PatchSiren

Red Hat CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Red Hat CVE published 2026-09-25

CVE-2026-96448

A flaw in Keycloak's Fine-Grained Admin Permissions (FGAP v2) feature allows an administrator with limited rights to assign a role that secretly includes full administrative control, potentially leading to complete management access over the entire realm. This issue arises from the system's failure to properly check composite roles, enabling an attacker to gain unauthorized access. Keycloak administrators [truncated]

MEDIUM Red Hat CVE published 2026-09-25

CVE-2026-97846

A flaw in Keycloak's Standard Token Exchange V2 feature allows an attacker with stolen client credentials to obtain an unrestricted token, bypassing security protections. This CVE was published on 2026-09-25T07:16:57.147Z and has not been modified since then. The vulnerability affects Keycloak configurations and client credentials, potentially leading to token compromise. Defenders should assess exposure [truncated]

HIGH Red Hat CVE published 2026-09-24

CVE-2026-90959

A path traversal vulnerability was found in pulpcore, allowing an authenticated user with low-privilege repository permissions to read any file accessible to the Pulp server process by supplying a specially crafted URL using relative path traversal sequences. This could lead to unauthorized access to sensitive files, exposure of container registry token signing private key, forgery of bearer tokens, and g [truncated]

HIGH Red Hat CVE published 2026-09-24

CVE-2026-95519

CVE-2026-95519 debrief based on the supplied source corpus. The vulnerability is a flaw in rpm that allows an attacker to supply a crafted manifest file, leading to arbitrary code execution due to unexpected macro-expansion of manifest entries. This affects systems processing untrusted manifest files, potentially compromising confidentiality, integrity, and availability. Defenders should assess exposure a [truncated]

HIGH Red Hat CVE published 2026-09-23

CVE-2026-96889

A use-after-free error occurs in librsvg when processing SVG documents with nested XML inclusions and duplicate entity declarations. This flaw could potentially lead to a denial of service or arbitrary code execution. The vulnerability arises from incorrect handling of XML entities in librsvg, allowing for potential denial of service or arbitrary code execution. Defenders of systems using librsvg, especia [truncated]

CRITICAL Red Hat CVE published 2026-09-23

CVE-2026-84719

A flaw in the Ansible Automation Platform automation-controller allows a user with organization workflow-admin permission to copy a WorkflowJobTemplate and launch jobs pinned to instance groups they are not authorized to use, bypassing the InstanceGroup use_role boundary. This could lead to attacker-influenced automation running in the control-plane execution context.

MEDIUM Red Hat CVE published 2026-09-23

CVE-2026-84713

A flaw in the automation-controller notification subsystem of Red Hat Ansible Automation Platform 2.7 allows an authenticated user with no privileges to recover secret recipient values of other tenants' notifications, including PagerDuty service keys and Slack/Mattermost/RocketChat/Webhook bearer-token URLs, affecting confidentiality. This issue arises because NotificationTemplate.notification_configurati [truncated]

HIGH Red Hat CVE published 2026-09-23

CVE-2026-84683

A flaw in Red Hat Ansible Automation Platform's automation-controller allows a low-privileged user to embed a javascript: link in the HTML view of job, ad hoc command, project update, and inventory update standard output, which can be executed as a higher-privileged user, potentially leading to full platform takeover. The vulnerability exists because the HTML view escapes HTML metacharacters but does not [truncated]

LOW Red Hat CVE published 2026-09-23

CVE-2026-96546

A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ahead after processing the final pixel. This may cause the plug-in to crash if the byte immediately following the pixel buffer is inaccessible; no information disclosure or code execution has been demonstrated.

LOW Red Hat CVE published 2026-09-23

CVE-2026-71463

CVE-2026-71463 debrief based on the supplied source corpus. The vulnerability is in Red Hat Ansible Automation Platform 2.5 for RHEL 8, allowing for potential sensitive information leakage and exploitation attempts via attacker-controlled webhook URLs. Defenders should assess exposure and prioritize patching or compensating controls. The CVE record and NVD detail page provide information on the vulnerabil [truncated]

MEDIUM Red Hat CVE published 2026-09-23

CVE-2026-71459

CVE-2026-71459 is a vulnerability in Red Hat Ansible Automation Platform 2.5 for RHEL 8, allowing any authenticated user to read event tree structure, event_processing_finished status, and enumerate Job IDs platform-wide. The vulnerability has a CVSS score of 5 and a severity of MEDIUM. This vulnerability affects product deployments in managed environments. Defenders should review the supplied official ad [truncated]

MEDIUM Red Hat CVE published 2026-09-23

CVE-2026-88839

CVE-2026-88839 BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers. This MEDIUM-severity vulnerability affects BusyBox installations and could lead to system instability or privilege escalation. Defenders should prioritize verification of affected systems, focusing on BusyBox installations, and review Red Hat errata and securi [truncated]

MEDIUM Red Hat CVE published 2026-09-23

CVE-2026-88837

CVE-2026-88837 debrief based on the supplied source corpus. The CVE record was published on 2026-09-23T18:17:10.493Z and was last modified on 2026-09-25T23:16:54.793Z. The NVD entry is currently Awaiting Analysis. BusyBox httpd incorrectly handles yescrypt ($y$) password hashes during Basic Authentication, treating them as plaintext and potentially allowing authentication bypass. Defenders should assess e [truncated]

MEDIUM Red Hat CVE published 2026-09-23

CVE-2026-88835

CVE-2026-88835 debrief based on the supplied source corpus. BusyBox dpkg has a vulnerability in the read_package_field() function, causing an out-of-bounds heap read on malformed .deb packages. Red Hat Hardened Images users and administrators should assess exposure and verify dpkg package handling. The CVE record and NVD entry provide details on the vulnerability in BusyBox dpkg. Red Hat has an affected p [truncated]

MEDIUM Red Hat CVE published 2026-09-23

CVE-2026-88831

CVE-2026-88831 debrief based on the supplied source corpus. BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients. This vulnerability affects defenders responsible for BusyBox httpd configurations, who should assess exposure and verify the effectiveness of current IP deny rules. The CVE record and NVD entry provide lim [truncated]

HIGH Red Hat CVE published 2026-09-23

CVE-2026-88832

CVE-2026-88832 debrief based on the supplied source corpus. The CVE record was published on 2026-09-23T17:17:18.573Z and was last modified on 2026-09-25T23:16:54.570Z. The NVD entry is currently Awaiting Analysis. Defenders responsible for BusyBox deployments, Linux systems, and filesystem image processing should assess potential exposure and verify heap buffer overflow risks. This heap buffer overflow in [truncated]

HIGH Red Hat CVE published 2026-09-23

CVE-2026-96275

A vulnerability in Flatpak allows a malicious or compromised repository to write content to arbitrary host filesystem locations via `extract_extra_data()`. On system installs, this write operation occurs as root. The issue arises from two problems: `files/extra` is resolved through path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal at [truncated]

HIGH Red Hat CVE published 2026-09-22

CVE-2026-94640

A flaw in rpcbind allows remote, unauthenticated attackers to cause Denial of Service (DoS) by sending numerous unique requests, leading to memory growth and increased CPU usage. This can degrade or exhaust service availability, impacting system performance and stability. Defenders should assess exposure, especially in networked environments, and consider rate limiting or access controls to mitigate poten [truncated]

HIGH Red Hat CVE published 2026-09-21

CVE-2026-94449

A memory leak vulnerability was found in the SmallRye Fault Tolerance library used by Quarkus. The flaw occurs when using ApplyGuard or ApplyFaultTolerance annotations, causing a steady increase in memory usage that eventually leads to application slowdown and crash due to lack of memory. This issue can cause significant performance degradation and potential denial-of-service conditions. Defenders should [truncated]

HIGH Red Hat CVE published 2026-09-21

CVE-2026-92574

A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the destination configuration. This can allow execution with elevated privileges across the cont [truncated]

HIGH Red Hat CVE published 2026-09-21

CVE-2026-15801

A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow a user with sufficient privileges to perform unintended operations on the host filesystem. Successful exploitation requires that container checkpoint and restore functionality is enabled, w [truncated]

LOW Red Hat CVE published 2026-09-21

CVE-2026-94218

A flaw in Keycloak's authentication session management allows users to bypass mandatory two-factor authentication (2FA) setup enforced through client policies by manually visiting a specific session restart web link during login. This issue affects Keycloak deployments where administrators have enforced stronger authentication flows. Defenders should review client policies and verify 2FA setup enforcement [truncated]

LOW Red Hat CVE published 2026-09-21

CVE-2026-94217

A flaw in Keycloak's User-Managed Access (UMA) implementation can cause incorrect permission merging for resources with the same name owned by different users, potentially allowing unauthorized access to a victim's resource. This issue arises in the authorization token endpoint during permission ticket processing, affecting deployments with multiple users and resources. Defenders should verify affected ve [truncated]

MEDIUM Red Hat CVE published 2026-09-21

CVE-2026-94215

A flaw in Keycloak's Admin REST API allows an administrator with limited privileges to read or modify sensitive client configurations in the master realm by accessing them through a realm they control, potentially exposing client credentials or redirecting administrative login attempts to malicious sites. The issue arises from the API's use of a per-request in-memory cache to resolve clients by their uniq [truncated]

MEDIUM Red Hat CVE published 2026-09-21

CVE-2026-94213

A flaw in Keycloak's Authorization Services component allows a delegated administrator with limited viewing privileges to access the full profile and role information of any user in the realm. This could expose sensitive information such as email addresses and assigned security roles. The issue arises from missing authorization checks in the policy evaluation endpoint used by administrators to test access [truncated]

HIGH Red Hat CVE published 2026-09-18

CVE-2026-87743

A flaw in Quarkus HTTP security allows an unauthenticated attacker to exploit discrepancies in path normalization between the security matcher and HTTP request dispatchers, potentially leading to unauthorized access to sensitive information. This vulnerability can have significant impacts on the security of Quarkus deployments, and defenders should assess their exposure and prioritize patching to prevent [truncated]

HIGH Red Hat CVE published 2026-09-18

CVE-2026-93494

A memory leak vulnerability was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this by sending a specially crafted STOMP frame body, leading to uncontrolled memory consumption and potential Denial of Service (DoS). The vulnerability is caused by a flaw in the StompSubframeDecoder component, which fails to properly handle STOMP frame bodies without a terminating null byte. T [truncated]

MEDIUM Red Hat CVE published 2026-09-18

CVE-2026-93493

A flaw in Netty's `netty-handler-ssl-ocsp` component can cause OCSP validation to be skipped, potentially bypassing security controls. This CVE was published on 2026-09-18T08:17:02.523Z and was last modified on 2026-09-18T19:06:08.407Z. The vulnerability allows a remote attacker to provide an Online Certificate Status Protocol (OCSP) response that omits the optional `nextUpdate` field, leading to applicat [truncated]

HIGH Red Hat CVE published 2026-09-18

CVE-2026-89059

A flaw in RESTEasy's IIOImageProvider allows a remote, unauthenticated attacker to send a crafted image declaring enormous dimensions, triggering a large memory allocation and resulting in a denial of service. This issue affects deployments using RESTEasy's IIOImageProvider for image processing. Defenders should assess exposure and prioritize patching to prevent potential denial-of-service attacks. The CV [truncated]

HIGH Red Hat CVE published 2026-09-18

CVE-2026-89058

A flaw in RESTEasy's CorsFilter allows a malicious website to make credentialed cross-origin requests and read authenticated responses from a victim's session, resulting in a loss of confidentiality. The vulnerability arises when the CorsFilter is configured to allow all origins (('*')). This permissive cross-origin policy enables credentialed cross-origin requests, potentially leading to unauthorized acc [truncated]