Threats Tagged 'cve-2026-45819'
View all threats tagged with 'cve-2026-45819'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-45819'
Click on any threat for detailed analysis and mitigation recommendations
0 Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.22.15. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:68552 Security Fix(es): * fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization (CVE-2026-84292) * fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency (CVE-2026-16221) * fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects (CVE-2026-76172) * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) * baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling (CVE-2026-45819) * fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority (CVE-2026-18446) * fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies (CVE-2026-84394) * fast-uri: fast-uri: Host confusion via skipped IDN canonicalization (CVE-2026-75931) * fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899) * fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.22 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli. Join the discussion | GCVE Database | 09/22/2026, 06:42:30 UTC Added: 07/22/2026, 00:11:09 UTC |
Red Hat Edge Manager (RHEM) provides simple, scalable, and security-focused management of edge devices and applications. It supports image-mode RHEL and container workloads that run on Podman/Docker or Kubernetes. RHEM is now available as a standalone feature, providing greater flexibility for edge deployments. In addition to the standalone version, RHEM continues to be offered as a plugin for the following platforms: * Red Hat Advanced Cluster Management (RHACM): Extends fleet management to edge devices. * Red Hat Ansible Automation Platform (AAP): Integrates edge management with Ansible automation. This integration enables organizations to optimize the management and orchestration of their fleets of edge devices; whether its thousands of dispersed retail point-of-sale systems or industrial machinery on remote factory floors. Value for customers and partners: * This solution not only helps customers manage thousands of devices but helps scale operations. * To manage large-scale deployments, customers need to be able to integrate with their existing management systems, support remote configuration and over-the-air updates, and collect telemetry data for advanced analytics. * Red Hat Edge Manager offers a simple and security-focused lifecycle management, from onboarding to decommissioning of edge devices. This complete end-to-end solution empowers organizations to gain the most value from the fleets of devices that generate data, all from a centralized location. Join the discussion | GCVE Database | 09/16/2026, 15:11:03 UTC Added: 09/07/2026, 16:08:33 UTC |
0 A security update for python-pytest-html addresses two vulnerabilities in the browserslist dependency. CVE-2026-73088 is a prototype pollution flaw caused by untrusted JSON keys in the normalizeStats() function, which can lead to application crashes and denial of service. CVE-2026-73089 involves unbounded in-memory caching of query pairs, enabling denial of service via memory exhaustion. These issues affect certain SUSE Linux Enterprise and openSUSE Leap 16.0 versions. The vulnerabilities are rated as important/high severity due to potential remote exploitation without authentication. Mitigation involves applying the update and ensuring browserslist processes only trusted input data. Join the discussion | GCVE Database | 08/18/2026, 15:53:05 UTC Added: 08/13/2026, 17:48:37 UTC |
0 baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service. Join the discussion | CVE Database V5 | 08/13/2026, 11:03:42 UTC Added: 08/13/2026, 11:26:54 UTC |
Red Hat has issued a security advisory for Red Hat Hardened Images RPMs including grafana12.4 version 12.4.8-0.1.1.hum1. This update addresses multiple vulnerabilities identified by CVE-2026-73086, CVE-2026-73088, CVE-2026-73089, and CVE-2026-45819. One notable flaw is in the nanoid JavaScript library used by grafana12.4, where an integer overflow can cause predictable ID generation, potentially compromising session tokens, CSRF tokens, and API keys. The vulnerabilities have been classified as important with a high severity rating by Red Hat. No explicit patch link is provided, but the advisory references updated RPM packages. The vendor advisory does not indicate that the vulnerabilities are already mitigated or that no action is required. Join the discussion | GCVE Database | 08/13/2026, 10:01:03 UTC Added: 08/17/2026, 16:14:07 UTC |
Showing 1 to 5 of 5 results