These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to view details of child groups they are not authorized to access directly, including group [truncated]
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see or manage. As a result, an attacker could inject unauthorized data or permissions into the [truncated]
A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a specific 'role' can also see a list of all groups assigned to that role. The system fails to check if the administrator has permis [truncated]
A flaw was found in HPLIP (HP Linux Imaging and Printing Software), an incomplete fix for CVE-2026-8631. This vulnerability may allow a remote attacker to escalate privileges or achieve arbitrary code execution through an integer overflow in the hpcups processing path when handling specially crafted print data. The CVE record was published on 2026-07-03T08:16:24.433Z and has not been modified since then.
A flaw in GIMP's PSP file format parser could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution. The CVE record was published on 2026-07-02T20:17:06.170Z and was last modified on 2026-09-22T15:21:43.420Z. The NVD entry is currently Analyzed. Defenders responsible for GIMP installations, especially in environments where untrusted PSP files ma [truncated]
CVE-2026-5142 is a medium-severity vulnerability in Red Hat Satellite and Foreman that allows authenticated users with 'view_keypairs' permission to bypass taxonomy scoping. This enables them to download private SSH keys from other organizations by directly querying key pair IDs, potentially compromising sensitive information in multi-tenant deployments. The vulnerability has a CVSS score of 6.5 and is cl [truncated]
A flaw was found in Foreman, an authenticated user with host-edit permissions could exploit a cross-tenant information disclosure vulnerability. This flaw occurs because the taxonomy_scope controller method does not properly validate organization and location IDs from nested request parameters, bypassing existing authorization checks. The vulnerability allows users to leak sensitive infrastructure metadat [truncated]
A flaw was found in Foreman, a broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. This is achieved by modifying the match field through nested host attributes, effectively bypassing authorisation checks. The consequence is the potential for unauthorised modification of managed host configurations ac [truncated]
A flaw was found in Foreman's Usergroup model, which does not properly validate role assignments against the calling user's permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and then add themselves as a member. Successful exploitation leads to full privilege escalation, granting the attacker admin [truncated]
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested within other elements like <method>, <signal>, <property> or <arg>. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.
A highly privileged user with manage-clients permission can exploit this vulnerability by injecting a hardcoded role mapper into any client, allowing the user to bypass existing scope restrictions and inject the realm-admin role into generated tokens, resulting in privilege escalation and full administrative access to the realm. This vulnerability affects Keycloak deployments where manage-clients permissi [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-30T13:17:10.317Z and has not been modified since then. The vulnerability in Keycloak's Admin UI extension allows certain administrative users with search permissions but not view permissions to access a user's full profile, including sensitive information and security metadata, via a specific 'brute [truncated]
A double free issue was identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition.
A flaw was found in p11-kit. The RPC message attribute parsing functions form a mutually-recursive call chain with no recursion depth limit when processing nested template attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request, causing stack exhaustion and crashing the p11-kit server process.
CVE-2026-12912 is a heap-based buffer overflow vulnerability in libtiff, which can be exploited by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value. The vulnerability has a CVSS score of 7.3 and is classified as HIGH severity.
The CVE-2026-12856 flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers, allowing a malicious Java file to include hidden commands. If a user clicks a specially crafted link within a JavaDoc hover popup, an attacker can execute arbitrary VS Code commands, which can lead to full syst [truncated]
CVE-2026-13601 is a HIGH-severity vulnerability with a CVSS score of 7.1. The flaw exists in Yelp's Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can exploit this vulnerability by opening crafted help content through the OpenURI portal, embedding an untrusted CSS stylesheet within a structured SVG document. This allows attacker-controlled content to byp [truncated]
A path traversal vulnerability was found in spice-vdagent. This flaw allows a malicious or compromised SPICE host to write arbitrary files to any location on the guest operating system. The vulnerability occurs because the filename provided by the SPICE host during file transfers is not properly sanitized before being used. An attacker could exploit this to write to sensitive locations with the privileges [truncated]
CVE-2026-57965 is an integer overflow vulnerability in the spice-vdagent. A malicious or compromised SPICE host can trigger this vulnerability by sending a specially crafted message, leading to a heap buffer overflow. This causes the spice-vdagent daemon to crash, resulting in a Denial of Service (DoS) for the virtual machine. The vulnerability has a CVSS score of 5.1 and is classified as MEDIUM severity. [truncated]
A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multus network configuration, the supplied networkName value is written verbatim into the launcher pod's v1.multus-cni.io/default-network annotation without format validation or sanitization. This vulnerability allows for cross-namespace network access and IP/MAC impersonation. Users with kub [truncated]
A flaw was found in KubeVirt's migration proxy when spec.configuration.migrations.disableTLS is set to true. This setting causes the target virt-handler to bind a plain TCP listener on all interfaces (0.0.0.0/::) on a random port with no authentication, peer allow-list, or handshake token. Consequently, an attacker with a running pod on the cluster network can connect to this listener and issue unfiltered [truncated]
A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely until a newline character is received, with no length limit or read deadline. A user with access to a VM guest that has the downward metrics virtio-serial device configured can write a continuous byte stream to the device, causing unbound [truncated]
A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualMachineInstance (VMI), virt-api reads the target IP from vmi.Status.Interfaces[0].IP and passes it directly to net.Dial() without validation. For VMIs using non-masquerade network bindings (bridge or secondary-only), this IP is reported by the QEMU guest agent [truncated]
A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a launcher-rooted path using os.WriteFile and os.Chown without symlink protection. A user with access to the virt-launcher container can plant a symlink at the cache file path, causing virt-handler to follow it and overwrite an arbitrary host file with JSON content and change its ownership. Th [truncated]
A flaw was found in Keycloak, a popular open-source identity and access management solution. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to impersonate any federated user linked to the af [truncated]
CVE-2026-9099 is a high-severity vulnerability in Keycloak that allows an authenticated user to reparent a highly privileged group, potentially leading to a full realm takeover. The flaw is caused by a missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API. When Fine-Grained Admin Permissions v2 (FGAPv2) is enabled, an attacker with management rights over a single l [truncated]
CVE-2026-9086 is a high-severity vulnerability in Keycloak that allows a remote attacker with administrative privileges to bypass client URI validation, leading to Cross-Site Scripting (XSS). An attacker can register a malicious client with a specially crafted redirect URI using a case-insensitive 'javascript:' or 'data:' scheme. When a victim clicks the crafted link, such as in the logout flow or the Adm [truncated]
A flaw was found in Keycloak, a popular open-source identity and access management solution. A realm administrator with the 'manage-realm' role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycl [truncated]
A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from the request body without validating it against the connection's origin. Each virt-launcher pod connects through a per-VMI pipe socket, but no identity tag is propagated from the pipe path to the server handlers. This allows a comp [truncated]
A flaw was found in foreman-mcp-server, which utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session identifiers at an informational level, treating them as authentication credentials. The other, when debug logging is enabled, incompletely sanitizes HTTP request headers, leading to cleartext logging of sensitive information such as au [truncated]