Vulnerabilities

Summary — last 7 days

New vulnerabilities2,570▼ 305 vs. last week
Critical / high1,353▲ 102 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)56▼ 472 vs. last week
–

5 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedMedium (6.5)7.1%⚠ Active exploitationEncode StarletteRedhat AI Inference ServerRedhat Ansible Automation PlatformRedhat Migration Toolkit FOR Applications+45/26/202610/1/2026
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make…
AnalyzedHigh (8.1)1.6%—Redhat Build OF KeycloakRedhat Jboss Middleware Text-only AdvisoriesRedhat KeycloakRedhat Migration Toolkit FOR Applications+64/17/20248/4/2026
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that…
ModifiedHigh (7.1)0.95%—Redhat KeycloakRedhat Single Sign-onRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM Z+31/26/20249/22/2026
A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users.
AnalyzedHigh (7.5)100%⚠ Active exploitationSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/20238/11/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModifiedHigh (7.5)0.60%—Redhat Build OF QuarkusRedhat Integration Camel FOR Spring BootRedhat Integration Camel KRedhat Integration Service Registry+62/23/20236/17/2026
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.