Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 CVE-2026-12112

Foreman-mcp-server: mcp server: active session hijacking via insecure session state reuse_CVE-2026-12112

A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active ...

Red Hat Red Hat Satellite 6 CVE
MEDIUM 6.5 CVE-2026-11820

Community.general: community.general nexmo — api credentials exposed in get url query string[security] community.general nexmo — api credentials exposed in get url query string_CVE-2026-11820

Module: plugins/modules/nexmo.py CVSS 3.1: 6.5 MEDIUM — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: api_key and api_secret are declared no_log=Tr...

Red Hat Red Hat Enterprise Linux 10 CVE
MEDIUM 5.5 CVE-2026-11819

Community.general: community.general keyring_info — os keyring passphrase returned in plaintext_CVE-2026-11819

Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase fro...

Red Hat Red Hat Enterprise Linux 10 CVE
CRITICAL 9.6 CVE-2026-11807

Eda-server: websocket missing authorization allows credential theft via activation_id spoofing_CVE-2026-11807

A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not...

Red Hat Red Hat Ansible Automation Platform 2.5 2.5 CVE
MEDIUM 5.1 CVE-2025-64105

FOSSBilling: IDOR Vulnerability in Support Ticket Creation_CVE-2025-64105

FOSSBilling is a billing and client management system that automates invoicing, payments, and communication for online service businesses. Versions...

FOSSBilling FOSSBilling >= 0.6.21, < 0.8.0 CVE
MEDIUM 6.5 CVE-2026-52673

CVE-2026-52673_CVE-2026-52673

SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote attacker to execute arbitrary code via the getDimensionsValues component

n/a n/a n/a CVE
MEDIUM 6.5 CVE-2025-55639

CVE-2025-55639_CVE-2025-55639

GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomedia/isom_write.c. This vulne...

n/a n/a n/a CVE
LOW 3.7 CVE-2026-56968

CVE-2026-56968_CVE-2026-56968

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosur...

GNU GNU SASL CVE
MEDIUM 5.7 CVE-2026-56117

dhcpcd Heap Use-After-Free via Control Socket Handling_CVE-2026-56117

dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handling within src/control.c th...

NetworkConfiguration dhcpcd CVE
HIGH 7.1 CVE-2026-56116

dhcpcd Memory Leak DoS via IPv6 Router Advertisement Handling_CVE-2026-56116

dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling th...

NetworkConfiguration dhcpcd CVE