CVE-2026-18508
- EPSS 0.14%
- Veröffentlicht 03.08.2026 14:51:41
- Zuletzt bearbeitet 21.08.2026 13:16:55
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can creat...
CVE-2026-68742
- EPSS 0.13%
- Veröffentlicht 03.08.2026 10:16:33
- Zuletzt bearbeitet 18.08.2026 16:36:32
A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS res...
CVE-2026-13757
- EPSS 0.15%
- Veröffentlicht 29.06.2026 18:44:24
- Zuletzt bearbeitet 21.08.2026 13:16:51
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRA...
CVE-2026-13595
- EPSS 0.11%
- Veröffentlicht 29.06.2026 08:06:09
- Zuletzt bearbeitet 21.08.2026 13:16:49
A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent par...
CVE-2026-55653
- EPSS 0.29%
- Veröffentlicht 23.06.2026 03:36:22
- Zuletzt bearbeitet 24.08.2026 12:16:52
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when...
CVE-2026-12725
- EPSS 0.4%
- Veröffentlicht 22.06.2026 13:55:05
- Zuletzt bearbeitet 24.08.2026 10:16:38
A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logg...
CVE-2026-54100
- EPSS 0.29%
- Veröffentlicht 22.06.2026 12:46:09
- Zuletzt bearbeitet 29.07.2026 13:18:58
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can inter...
CVE-2026-54099
- EPSS 0.11%
- Veröffentlicht 22.06.2026 12:46:04
- Zuletzt bearbeitet 29.07.2026 13:18:57
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additiona...
CVE-2026-44495
- EPSS 0.78%
- Veröffentlicht 11.06.2026 15:33:12
- Zuletzt bearbeitet 24.08.2026 13:18:52
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already po...
CVE-2026-1784
- EPSS 0.19%
- Veröffentlicht 02.06.2026 07:22:26
- Zuletzt bearbeitet 24.08.2026 13:17:26
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injectio...