Threats Tagged 'cve-2026-41240'
View all threats tagged with 'cve-2026-41240'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-41240'
Click on any threat for detailed analysis and mitigation recommendations
0 Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.17.57. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:60018 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/ Join the discussion | GCVE Database | 09/03/2026, 07:53:39 UTC Added: 05/26/2026, 20:58:28 UTC |
0 This release of Red Hat build of Apicurio Registry 3.3.1 GA includes the following security fixes. Security Fix(es): * DOMPurify: Cross-site scripting vulnerability allows code execution [rhint-serv-3] (CVE-2026-49978) * apicurio-registry: Unhardened SAXParser in content-type detection leads to blind XXE / SSRF / billion-laughs DoS [rhint-serv-3] (CVE-2026-12975) * apicurio-registry: SSRF via wsdl4j import dereference in WSDL FULL validation [rhint-serv-3] (CVE-2026-12992) * apicurio-registry: XML entity-expansion denial of service via internal DTD subset [rhint-serv-3] (CVE-2026-12993) * Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name [rhint-serv-3] (CVE-2026-44496) * DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization [rhint-serv-3] (CVE-2026-41240) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 08/25/2026, 10:07:13 UTC Added: 08/26/2026, 15:01:54 UTC |
0 Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. For details about this release, refer to the release notes listed in the References section. Join the discussion | GCVE Database | 07/20/2026, 18:19:51 UTC Added: 06/11/2026, 17:33:03 UTC |
0 Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution (CVE-2026-11332) * automation-controller: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite (CVE-2026-8643) * automation-controller: urllib3: Denial of Service due to excessive HTTP response decompression (CVE-2026-44432) * automation-platform-ui: fast-uri: Path traversal vulnerability allows bypass of security policies (CVE-2026-6321) * python3.12-pulpcore: relative_path_validator bypass via directory traversal in FilesystemExport (CVE-2026-12701) * receptor: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136) * receptor: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681) * receptor: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) * receptor: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) * receptor: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) * receptor: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) For details about this release, refer to the release notes listed in the References section. Join the discussion | GCVE Database | 07/20/2026, 16:17:57 UTC Added: 05/27/2026, 21:15:01 UTC |
An update is now available for the Red Hat build of Cryostat 4 on RHEL 9. Security Fix(es): * DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization (CVE-2026-41240) * crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) * shell-quote: Arbitrary code execution via command injection due to unescaped line terminators (CVE-2026-9277) * Apache Thrift: Security bypass due to improper certificate validation (CVE-2026-43869) * Netty: High integrity impact due to improper DNS domain name constraint enforcement (CVE-2026-42579) * Netty: Incorrect HTTP response parsing leads to data confusion (CVE-2026-42584) * Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers (CVE-2026-42581) * Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation (CVE-2026-42578) * Netty: Denial of Service via unbounded memory allocation in HTTP content decompression (CVE-2026-42587) * Apache Thrift c_glib: Denial of Service via specially crafted requests (CVE-2025-48431) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 06/22/2026, 17:15:26 UTC Added: 06/08/2026, 21:20:11 UTC |
OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform. This advisory contains OpenShift Virtualization v4.19 images. Join the discussion | GCVE Database | 06/22/2026, 12:31:39 UTC Added: 06/22/2026, 15:51:33 UTC |
An update is now available for Red Hat OpenShift GitOps. Bug Fix(es) and Enhancement(s): * GITOPS-8784 (Service-CA annotation removed from argocd-server Service during v1.12.3 -> v1.12.4 upgrade path, persists in later versions) Join the discussion | GCVE Database | 05/26/2026, 14:49:30 UTC Added: 05/26/2026, 20:57:56 UTC |
0 Red Hat OpenShift Data Foundation 4.16.26 security, enhancement & bug fix update FIXED BUGS: ========== DFBUGS-6193: Backport to odf-4.16.26 ocs-operator should not use image gcr.io/kubebuilder/kube-rbac-proxy DFBUGS-5940: Backport to odf-4.16.z [External Mode]: noobaa-default-backing-store is in creating state due to "CheckExternalConnection Status=UNKNOWN_FAILURE Error=SELF_SIGNED_CERT_IN_CHAIN" Join the discussion | GCVE Database | 05/14/2026, 11:50:27 UTC Added: 05/26/2026, 20:58:28 UTC |
Kiali 1.73.30, for Red Hat OpenShift Service Mesh 2.6, provides observability for the service mesh by offering a visual representation of the mesh topology and metrics, helping users monitor, trace, and manage efficiently. Security Fix(es): * CVE-2026-32280 Go: Denial of Service vulnerability in certificate chain building (OSSM-13521) * CVE-2026-40895 follow-redirects: Information disclosure via cross-domain redirects (OSSM-13550, OSSM-13551) * CVE-2026-41240 DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization (OSSM-13592) * CVE-2026-42033 Axios: HTTP Transport Hijacking via Prototype Pollution (OSSM-13687, OSSM-13688) * CVE-2026-42035 Axios: Arbitrary HTTP header injection via prototype pollution (OSSM-13594, OSSM-13595) * CVE-2026-42039 Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data (OSSM-13725, OSSM-13726) * CVE-2026-42041 Axios: Authentication bypass due to prototype pollution of HTTP error handling (OSSM-13739, OSSM-13740) * CVE-2026-42043 Axios: NO_PROXY bypass via crafted URL (OSSM-13711, OSSM-13712) Enhancement(s): * OSSM-12301 Migration from Yarn Classic (v1) to Yarn v4 or NPM For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 05/12/2026, 18:56:35 UTC Added: 05/26/2026, 20:58:28 UTC |
0 Red Hat Streams for Apache Kafka, based on the Apache Kafka project, offers a distributed backbone that allows microservices and other applications to share data with extremely high throughput and extremely low latency. This release of Red Hat Streams for Apache Kafka 3.2.0 serves as a replacement for Red Hat Streams for Apache Kafka 3.1.0, and includes security and bug fixes, and enhancements. Security Fix(es): * Drain Cleaner, Kafks Exporter - Eclipse Vert.x Web static handler file access denial [amq-st-3.2]"(CVE-2026-1002)" * Drain Cleaner, Kroxylicous - Netty denial of service[amqst-3.2]"(CVE-2026-33871)" * Drain Cleaner, Kroxylicous - Netty request smuggling attacks[amqst-3.2]"(CVE-2026-33870)" * Cruise Control - jose4j denial of service [amqst-3.2]"(CVE-2024-29371)" * Kafka Exporter - golang-github-danielqsj-kafka_exporter: Memory exhaustion in query parameter parsing in net/url [amq-st-3.2]"(CVE-2025-61726)" * Kafka Exporter - golang-github-danielqsj-kafka_exporter: golang: Denial of Service due to excessive resource consumption via crafted certificate [amq-st-3.2]"(CVE-2025-61729)" * Kafka Exporter - golang-github-danielqsj-kafka_exporter: Unexpected session resumption in crypto/tls [amqst-3.2]"(CVE-2025-68121)" * console UI - Next.js Server-Side Request Forgery in Server Actions [amqst-3.2]"(CVE-2024-34351)" * console UI - com.github.streamshub-console: Next.js: Unbounded next/image disk cache growth can exhaust storage[amqst-3.2]"(CVE-2026-27980)" * console UI - Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization [amqst-3.2]"(CVE-2025-62718)" * console UI - React Server Components: Denial of Service via specially crafted HTTP requests [amqst-3.2]"(CVE-2026-23864)" * console UI - Axios: Remote Code Execution via Prototype Pollution escalation [amqst-3.2]"(CVE-2026-40175)" * console UI - lodash: Arbitrary code execution via untrusted input in template imports [amqst-3.2]"(CVE-2026-4800)" Join the discussion | GCVE Database | 05/04/2026, 23:37:19 UTC Added: 05/26/2026, 20:58:13 UTC |
Showing 1 to 10 of 13 results