Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.9 CVE-2026-13083

Pen-drive: pen-drive: stored xss via unescaped cluster data in html report_CVE-2026-13083

A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An ...

Red Hat Pen Drive Powered by Red Hat Lightspeed CVE
MEDIUM 6.5 CVE-2026-12993

Apicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of service via internal dtd subset_CVE-2026-12993

A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE dec...

Red Hat Red Hat build of Apicurio Registry 3 CVE
LOW 3.8 CVE-2026-13322

Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of service_CVE-2026-13322

A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buff...

Red Hat Red Hat OpenShift Virtualization 4 CVE
MEDIUM 6 CVE-2026-6731

X.509 name constraint bypass via Subject CN treated as a DNS name_CVE-2026-6731

X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN violates an issuing CA's D...

wolfSSL wolfSSL 3.9.10 CVE
LOW 1 CVE-2026-6681

PKCS#7 decode ignores caller output buffer size, writing past buffer bounds_CVE-2026-6681

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the pro...

wolfSSL wolfSSL 3.10.0 CVE
HIGH 8.8 CVE-2026-6679

DTLS 1.3 ACK serialization heap buffer overflow via integer truncation_CVE-2026-6679

A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due ...

wolfSSL wolfSSL 5.4.0 CVE
LOW 1 CVE-2026-6678

Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info_CVE-2026-6678

Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption.

wolfSSL wolfSSL 3.15.5 CVE
LOW 1 CVE-2026-6450

CRL critical extension bypass in ParseCRL_Extensions_CVE-2026-6450

A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allowing a crafted CRL with an u...

wolfSSL wolfSSL 4.3.0 CVE
LOW 2.3 CVE-2026-6412

Continued acceptance of SHA-1/MD5 digests in certificate processing_CVE-2026-6412

Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate processing.

wolfSSL wolfSSL 3.9.10 CVE
HIGH 8.8 CVE-2026-56445

pydicom pynetdicom Library Path Traversal_CVE-2026-56445

The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitizat...

pydicom pynetdicom Library 1.0.0 CVE