Threats Tagged 'cve-2026-25646'
View all threats tagged with 'cve-2026-25646'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-25646'
Click on any threat for detailed analysis and mitigation recommendations
0 Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.15.64. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:14772 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html/release_notes/ Security Fix(es): * openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables (CVE-2026-3497) * libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive (CVE-2026-4111) * libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing (CVE-2026-4424) * libpng: LIBPNG has a heap buffer overflow in png_set_quantize (CVE-2026-25646) * nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination (CVE-2026-27135) * vim: Vim: Arbitrary code execution via command injection in glob() function (CVE-2026-33412) * grub2: Missing unregister call for gettext command may lead to use-after-free (CVE-2025-61662) * openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing (CVE-2025-69419) * libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing (CVE-2026-5121) * vim: Vim: Arbitrary code execution via 'helpfile' option processing (CVE-2026-25749) * vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin (CVE-2026-28417) * vim: Vim: Denial of service and information disclosure via crafted swap file (CVE-2026-28421) * kernel: crypto: algif_aead - Revert to operating out-of-place (CVE-2026-31431) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli. Join the discussion | GCVE Database | 05/13/2026, 14:17:24 UTC Added: 05/28/2026, 20:54:03 UTC |
0 Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.14.65. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:15086 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ Security Fix(es): * openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables (CVE-2026-3497) * libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive (CVE-2026-4111) * libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing (CVE-2026-4424) * libpng: LIBPNG has a heap buffer overflow in png_set_quantize (CVE-2026-25646) * nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination (CVE-2026-27135) * vim: Vim: Arbitrary code execution via command injection in glob() function (CVE-2026-33412) * grub2: Missing unregister call for gettext command may lead to use-after-free (CVE-2025-61662) * openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing (CVE-2025-69419) * libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing (CVE-2026-5121) * vim: Vim: Arbitrary code execution via 'helpfile' option processing (CVE-2026-25749) * vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin (CVE-2026-28417) * vim: Vim: Denial of service and information disclosure via crafted swap file (CVE-2026-28421) * kernel: crypto: algif_aead - Revert to operating out-of-place (CVE-2026-31431) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli. Join the discussion | GCVE Database | 05/13/2026, 13:55:59 UTC Added: 05/28/2026, 20:54:07 UTC |
0 Technology Preview features are not fully supported, may not be functionally complete, and are not suitable for deployment in production. Join the discussion | GCVE Database | 04/29/2026, 14:26:51 UTC Added: 05/26/2026, 20:58:36 UTC |
0 The java-17-openjdk packages provide the OpenJDK 17 Java Runtime Environment and the OpenJDK 17 Java Software Development Kit. Security Fix(es): * JDK: Enhance crypto algorithm support (CVE-2026-22007) * JDK: Improve Kerberos credentialing (CVE-2026-22013) * JDK: Enhance Path Factories Redux (CVE-2026-22016) * JDK: Enhance Zip file reading (CVE-2026-22018) * JDK: Enhance certificate chain validation (CVE-2026-22021) * JDK: Updating FreeType 2.14.1 (CVE-2026-23865) * JDK: Enhance TLS connection handling (CVE-2026-34282) * JDK: Enhance key generation (CVE-2026-34268) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 04/24/2026, 10:14:35 UTC Added: 05/26/2026, 20:58:01 UTC |
The OpenJDK 17 packages provide the OpenJDK 17 Java Runtime Environment and the OpenJDK 17 Java Software Development Kit. This release of the Red Hat build of OpenJDK 17 (17.0.19) for portable Linux serves as a replacement for the Red Hat build of OpenJDK 17 (17.0.18) and includes security and bug fixes as well as enhancements. For further information, refer to the release notes linked to in the References section. Security Fix(es): * JDK: Enhance crypto algorithm support (CVE-2026-22007) * JDK: Improve Kerberos credentialing (CVE-2026-22013) * JDK: Enhance Path Factories Redux (CVE-2026-22016) * JDK: Enhance Zip file reading (CVE-2026-22018) * JDK: Enhance certificate chain validation (CVE-2026-22021) * JDK: Updating FreeType 2.14.1 (CVE-2026-23865) * JDK: Enhance TLS connection handling (CVE-2026-34282) * JDK: Enhance key generation (CVE-2026-34268) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 04/23/2026, 16:07:04 UTC Added: 05/26/2026, 20:58:32 UTC |
0 The OpenJDK 11 ELS packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit. This release of the Red Hat build of OpenJDK 11 (11.0.31) with Extended Lifecycle Support for portable Linux serves as a replacement for the Red Hat build of OpenJDK 11 (11.0.30) and includes security and bug fixes as well as enhancements. For further information, refer to the release notes linked to in the References section. Security Fix(es): * JDK: LIBPNG: out-of-bounds read in png_image_read_composite (CVE-2025-66293) * JDK: LIBPNG: Information disclosure and denial of service via integer truncation in simplified write API (CVE-2026-22801) * JDK: LIBPNG: has a heap buffer overflow in png_set_quantize (CVE-2026-25646) * JDK: GIFLIB: Denial of Service via buffer overflow in EGifGCBToExtension (CVE-2026-26740) * JDK: LIBPNG: Arbitrary code execution due to use-after-free vulnerability (CVE-2026-33416) * JDK: LIBPNG: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion (CVE-2026-33636) * JDK: LIBPNG: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read (CVE-2026-22695) * JDK: (CVE-2026-22007) * JDK: (CVE-2026-22016) * JDK: (CVE-2026-22013) * JDK: (CVE-2026-22018) * JDK: (CVE-2026-22021) * JDK: (CVE-2026-34268) * JDK: (CVE-2026-34282) * JDK: (CVE-2026-23865) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 04/22/2026, 15:44:55 UTC Added: 05/26/2026, 20:58:33 UTC |
The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit. This release contains OpenJDK 11 with Extended Lifecycle Support for Red Hat Enterprise Linux versions 7, 8, and 9. Security Fix(es): * JDK: LIBPNG: out-of-bounds read in png_image_read_composite (CVE-2025-66293) * JDK: LIBPNG: Information disclosure and denial of service via integer truncation in simplified write API (CVE-2026-22801) * JDK: LIBPNG: has a heap buffer overflow in png_set_quantize (CVE-2026-25646) * JDK: GIFLIB: Denial of Service via buffer overflow in EGifGCBToExtension (CVE-2026-26740) * JDK: LIBPNG: Arbitrary code execution due to use-after-free vulnerability (CVE-2026-33416) * JDK: LIBPNG: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion (CVE-2026-33636) * JDK: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read (CVE-2026-22695) * JDK: (CVE-2026-22007) * JDK: (CVE-2026-22016) * JDK: (CVE-2026-22013) * JDK: (CVE-2026-22018) * JDK: (CVE-2026-22021) * JDK: (CVE-2026-34268) * JDK: (CVE-2026-34282) * JDK: (CVE-2026-23865) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 04/22/2026, 13:51:24 UTC Added: 05/26/2026, 20:58:33 UTC |
0 Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.13.65. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:7238 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/release_notes Security Fix(es): None For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html-single/updating_clusters/index#updating-cluster-within-minor. Join the discussion | GCVE Database | 04/16/2026, 10:25:29 UTC Added: 06/02/2026, 21:43:33 UTC |
0 This update includes the following RPMs: libpng: * libpng-1.6.56-1.hum1 (aarch64, x86_64) * libpng-devel-1.6.56-1.hum1 (aarch64, x86_64) * libpng-static-1.6.56-1.hum1 (aarch64, x86_64) * libpng-tools-1.6.56-1.hum1 (aarch64, x86_64) * libpng-1.6.56-1.hum1.src (source) Join the discussion | GCVE Database | 04/07/2026, 06:21:37 UTC Added: 05/26/2026, 20:58:48 UTC |
0 The Red Hat Storage Ceph container images are based on the latest ubi9 base image and Ceph 8.1. This release updates to the latest version. Join the discussion | GCVE Database | 03/24/2026, 10:00:07 UTC Added: 05/26/2026, 20:58:31 UTC |
Showing 1 to 10 of 27 results