Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cve-2026-4324'

View all threats tagged with 'cve-2026-4324'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-4324

Threats Tagged 'cve-2026-4324'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat Security Advisory: Satellite 6.19.1 Async UpdateCVE-2026-4324
0

Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Security Fix(es): * dynflow-utils: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) * rubygem-katello: Katello: Denial of Service and potential information disclosure via SQL injection (CVE-2026-4324)

Join the discussion
Red Hat Security Advisory: Satellite 6.17.7 Async UpdateCVE-2025-6176
0

Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Security Fix(es): * python-django: Django: SQL Injection via crafted column aliases (CVE-2026-1287) * python-django: Django: SQL Injection via RasterField band index parameter (CVE-2026-1207) * python-django: Django: Denial of Service via crafted HTML inputs (CVE-2026-1285) * python-django: Django: SQL injection via crafted column aliases in QuerySet.order_by() (CVE-2026-1312) * python-django: Django: Denial of Service via crafted request with duplicate headers (CVE-2025-14550) * python-brotli: Brotli decompression bomb DoS in scrapy/scrapy (CVE-2025-6176) * rubygem-foreman_kubevirt: foreman_kubevirt: Man-in-the-Middle due to insecure default SSL verification (CVE-2026-1531) * rubygem-fog-kubevirt: fog-kubevirt: Man-in-the-Middle vulnerability due to disabled certificate validation (CVE-2026-1530) * rubygem-rubyipmi: Red Hat Satellite: Remote Code Execution in rubyipmi via malicious BMC username (CVE-2026-0980) * foreman: Foreman: Remote Code Execution via command injection in WebSocket proxy (CVE-2026-1961) * yggdrasil-worker-forwarder: Unexpected session resumption in crypto/tls (CVE-2025-68121) * Katello: Denial of Service and potential information disclosure via SQL injection (CVE-2026-4324) Bug Fix(es): * High memory usage of postgres processes on scaled Capsule (SAT-42871) * AttributeError: 'NoneType' object has no attribute '_artifacts' when running pulpcore-container-handle-image-metadata in the post-upgrade step for Satellite 6.17 (SAT-42873) * Lifecycle Environment shows 2 Library options (SAT-42881) * Executing foreman-rake command in the satellite, prints warning "W, [2025-08-28T14:25:04.030121 #11656] WARN -- : Scoped order is ignored, it's forced to be batch order." (SAT-42882) * Upgrade to Sat 6.16 does not cleanup Postgresql12 which is reported as security risk/vulnerability by the scanners on Sat 6.17 & 6.18. (SAT-43118)

Join the discussion
Red Hat Security Advisory: Satellite 6.18.4 Async UpdateCVE-2025-61726
0

Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Security Fix(es): * yggdrasil-worker-forwarder: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726) * yggdrasil-worker-forwarder: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729) * yggdrasil-worker-forwarder: Unexpected session resumption in crypto/tls (CVE-2025-68121) * rubygem-rubyipmi: Remote Code Execution in rubyipmi via malicious BMC username (CVE-2026-0980) * rubygem-foreman_kubevirt: foreman_kubevirt: Man-in-the-Middle due to insecure default SSL verification (CVE-2026-1531) * foreman: Foreman: Remote Code Execution via command injection in WebSocket proxy (CVE-2026-1961) * rubygem-katello: Katello: Denial of Service and potential information disclosure via SQL injection (CVE-2026-4324)

Join the discussion
CVE-2026-4324: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Red Hat Red Hat Satellite 6.17 for RHEL 9CVE-2026-4324
0

A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of user-provided input, allows a remote attacker to inject arbitrary SQL commands into the sort_by parameter of the /api/hosts/bootc_images API endpoint. This can lead to a Denial of Service (DoS) by triggering database errors, and potentially enable Boolean-based Blind SQL injection, which could allow an attacker to extract sensitive information from the database.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: cve-2026-4324
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses