Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-24109

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `picName`. When this value is used in `sprintf` without validating variable sizes, it could lead to a buffer overflow vulnerability.

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
CRITICAL
Conflicts
1

CVE-2026-24108

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When this value is passed into the `getMibPrefix` function and concatenated using `sprintf` without proper size validation, it could lead to a buffer overflow vulnerability.

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
CRITICAL
Conflicts
1

CVE-2026-24107

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is directly used in `doSystemCmd`, may lead to critical command injection vulnerabilities.

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
CRITICAL
Conflicts
1

CVE-2026-24105

An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not checked, potentially leading to a command injection vulnerability if injected into doSystemCmd.

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
CRITICAL
Conflicts
1

CVE-2026-24103

A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi.

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
CRITICAL
Conflicts
1

CVE-2026-24101

An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` will be passed into sub_B0488, concatenated into `doSystemCmd`. The value of s1_1 is not validated, potentially leading to a command injection vulnerability.

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
CRITICAL
Conflicts
1

CVE-2026-2410

The Disable Admin Notices – Hide Dashboard Notifications plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing nonce validation in the `showPageContent()` function. This makes it possible for unauthenticated attackers to add arbitrary URLs to the blocked redirects list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PUBLISHED
Vendor
themeisle
Product
Disable Admin Notices – Hide Dashboard Notifications
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24098

Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later, which resolves this issue

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24097

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows authenticated users to enumerate existing hosts by observing different HTTP response codes in agent-receiver/register_existing endpoint, which could lead to information disclosure.

PUBLISHED
Vendor
Checkmk GmbH
Product
Checkmk
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24096

Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5.0b2 and 2.4.0 before version 2.4.0p25 allows low-privileged users to perform unauthorized actions or obtain sensitive information

PUBLISHED
Vendor
Checkmk GmbH
Product
Checkmk
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24095

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the "Use WATO" permission to access the "Analyze configuration" page by directly navigating to its URL, bypassing the intended "Access analyze configuration" permission check. If these users also have the "Make changes, perform actions" permission, they can perform unauthorized actions such as disabling checks or acknowledging results.

PUBLISHED
Vendor
Checkmk GmbH
Product
Checkmk
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24092

Memory Corruption when processing fastboot commands to set display mode.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-24091

Memory corruption while processing fastboot commands with improperly formatted input.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-24090

Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-2409

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Delinea Cloud Suite allows Argument Injection.This issue affects Cloud Suite: before 25.2 HF1.

PUBLISHED
Vendor
Delinea
Product
Cloud Suite
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24089

Memory corruption while processing fastboot commands with invalid input.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-24088

Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-24087

Memory corruption while processing fastboot OEM commands.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-24085

Memory Corruption when processing display command line information due to improper initialization of a variable.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-24082

Memory Corruption when copying data from a freed source while executing performance counter deselect operation.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-2408

Tanium addressed a use-after-free vulnerability in the Cloud Workloads Enforce client extension.

PUBLISHED
Vendor
Tanium
Product
Cloud Workloads
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24072

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache HTTP Server
Provider severity
HIGH
Conflicts
0

CVE-2026-24071

It was found that the XPC service offered by the privileged helper of Native Access uses the PID of the connecting client to verify its code signature. This is considered insecure and can be exploited by PID reuse attacks. The connection handler function uses _xpc_connection_get_pid(arg2) as argument for the hasValidSignature function. This value can not be trusted since it is vulnerable to PID reuse attacks.

PUBLISHED
Vendor
Native Instruments
Product
Native Access
Provider severity
HIGH
Conflicts
0

CVE-2026-24070

During the installation of the Native Access application, a privileged helper `com.native-instruments.NativeAccess.Helper2`, which is used by Native Access to trigger functions via XPC communication like copy-file, remove or set-permissions, is deployed as well. The communication with the XPC service of the privileged helper is only allowed if the client process is signed with the corresponding certificate and fulfills the following code signing requirement: "anchor trusted and certificate leaf[

PUBLISHED
Vendor
Native Instruments
Product
Native Access
Provider severity
HIGH
Conflicts
0

CVE-2026-24069

Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application. Kiuwan Cloud was affected, and Kiuwan SAST on-premise (KOP) was affected before 2.8.2509.4.

PUBLISHED
Vendor
Kiuwan
Product
SAST
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24068

The VSL privileged helper does utilize NSXPC for IPC. The implementation of the "shouldAcceptNewConnection" function, which is used by the NSXPC framework to validate if a client should be allowed to connect to the XPC listener, does not validate clients at all. This means that any process can connect to this service using the configured protocol. A malicious process is able to call all the functions defined in the corresponding HelperToolProtocol. No validation is performed in the functions "wr

PUBLISHED
Vendor
Vienna Symphonic Library GmbH
Product
Vienna Assistant
Provider severity
HIGH
Conflicts
0

CVE-2026-24067

Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by obtaining the client's process identifier and using it to retrieve code-signing information for the process. This PID-based client validation is subject to a time-of-check time-of-use race condition because process identifiers can be reused. A local

PUBLISHED
Vendor
Slate Digital LLC
Product
Slate Digital Connect
Provider severity
HIGH
Conflicts
0

CVE-2026-24066

Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by checking only the subject.OU value of the client's signing certificate and does not verify that the certificate chains to a trusted code-signing authority. A local attacker can sign a malicious client with a self-signed certificate containing the exp

PUBLISHED
Vendor
Slate Digital LLC
Product
Slate Digital Connect
Provider severity
HIGH
Conflicts
0

CVE-2026-24065

Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privileged helper service. The helper validates connecting XPC clients using the client process identifier (PID) to verify code-signing identity. Because process identifiers can be reused, a local attacker can exploit a race condition between the time a connection request is made and the time the helper performs validation, causing the helper to trust an attacker-controlled process. T

PUBLISHED
Vendor
Waves Audio Ltd.
Product
Waves Central
Provider severity
HIGH
Conflicts
0

CVE-2026-24064

Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC client component included with the product is signed with hardened runtime entitlements that permit dynamic library injection. A local attacker can set the DYLD_INSERT_LIBRARIES environment variable to inject an attacker-controlled dynamic library into the trusted client process at launch. The injected code runs within the signed process and can connect to the product's privil

PUBLISHED
Vendor
Waves Audio Ltd.
Product
Waves Central
Provider severity
HIGH
Conflicts
0

CVE-2026-24063

When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a root owned path. This script is written to disk with the file permissions 777, meaning it is writable by any user. When uninstalling a plugin via the Arturia Software Center the Privileged Helper gets instructed to execute this script. When the bash script is manipulated by an attacker this scenario will lead to privilege escalation.

PUBLISHED
Vendor
Arturia
Product
Software Center
Provider severity
HIGH
Conflicts
0

CVE-2026-24062

The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signature validation when a client connects. This leads to an attacker being able to connect to the helper and execute privileged actions leading to local privilege escalation.

PUBLISHED
Vendor
Arturia
Product
Software Center
Provider severity
HIGH
Conflicts
0

CVE-2026-24061

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

PUBLISHEDCISA KEV
Vendor
GNU
Product
Inetutils
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24060

Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the File Start Position and File Data can be sniffed from network traffic using Wireshark's BACnet dissector filter. The proprietary format used by WebCTRL to receive updates from the PLC can also be sniffed and reverse engineered.

PUBLISHED
Vendor
Automated Logic
Product
WebCTRL Premium Server
Provider severity
CRITICAL
Conflicts
1

CVE-2026-2406

Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System allows Exploiting Trust in Client. This issue affects Online Registration and Workflow Management System: through 12022026.

PUBLISHED
Vendor
Universe Software Computer Marketing Trade and Industry Inc.
Product
Online Registration and Workflow Management System
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24058

Soft Serve is a self-hostable Git server for the command line. Versions 0.11.2 and below have a critical authentication bypass vulnerability that allows an attacker to impersonate any user (including admin) by "offering" the victim's public key during the SSH handshake before authenticating with their own valid key. This occurs because the user identity is stored in the session context during the "offer" phase and is not cleared if that specific authentication attempt fails. This issue has been

PUBLISHED
Vendor
charmbracelet
Product
soft-serve
Provider severity
HIGH
Conflicts
0

CVE-2026-24056

pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it follows symlinks and reads their target contents without constraining them to the package root. A malicious package containing a symlink to an absolute path (e.g., `/etc/passwd`, `~/.ssh/id_rsa`) causes pnpm to copy that file's contents into `node_modules`, leaking local data. The vulnerability only affects `file:` and `git:` dependencies. Registry packages (npm) have symlinks s

PUBLISHED
Vendor
pnpm
Product
pnpm
Provider severity
MEDIUM
Conflicts
1

CVE-2026-24055

Langfuse is an open source large language model engineering platform. In versions 3.146.0 and below, the /api/public/slack/install endpoint initiates Slack OAuth using a projectId provided by the client without authentication or authorization. The projectId is preserved throughout the OAuth flow, and the callback stores installations based on this untrusted metadata. This allows an attacker to bind their Slack workspace to any project and potentially receive changes to prompts stored in Langfuse

PUBLISHED
Vendor
langfuse
Product
langfuse
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24054

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.26.0, when a container image is malformed or contains no layers, containerd falls back to bind-mounting an empty snapshotter directory for the container rootfs. When the Kata runtime attempts to mount the container rootfs, the bind mount causes the rootfs to be detected as a block device, leading to the underlying device being

PUBLISHED
Vendor
kata-containers
Product
kata-containers
Provider severity
HIGH
Conflicts
0

CVE-2026-24053

Claude Code is an agentic coding tool. Prior to version 2.0.74, due to a Bash command validation flaw in parsing ZSH clobber syntax, it was possible to bypass directory restrictions and write files outside the current working directory without user permission prompts. Exploiting this required the user to use ZSH and the ability to add untrusted content into a Claude Code context window. This issue has been patched in version 2.0.74.

PUBLISHED
Vendor
anthropics
Product
claude-code
Provider severity
HIGH
Conflicts
1

CVE-2026-24052

Claude Code is an agentic coding tool. Prior to version 1.0.111, Claude Code contained insufficient URL validation in its trusted domain verification mechanism for WebFetch requests. The application used a startsWith() function to validate trusted domains (e.g., docs.python.org, modelcontextprotocol.io), this could have enabled attackers to register domains like modelcontextprotocol.io.example.com that would pass validation. This could enable automatic requests to attacker-controlled domains wit

PUBLISHED
Vendor
anthropics
Product
claude-code
Provider severity
HIGH
Conflicts
0

CVE-2026-24051

OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application. A fix was released with v1.40.0.

PUBLISHED
Vendor
open-telemetry
Product
opentelemetry-go
Provider severity
HIGH
Conflicts
0

CVE-2026-24050

Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored XSS in group names or channel names. Exploiting these vulnerabilities required the user explicitly interacting with the problematic object. This vulnerability is fixed in 11.5.

PUBLISHED
Vendor
zulip
Product
zulip
Provider severity
LOW
Conflicts
0

CVE-2026-2405

CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of service when a Web Admin user floods the system with POST /helpabout requests.

PUBLISHED
Vendor
Schneider Electric
Product
PowerChute™ Serial Shutdown
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24049

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of c

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, pypa, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Ansible Automation Platform 2, OpenShift Service Mesh 3, Red Hat AI Inference Server, Red Hat OpenShift Dev Spaces 3.27, Logging Subsystem for Red Hat OpenShift, Red Hat Quay 3.1, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), wheel, Red Hat Quay 3.9, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 7, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Ansible Automation Platform 2, Discovery 2 for RHEL 10, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Trusted Artifact Signer 1.2, Red Hat Enterprise Linux 9, Red Hat AI Inference Server, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8, Red Hat Quay 3, OpenShift Service Mesh 2, Red Hat AI Inference Server, Red Hat OpenShift AI 2.25, Red Hat Satellite 6, Red Hat Ansible Automation Platform 2, Multicluster Engine for Kubernetes, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat AI Inference Server 3.2, Red Hat Enterprise Linux 10, Red Hat Satellite 6, Red Hat Quay 3.13, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat OpenShift AI (RHOAI), OpenShift Lightspeed, Red Hat Ansible Automation Platform Ansible Core 2, Red Hat OpenShift AI 3.3, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, OpenShift Lightspeed, Red Hat OpenShift AI 3.4, Red Hat Enterprise Linux 8, Red Hat Ansible Automation Platform 2, Discovery 2 for RHEL 9, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3.16, Red Hat Trusted Artifact Signer 1.3, Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift Container Platform 4, Red Hat Satellite 6, Logging Subsystem for Red Hat OpenShift, Red Hat Ansible Automation Platform Ansible Core 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Container Platform 4.21, Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift Container Platform 4.17, OpenShift Service Mesh 2, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform Ansible Core 2, Red Hat Ansible Automation Platform 2, Red Hat Quay 3, Migration Toolkit for Virtualization, Red Hat OpenShift AI 2.25, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server 3.2, Service Telemetry Framework 1.5, Red Hat Ansible Automation Platform 2, Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3.14, OpenShift Lightspeed, OpenShift Service Mesh 2, Red Hat Quay 3, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, OpenShift Service Mesh 2, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Logging Subsystem for Red Hat OpenShift, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Service Telemetry Framework 1.5, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Dev Spaces 3.27, Red Hat OpenShift Container Platform 4.18, Red Hat OpenShift Container Platform 4, Red Hat Satellite 6.18, Network Observability (NETOBSERV) 1.11.1, Red Hat Ansible Automation Platform 2, Discovery 2 for RHEL 8, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.25, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Logging Subsystem for Red Hat OpenShift, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Multicluster Engine for Kubernetes, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4.19, Red Hat Enterprise Linux 8, Red Hat Ansible Automation Platform 2, Red Hat Discovery 2, OpenShift Service Mesh 2, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Ansible Automation Platform 2, Red Hat AI Inference Server, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.3, Red Hat Ansible Automation Platform 2, Red Hat Developer Hub 1.8, Red Hat Enterprise Linux 9, Red Hat Quay 3, Red Hat OpenShift AI 3.3, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Ansible Automation Platform 2, OpenShift Service Mesh 2, Red Hat Enterprise Linux 9, Red Hat OpenStack 1.5, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Dev Spaces 3.27, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI 2.25, Red Hat OpenShift Dev Spaces, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3, Red Hat OpenShift Container Platform 4.2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Quay 3, Red Hat Satellite 6, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Satellite 6, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Security 4, Red Hat Satellite 6, OpenShift Service Mesh 2, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI), OpenShift Service Mesh 2, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3.12, Red Hat Quay 3, Red Hat Ansible Automation Platform Ansible Core 2, Red Hat Satellite 6, Red Hat Ansible Automation Platform 2, Migration Toolkit for Virtualization, Red Hat Quay 3.15, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Fence Agents Remediation Operator, OpenShift Lightspeed, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Container Platform 4.16
Provider severity
HIGH
Conflicts
2

CVE-2026-24048

Backstage is an open framework for building developer portals, and @backstage/backend-defaults provides the default implementations and setup for a standard Backstage backend app. Prior to versions 0.12.2, 0.13.2, 0.14.1, and 0.15.0, the `FetchUrlReader` component, used by the catalog and other plugins to fetch content from URLs, followed HTTP redirects automatically. This allowed an attacker who controls a host listed in `backend.reading.allow` to redirect requests to internal or sensitive URLs

PUBLISHED
Vendor
backstage
Product
backstage
Provider severity
LOW
Conflicts
0

CVE-2026-24047

Backstage is an open framework for building developer portals, and @backstage/cli-common provides config loading functionality used by the backend and command line interface of Backstage. Prior to version 0.1.17, the `resolveSafeChildPath` utility function in `@backstage/backend-plugin-api`, which is used to prevent path traversal attacks, failed to properly validate symlink chains and dangling symlinks. An attacker could bypass the path validation via symlink chains (creating `link1 → link2 → /

PUBLISHED
Vendor
backstage
Product
backstage
Provider severity
MEDIUM
Conflicts
1

CVE-2026-24046

Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to read arbitrary files via the `debug:log` action by creating a symlink pointing to sensitive files (e.g., `/etc/passwd`, configuration files, secrets); delete arbitrary files via the `fs:delete` action by creating symlinks poin

PUBLISHED
Vendor
backstage, Red Hat, Red Hat
Product
backstage, Red Hat Developer Hub 1.9, Red Hat Developer Hub 1.8
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-24045

Docmost is open-source collaborative wiki and documentation software. From 0.20.0 and before 0.25.0, the public share page functionality in Docmost does not properly HTML-escape page titles before inserting them into meta tags and the title tag. This allows Stored Cross-Site Scripting (XSS) attacks, where an attacker can execute arbitrary JavaScript in the context of any user who opens a shared page link. This vulnerability is fixed in 0.25.0.

PUBLISHED
Vendor
docmost
Product
docmost
Provider severity
HIGH
Conflicts
0

CVE-2026-24044

Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (using matrix-tools container before 0.5.7) is using an insecure Matrix server key generation method, allowing network attackers to potentially recreate the same key pair, allowing them to impersonate the victim server. The secret is generated by the secrets initialization hook, in the ESS Community Helm

PUBLISHED
Vendor
element-hq, element-hq
Product
ess-helm, matrix-tools
Provider severity
CRITICAL
Conflicts
1