenShift AI 2.25, cert-manager Operator for Red Hat OpenShift, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat OpenStack Platform 18.0, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat Lightspeed for Runtimes Operator, Red Hat OpenStack Platform 16.2, Red Hat OpenShift AI (RHOAI), File Integrity Operator, Multicluster Engine for Kubernetes, Red Hat Enterprise Linux 10, Logging Subsystem for Red Hat OpenShift 6.4, Red Hat OpenShift AI (RHOAI), Red Hat Service Interconnect 2, Red Hat OpenShift Service Mesh 3.0, Logging for Red Hat OpenShift 6.2, Zero Trust Workload Identity Manager - Tech Preview, Red Hat Enterprise Linux 8, Multicluster Engine for Kubernetes, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Service Mesh 3.2, Red Hat OpenShift Service Mesh 3.0, Red Hat Web Terminal 1.11, Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, OpenShift Service Mesh 3, Power monitoring for Red Hat OpenShift, Red Hat OpenShift Service Mesh 3.3, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Satellite 6.19 for RHEL 9, Logical Volume Manager Storage, Red Hat Service Interconnect 2, OpenShift Service Mesh 2, Gatekeeper 3, Red Hat Developer Hub 1.9, Red Hat Enterprise Linux 8, Red Hat Satellite 6, Red Hat build of Apicurio Registry 2, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift GitOps 1.21, Red Hat Satellite 6.16 for RHEL 8, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Web Terminal 1.15, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenStack Platform 17.1, Red Hat Openshift Data Foundation 4, Red Hat OpenShift Service Mesh 3.0, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), OpenShift Serverless, Red Hat OpenStack Platform 16.2, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Service Mesh 3.2, OpenShift API for Data Protection 1.6, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.6, Red Hat Advanced Cluster Security 4.9
Provider severity
HIGH
Conflicts
2

CVE-2026-33810

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Go standard library, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat multicluster global hub 1.4.4, Confidential Compute Attestation, Red Hat OpenShift AI (RHOAI), mirror registry for Red Hat OpenShift 2, Red Hat OpenShift AI (RHOAI), Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 10, OpenShift API for Data Protection 1.5, Assisted Installer for Red Hat OpenShift Container Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, OpenShift Service Mesh 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4, Logging Subsystem for Red Hat OpenShift 6, Red Hat Ansible Automation Platform 2.6, Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), OpenShift Service Mesh 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Gatekeeper 3, Red Hat Enterprise Linux 9, Red Hat AI Inference Server, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, OpenShift Pipelines, Red Hat OpenStack Platform 16.2, streams for Apache Kafka 3, Logical Volume Manager Storage, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Migration Toolkit for Applications 8, Red Hat Service Interconnect 1, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat 3scale API Management Platform 2, Red Hat Satellite 6, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Zero Trust Workload Identity Manager - Tech Preview, OpenShift Service Mesh 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), OpenShift Serverless, Red Hat Enterprise Linux 9, Red Hat OpenShift Dev Workspaces Operator, Red Hat OpenShift Cluster Manager CLI, Red Hat Enterprise Linux 10, Red Hat OpenShift Builds 1.7.3, Red Hat Enterprise Linux 10, Red Hat Ansible Automation Platform 2, Red Hat Edge Manager 1.1, Red Hat OpenStack Platform 17.1, OpenShift Service Mesh 3, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat Lightspeed (formerly Insights) for Runtimes 1, Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Container Platform 4, Security Profiles Operator, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux AI (RHEL AI) 3, Logging Subsystem for Red Hat OpenShift 6.4, mirror registry for Red Hat OpenShift, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat Migration Toolkit 1.8, Red Hat Ansible Automation Platform 2, OpenShift Lightspeed, Red Hat OpenShift AI (RHOAI), OpenShift Service Mesh 2, Red Hat Certification Program for Red Hat Enterprise Linux 9, OpenShift Service Mesh 2, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat OpenShift Container Platform 4, OpenShift Service Mesh 3, Red Hat OpenShift Container Platform 4, cert-manager Operator for Red Hat OpenShift, Red Hat Enterprise Linux 8, External Secrets Operator for Red Hat OpenShift, Red Hat AI Inference Server, OpenShift Service Mesh 3, Logical Volume Manager Storage, Red Hat OpenStack Platform 18.0, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3, Red Hat OpenStack Platform 16.2, Red Hat Satellite 6, Red Hat Enterprise Linux 10, OpenShift Developer Tools and Services, Red Hat Enterprise Linux 9, Red Hat Web Terminal 1.15, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Edge Manager 1.1, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Custom Metric Autoscaler operator for Red Hat Openshift, Red Hat Enterprise Linux 9, Red Hat Web Terminal 1.12, Red Hat Satellite 6.19 for RHEL 9, Machine Deletion Remediation Operator, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Multicluster Global Hub 1.5.4, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 7, Builds for Red Hat OpenShift 1.6.0, OpenShift Service Mesh 2, Red Hat OpenShift Container Platform 4, Logging Subsystem for Red Hat OpenShift, Network Observability Operator, Red Hat OpenShift for Windows Containers, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Red Hat OpenStack Services on OpenShift 18.0, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Service Telemetry Framework 1.5, Fence Agents Remediation Operator, Red Hat Enterprise Linux 9, RHEM 1.0 for RHEL 9, Red Hat OpenShift on AWS, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat Web Terminal 1.13, Red Hat OpenShift AI (RHOAI), Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift Container Platform 4, Power monitoring for Red Hat OpenShift, Red Hat Enterprise Linux 9, OpenShift Serverless, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Service Interconnect 2, Red Hat Enterprise Linux 9.4 Extended Update Support, File Integrity Operator, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), OpenShift Service Mesh 3, Red Hat Openshift Data Foundation 4, Red Hat Enterprise Linux 8, OpenShift Serverless, Red Hat OpenShift AI (RHOAI), Confidential Compute Attestation, Red Hat OpenStack Platform 16.2, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Red Hat Developer Hub, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Red Hat multicluster global hub 1.6.0, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), OpenShift Developer Tools and Services, Red Hat OpenShift AI (RHOAI), Compliance Operator 1, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Spaces 3.28, Red Hat OpenShift AI (RHOAI), Zero Trust Workload Identity Manager, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Multicluster Engine for Kubernetes, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat Web Terminal 1.11, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), OpenShift Service Mesh 3, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), OpenShift Service Mesh 2, Multicluster Engine for Kubernetes, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, ExternalDNS Operator, Red Hat Enterprise Linux 10, HawtIO HawtIO 4.4.0, Deployment Validation Operator, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat Web Terminal 1.14, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Node HealthCheck Operator, Red Hat Enterprise Linux 10, Red Hat Quay 3, Red Hat OpenShift AI (RHOAI), Red Hat 3scale API Management Platform 2, OpenShift Service Mesh 2, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Virtualization 4, ExternalDNS Operator, Red Hat OpenShift AI (RHOAI), crypto/x509, Red Hat OpenStack Platform 17.1, Red Hat OpenShift AI (RHOAI), Red Hat 3scale API Management Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenStack Platform 17.1 for RHEL 9, Red Hat 3scale API Management Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat Edge Manager 1.0, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Cryostat 4 on RHEL 9, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Virtualization 4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Connectivity Link 1, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift GitOps, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Virtualization 4, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Logging for Red Hat OpenShift 6.2, Logical Volume Manager Storage, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3, Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), OpenShift Developer Tools and Services, Red Hat Advanced Cluster Security 4, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux AI (RHEL AI) 3, OpenShift API for Data Protection 1.4, Red Hat OpenShift distributed tracing 3.9.2, Red Hat OpenStack Platform 17.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Virtualization 4
Provider severity
HIGH
Conflicts
3

CVE-2026-3381

Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. Compress::Raw::Zlib includes a copy of the zlib library. Compress::Raw::Zlib version 2.220 includes zlib 1.3.2, which addresses findings fron the 7ASecurity audit of zlib. The includes fixs for CVE-2026-27171.

PUBLISHED
Vendor
PMQS
Product
Compress::Raw::Zlib
Provider severity
CRITICAL
Conflicts
0

CVE-2026-33809

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

PUBLISHED
Vendor
golang.org/x/image
Product
golang.org/x/image/tiff
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33808

Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express middleware when Fastify router normalization options are enabled. This allows complete bypass of path-scoped authentication middleware via duplicate slashes when ignoreDuplicateSlashes is enabled, or via semicolon delimiters when useSemicolonDelimiter is enabled. In both cases, Fastify router normalizes the URL and matches the route, but @fastify/express passes the original un-normalized URL to Expre

PUBLISHED
Vendor
fastify
Product
@fastify/express
Provider severity
CRITICAL
Conflicts
0

CVE-2026-33807

@fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths to be doubled when inherited by child plugins. When a child plugin is registered with a prefix that matches a middleware path, the middleware path is prefixed a second time, causing it to never match incoming requests. This results in complete bypass of Express middleware security controls, including authentication, authorization, and rate limiting, for all routes defined with

PUBLISHED
Vendor
fastify
Product
@fastify/express
Provider severity
CRITICAL
Conflicts
0

CVE-2026-33806

Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still parsed correctly but schema validation is skipped. This is a regression introduced in fastify >= 5.3.2 by the fix for CVE-2025-32442 Patches: Upgrade to fastify v5.8.5 or later. Workarounds: None. Upgrade to the patched version.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, fastify, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Dev Spaces, Red Hat OpenShift AI (RHOAI), fastify, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI)
Provider severity
HIGH
Conflicts
3

CVE-2026-33805

@fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection header after the proxy has added its own headers via rewriteRequestHeaders. This allows attackers to retroactively strip proxy-added headers from upstream requests by listing them in the Connection header value. Any header added by the proxy for routing, access control, or security purposes can be selectively removed by a client. @fastify/http-proxy is also affected as it delegates

PUBLISHED
Vendor
@fastify/reply-from, Red Hat, Red Hat, @fastify/reply-from, Red Hat, Red Hat, Red Hat, Red Hat
Product
@fastify/http-proxy, Red Hat OpenShift Dev Spaces 3.27, Red Hat OpenShift AI (RHOAI), @fastify/reply-from, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI)
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-33804

@fastify/middie versions 9.3.1 and earlier are vulnerable to middleware bypass when the deprecated Fastify ignoreDuplicateSlashes option is enabled. The middleware path matching logic does not account for duplicate slash normalization performed by Fastify's router, allowing requests with duplicate slashes to bypass middleware authentication and authorization checks. This only affects applications using the deprecated ignoreDuplicateSlashes option. Upgrade to @fastify/middie 9.3.2 to fix this iss

PUBLISHED
Vendor
@fastify/middie
Product
@fastify/middie
Provider severity
HIGH
Conflicts
0

CVE-2026-33803

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device. Due to a wrong initialization, a process which should only be able to communicate internally within the device can be reached over the network via an open port. This leads to a device being inadvertently exposed and increased CPU cycles spent pr

PUBLISHED
Vendor
Juniper Networks
Product
Junos OS Evolved
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33802

A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS). On EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400 switches, an authenticated, local attacker with no specific permissions or class can execute a specific, privileged CLI 'request' command which will cause complete traffic impact until the system automatically recovers. This issue affects Junos OS on EX2300, EX4000,

PUBLISHED
Vendor
Juniper Networks
Product
Junos OS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33801

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a specific BGP update over an established BGP session to cause a Denial-of-Service (DoS). Upon receipt of a specifically malformed non-inet/inet6 unicast BGP update, an RPD crash and restart is triggered, which will cause a complete service outage until routing has reconverged. The rpd cr

PUBLISHED
Vendor
Juniper Networks, Juniper Networks
Product
Junos OS Evolved, Junos OS
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-33800

An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).Micro-BFD session flaps generate respective up/down events which are queued by PFEMAN for processing. Especially in a Virtual-Chassis (VC) scenario with locality‑bias configured, processing takes a significant amount of time for each event. If these sessions keep flapping, new events are

PUBLISHED
Vendor
Juniper Networks
Product
Junos OS
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-3380

A vulnerability was found in Tenda F453 1.0.0.3. This issue affects the function frmL7ImForm of the file /goform/L7Im. The manipulation of the argument page results in buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
Tenda
Product
F453
Provider severity
HIGH
Conflicts
2

CVE-2026-33799

An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak. Over time, continuous receipt of these queries will result in snmpd process memory exhaustion, resulting in a process crash and restart, impacting the ability to monitor the system via SNMP. Memory usage can be monitored using the following command: user@device> show syste

PUBLISHED
Vendor
Juniper Networks, Juniper Networks
Product
Junos OS Evolved, Junos OS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-33797

An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to reset only that session causing a Denial of Service (DoS). An attacker repeatedly sending the packet will sustain the Denial of Service (DoS).This issue affects Junos OS: * 25.2 versions before 25.2R2 This issue does not affect Junos OS versions before 25.2R1. This issue af

PUBLISHED
Vendor
Juniper Networks, Juniper Networks
Product
Junos OS Evolved, Junos OS
Provider severity
HIGH
Conflicts
2

CVE-2026-33794

An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating continuous routing updates, resulting in unilist ECMP routes, to crash the evo-aftmand process on the PFE, leading to a Denial-of-Service (DoS). The conditions required for successful exploitation are based on a sequence of events that are outside an attacker's di

PUBLISHED
Vendor
Juniper Networks
Product
Junos OS Evolved
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-33793

An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the system. When a configuration that allows unsigned Python op scripts is present on the device, a non-root user is able to execute malicious op scripts as a root-equivalent user, leading to privilege escalation.  This issue affects Junos OS:  * All versions before 22.4R3-S7, 

PUBLISHED
Vendor
Juniper Networks, Juniper Networks
Product
Junos OS Evolved, Junos OS
Provider severity
HIGH
Conflicts
2

CVE-2026-33791

An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI commands to inject arbitrary shell commands as root, leading to a complete compromise of the system. Certain 'set system' commands, when executed with crafted arguments, are not properly sanitized, allowing for arbitrary shell injection. These shell commands are executed as root, potentially allowing for complete c

PUBLISHED
Vendor
Juniper Networks, Juniper Networks
Product
Junos OS, Junos OS Evolved
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-33790

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker sending a specific, malformed ICMPv6 packet to cause the srxpfe process to crash and restart. Continued receipt and processing of these packets will repeatedly crash the srxpfe process and sustain the Denial of Service (DoS) condition. During NAT64 translation, receipt of a specific, malformed ICMPv6 packet destined to the device will cau

PUBLISHED
Vendor
Juniper Networks
Product
Junos OS
Provider severity
HIGH
Conflicts
1

CVE-2026-3379

A vulnerability has been found in Tenda F453 1.0.0.3. This vulnerability affects the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Tenda
Product
F453
Provider severity
HIGH
Conflicts
2

CVE-2026-33788

A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to FPCs installed in the device. A local user with low privileges can gain direct access to the installed FPCs as a high privileged user, which can potentially lead to a full compromise of the affected component. This issue affects Junos OS Evolved on PTX10004, PT

PUBLISHED
Vendor
Juniper Networks
Product
Junos OS Evolved
Provider severity
HIGH
Conflicts
1

CVE-2026-33787

An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1500, SRX4100, SRX4200 and SRX4600 allows a local attacker with low privileges to cause a complete Denial of Service (DoS). When a specific 'show chassis' CLI command is executed, chassisd crashes and restarts which causes a momentary impact to all traffic until all modules are online again. This issue affects Junos OS on SRX1500, SRX4100, SRX4200

PUBLISHED
Vendor
Juniper Networks
Product
Junos OS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33786

An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300 and SRX4300 allows a local attacker with low privileges to cause a complete Denial of Service (DoS). When a specific 'show chassis' CLI command is executed, chassisd crashes and restarts which causes a momentary impact to all traffic until all modules are online again. This issue affects Junos OS on SRX1600, SRX2300 and SRX4300: *

PUBLISHED
Vendor
Juniper Networks
Product
Junos OS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33785

A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute specific commands which will lead to a complete compromise of managed devices. Any user logged in, without requiring specific privileges, can issue 'request csds' CLI operational commands. These commands are only meant to be executed by high privileged or users designated for Juniper Device Manager (JDM) / Connected Security Distributed Ser

PUBLISHED
Vendor
Juniper Networks
Product
Junos OS
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-33784

A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device. vLWC software images ship with an initial password for a high privileged account. A change of this password is not enforced during the provisioning of the software, which can make full access to the system by unauthorized actors possible.This issue affects all versions of vLWC before

PUBLISHED
Vendor
Juniper Networks
Product
JSI LWC
Provider severity
CRITICAL
Conflicts
1

CVE-2026-33783

A Function Call With Incorrect Argument Type vulnerability in the sensor interface of Juniper Networks Junos OS Evolved on PTX Series allows a network-based, authenticated attacker with low privileges to cause a complete Denial of Service (DoS). If colored SRTE policy tunnels are provisioned via PCEP, and gRPC is used to monitor traffic in these tunnels, evo-aftmand crashes and doesn't restart which leads to a complete and persistent service impact. The system has to be manually restarted to r

PUBLISHED
Vendor
Juniper Networks
Product
Junos OS Evolved
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-33782

A Missing Release of Memory after Effective Lifetime vulnerability in the DHCP daemon (jdhcpd) of Juniper Networks Junos OS on MX Series, allows an adjacent, unauthenticated attacker to cause a memory leak, that will eventually cause a complete Denial-of-Service (DoS). In a DHCPv6 over PPPoE, or DHCPv6 over VLAN with Active lease query or Bulk lease query scenario, every subscriber logout will leak a small amount of memory. When all available memory has been exhausted, jdhcpd will crash and res

PUBLISHED
Vendor
Juniper Networks
Product
Junos OS
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-33781

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX and QFX Series devices allow an unauthenticated, adjacent attacker to cause a complete Denial of Service (DoS). On EX4k, and QFX5k platforms configured as service-provider edge devices, if L2PT is enabled on the UNI and VSTP is enabled on NNI in VXLAN scenarios, receiving VSTP BPDUs on UNI leads to packet buffer allocation failures, resulting in

PUBLISHED
Vendor
Juniper Networks
Product
Junos OS
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-33780

A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a memory leak ultimately leading to a Denial of Service (DoS). In an EVPN-MPLS scenario, routes learned from remote multi-homed Provider Edge (PE) devices are programmed as ESI routes. Due to a logic issue in the l2ald memory management, memory allocated for these routes is not

PUBLISHED
Vendor
Juniper Networks, Juniper Networks
Product
Junos OS, Junos OS Evolved
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-3378

A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromqossetting of the file /goform/qossetting. Executing a manipulation of the argument qos can lead to buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
Tenda
Product
F453
Provider severity
HIGH
Conflicts
2

CVE-2026-33779

An Improper Following of a Certificate's Chain of Trust vulnerability in J-Web of Juniper Networks Junos OS on SRX Series allows a PITM to intercept the communication of the device and get access to confidential information and potentially modify it. When an SRX device is provisioned to connect to Security Director (SD) cloud, it doesn't perform sufficient verification of the received server certificate. This allows a PITM to intercept the communication between the SRX and SD cloud and access c

PUBLISHED
Vendor
Juniper Networks
Product
Junos OS
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-33778

An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a complete Denial-of-Service (DoS). If an affected device receives a specifically malformed first ISAKMP packet from the initiator, the kmd/iked process will crash and restart, which momentarily prevents new security associations (SAs) for from being established. Repea

PUBLISHED
Vendor
Juniper Networks
Product
Junos OS
Provider severity
HIGH
Conflicts
1