Threats Tagged 'cve-2026-39833'
View all threats tagged with 'cve-2026-39833'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-39833'
Click on any threat for detailed analysis and mitigation recommendations
0 The multicluster engine for Kubernetes provides the foundational components that are necessary for the centralized management of multiple Kubernetes-based clusters across data centers, public clouds, and private clouds. You can use the engine to create new Red Hat OpenShift Container Platform clusters or to bring existing Kubernetes-based clusters under management by importing them. After the clusters are managed, you can use the APIs that are provided by the engine to distribute configuration based on placement policy. Join the discussion | GCVE Database | 08/25/2026, 19:37:51 UTC Added: 05/26/2026, 20:58:49 UTC |
OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform. This advisory contains OpenShift Virtualization v4.20 images. Join the discussion | GCVE Database | 08/11/2026, 17:20:11 UTC Added: 07/21/2026, 20:03:31 UTC |
OpenShift API for Data Protection (OADP) enables you to back up and restore application resources, persistent volume data, and internal container images to external backup storage. OADP enables both file system-based and snapshot-based backups for persistent volumes. Join the discussion | GCVE Database | 07/22/2026, 15:57:51 UTC Added: 07/22/2026, 23:23:21 UTC |
Red Hat Edge Manager (RHEM) provides simple, scalable, and security-focused management of edge devices and applications. It supports image-mode RHEL and container workloads that run on Podman/Docker or Kubernetes. RHEM is now available as a standalone feature, providing greater flexibility for edge deployments. In addition to the standalone version, RHEM continues to be offered as a plugin for the following platforms: Red Hat Advanced Cluster Management (RHACM): Extends fleet management to edge devices. Red Hat Ansible Automation Platform (AAP): Integrates edge management with Ansible automation. This integration enables organizations to optimize the management and orchestration of their fleets of edge devices; whether its thousands of dispersed retail point-of-sale systems or industrial machinery on remote factory floors. Value for customers and partners: * This solution not only helps customers manage thousands of devices but helps scale operations. * To manage large-scale deployments, customers need to be able to integrate with their existing management systems, support remote configuration and over-the-air updates, and collect telemetry data for advanced analytics. * Red Hat Edge Manager offers a simple and security-focused lifecycle management, from onboarding to decommissioning of edge devices. This complete end-to-end solution empowers organizations to gain the most value from the fleets of devices that generate data, all from a centralized location. Security Fixes: * flightctl: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) * flightctl: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * flightctl: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178) * flightctl: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740) * flightctl: Arc: Information disclosure and Denial of Service via unauthenticated debug endpoints (CVE-2026-48050) * flightctl: golang.org/x/text: Denial of Service via invalid UTF-8 input (CVE-2026-56852) * flightctl: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * flightctl: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * flightctl: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) * flightctl: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * flightctl: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * flightctl: go-git: Arbitrary file read/write via symbolic link resolution (CVE-2026-71556) Join the discussion | GCVE Database | 07/20/2026, 13:56:26 UTC Added: 06/03/2026, 01:45:14 UTC |
0 Multiple security vulnerabilities affecting the cosign tool and related Go cryptography libraries have been identified and fixed. These include issues parsing HTML files, a memory-safety vulnerability, and multiple issues in golang.org/x/crypto/ssh. The vulnerabilities have been addressed in updated versions provided by SUSE and Red Hat. A patch is available to remediate these issues. Join the discussion | GCVE Database | 07/10/2026, 08:42:03 UTC Added: 06/06/2026, 21:13:43 UTC |
The RHTAS Operator can be used with OpenShift Container Platform 4.17, 4.18, 4.19, 4.20, 4.21, 4.22 Join the discussion | GCVE Database | 07/09/2026, 11:43:07 UTC Added: 07/10/2026, 09:24:17 UTC |
GCVE Database | 07/08/2026, 09:20:18 UTC Added: 07/08/2026, 13:20:58 UTC | |
0 This security update for Apptainer addresses multiple vulnerabilities, including CVE-2024-45310 and several CVE-2026 series issues. The update includes fixes for at least 13 CVEs and updates dependencies such as golang.org/x/crypto and golang.org/x/net to newer versions. The update also integrates vulnchecker optionally into the build process and synchronizes with the Factory version to ensure comprehensive vulnerability mitigation. Join the discussion | GCVE Database | 05/28/2026, 12:23:45 UTC Added: 09/17/2026, 01:59:29 UTC |
0 The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested. Join the discussion | GCVE Database | 05/22/2026, 02:31:26 UTC Added: 07/21/2026, 20:03:17 UTC |
0 The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested. Join the discussion | CVE Database V5 | 05/22/2026, 02:31:26 UTC Added: 05/22/2026, 03:29:47 UTC |
Showing 1 to 10 of 12 results