Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-32325

Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the server where the affected product is installed may obtain SYSTEM privilege.

PUBLISHED
Vendor
Fsas Technologies Inc.
Product
ServerView Agents for Windows
Provider severity
HIGH
Conflicts
1

CVE-2026-32324

Anviz CX7 Firmware is  vulnerable because the application embeds reusable certificate/key material, enabling decryption of MQTT traffic and potential interaction with device messaging channels at scale.

PUBLISHED
Vendor
Anviz
Product
Anviz CX7 Firmware
Provider severity
HIGH
Conflicts
0

CVE-2026-32323

Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may allow local privilege escalation during installation or upgrade. The installer package executes binaries from /Applications/Mullvad VPN.app without verifying if the bundle is attacker-controlled or that the path is the legitimate Mullvad application. A user in the admin group can pre-place a crafted application bundle at that location and may be able to achieve code execution

PUBLISHED
Vendor
mullvad
Product
mullvadvpn-app
Provider severity
HIGH
Conflicts
1

CVE-2026-32322

soroban-sdk is a Rust SDK for Soroban contracts. Prior to 22.0.11, 23.5.3, and 25.3.0, The Fr (scalar field) types for BN254 and BLS12-381 in soroban-sdk compared values using their raw U256 representation without first reducing modulo the field modulus r. This caused mathematically equal field elements to compare as not-equal when one or both values were unreduced (i.e., >= r). The vulnerability requires an attacker to supply crafted Fr values through contract inputs, and compare them directly

PUBLISHED
Vendor
stellar
Product
rs-soroban-sdk
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32321

ClipBucket v5 is an open source video sharing platform. An authenticated time-based blind SQL injection vulnerability exists in ClipBucket prior to 5.5.3 #80 within the `actions/ajax.php` endpoint. Due to insufficient input sanitization of the `userid` parameter, an authenticated attacker can execute arbitrary SQL queries, leading to full database disclosure and potential administrative account takeover. Version 5.5.3 #80 fixes the issue.

PUBLISHED
Vendor
MacWarrior
Product
clipbucket-v5
Provider severity
HIGH
Conflicts
0

CVE-2026-32320

Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a PathSwitchRequest containing UE Security Capabilities with zero-length NR encryption or integrity protection algorithm bitstrings, resulting in a denial of service. An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required. This vulnerability is fixed in 1.5.1.

PUBLISHED
Vendor
ellanetworks
Product
core
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32319

Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a malformed integrity protected NGAP/NAS message with a length under 7 bytes. An attacker able to send crafted NAS messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required. This vulnerability is fixed in 1.5.1.

PUBLISHED
Vendor
ellanetworks
Product
core
Provider severity
HIGH
Conflicts
0

CVE-2026-32318

Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.8.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before this fix, the client trusted endpoints from the vault config without host authenticity checks, which could allow token exfiltration by mixing a legitimate auth endpoint with a malicious API endpoint.

PUBLISHED
Vendor
cryptomator
Product
ios
Provider severity
HIGH
Conflicts
1

CVE-2026-32317

Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 1.12.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before this fix, the client trusted endpoints from the vault config without host authenticity checks, which could allow token exfiltration by mixing a legitimate auth endpoint with a malicious API endpo

PUBLISHED
Vendor
cryptomator
Product
android
Provider severity
HIGH
Conflicts
1

CVE-2026-32316

jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad functions, where concatenating strings with a combined length exceeding 2^31 bytes causes a 32-bit unsigned integer overflow in the buffer allocation size calculation, resulting in a drastically undersized heap buffer. Subsequent memory copy operations then write the full string data into this undersized buffer, causing a heap buffer o

PUBLISHED
Vendor
jqlang
Product
jq
Provider severity
HIGH
Conflicts
1

CVE-2026-32315

motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the configuration file /etc/motioneye/motion.conf with 644 permissions (-rw-r--r--), making it readable by any local user on the system. This file contains sensitive data including the admin password hash, which can be leveraged by other vulnerabilities to escalate privileges. Additionally, per-camera configuration files (camera-*.conf) are also created

PUBLISHED
Vendor
motioneye-project
Product
motioneye
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32314

Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. Prior to 0.13.10, the Rust implementation of Yamux can panic when processing a crafted inbound Data frame that sets SYN and uses a body length greater than DEFAULT_CREDIT (e.g. 262145). On the first packet of a new inbound stream, stream state is created and a receiver is queued before oversized-body validation completes. When validation fails, the temporary stream is dropped and cleanup may call remove(...).expect(

PUBLISHED
Vendor
libp2p
Product
rust-yamux
Provider severity
HIGH
Conflicts
0

CVE-2026-32313

xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Prior to 3.1.5, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the authentication tag length. An attacker can use this to brute-force an authentication tag, recover the GHASH key, and decrypt the encrypted nodes. It also allows to forge arbitrary ciphertexts without knowing the encryption key. This vulnerability is fixed in 3.1.5.

PUBLISHED
Vendor
robrichards
Product
xmlseclibs
Provider severity
HIGH
Conflicts
0

CVE-2026-32312

GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the structure of unauthorized forms. This issue has been fixed in version 11.0.7.

PUBLISHED
Vendor
glpi-project
Product
glpi
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32311

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Flowsint allows a user to create investigations, which are used to manage sketches and analyses. Sketches have controllable graphs, which are comprised of nodes and relationships. The sketches contain information on an OSINT target (usernames, websites, etc) within these nodes and relationships. The nodes can have automated processes execute on them called 'transforme

PUBLISHED
Vendor
reconurge
Product
flowsint
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32310

Cryptomator encrypts data being stored on cloud infrastructure. From version 1.6.0 to before version 1.19.1, vault configuration is parsed before its integrity is verified, and the masterkeyfile loader uses the unverified keyId as a filesystem path. The loader resolves keyId.getSchemeSpecificPart() directly against the vault path and immediately calls Files.exists(...). This allows a malicious vault config to supply parent-directory escapes, absolute local paths, or UNC paths (e.g., masterkeyfil

PUBLISHED
Vendor
cryptomator
Product
cryptomator
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3231

The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom radio and checkboxgroup field values submitted through the WooCommerce Block Checkout Store API in all versions up to, and including, 2.1.7. This is due to the `prepare_single_field_data()` method in `class-thwcfd-block-order-data.php` first escaping values with `esc_html()` then immediately reversing the escaping with `html_entity_decode()` for radio and chec

PUBLISHED
Vendor
themehigh
Product
Checkout Field Editor (Checkout Manager) for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-32309

Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow explicitly supports hub+http and consumes Hub endpoints from vault metadata without enforcing HTTPS. As a result, a vault configuration can drive OAuth and key-loading traffic over plaintext HTTP or other insecure endpoint combinations. An active network attacker can tamper with or observe this traffic. Even when the vault key is encrypted for the device, bearer tokens and endpoint-

PUBLISHED
Vendor
cryptomator
Product
cryptomator
Provider severity
HIGH
Conflicts
0

CVE-2026-32308

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the Markdown viewer component renders Mermaid diagrams with securityLevel: "loose" and injects the SVG output via innerHTML. This configuration explicitly allows interactive event bindings in Mermaid diagrams, enabling XSS through Mermaid's click directive which can execute arbitrary JavaScript. Any field that renders markdown (incident descriptions, status page announcements, monitor notes) is vulnerable. Thi

PUBLISHED
Vendor
OneUptime
Product
oneuptime
Provider severity
HIGH
Conflicts
0

CVE-2026-32306

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API accepts user-controlled aggregationType, aggregateColumnName, and aggregationTimestampColumnName parameters and interpolates them directly into ClickHouse SQL queries via the .append() method (documented as "trusted SQL"). There is no allowlist, no parameterized query binding, and no input validation. An authenticated user can inject arbitrary SQL into ClickHouse, enabling full da

PUBLISHED
Vendor
OneUptime
Product
oneuptime
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32305

Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1 are vulnerable to mTLS bypass through the TLS SNI pre-sniffing logic related to fragmented ClientHello packets. When a TLS ClientHello is fragmented across multiple records, Traefik's SNI extraction may fail with an EOF and return an empty SNI. The TCP router then falls back to the default TLS configuration, which does not require client certificates by default. This allows

PUBLISHED
Vendor
traefik, Red Hat, Red Hat, Red Hat
Product
traefik, Red Hat OpenShift Dev Spaces 3.28, Red Hat OpenShift Dev Spaces 3.27, Red Hat OpenShift GitOps
Provider severity
HIGH
Conflicts
3

CVE-2026-32304

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) function passes both parameters directly to the Function constructor without any sanitization, allowing arbitrary code execution. This is distinct from CVE-2026-29091 which was call_user_func_array using eval() in v2.x. This finding affects create_function using new Function() in v3.x. This vulnerability is fixed in 3.0.14.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, locutusjs
Product
Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, locutus
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-32303

Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerability allows an attacker to tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before this fix, the client trusted endpoints from the vault config without host authenticity checks, which could allow token exfiltration by mixing a legitimate auth endpoint with a malicious API endpoint. Impacted are users unlocking Hub-

PUBLISHED
Vendor
cryptomator
Product
cryptomator
Provider severity
HIGH
Conflicts
1

CVE-2026-32302

OpenClaw is a personal AI assistant. Prior to 2026.3.11, browser-originated WebSocket connections could bypass origin validation when gateway.auth.mode was set to trusted-proxy and the request arrived with proxy headers. A page served from an untrusted origin could connect through a trusted reverse proxy, inherit proxy-authenticated identity, and establish a privileged operator session. This vulnerability is fixed in 2026.3.11.

PUBLISHED
Vendor
openclaw
Product
openclaw
Provider severity
HIGH
Conflicts
0

CVE-2026-32301

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Side Request Forgery (SSRF) when configured with a dynamic JWKS endpoint URL using template variables (e.g. {{tenant}}). An unauthenticated attacker can craft a JWT with a malicious iss or aud claim value that gets interpolated into the JWKS fetch URL before the token signature is verified, causing Centrifugo to make an outbound HTTP request to an attacker-controlled destination.

PUBLISHED
Vendor
centrifugal
Product
centrifugo
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32300

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Versions 1.41.1 and 2.41.1 contain a patch.

PUBLISHED
Vendor
opensource-workshop
Product
connect-cms
Provider severity
HIGH
Conflicts
1

CVE-2026-3230

Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.

PUBLISHED
Vendor
wolfSSL
Product
wolfSSL
Provider severity
LOW
Conflicts
0

CVE-2026-32299

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Versions 1.41.1 and 2.41.1 contain a patch.

PUBLISHED
Vendor
opensource-workshop
Product
connect-cms
Provider severity
HIGH
Conflicts
0

CVE-2026-32298

The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authenticated attacker to execute OS-level commands.

PUBLISHED
Vendor
ANGEET
Product
ES3 KVM
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-32297

The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or system binaries. Modified configuration files or system binaries could allow an attacker to take complete control of a vulnerable system.

PUBLISHED
Vendor
ANGEET
Product
ES3 KVM
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-32296

Sipeed NanoKVM before 2.3.1 exposes a Wi-Fi configuration endpoint without proper security checks, allowing an unauthenticated attacker with network access to change the saved configured Wi-Fi network to one of the attacker's choosing, or craft a request to exhaust the system memory and terminate the KVM process.

PUBLISHED
Vendor
Sipeed
Product
NanoKVM
Provider severity
HIGH
Conflicts
1

CVE-2026-32295

JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials.

PUBLISHED
Vendor
JetKVM
Product
JetKVM
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-32294

JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding SHA256 hash to pass verification.

PUBLISHED
Vendor
JetKVM
Product
JetKVM
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-32293

The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. The GL-RM1 does not verify certificates used for this connection, allowing an attacker-in-the-middle to serve invalid client and CA certificates. The GL-RM1 will attempt to use the invalid certificates and fail to connect to the legitimate GL-iNet KVM cloud service.

PUBLISHED
Vendor
GL-iNet
Product
Comet KVM
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2026-32292

The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials.

PUBLISHED
Vendor
GL-iNet
Product
Comet KVM
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-32291

The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the device and connecting to the UART pins.

PUBLISHED
Vendor
GL-iNet
Product
Comet KVM
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-32290

The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding MD5 hash to pass verification.

PUBLISHED
Vendor
GL-iNet
Product
Comet KVM
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-3229

An integer overflow vulnerability existed in the static function wolfssl_add_to_chain, that caused heap corruption when certificate data was written out of bounds of an insufficiently sized certificate buffer. wolfssl_add_to_chain is called by these API: wolfSSL_CTX_add_extra_chain_cert, wolfSSL_CTX_add1_chain_cert, wolfSSL_add0_chain_cert. These API are enabled for 3rd party compatibility features: enable-opensslall, enable-opensslextra, enable-lighty, enable-stunnel, enable-nginx, enable-hapro

PUBLISHED
Vendor
wofSSL
Product
wolfSSL
Provider severity
LOW
Conflicts
0

CVE-2026-32289

Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.

PUBLISHED
Vendor
Go standard library
Product
html/template
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32288

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

PUBLISHED
Vendor
Go standard library
Product
archive/tar
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32287

Boolean XPath expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU usage. This can be triggered by top-level selectors such as "1=1" or "true()".

PUBLISHED
Vendor
github.com/antchfx/xpath
Product
github.com/antchfx/xpath
Provider severity
HIGH
Conflicts
0

CVE-2026-32286

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, github.com/jackc/pgproto3/v2, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Multicluster Engine for Kubernetes, Red Hat Quay 3, Red Hat Quay 3, Red Hat Enterprise Linux 8, Red Hat Trusted Artifact Signer, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer, Red Hat Advanced Cluster Security 4.8, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Multicluster Global Hub 1.3.4, Multicluster Engine for Kubernetes, Red Hat OpenShift on AWS, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Quay 3.1, Red Hat Quay 3.17, Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, Multicluster Global Hub 1.3.4, Red Hat OpenShift Cluster Manager CLI, Red Hat Quay 3, Multicluster Engine for Kubernetes, Red Hat Hardened Images, Red Hat Advanced Cluster Security 4, Red Hat Hardened Images, Multicluster Global Hub 1.5.4, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Security 4, github.com/jackc/pgproto3/v2, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Quay 3, Multicluster Global Hub 1.3.4, Red Hat Advanced Cluster Management for Kubernetes 2, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4, Red Hat Quay 3.9, Red Hat Quay 3.12, Red Hat multicluster global hub 1.6.0, Red Hat Quay 3.15, Red Hat multicluster global hub 1.4.4, Assisted Installer for Red Hat OpenShift Container Platform 2, Red Hat OpenShift AI (RHOAI), Assisted Installer for Red Hat OpenShift Container Platform 2, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Multicluster Global Hub, Red Hat Trusted Artifact Signer, Red Hat Quay 3.16, Multicluster Engine for Kubernetes, Red Hat Quay 3.14, Red Hat Trusted Artifact Signer, Multicluster Engine for Kubernetes, Red Hat Advanced Cluster Security 4.8, Red Hat Trusted Artifact Signer, Red Hat OpenShift Container Platform 4
Provider severity
HIGH
Conflicts
2

CVE-2026-32285

The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, github.com/buger/jsonparser, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
multicluster engine for Kubernetes 2.8, Red Hat Ansible Automation Platform 2, Logging Subsystem for Red Hat OpenShift 6.4, Multicluster Global Hub 1.5.4, Red Hat OpenShift for Windows Containers, Red Hat multicluster global hub 1.4.4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift GitOps, multicluster engine for Kubernetes 2.1, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat OpenShift distributed tracing 3.9.2, Red Hat Hardened Images, Red Hat OpenShift for Windows Containers, Red Hat OpenShift distributed tracing 3.9.2, Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift GitOps, Red Hat Advanced Cluster Management for Kubernetes 2.15, Red Hat OpenShift Container Platform 4, Multicluster Global Hub 1.3.4, Red Hat OpenStack Platform 18.0, github.com/buger/jsonparser, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Red Hat multicluster global hub 1.6.0, Red Hat OpenShift Container Platform 4, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, multicluster engine for Kubernetes 2.8, Red Hat OpenShift Container Platform 4
Provider severity
HIGH
Conflicts
2

CVE-2026-32284

The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack.

PUBLISHED
Vendor
github.com/shamaton/msgpack, github.com/shamaton/msgpack/v3, github.com/shamaton/msgpack/v2
Product
github.com/shamaton/msgpack, github.com/shamaton/msgpack/v3, github.com/shamaton/msgpack/v2
Provider severity
HIGH
Conflicts
1

CVE-2026-32283

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Go standard library, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Service Interconnect 2, Red Hat OpenShift GitOps, Red Hat Enterprise Linux 9, ExternalDNS Operator, Compliance Operator 1, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Cluster Manager CLI, Red Hat OpenStack Platform 17.1, OpenShift Pipelines, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Workspaces Operator, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Multicluster Global Hub 1.3.4, Red Hat Enterprise Linux AI (RHEL AI) 3, Node HealthCheck Operator, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, RHEM 1.1 for RHEL 10, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Confidential Compute Attestation, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat multicluster global hub 1.6.0, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Logging Subsystem for Red Hat OpenShift, Red Hat Ansible Automation Platform 2.5 for RHEL 8, OpenShift Service Mesh 3, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Logical Volume Manager Storage, Migration Toolkit for Applications 8, Red Hat Enterprise Linux 9, Service Telemetry Framework 1.5, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat Certification Program for Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat OpenShift distributed tracing 3.9.2, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6.19 for RHEL 9, Red Hat OpenStack Platform 16.2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Container Platform 4, Deployment Validation Operator, Red Hat Enterprise Linux 10, Logical Volume Manager Storage, Gatekeeper 3, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9.6 Extended Update Support, File Integrity Operator, Red Hat Enterprise Linux 10, Machine Deletion Remediation Operator, Red Hat AMQ Broker 7, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Red Hat Service Interconnect 1, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Quay 3, Custom Metric Autoscaler 2.19, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Network Observability Operator, Red Hat Trusted Artifact Signer, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat OpenShift AI (RHOAI), Zero Trust Workload Identity Manager, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Connectivity Link 1, Red Hat OpenStack Platform 16.2, Red Hat Enterprise Linux 10, Red Hat OpenShift distributed tracing 3.9.2, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat Migration Toolkit 1.8, Red Hat Ansible Automation Platform 2, ExternalDNS Operator, Red Hat OpenShift Dev Spaces, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat AI Inference Server, Zero Trust Workload Identity Manager - Tech Preview, Red Hat Hardened Images, Red Hat 3scale API Management Platform 2, OpenShift Developer Tools and Services, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Security 4, OpenShift Service Mesh 3, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, OpenShift Developer Tools and Services, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat OpenShift AI (RHOAI), Red Hat OpenStack Platform 16.2, Red Hat OpenShift Container Platform 4, Red Hat AI Inference Server, OpenShift API for Data Protection, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, OpenShift Lightspeed, OpenShift Developer Tools and Services, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10.0 Extended Update Support, RHEM 1.0 for RHEL 9, Red Hat OpenShift Virtualization 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat AMQ Broker 7, OpenShift Serverless, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Logical Volume Manager Storage, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift for Windows Containers, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat OpenShift AI (RHOAI), Red Hat Web Terminal, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Satellite 6, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat multicluster global hub 1.4.4, Multicluster Engine for Kubernetes, Red Hat Developer Hub, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Ansible Automation Platform 2.6 for RHEL 10, Red Hat Enterprise Linux 9.6 Extended Update Support, cert-manager Operator for Red Hat OpenShift, Red Hat Enterprise Linux 8, Red Hat Openshift Data Foundation 4, Power monitoring for Red Hat OpenShift, Red Hat OpenShift AI (RHOAI), Red Hat OpenStack Platform 17.1 for RHEL 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenStack Platform 18.0, Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat OpenShift AI (RHOAI), Red Hat OpenStack Platform 17.1, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 9, Red Hat OpenStack Platform 17.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Fence Agents Remediation Operator, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Hardened Images, Red Hat OpenShift AI 2.25, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat OpenShift AI (RHOAI), Red Hat OpenStack Services on OpenShift 18.0, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Lightspeed (formerly Insights) for Runtimes 1, Red Hat OpenShift Container Platform 4, crypto/tls, Red Hat Enterprise Linux 10, RHEM 1.1 for RHEL 9, Red Hat AI Inference Server, Red Hat Satellite 6.16 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat OpenShift Virtualization 4, Red Hat OpenShift AI (RHOAI), OpenShift Developer Tools and Services, streams for Apache Kafka 3, Red Hat Enterprise Linux 9, OpenShift Serverless, Red Hat build of Apicurio Registry 2, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.5 for RHEL 9, Multicluster Global Hub 1.5.4, mirror registry for Red Hat OpenShift 2, Red Hat Satellite 6.16 for RHEL 8, OpenShift Service Mesh 2, OpenShift Developer Tools and Services, Red Hat Satellite 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Edge Manager 1, Red Hat Enterprise Linux 9, Confidential Compute Attestation, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Enterprise Linux 9, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9.6 Extended Update Support, OpenShift Service Mesh 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Builds for Red Hat OpenShift, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Assisted Installer for Red Hat OpenShift Container Platform 2, External Secrets Operator for Red Hat OpenShift, Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat build of Apache Camel - HawtIO 4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat OpenShift on AWS, Red Hat build of Apicurio Registry 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift distributed tracing 3.9.2, Red Hat OpenShift Virtualization 4, Cryostat 4 on RHEL 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), OpenShift Serverless, Security Profiles Operator, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat OpenShift Container Platform 4, Red Hat 3scale API Management Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat OpenShift Virtualization 4, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 10, Red Hat JBoss Web Server 6, Red Hat OpenShift AI (RHOAI), mirror registry for Red Hat OpenShift
Provider severity
HIGH
Conflicts
2

CVE-2026-32282

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced

PUBLISHED
Vendor
Go standard library
Product
internal/syscall/unix
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32281

Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

PUBLISHED
Vendor
Go standard library
Product
crypto/x509
Provider severity
HIGH
Conflicts
0

CVE-2026-32280

A flaw was found in the Go standard library packages `crypto/x509` and `crypto/tls`. During the process of building a certificate chain, an attacker can provide a large number of intermediate certificates. This excessive input is not properly limited, leading to an uncontrolled amount of work being performed. This can result in a denial of service (DoS) condition, making the affected system or application unavailable to legitimate users.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Go standard library, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Security Profiles Operator, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Security 4.9, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Connectivity Link 1, mirror registry for Red Hat OpenShift, multicluster engine for Kubernetes 2.11, Red Hat OpenShift Service Mesh 2.6, Red Hat OpenShift Service Mesh 3.3, Red Hat Enterprise Linux AI (RHEL AI) 3, OpenShift Lightspeed, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6, Red Hat OpenShift Container Platform 4.14, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat OpenShift Service Mesh 3.2, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Logging for Red Hat OpenShift 6.2, Red Hat Web Terminal 1.13, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), Red Hat Web Terminal 1.12, Red Hat Ansible Automation Platform 2.6 for RHEL 10, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 7, Red Hat OpenShift distributed tracing 3.9.2, multicluster engine for Kubernetes 2.6, Red Hat Enterprise Linux 10, Custom Metric Autoscaler 2.19, Red Hat OpenShift AI (RHOAI), Power monitoring for Red Hat OpenShift, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 10, Red Hat OpenShift Service Mesh 3.1, Red Hat Quay 3.15, Red Hat OpenShift Container Platform 4.19, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), OpenShift Serverless, Red Hat Hardened Images, Deployment Validation Operator, Red Hat Advanced Cluster Security 4.9, RHEM 1.0 for RHEL 9, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4.19, Red Hat OpenShift Service Mesh 3.0, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Virtualization 4, multicluster engine for Kubernetes 2.8, Confidential Compute Attestation, Red Hat Advanced Cluster Security for Kubernetes 4.10, File Integrity Operator, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Service Mesh 3.3, Red Hat OpenShift Container Platform 4.18, Red Hat OpenShift Virtualization 4, Red Hat OpenShift Service Mesh 3.2, Red Hat Edge Manager 1.1, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat OpenShift Builds 1.7.3, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat Web Terminal 1.14, Red Hat Enterprise Linux 8, Red Hat 3scale API Management Platform 2, Red Hat OpenShift Container Platform 4.15, Red Hat Migration Toolkit 1.8, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat OpenShift Container Platform 4.17, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat OpenStack Platform 17.1, OpenShift Service Mesh 2, Red Hat OpenShift GitOps, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Trusted Artifact Signer 1.3, Red Hat Openshift Data Foundation 4, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat OpenShift Service Mesh 2.6, OpenShift Developer Tools and Services, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4.18, Red Hat Service Interconnect 1, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, HawtIO HawtIO 4.4.0, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat OpenShift Service Mesh 2.6, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Red Hat OpenShift Service Mesh 2.6, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat OpenShift AI (RHOAI), Network Observability (NETOBSERV) 1.11.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Web Terminal 1.11, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Security 4.9, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat OpenShift Container Platform 4.17, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9, Red Hat OpenStack Platform 17.1, Red Hat OpenShift Container Platform 4.14, Red Hat OpenShift AI (RHOAI), OpenShift Serverless, Red Hat OpenShift for Windows Containers, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4.15, Red Hat OpenShift distributed tracing 3.9.2, Red Hat Satellite 6, Red Hat OpenStack Services on OpenShift 18.0, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat OpenShift AI (RHOAI), Red Hat Hardened Images, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat multicluster global hub 1.6.0, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat OpenShift Service Mesh 3.3, Red Hat OpenShift AI (RHOAI), OpenShift Developer Tools and Services, Red Hat Enterprise Linux 9, Red Hat OpenStack Platform 16.2, Red Hat Satellite 6.16 for RHEL 9, Red Hat Quay 3.17, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4.17, Red Hat OpenShift Container Platform 4, Red Hat Ansible Automation Platform 2, Migration Toolkit for Applications 8, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4.17, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat OpenShift on AWS, Red Hat OpenShift Service Mesh 3.0, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, OpenShift Service Mesh 3, Compliance Operator 1, Red Hat OpenShift AI (RHOAI), Logical Volume Manager Storage, Red Hat Advanced Cluster Security 4.9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Workspaces Operator, Machine Deletion Remediation Operator, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Service Mesh 3.0, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Cluster Manager CLI, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat OpenShift AI (RHOAI), multicluster engine for Kubernetes 2.17, Red Hat AI Inference Server, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Red Hat Certification Program for Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4.17, Red Hat OpenStack 1.5, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Developer Hub 1.8, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6.19 for RHEL 9, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4.18, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat Enterprise Linux 10, Red Hat Developer Hub 1.9, RHEM 1.1 for RHEL 9, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat AI Inference Server, Red Hat OpenShift Container Platform 4.17, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat OpenShift AI (RHOAI), Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4.18, Logging Subsystem for Red Hat OpenShift 6, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat OpenStack Platform 17.1, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat Quay 3.1, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4.17, Red Hat OpenShift Service Mesh 2.6, Red Hat Enterprise Linux 9.6 Extended Update Support, streams for Apache Kafka 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4.14, Red Hat Enterprise Linux 10.0 Extended Update Support, crypto/x509, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Container Platform 4, multicluster engine for Kubernetes 2.1, Red Hat Enterprise Linux 9, Red Hat Web Terminal 1.15, OpenShift Service Mesh 2, Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Service Mesh 3.1, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat OpenShift AI (RHOAI), mirror registry for Red Hat OpenShift 2.0, Node HealthCheck Operator, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Confidential Compute Attestation, Red Hat OpenShift Service Mesh 3.1, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Logical Volume Manager Storage, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Advanced Cluster Security 4.9, Assisted Installer for Red Hat OpenShift Container Platform 2, Red Hat Satellite 6.16 for RHEL 8, Red Hat OpenShift distributed tracing 3.9.2, OpenShift Developer Tools and Services, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.5 for RHEL 8, multicluster engine for Kubernetes 2.6, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 10, External Secrets Operator for Red Hat OpenShift, Red Hat Enterprise Linux 9.6 Extended Update Support, Zero Trust Workload Identity Manager, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat OpenShift Virtualization 4, Red Hat Enterprise Linux 9, Red Hat Quay 3, Red Hat multicluster global hub 1.4.4, Red Hat OpenStack Platform 16.2, OpenShift API for Data Protection 1.4, Red Hat OpenShift AI (RHOAI), Multicluster Global Hub 1.5.4, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Ansible Automation Platform 2, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Logical Volume Manager Storage, Red Hat OpenShift Container Platform 4.18, Red Hat OpenShift AI (RHOAI), Red Hat OpenStack Platform 17.1 for RHEL 9, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, OpenShift API for Data Protection 1.5, Red Hat Enterprise Linux 8, RHEM 1.1 for RHEL 10, Logging Subsystem for Red Hat OpenShift 6.4, multicluster engine for Kubernetes 2.8, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Management for Kubernetes 2, cert-manager Operator for Red Hat OpenShift, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, OpenShift Pipelines, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Cryostat 4 on RHEL 9, Red Hat OpenShift Service Mesh 3.3, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Service Interconnect 2, Red Hat Ansible Automation Platform 2, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat Enterprise Linux 9, Red Hat Quay 3.16, Red Hat OpenStack Services on OpenShift 18.0, OpenShift Service Mesh 3, Red Hat OpenStack Platform 16.2, Red Hat OpenShift Service Mesh 3.1, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Service Mesh 3.2, Red Hat Advanced Cluster Security 4.9, Red Hat OpenShift Service Mesh 3.2, Logging Subsystem for Red Hat OpenShift, ExternalDNS Operator, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat OpenShift Container Platform 4, ExternalDNS Operator, Red Hat OpenShift Service Mesh 3.0, Red Hat OpenShift Container Platform 4.18, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Quay 3.14, Fence Agents Remediation Operator, Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4, Red Hat Lightspeed (formerly Insights) for Runtimes 1, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Gatekeeper 3, Zero Trust Workload Identity Manager - Tech Preview, Red Hat Enterprise Linux 10, Red Hat Edge Manager 1.1, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Red Hat Quay 3.9, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, OpenShift Serverless, Red Hat Edge Manager 1.0, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat OpenShift Dev Spaces 3.28, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Virtualization 4, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4.18, Red Hat OpenShift distributed tracing 3.9.2, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9.6 Extended Update Support
Provider severity
HIGH
Conflicts
2

CVE-2026-3228

The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[nxs_fbembed]` shortcode in all versions up to, and including, 4.4.6. This is due to insufficient input sanitization and output escaping on the `snapFB` post meta value. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
nextscripts
Product
NextScripts: Social Networks Auto-Poster
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32279

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Versions 1.41.1 and 2.41.1 contain a patch.

PUBLISHED
Vendor
opensource-workshop
Product
connect-cms
Provider severity
MEDIUM
Conflicts
0