« Back to list

Redhat

Redhat Update Infrastructure: vulnerabilities and CVEs

Redhat Update Infrastructure has 9 published vulnerabilities, 5 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs9
Last 12 months5
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-42055Critical (9.2)2.4%—Jun 17, 2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to…
CVE-2026-48864High (7.8)0.26%—May 26, 2026
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a…
CVE-2026-9256Critical (9.2)2.7%—May 22, 2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular…
CVE-2026-9149Medium (6.5)0.57%—May 21, 2026
A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an…
CVE-2026-9150Medium (6.5)0.58%—May 20, 2026
A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by…
CVE-2023-50782High (7.5)1.1%—Feb 5, 2024
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive…
CVE-2023-50781High (7.5)1.1%—Feb 5, 2024
A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
CVE-2022-3644Medium (5.5)0.29%—Oct 25, 2022
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
CVE-2013-4518Medium (5.5)0.26%—Nov 4, 2019
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates

Other products by Redhat