<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/cna-root/redhat/recent</id>
  <title>Most recent vulnerabilities from the redhat CNA root</title>
  <updated>2026-10-02T07:10:15.155899+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Latest vulnerabilities published by the CNAs operating under the redhat root of the CVE Program.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-86345</id>
    <title>CVE-2026-86345 (redhat)</title>
    <updated>2026-10-01T23:27:47.752000+00:00</updated>
    <content>389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-86345"/>
    <summary>389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result</summary>
    <published>2026-10-01T23:27:47.752000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-86344</id>
    <title>CVE-2026-86344 (redhat)</title>
    <updated>2026-10-01T21:29:55.877000+00:00</updated>
    <content>389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-86344"/>
    <summary>389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue</summary>
    <published>2026-10-01T21:29:55.877000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-103484</id>
    <title>CVE-2026-103484 (PostgreSQL)</title>
    <updated>2026-10-01T19:49:03.670000+00:00</updated>
    <content>pgvector buffer overflow in IVFFlat index build</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-103484"/>
    <summary>pgvector buffer overflow in IVFFlat index build</summary>
    <published>2026-10-01T19:49:03.670000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-103884</id>
    <title>CVE-2026-103884 (redhat)</title>
    <updated>2026-10-01T17:16:21.093000+00:00</updated>
    <content>Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-103884"/>
    <summary>Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read</summary>
    <published>2026-10-01T17:16:21.093000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-56098</id>
    <title>CVE-2026-56098 (redhat)</title>
    <updated>2026-10-01T17:14:56.199000+00:00</updated>
    <content>Rubygem-katello: improper authorization logic allows resource enumeration</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-56098"/>
    <summary>Rubygem-katello: improper authorization logic allows resource enumeration</summary>
    <published>2026-10-01T17:14:56.199000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-56097</id>
    <title>CVE-2026-56097 (redhat)</title>
    <updated>2026-10-01T17:14:50.454000+00:00</updated>
    <content>Rubygem-katello: sql injection in registry proxy via labels</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-56097"/>
    <summary>Rubygem-katello: sql injection in registry proxy via labels</summary>
    <published>2026-10-01T17:14:50.454000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-12542</id>
    <title>CVE-2026-12542 (redhat)</title>
    <updated>2026-10-01T17:14:49.985000+00:00</updated>
    <content>Foreman: command injection in foreman-tail</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-12542"/>
    <summary>Foreman: command injection in foreman-tail</summary>
    <published>2026-10-01T17:14:49.985000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-12545</id>
    <title>CVE-2026-12545 (redhat)</title>
    <updated>2026-10-01T17:14:49.943000+00:00</updated>
    <content>Rubygem-hammer_cli: command injection via insecure editor invocation</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-12545"/>
    <summary>Rubygem-hammer_cli: command injection via insecure editor invocation</summary>
    <published>2026-10-01T17:14:49.943000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-96658</id>
    <title>CVE-2026-96658 (redhat)</title>
    <updated>2026-10-01T16:23:23.688000+00:00</updated>
    <content>Foreman: safemode bypass leading to rce</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-96658"/>
    <summary>Foreman: safemode bypass leading to rce</summary>
    <published>2026-10-01T16:23:23.688000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-96659</id>
    <title>CVE-2026-96659 (redhat)</title>
    <updated>2026-10-01T16:23:23.666000+00:00</updated>
    <content>Foreman: excessive permissions for viewer role on preview</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-96659"/>
    <summary>Foreman: excessive permissions for viewer role on preview</summary>
    <published>2026-10-01T16:23:23.666000+00:00</published>
  </entry>
</feed>
