| | CVE-2026-20889 | Red Hat | high | 7.5 | — | | A flaw was found in LibRaw, a library used for processing raw image files. This vulnerability, a hea… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-21413 | Red Hat | high | 7.5 | — | | A flaw was found in LibRaw. A heap-based buffer overflow vulnerability exists in the `lossless_jpeg_… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-20911 | Red Hat | high | 7.5 | — | | A flaw was found in LibRaw. A remote attacker can exploit a heap-based buffer overflow vulnerability… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-4740 | Red Hat | high | 8.2 | — | | A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluste… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-35554 | Apache | high | 8.7 | 0.3%
| | A race condition in the Apache Kafka Java producer client’s buffer pool management can cause message… | Apr 7, 2026 | Aug 17, 2026 |
| | CVE-2026-3902 | Red Hat | medium | 5.3 | — | | A flaw was found in Django. A remote attacker can exploit an ambiguous mapping of header variants (w… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-4277 | Red Hat | medium | 5.4 | — | | A flaw was found in Django. This vulnerability allows an attacker to bypass permission validation by… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-4292 | Red Hat | medium | 5.3 | — | | A flaw was found in Django. Admin changelist forms utilizing `ModelAdmin.list_editable` were suscept… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-33033 | Red Hat | medium | 5.3 | — | | A flaw was found in Django. A remote attacker can exploit this vulnerability by submitting specially… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-33034 | Red Hat | medium | 5.3 | — | | A flaw was found in Django. A remote attacker can exploit this vulnerability by sending ASGI (Asynch… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-33551 | Red Hat | low | 3.5 | 0.0%
| | A flaw was found in OpenStack Keystone. An authenticated user with a reader role can exploit a vulne… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-35515 | Red Hat | medium | 6.5 | 0.0%
| | A flaw was found in Nest, a framework for building Node.js server-side applications. An attacker can… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-33815 | Red Hat | high | 8.3 | 0.0%
| ✓ Fix | Memory-safety vulnerability in github.com/jackc/pgx/v5. | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-33816 | Red Hat | high | 8.3 | 0.0%
| ✓ Fix | Memory-safety vulnerability in github.com/jackc/pgx/v5. | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-4631 | Red Hat | critical | 9.8 | — | | Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface t… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-35611 | Red Hat | medium | 6.5 | 0.0%
| | Addressable is an alternative implementation to the URI implementation that is part of Ruby's standa… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-32588 | Red Hat | medium | 4.3 | 0.1%
| | Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise quer… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-39314 | Red Hat | medium | 4.0 | 0.0%
| ✓ Fix | A flaw was found in CUPS, an open-source printing system. An unprivileged local user can exploit an … | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-39316 | Red Hat | medium | 4.0 | 0.0%
| ✓ Fix | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems.… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-27314 | Apache | high | 8.8 | 0.0%
| | Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator all… | Apr 7, 2026 | Apr 15, 2026 |
| | CVE-2026-27315 | Apache | medium | 5.5 | 0.0%
| | Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, … | Apr 7, 2026 | Apr 15, 2026 |
| | CVE-2026-39363 | Red Hat | high | 7.5 | — | | A flaw was found in Vite, a frontend tooling framework. A remote attacker can exploit this vulnerabi… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-39364 | Red Hat | high | 7.5 | — | | A flaw was found in Vite, a frontend tooling framework for JavaScript. On the Vite development serve… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-39365 | Red Hat | medium | 5.3 | — | | A flaw was found in Vite. The development server's handling of `.map` requests contains a path trave… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-39373 | Red Hat | high | 7.5 | — | | A flaw was found in JWCrypto, a Python library for JSON Web Key (JWK), JSON Web Signature (JWS), and… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-39395 | Red Hat | medium | 6.5 | 0.0%
| | A flaw was found in Cosign, a tool for code signing and transparency for containers and binaries. A … | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-34045 | Red Hat | high | 8.2 | 0.1%
| ✓ Fix | A flaw was found in Podman Desktop. A remote attacker can exploit an unauthenticated HTTP server, wh… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-34080 | Red Hat | medium | 5.5 | 0.0%
| | xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerabi… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-34580 | Red Hat | high | 9.1 | 0.0%
| | Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known ha… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-34582 | Red Hat | high | 9.1 | 0.0%
| | A flaw was found in Botan, a C++ cryptography library. The TLS 1.3 implementation in Botan allows ap… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-34765 | Red Hat | medium | 7.1 | 0.0%
| | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-34781 | Red Hat | medium | 5.0 | 0.0%
| | A flaw was found in Electron. An application that calls `clipboard.readImage()` may be vulnerable to… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-34078 | Red Hat | high | 9.0 | 0.1%
| | Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak p… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-34079 | Red Hat | medium | 6.7 | 0.2%
| | Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching f… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-35406 | Red Hat | medium | 6.5 | 0.0%
| | A flaw was found in aardvark-dns where a specially crafted TCP DNS query followed by a connection re… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-28390 | Red Hat | medium | 7.5 | 0.1%
| ✓ Fix | Issue summary: During processing of a crafted CMS EnvelopedData message
with KeyTransportRecipientIn… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-6846 | Red Hat | high | 7.8 | 0.0%
| | A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a speciall… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-31411 | Red Hat | medium | 7.0 | — | | A flaw was found in the Linux kernel's Asynchronous Transfer Mode (ATM) networking component. A loca… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-32591 | Red Hat | high | 5.2 | — | | A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administr… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-32590 | Red Hat | medium | 7.1 | — | | A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload p… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-32589 | Red Hat | high | 7.1 | — | | A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push a… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-32282 | Red Hat | medium | 7.8 | 0.0%
| ✓ Fix | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in pro… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-33810 | Red Hat | high | 8.8 | 0.0%
| ✓ Fix | When verifying a certificate chain containing excluded DNS constraints, these constraints are not co… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-27144 | Red Hat | medium | 8.1 | 0.0%
| | A flaw was found in the cmd/compile package in the Go standard library. A no-op interface conversion… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-32289 | Red Hat | medium | 5.4 | 0.0%
| | A flaw was found in the `html/template` package. This vulnerability arises from improper tracking of… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-27140 | Red Hat | high | 9.0 | 0.0%
| ✓ Fix | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrar… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-32283 | Red Hat | high | 7.5 | 0.0%
| ✓ Fix | A flaw was found in the `crypto/tls` package within the Go (golang) standard library, specifically a… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-27143 | Red Hat | medium | 8.1 | 0.0%
| | A flaw was found in the cmd/compile package in the Go standard library. The compiler fails to correc… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-32288 | Red Hat | medium | 4.3 | 0.0%
| | A flaw was found in Go's `archive/tar` package. A remote attacker could exploit this vulnerability b… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-32280 | Red Hat | high | 7.5 | 0.0%
| ✓ Fix | A flaw was found in the Go standard library packages `crypto/x509` and `crypto/tls`. During the proc… | Apr 8, 2026 | Apr 8, 2026 |