Threats Tagged 'cve-2026-49825'
View all threats tagged with 'cve-2026-49825'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-49825'
Click on any threat for detailed analysis and mitigation recommendations
0 The `xmlattr` filter in affected versions of Jinja accepts keys containing spaces. XML/HTML attributes cannot contain spaces, as each would then be interpreted as a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. Note that accepting keys as user input is not common or a particularly intended use case of the `xmlattr` filter, and an application doing so should already be verifying what keys are provided regardless of this fix. Join the discussion | GCVE Database | 10/08/2026, 08:23:05 UTC Added: 06/02/2026, 21:44:03 UTC |
0 Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Security Fix(es): * python-dynaconf: Dynaconf: Arbitrary code execution via Server-Side Template Injection [rhn_satellite_6.16] (CVE-2026-33154) * foreman: Excessive Permissions for Viewer Role on Preview [rhn_satellite_6.16] (CVE-2026-96659) * foreman: Safemode Bypass leading to RCE [rhn_satellite_6.16] (CVE-2026-96658) * satellite:el8/python-sqlparse: sqlparse: Denial of Service via inefficient SQL parsing [rhn_satellite_6.16] (CVE-2026-59893) * python-sqlparse: sqlparse: Denial of Service via inefficient SQL parsing [rhn_satellite_6.16] (CVE-2026-59893) * satellite:el8/python-sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing [rhn_satellite_6.16] (CVE-2026-54284) * python-sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing [rhn_satellite_6.16] (CVE-2026-54284) * satellite:el8/yggdrasil-worker-forwarder: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages [rhn_satellite_6.16] (CVE-2026-56862) * satellite:el8/yggdrasil-worker-forwarder: Go html/template: Cross-Site Scripting via pathological input [rhn_satellite_6.16] (CVE-2026-56858) * satellite:el8/yggdrasil-worker-forwarder: golang net/url: Denial of Service from quadratic complexity in path resolution [rhn_satellite_6.16] (CVE-2026-56860) * satellite:el8/yggdrasil-worker-forwarder: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal [rhn_satellite_6.16] (CVE-2026-33818) * satellite:el8/rubygem-katello: Katello Content View History API Cross-Organization Authorization Bypass [rhn_satellite_6.16] (CVE-2026-79654) * python-gitpython: GitPython: Arbitrary file read via TagReference.create() [rhn_satellite_6.16] (CVE-2026-78679) * python-gitpython: GitPython: Remote Code Execution via Git directory impersonation [rhn_satellite_6.16] (CVE-2026-87817) * satellite-capsule:el8/python-lxml: lxml: URL bypass vulnerability in Cleaner via missing xlink:href [rhn_satellite_6.16] (CVE-2026-49825) * yggdrasil-worker-forwarder: Golang MIME: Denial of Service via maliciously-crafted MIME header [rhn_satellite_6.16] (CVE-2026-42504) * satellite:el8/yggdrasil-worker-forwarder: Golang MIME: Denial of Service via maliciously-crafted MIME header [rhn_satellite_6.16] (CVE-2026-42504) * rubygem-katello: Katello Content View History API Cross-Organization Authorization Bypass [rhn_satellite_6.16] (CVE-2026-79654) * yggdrasil-worker-forwarder: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal [rhn_satellite_6.16] (CVE-2026-33818) * yggdrasil-worker-forwarder: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages [rhn_satellite_6.16] (CVE-2026-56862) * yggdrasil-worker-forwarder: Go html/template: Cross-Site Scripting via pathological input [rhn_satellite_6.16] (CVE-2026-56858) * yggdrasil-worker-forwarder: golang net/url: Denial of Service from quadratic complexity in path resolution [rhn_satellite_6.16] (CVE-2026-56860) * satellite:el8/rubygem-katello: improper authorization logic allows resource enumeration [rhn_satellite_6.16] (CVE-2026-56098) * rubygem-katello: improper authorization logic allows resource enumeration [rhn_satellite_6.16] (CVE-2026-56098) * rubygem-katello: SQL injection in Registry Proxy via labels [rhn_satellite_6.16] (CVE-2026-56097) * satellite:el8/rubygem-katello: SQL injection in Registry Proxy via labels [rhn_satellite_6.16] (CVE-2026-56097) * satellite-utils:el8/rubygem-hammer_cli: command injection via insecure editor invocation [rhn_satellite_6.16] (CVE-2026-12545) * rubygem-hammer_cli: command injection via insecure editor invocation [rhn_satellite_6.16] (CVE-2026-12545) * foreman: SSTI and insecure deserialization in foreman-rake configuration [rhn_satellite_6.16] (CVE-2026-12544) * satellite:el8/foreman: SSTI and insecure deserialization in foreman-rake configuration [rhn_satellite_6.16] (CVE-2026-12544) * satellite:el8/foreman: command injection in foreman-tail [rhn_satellite_6.16] (CVE-2026-12542) * foreman: command injection in foreman-tail [rhn_satellite_6.16] (CVE-2026-12542) * satellite:el8/foreman: command injection in foreman-rake database tasks [rhn_satellite_6.16] (CVE-2026-12541) * foreman: command injection in foreman-rake database tasks [rhn_satellite_6.16] (CVE-2026-12541) * satellite:el8/foreman: command injection in foreman-rake errors:fetch_log via request_id parameter [rhn_satellite_6.16] (CVE-2026-12540) * foreman: command injection in foreman-rake errors:fetch_log via request_id parameter [rhn_satellite_6.16] (CVE-2026-12540) * satellite:el8/foreman: unauthenticated information disclosure via provisioning token validation flaw [rhn_satellit Join the discussion | GCVE Database | 10/01/2026, 23:06:35 UTC Added: 10/01/2026, 19:26:31 UTC |
0 Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Security Fix(es): * rubygem-foreman_remote_execution: command injection in job invocations via effective_user parameter (CVE-2026-12405) * foreman: unauthenticated information disclosure via provisioning token validation flaw (CVE-2026-12423) * foreman: command injection in foreman-rake errors:fetch_log via request_id parameter (CVE-2026-12540) * foreman: command injection in foreman-rake database tasks (CVE-2026-12541) * foreman: command injection in foreman-tail (CVE-2026-12542) * foreman: SSTI and insecure deserialization in foreman-rake configuration (CVE-2026-12544) * rubygem-hammer_cli: command injection via insecure editor invocation (CVE-2026-12545) * python3.12-dynaconf: Dynaconf: Arbitrary code execution via Server-Side Template Injection (CVE-2026-33154) * yggdrasil-worker-forwarder: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * yggdrasil-worker-forwarder: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * nodejs-sanitize-html: PostCSS: Information disclosure and denial of service via crafted CSS input (CVE-2026-45623) * python-sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing (CVE-2026-54284) * python3.12-sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing (CVE-2026-54284) * rubygem-katello: SQL injection in Registry Proxy via labels (CVE-2026-56097) * rubygem-katello: improper authorization logic allows resource enumeration (CVE-2026-56098) * yggdrasil-worker-forwarder: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * yggdrasil-worker-forwarder: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * yggdrasil-worker-forwarder: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * nodejs-connected-react-router: Immutable.js: Denial of Service due to mishandling of large index values in List operations (CVE-2026-59879) * nodejs-sass: Immutable.js: Denial of Service due to mishandling of large index values in List operations (CVE-2026-59879) * python-sqlparse: sqlparse: Denial of Service via inefficient SQL parsing (CVE-2026-59893) * python3.12-sqlparse: sqlparse: Denial of Service via inefficient SQL parsing (CVE-2026-59893) * python-sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in comment grouping (CVE-2026-71491) * python3.12-sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in comment grouping (CVE-2026-71491) * nodejs-css-loader: nanoid: Predictable ID generation due to integer overflow (CVE-2026-73086) * nodejs-sanitize-html: nanoid: Predictable ID generation due to integer overflow (CVE-2026-73086) * nodejs-compression-webpack-plugin: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899) * nodejs-mini-css-extract-plugin: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899) * nodejs-webpack: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899) * nodejs-compression-webpack-plugin: fast-uri: Host confusion via skipped IDN canonicalization (CVE-2026-75931) * nodejs-mini-css-extract-plugin: fast-uri: Host confusion via skipped IDN canonicalization (CVE-2026-75931) * nodejs-webpack: fast-uri: Host confusion via skipped IDN canonicalization (CVE-2026-75931) * nodejs-compression-webpack-plugin: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975) * nodejs-mini-css-extract-plugin: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975) * nodejs-webpack: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975) * python3.12-gitpython: GitPython: Arbitrary file read via TagReference.create() (CVE-2026-78679) * rubygem-katello: Katello Content View History API Cross-Organization Authorization Bypass (CVE-2026-79654) * nodejs-compression-webpack-plugin: fast-uri: Authority Injection via Unvalidated Port Serialization (CVE-2026-84292) * nodejs-mini-css-extract-plugin: fast-uri: Authority Injection via Unvalidated Port Serialization (CVE-2026-84292) * nodejs-webpack: fast-uri: Authority Injection via Unvalidated Port Serialization (CVE-2026-84292) * nodejs-compression-webpack-plugin: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies (CVE-2026-84394) * nodejs-mini-css-extract-plugin: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies (CVE-2026-84394) * nodejs-webpack: fast-uri: Host confusion via unbalanced URI brackets can bypa Join the discussion | GCVE Database | 10/01/2026, 15:04:05 UTC Added: 10/01/2026, 19:26:41 UTC |
0 Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. For details about this release, refer to the release notes listed in the References section. Join the discussion | GCVE Database | 09/23/2026, 22:49:25 UTC Added: 07/21/2026, 20:03:47 UTC |
Red Hat Update Infrastructure (RHUI) container images are based on the latest RHUI RPM packages and the ubi9 or ubi9-init base images. This release updates to the latest version. Join the discussion | GCVE Database | 09/16/2026, 10:07:58 UTC Added: 07/16/2026, 10:39:53 UTC |
0 Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href (CVE-2026-49825) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/14/2026, 00:00:00 UTC Added: 08/24/2026, 13:51:20 UTC |
A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This can cause unexpected memory reads and potential crashes. While difficult to exploit, the flaw could lead to application instability or denial of service. Join the discussion | CVE Database V5 | 06/29/2026, 00:00:00 UTC Added: 10/14/2025, 06:19:03 UTC |
Showing 1 to 7 of 7 results