| | CVE-2026-55970 | Apache | medium | 6.5 | — | | Buffer Over-read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: bef… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-55971 | Apache | critical | 9.8 | — | | Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings.
This issue affects Apache T… | Jul 27, 2026 | Jul 28, 2026 |
| | CVE-2026-58023 | Apache | critical | 9.1 | — | | Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-58389 | Apache | high | 7.5 | — | | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings.
… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-58662 | Apache | critical | 9.1 | — | | Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrif… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-66053 | Apache | medium | 5.9 | — | | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-17512 | Red Hat | low | 3.3 | — | | A flaw was found in whisper.cpp. A local attacker can exploit an out-of-bounds read vulnerability in… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-17513 | Red Hat | low | 3.3 | — | | A flaw was found in whisper.cpp, a library for machine learning. A local attacker can exploit a vuln… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-15003 | Red Hat | medium | 5.6 | — | | A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-ov… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-66390 | Apache | medium | 6.1 | 0.2%
| | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i… | Jul 27, 2026 | Aug 5, 2026 |
| | CVE-2026-66391 | Apache | medium | 6.5 | 0.2%
| | Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket.
T… | Jul 27, 2026 | Aug 5, 2026 |
| | CVE-2026-12383 | Red Hat | high | 7.5 | — | | A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permi… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-59248 | Red Hat | high | 7.5 | — | ✓ Fix | A flaw was found in cowlib, an HTTP parser. An unauthenticated remote attacker could exploit this vu… | Jul 28, 2026 | Jul 28, 2026 |
| | CVE-2026-17072 | Red Hat | low | 3.3 | — | | A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occ… | Jul 28, 2026 | Jul 28, 2026 |
| | CVE-2026-65624 | Red Hat | high | 7.5 | — | ✓ Fix | A flaw was found in Cowboy. An unauthenticated remote attacker can exploit this vulnerability by sen… | Jul 28, 2026 | Jul 28, 2026 |
| | CVE-2026-18047 | Red Hat | medium | 6.5 | — | | A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL… | Jul 28, 2026 | Jul 28, 2026 |
| | CVE-2026-58341 | Red Hat | medium | 3.5 | — | | A flaw was found in Moodle. The actions to enable and disable group messaging did not include the ne… | Jul 28, 2026 | Jul 28, 2026 |
| | CVE-2026-49332 | Red Hat | high | 8.5 | — | | A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only … | Jul 28, 2026 | Jul 28, 2026 |
| | CVE-2026-59878 | Apache | high | 7.5 | 0.5%
| | Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ Al… | Jul 28, 2026 | Aug 5, 2026 |
| | CVE-2026-61487 | Apache | medium | 6.5 | 0.4%
| | Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ… | Jul 28, 2026 | Aug 5, 2026 |
| | CVE-2026-66299 | Apache | medium | 5.3 | 0.5%
| | Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.
This iss… | Jul 28, 2026 | Aug 27, 2026 |
| | CVE-2026-66713 | Apache | critical | 9.8 | 1.2%
| | Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component
in Apache So… | Jul 28, 2026 | Aug 5, 2026 |
| | CVE-2026-62828 | Microsoft | medium | 5.4 | 0.2%
| | Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform t… | Jul 28, 2026 | Aug 5, 2026 |
| | CVE-2026-18107 | Red Hat | medium | 7.8 | — | | A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A mal… | Jul 28, 2026 | Jul 28, 2026 |
| | CVE-2026-64557 | Red Hat | medium | 7.0 | — | | A flaw was found in the Linux kernel's Bluetooth L2CAP component. A race condition exists during the… | Jul 29, 2026 | Jul 29, 2026 |
| | CVE-2026-64556 | Red Hat | high | 7.0 | — | | A flaw was found in the Linux kernel's performance monitoring unit (PMU) subsystem. This vulnerabili… | Jul 29, 2026 | Jul 29, 2026 |
| | CVE-2026-22068 | Apache | high | 8.2 | 0.2%
| | Regular Expression without Anchors vulnerability in Apache Traffic Server.
This issue affects Apach… | Jul 29, 2026 | Aug 5, 2026 |
| | CVE-2026-24033 | Apache | high | 7.2 | 0.2%
| | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Ap… | Jul 29, 2026 | Aug 5, 2026 |
| | CVE-2026-33267 | Apache | critical | 10.0 | 0.2%
| | Improper Input Validation vulnerability in Apache Traffic Server.
This issue affects Apache Traffic… | Jul 29, 2026 | Aug 5, 2026 |
| | CVE-2026-33930 | Apache | medium | 5.9 | 0.2%
| | Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound d… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-41920 | Apache | critical | 9.3 | 0.2%
| | Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic S… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-57834 | Apache | critical | 10.0 | 0.3%
| | Apache Traffic Server allows request smuggling if chunked messages are malformed.
This issue affect… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58150 | Apache | critical | 10.0 | 0.2%
| | Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade reque… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58151 | Apache | high | 7.5 | 0.3%
| | Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and … | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58152 | Apache | medium | 5.9 | 0.2%
| | Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory.
Th… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58153 | Apache | high | 8.3 | 0.2%
| | Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked frami… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58154 | Apache | high | 8.9 | 0.3%
| | Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP heade… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58155 | Apache | critical | 9.3 | 0.3%
| | Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling,… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58156 | Apache | medium | 4.9 | 0.1%
| | Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypa… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-65324 | Apache | high | 7.5 | 0.3%
| | Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, le… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-65325 | Apache | medium | 4.8 | 0.1%
| | Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server cert… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-18220 | Red Hat | high | 7.8 | — | | An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c… | Jul 29, 2026 | Jul 29, 2026 |
| | CVE-2026-50642 | Red Hat | medium | 4.4 | — | | A flaw was found in diff-so-fancy. The application does not properly sanitize non-SGR (Select Graphi… | Jul 29, 2026 | Jul 29, 2026 |
| | CVE-2026-23904 | Apache | high | 7.3 | 0.3%
| | Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to th… | Jul 29, 2026 | Aug 5, 2026 |
| | CVE-2026-50622 | Apache | high | 8.8 | 0.3%
| | Description:
Missing Authorization in Apache Atlas.
A missing authorization vulnerability in Apache … | Jul 29, 2026 | Aug 5, 2026 |
| | CVE-2026-58157 | Apache | high | 8.7 | 0.3%
| | Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client … | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58158 | Apache | medium | 5.9 | 0.4%
| | Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack.
… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58159 | Apache | high | 8.2 | 0.4%
| | Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58160 | Apache | medium | 6.5 | 0.4%
| | Apache Traffic Server reads out of bounds while parsing DNS answers.
This issue affects Apache Traf… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58161 | Apache | high | 7.5 | 0.4%
| | Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handli… | Jul 29, 2026 | Aug 3, 2026 |