These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A flaw in Undertow allows remote attackers to perform request smuggling by exploiting incorrect processing of HTTP requests with leading spaces in the first header line. This vulnerability, which violates HTTP standards, can potentially allow attackers to bypass security mechanisms, access restricted information, or manipulate web caches. Defenders responsible for Undertow-based systems, especially those [truncated]
A flaw in Undertow allows remote attackers to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources. The vulnerability affects Undertow instances, particularly in envir [truncated]
A local user can exploit a flaw in polkit by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin), leading to an out-of-memory (OOM) condition and a Denial of Service (DoS) for the system. This vulnerability, tracked as CVE-2026-4897, affects systems using polkit, particularly those using Red Hat Enterprise Linux and OpenShift Contai [truncated]
A heap buffer over-read vulnerability exists in the GIMP PCX file loader due to an off-by-one error. The flaw allows a remote attacker to trigger out-of-bounds memory disclosure and application crash via a specially crafted PCX image file. The vulnerability affects GIMP versions prior to 3.2.0, including release candidates 3.2.0-rc1, -rc2, and -rc3. The issue was published on March 26, 2026, with the CVE [truncated]
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose uninte [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-19T15:16:28.510Z and has not been modified since then. The NVD entry is currently Modified. The CVE-2026-4426 vulnerability exists in libarchive's zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploi [truncated]
A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain client configuration requests. This behavior allows an attacker to trick the server into making unintended requests to internal or restricted resources. As a result, sensitive internal services such as cloud metadata endpoints could be accessed. This issue may l [truncated]
CVE-2026-2603 is a high-severity vulnerability in Keycloak that allows remote attackers to bypass security controls and complete broker logins even when the SAML Identity Provider is disabled. This flaw enables unauthorized authentication by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. The vulnerability has a CVSS sco [truncated]
CVE-2026-2092 is a high-severity vulnerability in Keycloak's Security Assertion Markup Language (SAML) broker endpoint. The flaw allows an attacker to inject an encrypted assertion for an arbitrary principal, leading to unauthorized access and potential information disclosure. This is possible because Keycloak does not properly validate encrypted assertions when the overall SAML response is not signed. An [truncated]
CVE-2026-3442 is a heap-based buffer overflow vulnerability in GNU Binutils, specifically an out-of-bounds read in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of [truncated]
CVE-2026-3441 is a heap-based buffer overflow vulnerability in GNU Binutils, specifically an out-of-bounds read in the bfd linker. This vulnerability allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service. The [truncated]
CVE-2026-4111 describes an availability issue in libarchive’s RAR5 decompression logic. A specially crafted RAR5 archive can cause the archive_read_data() processing path to stop making forward progress and spin in an infinite loop, consuming CPU until the affected service is impacted. Because the archive can pass checksum validation and appear structurally valid, the problem may not be detectable before [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-13T19:55:13.673Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This Improper Access Control vulnerability in systemd's systemd-machined service allows a local unprivileged user to potentially execute arbitrary commands with root privileges by attempting to regis [truncated]
A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This c [truncated]
A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-2366 was published on 2026-03-12T11:15:55.860Z. This vulnerability is an authorization bypass issue in the Keycloak Admin API, allowing any authenticated user to enumerate organization memberships of other users if they know the victim's unique identifier (UUID) and the Organizations feature is enabled. The vul [truncated]
A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the victim’s registered MFA/OTP credential without first proving possession of that factor. The attacker can then register their own MF [truncated]
CVE-2026-3047 is a high-severity security flaw in Redhat Build Of Keycloak. A disabled SAML client can still complete the login process and establish a Single Sign-On (SSO) session, allowing a remote attacker to gain unauthorized access to other enabled clients without re-authentication. This flaw has a CVSS score of 8.8 and is considered a high-risk vulnerability. The CVE was published on March 5, 2026, [truncated]
A security flaw in Keycloak's IdentityBrokerService.performLogin endpoint allows authentication to proceed using a disabled Identity Provider (IdP). An attacker who knows the IdP alias can reuse a previously generated login request to bypass administrative restrictions. This undermines access control enforcement and may allow unauthorized authentication through a disabled external provider.
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attrib [truncated]
CVE-2026-26103 is a high-severity vulnerability in the Udisks storage management daemon. A flaw in the daemon exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. This allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices, permanently invalidating encryption keys and rendering encrypt [truncated]
CVE-2025-14905 is a high-severity heap buffer overflow vulnerability in the 389-ds-base server. The vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file due to incorrect buffer size calculations. This flaw can lead to a heap overflow when processing a large number of aliases, potentially allowing remote attackers to cause a Denial of Service (DoS) or achieve Remote C [truncated]
A flaw was found in QEMU, a widely used open-source emulator. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS). This vulnerability affects systems using QEMU, particularly those handling VMDK images. The impact could include sensitive information leakage or service disrupt [truncated]
CVE-2026-1529 is a high-severity vulnerability in Keycloak that allows attackers to self-register into unauthorized organizations, leading to unauthorized access. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verification enables the attacker to successfu [truncated]
CVE-2026-1486 is a high-severity vulnerability in Keycloak's jwt-authorization-grant flow. The flaw allows an attacker to obtain valid access tokens even if an Identity Provider (IdP) is disabled. This occurs because the server fails to verify if an IdP is enabled before issuing tokens. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. The issue arises from the issuer lookup mecha [truncated]
A critical vulnerability, CVE-2026-1709, was found in Keylime, a security framework used for remote attestation of machine state. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing agents, r [truncated]
CVE-2026-1761 is a high-severity stack-based buffer overflow vulnerability in libsoup, a library used for parsing HTTP responses. This vulnerability can lead to memory corruption, application crashes, or arbitrary code execution in applications that process untrusted server responses. The vulnerability has a CVSS score of 8.6 and is considered high severity. The issue was publicly disclosed on February 2, [truncated]
A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can ex [truncated]
A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set. This insecure default allows a remote attacker, capable of intercepting network traffic between Satellite and OpenShift, to perform a Man-in-the-Middle (MITM) attack. Such an attack could lead to the disclosure or altera [truncated]
CVE-2026-1530 is a high-severity vulnerability in fog-kubevirt that allows remote attackers to perform Man-in-the-Middle (MITM) attacks due to disabled TLS/SSL certificate validation. This enables attackers to intercept and potentially alter sensitive communications between Satellite and OpenShift, resulting in information disclosure and data integrity compromise. The vulnerability has a CVSS score of 8.1 [truncated]