Skip to main content

Threats Tagged 'cve-2026-59893'

View all threats tagged with 'cve-2026-59893'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-59893

Threats Tagged 'cve-2026-59893'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat Satellite 6.19.5 includes multiple critical security fixes addressing command injection, information disclosure, server-side template injection, denial of service, SQL injection, cross-site scripting, authorization bypass, and other vulnerabilities across various components such as foreman, rubygem-foreman_remote_execution, python3.12-dynaconf, yggdrasil-worker-forwarder, and nodejs packages. These vulnerabilities could allow attackers to execute arbitrary code, disclose sensitive information, cause denial of service, or bypass authorization controls. The update is rated critical by Red Hat Product Security and is intended for Red Hat Satellite 6.19 on RHEL 9.

Join the discussion

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. For details about this release, refer to the release notes listed in the References section.

Join the discussion

Red Hat Ansible Automation Platform 2.5 for RHEL 9 has multiple critical security vulnerabilities affecting its automation-controller and related components. These include remote code execution, privilege escalation, information disclosure, denial of service, cross-tenant data exposure, command injection, and other severe issues. The vulnerabilities impact the core automation framework used for IT automation at scale. Red Hat has issued a security advisory with updates addressing these issues.

Join the discussion

Red Hat Ansible Automation Platform 2.6 has multiple critical security vulnerabilities affecting its automation-controller, automation-gateway-proxy, and automation-platform-ui components. These include remote code execution, privilege escalation, credential disclosure, denial of service, cross-site scripting, and unauthorized information disclosure. The vulnerabilities impact the ability to securely manage IT automation at scale and could allow attackers to execute arbitrary code, escalate privileges, or access sensitive data. Red Hat has issued a security advisory with updates addressing these issues.

Join the discussion

Release of RHOAI 3.5.1 provides these changes:

Join the discussion

Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network.

Join the discussion

Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network.

Join the discussion
0

This update for python-sqlparse fixes the following issues: - CVE-2026-54284: high algorithm complexity when parsing SQL payloads with hundreds of nesting levels can lead to denial of service via excessive resource consumption (bsc#1275459). - CVE-2026-59893: quadratic complexity when processing unmatched dollar-quoted literal and multiline-comment delimiters can lead to denial of service (bsc#1275461). - CVE-2026-59894: improper backlash escaping allows for injection of Python or PHP code via a crafted SQL input (bsc#1275460). - CVE-2026-71491: quadratic complexity in `group_comments` when processing comment-only statements can lead to denial of services (bsc#1275466). - Incomplete GHSA-27jp-wm6q-gp25 patch (bsc#1268597).

Join the discussion

CVE-2026-54284 is a high-severity vulnerability in the Python sqlparse module prior to version 0.6.0. The issue arises from inefficient algorithmic complexity during TokenList construction and string conversion, causing quadratic CPU consumption when using sqlparse.parse(), sqlparse.format(), and sqlparse.split(). This inefficiency is due to repeatedly flattening nested token subtrees. The vulnerability is fixed in sqlparse version 0.6.0.

Join the discussion

CVE-2026-59893 is a high-severity vulnerability in the Python sqlparse module prior to version 0.6.0. The issue involves inefficient regular expression complexity causing quadratic CPU consumption when parsing certain SQL constructs such as unmatched dollar-quoted literals and multiline comments. This can lead to denial of service through excessive CPU usage. The vulnerability is fixed in sqlparse version 0.6.0.

Join the discussion

Showing 1 to 10 of 11 results

Filters:Tag: cve-2026-59893
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses