Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
6104 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.49% | — | Dogtag PKIAIApache TomcatAIRedhat ResteasyAI | 28/7/2026 | 28/7/2026 | A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker can bypass the Tomcat authentication constraint while RESTEasy still routes the request to… | |
| Analizada | Alta (7.1) | 0.30% | — | GimpRedhat Enterprise Linux | 27/7/2026 | 24/8/2026 | A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues… | |
| Analizada | Media (5.5) | 0.23% | — | GimpRedhat Enterprise Linux | 27/7/2026 | 10/8/2026 | A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a crafted file sets both dimensions to their maximum value (65535), the multiplication ysize… | |
| Modificada | Alta (7.8) | 0.30% | — | GimpRedhat Enterprise Linux | 27/7/2026 | 30/9/2026 | A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based… | |
| Analizada | Media (6.5) | 0.25% | — | Gnome LibsoupRedhat Enterprise Linux | 24/7/2026 | 24/8/2026 | A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information… | |
| Analizada | Alta (7.2) | 0.28% | — | Gnome LibsoupRedhat Enterprise Linux | 24/7/2026 | 24/8/2026 | A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a strict frontend proxy, this parsing… | |
| Analizada | Media (6.5) | 0.38% | — | Gnome LibsoupRedhat Enterprise Linux | 24/7/2026 | 24/8/2026 | A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or… | |
| Pendiente de análisis | Alta (8.5) | 0.57% | — | Redhat Advanced Cluster Management FOR KubernetesAIRedhat Multicluster-engineAI | 24/7/2026 | 29/9/2026 | A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds… | |
| Modificada | Media (6.5) | 0.41% | — | Redhat Build OF Keycloak | 24/7/2026 | 16/9/2026 | A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when listing members of a role. This allows a… | |
| Modificada | Media (4.9) | 0.42% | — | Redhat Build OF Keycloak | 24/7/2026 | 19/8/2026 | A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve… | |
| Pendiente de análisis | Media (5.5) | 0.29% | — | Redhat QuayAI | 24/7/2026 | 24/7/2026 | A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST requests to internal network addresses or cloud infrastructure endpoints that… | |
| Pendiente de análisis | Media (5.3) | 0.44% | — | Oracle JavaAIRedhat Cloudforms SystemAI | 23/7/2026 | 24/7/2026 | An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary. | |
| Pendiente de análisis | Alta (8.8) | 0.46% | — | Redhat Openshift AIAIRedhat ODH DashboardAI | 23/7/2026 | 30/9/2026 | A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the… | |
| Pendiente de análisis | Alta (7.8) | 0.82% | — | Microsoft Visual Studio CodeAIRedhat Ansible LightspeedAI | 22/7/2026 | 22/7/2026 | A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker to inject shell separators. This can be… | |
| Pendiente de análisis | Alta (7.8) | 0.95% | — | Microsoft Visual Studio CodeAIRedhat AnsibleAI | 22/7/2026 | 22/7/2026 | A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters are not properly sanitized, leading to… | |
| Pendiente de análisis | Media (6.5) | 0.39% | — | Redhat AWXAI | 22/7/2026 | 22/7/2026 | A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_command_events). Three event groups - inventory_update_events, project_update_events, and system_job_events — are not… | |
| Analizada | Media (4.2) | 0.25% | — | Gnome LibsoupRedhat Enterprise Linux | 21/7/2026 | 24/8/2026 | A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause the length parameter to be incorrectly truncated, leading to a heap buffer over-read. A remote attacker could use this flaw to crash an application… | |
| Modificada | Alta (8.8) | 0.49% | — | LibsshRedhat Hardened ImagesRedhat Enterprise Linux | 21/7/2026 | 17/8/2026 | A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users. | |
| Modificada | Alta (7.5) | 0.35% | — | LibsshRedhat Hardened ImagesRedhat Enterprise Linux | 21/7/2026 | 1/9/2026 | A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions. | |
| Modificada | Media (5.3) | 0.34% | — | LibsshRedhat Hardened ImagesRedhat Enterprise Linux | 21/7/2026 | 1/9/2026 | A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service. | |
| Analizada | Alta (7.5) | 0.33% | — | LibsshRedhat Hardened ImagesRedhat Enterprise Linux | 21/7/2026 | 4/9/2026 | A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection. | |
| Modificada | Baja (3.9) | 0.12% | — | LibsshRedhat Hardened ImagesRedhat Enterprise Linux | 21/7/2026 | 1/9/2026 | A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior. | |
| Analizada | Alta (7.5) | 0.44% | — | LibsshRedhat Hardened ImagesRedhat Enterprise LinuxRedhat Enterprise Linux FOR ELS+7 | 21/7/2026 | 22/9/2026 | A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service. | |
| Modificada | Media (5.9) | 0.10% | — | LibsshRedhat Hardened ImagesRedhat Enterprise Linux | 21/7/2026 | 1/9/2026 | A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service. | |
| Modificada | Media (6.5) | 0.57% | — | LibsshRedhat Hardened ImagesRedhat Enterprise Linux | 21/7/2026 | 1/9/2026 | A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests. |