Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-42789: CWE-295 Improper Certificate Validation in Erlang OTPCVE-2026-42789 0 Two security vulnerabilities were identified in the Erlang OTP public_key module used by Red Hat OpenStack Services on OpenShift 18.0. These include a certificate chain forgery vulnerability due to improper trust chain validation (CVE-2026-42789) and a certificate validation bypass that allows hostname spoofing (CVE-2026-42790). Red Hat has issued an important security update addressing these issues. The vulnerabilities relate to improper certificate validation which could undermine trust in secure communications. No CVSS score is provided, but the impact is rated as high by Red Hat. A security update is available and should be applied to affected systems. No known exploits in the wild have been reported at this time. Join the discussion | GCVE Database | 05/27/2026, 12:23:06 UTC Added: 08/14/2026, 16:36:28 UTC |
CVE-2026-59251: CWE-770 Allocation of Resources Without Limits or Throttling in Erlang OTPCVE-2026-59251 0 Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial of service by sending a crafted X.509 certificate chain during the TLS handshake. During RFC 5280 policy processing in public_key:pkix_path_validation/3, the certificate policy tree maintained by pubkey_policy_tree grows without an upper bound. When a certificate chain contains M policies per certificate and K certificates, the tree grows on the order of M^K nodes because pubkey_policy_tree:add_leaves/2 and pubkey_policy_tree:add_leaf_siblings/2 extend the tree per policy per certificate. A modest chain with many policies per certificate is enough to pin BEAM schedulers and exhaust the node's memory, taking down the entire VM. The attacker only needs to be able to present a certificate chain to the victim, which is the normal precondition for a TLS handshake, so exploitation succeeds against any incoming or outgoing TLS connection that validates the peer's chain (the default for SSL/TLS clients and mutual-TLS servers). This is the same vulnerability class as OpenSSL's X509_verify_cert policy tree DoS. This vulnerability is associated with program files lib/public_key/src/pubkey_policy_tree.erl and program routines pubkey_policy_tree:add_leaves/2 and pubkey_policy_tree:add_leaf_siblings/2. This issue affects OTP from OTP 26.2 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15, corresponding to public_key from 1.15 before 1.21.4, 1.20.3.4 and 1.17.1.5. Join the discussion | CVE Database V5 | 07/27/2026, 15:30:47 UTC Added: 07/27/2026, 16:23:31 UTC |
Showing 1 to 2 of 2 results