Threats Tagged 'cve-2026-15307'
View all threats tagged with 'cve-2026-15307'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-15307'
Click on any threat for detailed analysis and mitigation recommendations
0 Red Hat Ansible Automation Platform 2.1 delivers an Ansible-first Red Hat Developer Hub user experience that simplifies the automation experience for Ansible users of all skill levels. The Ansible plug-ins provide curated content and features to accelerate Ansible learner onboarding and streamline Ansible use case adoption across your organization. Join the discussion | GCVE Database | 09/08/2026, 07:34:17 UTC Added: 09/09/2026, 13:30:16 UTC |
0 Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. For details about this release, refer to the release notes listed in the References section. Join the discussion | GCVE Database | 08/24/2026, 18:19:17 UTC Added: 05/26/2026, 20:58:16 UTC |
0 Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-controller: notification backends allow SSRF and credential leakage (CVE-2026-71366) * automation-controller: webhook status callback SSRF leaks the Git PAT (CVE-2026-71365) * automation-controller: project archive extraction allows path traversal file writes (CVE-2026-71364) * automation-controller: AIOHTTP: Denial of Service via malformed HTTP responses (CVE-2026-69244) * automation-controller: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886) * automation-controller: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() (CVE-2026-34993) * automation-controller: path traversal via YAML !include directive (CVE-2026-52902) * automation-controller: JWCrypto: Memory exhaustion via crafted compressed JWE tokens (CVE-2026-39373) * automation-gateway: path Traversal via unsanitized prefix/postfix enables directory escape (CVE-2026-44705) * python3.12-aiohttp: HTTP Request Smuggling via WebSocket Upgrade (CVE-2026-69243) * python3.12-aiohttp: Denial of Service via malformed HTTP responses (CVE-2026-69244) * python3.12-django: Remote code execution via GeoDjango spatial lookups (CVE-2026-15307) * python3.12-gitpython: Command Injection via Git option prefix abbreviation (CVE-2026-67325) * python3.12-gitpython: Arbitrary Code Execution via Joined Short Options Bypass (CVE-2026-67324) * python3.12-gitpython: Arbitrary code execution via command injection due to unguarded Git options (CVE-2026-67323) * python3.12-gitpython: Environment variable exfiltration via attacker-controlled clone URL (CVE-2026-67322) * python3.12-gitpython: Arbitrary file overwrite and read via unsafe git option forwarding (CVE-2026-73620) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. For details about this release, refer to the release notes listed in the References section. Join the discussion | GCVE Database | 08/24/2026, 16:36:07 UTC Added: 08/25/2026, 13:38:46 UTC |
0 Red Hat build of Podman Desktop is a graphical tool for managing containers using Podman. It allows users to run, manage, and configure containers and container images using a desktop GUI. Security Fix(es): * github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) * ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338) * protobufjs: protobufjs: Denial of Service via crafted JSON descriptors (CVE-2026-45740) * ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray` (CVE-2026-45736) * devalue: devalue: Excessive memory consumption via deserialization of sparse arrays (CVE-2026-42570) * tmp: path Traversal via unsanitized prefix/postfix enables directory escape (CVE-2026-44705) * form-data: form-data: Form field override via CRLF injection (CVE-2026-12143) * webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration (CVE-2026-9595) * ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments (CVE-2026-48779) * extract-zip: github.com/maxogden/extract-zip: extract-zip: Arbitrary file write and information disclosure via symlink validation bypass (CVE-2026-56876) * fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization (CVE-2026-13676) * brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149) * tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874) * tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873) * js-yaml: js-yaml: Denial of Service via crafted YAML documents (CVE-2026-59869) * protobufjs: protobufjs: Denial of Service via crafted .proto schema (CVE-2026-59877) * grpc-js: @grpc/grpc-js: Server crash via malformed HTTP/2 stream initiation (CVE-2026-48068) * linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability (CVE-2026-48801) * dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution (CVE-2026-49978) * brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257) * postcss: PostCSS: Information disclosure and denial of service via crafted CSS input (CVE-2026-45623) * postcss: PostCSS: Information disclosure via crafted sourceMappingURL (CVE-2026-69153) * brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation (CVE-2026-69152) * ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass (CVE-2026-69192) Bug Fix(es) and Enhancement(s): * Release RH Podman Desktop 1.1.2 to RHEL 10.2 Extensions (JIRA:RHEL-238929) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 08/20/2026, 16:08:12 UTC Added: 07/08/2026, 13:21:09 UTC |
0 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a spatial lookup against a `GeometryField` or `RasterField` reaches this constructor, including untrusted input, for example a spatial-field filter submitted through the Django admin changelist query string by a staff user with view permission. A `dict`, or a `str` holding its JSON representation, is opened in write mode regardless of the constructor's `write=False` default, allowing a file with an attacker-chosen name and contents to be written through a file-backed GDAL driver. Any other `str` is treated as a datasource, allowing an outbound network request through a GDAL virtual filesystem handler. Writing a file to a location later imported by the application can result in remote code execution. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy, localhost-detect, and kimchunbok_ for reporting this issue. Join the discussion | CVE Database V5 | 08/19/2026, 08:39:50 UTC Added: 08/04/2026, 16:28:46 UTC |
0 Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.22.10. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:54768 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ Join the discussion | GCVE Database | 08/18/2026, 12:04:14 UTC Added: 06/24/2026, 17:00:19 UTC |
0 This update for python-Django fixes the following issues: Changes in python-Django: - CVE-2026-15307: server-side file-write and request forgery via spatial lookups (bsc#1272997) - CVE-2026-15337: potential denial-of-service vulnerability in `check_for_language()` (bsc#1272998) - CVE-2026-15830: potential denial-of-service vulnerability via nested geometry collections (bsc#1272999) - CVE-2026-15920: potential cross-site scripting via `URLField` values in the admin (bsc#1273000) Join the discussion | GCVE Database | 08/06/2026, 14:20:58 UTC Added: 08/25/2026, 13:38:33 UTC |
0 Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. For details about this release, refer to the release notes listed in the References section. Join the discussion | GCVE Database | 03/31/2026, 22:34:16 UTC Added: 05/26/2026, 20:58:16 UTC |
Showing 1 to 8 of 8 results