Threats Tagged 'cve-2026-28390'
View all threats tagged with 'cve-2026-28390'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-28390'
Click on any threat for detailed analysis and mitigation recommendations
0 Multiple security vulnerabilities have been identified in OpenSSL, affecting Red Hat Enterprise Linux 10.0 Extended Update Support and related variants. These include information disclosure, data tampering, denial of service, acceptance of forged messages, unbounded memory growth, and use-after-free issues. The vulnerabilities impact various cryptographic operations such as OCB encryption/decryption, RSA public key handling, CMS EnvelopedData processing, QUIC PATH_CHALLENGE handling, and PKCS7 verification. Red Hat has issued an important security advisory with updates to address these issues. Join the discussion | GCVE Database | 09/24/2026, 11:15:45 UTC Added: 09/29/2026, 04:41:38 UTC |
0 This advisory addresses a security issue in the qemu-kvm component used in Red Hat Enterprise Linux 9, specifically a use-after-free vulnerability in the VNC WebSocket handshake (CVE-2025-11234). The vulnerability is rated with moderate severity by Red Hat Product Security. The advisory is part of the Red Hat OpenShift Container Platform 4.12.97 update, which does not include additional security fixes for OpenShift itself. Users of affected Red Hat Enterprise Linux 9 versions are advised to apply the update to remediate the qemu-kvm vulnerability. Join the discussion | GCVE Database | 09/03/2026, 12:01:51 UTC Added: 07/12/2026, 09:18:51 UTC |
0 Red Hat JBoss Core Services is a set of supplementary software for Red Hat JBoss middleware products. This software, such as Apache HTTP Server, is common to multiple JBoss middleware products and packaged under Red Hat JBoss Core Services, to allow for faster distribution of updates and for a more consistent update experience. This release of Red Hat JBoss Core Services Apache HTTP Server 2.4.62 serves as a replacement for Red Hat JBoss Core Services Apache HTTP Server 2.4.57 Service Pack 6, and includes bug fixes and enhancements, which are documented in the Release Notes linked to in the References section. Security Fix(es): * httpd: HTTP Response Splitting in multiple modules (CVE-2024-24795) * mod_http2: DoS by null pointer in websocket over HTTP/2 (CVE-2024-36387) * openssl: SSL_select_next_proto buffer overread (CVE-2024-5535) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 08/24/2026, 03:05:12 UTC Added: 06/02/2026, 21:43:56 UTC |
0 This security update provides a functional equivalent of RHSA-2026:58563. The original Red Hat(R) advisory is available from the Red Hat web site at https://access.redhat.com/errata/RHSA-2026:58563. Join the discussion | GCVE Database | 08/24/2026, 00:00:00 UTC Added: 06/02/2026, 21:43:37 UTC |
0 The OpenSSL toolkit provides support for secure communications between machines. This version of OpenSSL package contains only the libraries from the 1.1.1 version and is provided for compatibility with previous releases. Security Fix(es): * openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing (CVE-2026-28390) * openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() (CVE-2026-45447) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 07/06/2026, 00:00:00 UTC Added: 05/31/2026, 21:00:08 UTC |
0 Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network. Join the discussion | GCVE Database | 06/24/2026, 16:29:56 UTC Added: 05/26/2026, 20:58:31 UTC |
0 Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network. Join the discussion | GCVE Database | 06/24/2026, 16:29:56 UTC Added: 05/26/2026, 20:58:31 UTC |
0 This update for openssl-3 fixes the following issues - CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652). - CVE-2026-7383: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion (bsc#1266340). - CVE-2026-9076: Out-of-Bounds Read in CMS Password-Based Decryption (bsc#1266341). - CVE-2026-34180: Heap Buffer Over-read in ASN.1 Content Parsing (bsc#1266342). - CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344). - CVE-2026-34183: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler (bsc#1266345). - CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347). - CVE-2026-42766: Possible NULL Dereference in Password-Based CMS Decryption (bsc#1266349). - CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). - CVE-2026-42768: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() (bsc#1266351). - CVE-2026-42769: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate (bsc#1266352). - CVE-2026-42770: FFC-DH Peer Validation Uses Attacker-Supplied q (bsc#1266353). - CVE-2026-45445: AES-OCB IV Ignored on EVP_Cipher() Path (bsc#1266355). - CVE-2026-45446: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes (bsc#1266356). - CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266357). Join the discussion | GCVE Database | 06/22/2026, 12:23:46 UTC Added: 05/31/2026, 21:00:03 UTC |
0 This security update provides a functional equivalent of RHSA-2026:20613. The original Red Hat(R) advisory is available from the Red Hat web site at https://access.redhat.com/errata/RHSA-2026:20613. Join the discussion | GCVE Database | 06/16/2026, 16:53:26 UTC Added: 06/01/2026, 21:15:10 UTC |
0 This security update for OpenSSL 3 addresses multiple vulnerabilities including remote denial-of-service via expensive Diffie-Hellman key agreement computations, heap buffer overflows, out-of-bounds reads, null pointer dereferences, acceptance of forged CMS messages, and cryptographic processing errors in AES modes. These issues affect the OpenSSL 3 library and could lead to crashes, memory corruption, or cryptographic failures. Join the discussion | GCVE Database | 06/11/2026, 12:42:44 UTC Added: 09/29/2026, 21:04:21 UTC |
Showing 1 to 10 of 18 results