Skip to main content

Threats Tagged 'cve-2026-53550'

View all threats tagged with 'cve-2026-53550'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-53550

Threats Tagged 'cve-2026-53550'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.19.46. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:63043 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/

Join the discussion

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.17.57. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:60023 Security Fix(es): * golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs (CVE-2026-46597) * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) * js-yaml: js-yaml: Denial of Service via crafted YAML documents (CVE-2026-59869) * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) * crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) * brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli.

Join the discussion

shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time relative to the number of input tokens. An attacker who can supply an attacker-controlled string to any code path that calls parse() (no shell metacharacters are required; plain space-separated words suffice) can block the single-threaded Node.js event loop for an extended period with a small input, resulting in a denial of service. There is no code execution or data disclosure; impact is to availability only. Fixed in 1.8.5.

Join the discussion

This update includes the following RPMs: nodejs24: * nodejs24-24.18.0-0.3.hum1 (aarch64, x86_64) * nodejs24-bin-24.18.0-0.3.hum1 (noarch) * nodejs24-devel-24.18.0-0.3.hum1 (aarch64, x86_64) * nodejs24-docs-24.18.0-0.3.hum1 (noarch) * nodejs24-full-i18n-24.18.0-0.3.hum1 (aarch64, x86_64) * nodejs24-libs-24.18.0-0.3.hum1 (aarch64, x86_64) * nodejs24-npm-11.16.0-1.24.18.0.0.3.hum1 (noarch) * nodejs24-npm-bin-24.18.0-0.3.hum1 (noarch) * v8-13.6-devel-13.6.233.17-1.24.18.0.0.3.hum1 (aarch64, x86_64) * nodejs24-24.18.0-0.3.hum1.src (src) Security Fix(es): nodejs24: * CVE-2026-59869

Join the discussion

This update includes the following RPMs: nodejs25: * nodejs25-25.9.0-1.3.hum1 (aarch64, x86_64) * nodejs25-bin-25.9.0-1.3.hum1 (noarch) * nodejs25-devel-25.9.0-1.3.hum1 (aarch64, x86_64) * nodejs25-docs-25.9.0-1.3.hum1 (noarch) * nodejs25-full-i18n-25.9.0-1.3.hum1 (aarch64, x86_64) * nodejs25-libs-25.9.0-1.3.hum1 (aarch64, x86_64) * nodejs25-npm-11.12.1-1.25.9.0.1.3.hum1 (noarch) * nodejs25-npm-bin-25.9.0-1.3.hum1 (noarch) * v8-14.1-devel-14.1.146.11-1.25.9.0.1.3.hum1 (aarch64, x86_64) * nodejs25-25.9.0-1.3.hum1.src (src) Security Fix(es): nodejs25: * CVE-2026-59869

Join the discussion
0

This security update for python-pytest-html addresses vulnerabilities in its dependencies shell-quote and js-yaml. The shell-quote vulnerability (CVE-2026-13311) involves inefficient input parsing that can lead to denial of service. The js-yaml vulnerability (CVE-2026-53550) involves quadratic complexity when processing crafted YAML documents, potentially causing CPU exhaustion. Both issues are fixed by updating the respective dependencies.

Join the discussion

js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. The issue is in merge handling inside lib/loader.js. This vulnerability is fixed in 4.2.0 and 3.15.0.

Join the discussion

This update includes the following RPMs: yarnpkg: * yarnpkg-1.22.22-18.1.hum1 (aarch64, x86_64) * yarnpkg-1.22.22-18.1.hum1.src (src)

Join the discussion

Showing 1 to 8 of 8 results

Filters:Tag: cve-2026-53550
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses