Skip to main content

Threats Tagged 'cve-2026-32283'

View all threats tagged with 'cve-2026-32283'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-32283

Threats Tagged 'cve-2026-32283'

Click on any threat for detailed analysis and mitigation recommendations

0

The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards. Security Fix(es): * crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137) * crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810) * golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server. Security Fix(es): * crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption (CVE-2025-68121) * crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) * golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) * crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) * crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) * golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Red Hat Quay versions prior to 3.9.26 contain multiple security vulnerabilities addressed in the Red Hat Quay 3.9.26 update. These vulnerabilities affect the logging subsystem for Red Hat OpenShift and related components. The advisory highlights the availability of an important security update to fix these issues.

Join the discussion

Red Hat multicluster global hub is a set of components that enable you to import one or more hub clusters and manage them from a single hub cluster.

Join the discussion

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients. Security Fix(es): * golang-fips: Golang FIPS zeroed buffer (CVE-2024-9355) * golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect (CVE-2024-45336) * crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866) * crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption (CVE-2025-68121) * crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) * crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810) * golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) * crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) * crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) * golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

A local binary for building customized OS artifacts such as VM images and OSTree commits. Uses osbuild under the hood. Security Fix(es): * crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) * crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499) * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820) * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) * golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

This release of the Red Hat OpenShift distributed tracing platform (Tempo) provides new features, security improvements, and bug fixes. Breaking changes: * High availability defaults for TempoStack deployment sizes: Before this update, only the ingester component was scaled for high availability while all other components defaulted to a single replica, leaving the overall ingest and query paths vulnerable to single points of failure. With this update, when you set a non-demo deployment size (1x.pico, 1x.extra-small, 1x.small, or 1x.medium) in the spec.size field of the TempoStack custom resource, the Operator defaults each component to at least 2 replicas, and scales throughput-bound components at larger sizes. Watch your resource consumption, as running more replicas per component increases the total CPU and memory consumed by the deployment. Explicit per-component replicas values always take precedence. For more information, see https://redhat.atlassian.net/browse/TRACING-6169. Deprecations: * Jaeger Query is deprecated: The Jaeger Query component in the Tempo Operator is deprecated and will be removed in a future release. The Tempo Operator emits a warning when the Jaeger Query feature is enabled. To visualize traces, use the distributed tracing UI plugin as the recommended replacement for the Jaeger UI. For more information, see https://redhat.atlassian.net/browse/TRACING-6509. Technology Preview features: * None Enhancements: * High availability for TempoStack deployments: You can use the spec.replicationZones field in the TempoStack custom resource to define zone-aware replication. By using this feature, you can deploy TempoStack instances with higher resilience by spreading replicas across topology zones and ensuring minimum pod availability during disruptions. For more information, see https://redhat.atlassian.net/browse/TRACING-6168. * Service name and namespace auto-complete with query RBAC enabled: When you enable query Role-Based Access Control (RBAC) in a multi-tenant TempoStack deployment, the Tempo gateway supports auto-complete for non-sensitive attributes such as service name and namespace. Before this update, all tag value API endpoints were blocked when query RBAC was enabled, which prevented the Service Name drop-down filter in the distributed tracing console plugin from displaying results. With this update, the gateway allows the search tags API for non-sensitive attributes while still protecting sensitive span data. As a result, the Service Name filter and other non-sensitive attribute drop-down list items work correctly in multi-tenant RBAC mode. For more information, see https://redhat.atlassian.net/browse/TRACING-6485. Bug fixes: * TempoStack and TempoMonolithic status conditions accurately reflect pod readiness: Before this update, the status field of the TempoStack or TempoMonolithic custom resource might show Ready=false even when all pods were ready, or vice versa. With this update, the Operator watches Deployment and StatefulSet status changes, and the status conditions accurately reflect actual pod readiness. Deleted pods are removed from the pod status map. As a result, the status field reliably indicates the current state of the deployment. For more information, see https://redhat.atlassian.net/browse/TRACING-6453. * Gateway redirect URL respects the custom ingress hostname: Before this update, setting a custom hostname with the spec.template.gateway.ingress.host field in the TempoStack custom resource did not update the OpenShift OAuth redirect URL, so authentication redirects pointed to the wrong URL. With this update, the Operator uses the custom hostname when generating the redirect URL, and gateway authentication works correctly with custom ingress hostnames. For more information, see https://redhat.atlassian.net/browse/TRACING-6435. * Gateway starts on clusters that use external OIDC authentication: Before this update, on clusters using external OpenID Connect (OIDC) authentication instead of the built-in OpenShift OAuth server, the Tempo gateway container failed to start because it could not auto-discover the OpenShift OAuth endpoints. With this update, the gateway handles external authentication and starts correctly on such clusters. For more information, see https://redhat.atlassian.net/browse/TRACING-6646. Known issues: * None

Join the discussion

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.17.57. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:60018 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/

Join the discussion

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.17.57. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:60018 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/

Join the discussion

The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): * urllib3: urllib3 Streaming API improperly handles highly compressed data (CVE-2025-66471) * urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) (CVE-2026-21441) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Showing 1 to 10 of 78 results

Filters:Tag: cve-2026-32283
Page 1 of 8
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses