CVE-2026-9149
- EPSS 0.31%
- Veröffentlicht 20.05.2026 23:34:56
- Zuletzt bearbeitet 31.07.2026 18:17:37
A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a ...
CVE-2026-9150
- EPSS 0.41%
- Veröffentlicht 20.05.2026 23:16:36
- Zuletzt bearbeitet 31.07.2026 18:17:38
A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA51...
- EPSS 1.41%
- Veröffentlicht 26.03.2026 12:53:09
- Zuletzt bearbeitet 15.07.2026 02:18:21
A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability arises from the system's use of unsanitized hostname values from compute resource providers...
CVE-2026-4324
- EPSS 0.26%
- Veröffentlicht 17.03.2026 14:16:19
- Zuletzt bearbeitet 01.06.2026 19:16:54
A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of user-provided input, allows a remote attacker to inject arbitrary SQL commands into the sort_by parameter of the /api/hosts/bootc_ima...
CVE-2026-0980
- EPSS 0.77%
- Veröffentlicht 27.02.2026 07:30:42
- Zuletzt bearbeitet 27.03.2026 00:16:21
A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creation or update permissions could exploit this vulnerability by crafting a malicious username...
CVE-2025-9572
- EPSS 0.35%
- Veröffentlicht 27.02.2026 07:28:44
- Zuletzt bearbeitet 24.03.2026 12:16:12
n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leadi...
CVE-2026-1530
- EPSS 0.25%
- Veröffentlicht 02.02.2026 05:47:10
- Zuletzt bearbeitet 15.07.2026 02:18:16
A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) attack due to disabled certificate validation. This enables the attacker to intercept and potentially alter sensitive communications b...
CVE-2026-1531
- EPSS 0.27%
- Veröffentlicht 02.02.2026 05:47:09
- Zuletzt bearbeitet 15.07.2026 02:18:16
A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set. This insecure default allows a remote attacker, capable of int...
CVE-2025-12790
- EPSS 0.35%
- Veröffentlicht 06.11.2025 21:15:40
- Zuletzt bearbeitet 15.04.2026 00:35:42
A flaw was found in Rubygem MQTT. By default, the package used to not have hostname validation, resulting in possible Man-in-the-Middle (MITM) attack.
- EPSS 0.58%
- Veröffentlicht 05.11.2025 07:32:14
- Zuletzt bearbeitet 15.04.2026 00:35:42
A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_settings permissions to achieve arbitrary command execution on the underlying operating system via insufficient server-side validatio...