Threats Tagged 'cve-2026-33846'
View all threats tagged with 'cve-2026-33846'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-33846'
Click on any threat for detailed analysis and mitigation recommendations
0 Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.13.71. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:65838 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/release_notes Security Fix(es): None For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html-single/updating_clusters/index#updating-cluster-within-minor. Join the discussion | GCVE Database | 09/17/2026, 18:01:22 UTC Added: 06/25/2026, 21:47:18 UTC |
0 This advisory relates to Red Hat OpenShift Container Platform 4.12.97 and includes updates primarily for container images. No direct security fixes are included in this release for OpenShift itself. However, a related Red Hat Enterprise Linux 9 update addresses a moderate severity security vulnerability (CVE-2025-11234) in the qemu-kvm package, specifically a use-after-free issue in the VNC WebSocket handshake. Users of affected Red Hat Enterprise Linux 9 versions should apply the qemu-kvm update to mitigate this vulnerability. The OpenShift advisory recommends upgrading to the updated packages and images when available but does not list new security fixes for OpenShift 4.12.97 itself. Join the discussion | GCVE Database | 09/03/2026, 12:01:51 UTC Added: 07/12/2026, 09:18:51 UTC |
0 Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.18.54. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:57482 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ Security Fix(es): * samba: Missing access check on reparse point operations (CVE-2026-1933) * samba: group policy certificate enrollment uses http:// without validation (CVE-2026-3012) * samba: Remote Code Execution in SAMR (CVE-2026-4408) * sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (CVE-2026-14474) * gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment (CVE-2026-33845) * gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly (CVE-2026-33846) * vim: arbitrary command execution via modeline sandbox bypass (CVE-2026-34982) * gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability (CVE-2026-42009) * gnutls: gnutls: Authentication Bypass via NUL Character in Username (CVE-2026-42010) * kernel: net: openvswitch: reject oversized nested action attrs (CVE-2026-64531) * samba: vfs_worm does not block directory modification (CVE-2026-2340) * gnutls: gnutls: Information disclosure via heap overread in RSA key exchange (CVE-2026-5260) * glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width (CVE-2026-5450) * sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (CVE-2026-14476) * vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass (CVE-2026-35177) * vim: Vim: Command injection allows arbitrary code execution via malicious tag files (CVE-2026-41411) * gnutls: gnutls: Security bypass due to incorrect name constraint handling (CVE-2026-42011) * gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name (CVE-2026-42013) * vim: command injection when decompressing .tgz archives (CVE-2026-46483) * libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data (CVE-2026-48864) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Join the discussion | GCVE Database | 08/26/2026, 15:56:34 UTC Added: 06/04/2026, 21:16:09 UTC |
Red Hat® AI Inference Server Join the discussion | GCVE Database | 07/06/2026, 16:44:03 UTC Added: 07/22/2026, 23:24:15 UTC |
Red Hat® AI Inference Server Join the discussion | GCVE Database | 07/06/2026, 16:44:03 UTC Added: 06/30/2026, 23:36:10 UTC |
The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS. Security Fix(es): * libtasn1: Inefficient DER Decoding in libtasn1 Leading to Potential Remote DoS (CVE-2024-12133) * gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification (CVE-2025-14831) * gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison (CVE-2026-3833) * gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment (CVE-2026-33845) * gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly (CVE-2026-33846) * gnutls: Fix qsort comparator in DTLS reassembly (CVE-2026-42009) * gnutls: gnutls: Authentication Bypass via NUL Character in Username (CVE-2026-42010) * gnutls: gnutls: Security bypass due to incorrect name constraint handling (CVE-2026-42011) * gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs (CVE-2026-42012) * gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name (CVE-2026-42013) * gnutls: gnutls: Information disclosure via heap overread in RSA key exchange (CVE-2026-5260) * gnutls: Fix use-after-free in gnutls_pkcs11_token_set_pin (CVE-2026-42014) * gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling (CVE-2026-42015) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 06/29/2026, 15:13:23 UTC Added: 06/02/2026, 21:43:35 UTC |
0 Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network. Join the discussion | GCVE Database | 06/24/2026, 16:29:56 UTC Added: 05/26/2026, 20:58:31 UTC |
0 Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network. Join the discussion | GCVE Database | 06/24/2026, 16:29:56 UTC Added: 05/26/2026, 20:58:31 UTC |
0 The OpenSSL toolkit provides support for secure communications between machines. This version of OpenSSL package contains only the libraries from the 1.1.1 version and is provided for compatibility with previous releases. Security Fix(es): * openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing (CVE-2025-69419) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 05/19/2026, 18:28:57 UTC Added: 06/09/2026, 10:23:14 UTC |
0 The RHEL-8 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2026:11077 RHSA-2026:7667 RHSA-2026:8534 RHSA-2026:9745 (see References) Security Fixes: * rsync: Rsync: Out of bounds array access via negative index (CVE-2025-10158) * gnutls: Stack-based Buffer Overflow in gnutls_pkcs11_token_init() Function (CVE-2025-9820) * gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification (CVE-2025-14831) * openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables (CVE-2026-3497) * nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination (CVE-2026-27135) * libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing (CVE-2026-4424) * python: Python: Command-line option injection in webbrowser.open() via crafted URLs (CVE-2026-4519) * libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing (CVE-2026-5121) * python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules (CVE-2026-6100) * python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API (CVE-2026-4786) Users of RHEL-8 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images. You can find images updated by this advisory in Red Hat Container Catalog (see References). Join the discussion | GCVE Database | 05/05/2026, 17:47:50 UTC Added: 05/26/2026, 20:58:31 UTC |
Showing 1 to 10 of 15 results