Threats Tagged 'cve-2026-73086'
View all threats tagged with 'cve-2026-73086'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-73086'
Click on any threat for detailed analysis and mitigation recommendations
0 Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-controller: GitPython: Remote Code Execution via Git directory impersonation (CVE-2026-87817) * automation-controller: Job template enumeration via unauthenticated Bitbucket webhook oracle (CVE-2026-84717) * automation-controller: Command argument injection via SystemJob extra_vars (CVE-2026-84724) * automation-controller: Masked credential data disclosure via workflow job node artifact search (CVE-2026-84720) * automation-controller: Instance-group privilege escalation via workflow job template copy (CVE-2026-84719) * automation-controller: Audit log falsification via unrestricted X-Forwarded-For trust (CVE-2026-84718) * automation-controller: Mesh certificate issuance for arbitrary hostnames via install bundle (CVE-2026-84716) * automation-controller: Template injection via sanitize_jinja regex bypass (CVE-2026-84714) * automation-controller: Automation mesh topology disclosure via unauthenticated ping endpoint (CVE-2026-84712) * automation-controller: Arbitrary file read via Project scm_branch git argument injection (CVE-2026-84711) * automation-controller: Denial of service via credential type injector Jinja rendering (CVE-2026-84709) * automation-controller: Control-plane secret exposure via container group pod spec override (CVE-2026-84708) * automation-controller: Unauthorized job output disclosure via host filter query traversal (CVE-2026-84707) * automation-controller: Code execution via credential type environment-injector blocklist bypass (CVE-2026-84706) * automation-controller: Cross-tenant credential exposure via execution environment binding (CVE-2026-84703) * automation-controller: Cross-tenant execution privilege bypass via workflow job template node patch (CVE-2026-84692) * automation-controller: Secret key and database credential disclosure via format-string injection (CVE-2026-84691) * automation-controller: Cross-tenant job hijack via Bulk Job Launch node reference (CVE-2026-84689) * automation-controller: Credential token disclosure via notification template type-switch replay (CVE-2026-84686) * automation-controller: Privilege escalation via constructed inventory attachment (CVE-2026-84684) * automation-controller: Stored cross-site scripting via ANSI hyperlink sequence in job output (CVE-2026-84683) * automation-controller: Credential-use privilege escalation via organization Galaxy credential attachment (CVE-2026-84680) * automation-controller: Arbitrary environment variable injection via AWX_TASK_ENV setting (CVE-2026-84679) * automation-controller: Server-side request forgery via Thycotic Secret Server credential test (CVE-2026-84644) * automation-controller: Cross-organization credential exposure via Project signature-validation binding (CVE-2026-84643) * automation-controller: Instance-group privilege escalation via Schedule and workflow node attachment (CVE-2026-84638) * automation-controller: Remote code execution via Project scm_url git argument injection (CVE-2026-84502) * automation-controller: Survey password disclosure via validation error message (CVE-2026-84499) * automation-controller: Unauthenticated scheduler-trigger endpoint exposure (regression) (CVE-2026-84486) * automation-controller: Privilege escalation via provisioning-callback host-match bypass (CVE-2026-84474) * automation-controller: Instance-group privilege escalation via Bulk Job Launch permission check (CVE-2026-84470) * automation-controller: GitPython: Arbitrary file read via TagReference.create() (CVE-2026-78679) * automation-controller: awx: Privilege escalation to OpenShift namespace via pod_spec_override injection in container groups (CVE-2026-75884) * automation-controller: Command-line argument injection via ad hoc command limit field (CVE-2026-71465) * automation-controller: Git argument-injection guard bypass via Schedule scm_branch prompt (CVE-2026-71464) * automation-controller: Stack trace disclosure via notification-template Jinja whitelist bypass (CVE-2026-71463) * automation-controller: Filesystem path-existence oracle via CUSTOM_VENV_PATHS validation (CVE-2026-71462) * automation-controller: Cross-tenant job event data exposure via missing RBAC check (CVE-2026-71459) * automation-controller: Cross-tenant resource enumeration via Named-URL 404 response oracle (CVE-2026-71458) * automation-controller: Unrestricted subscription and license information disclosure (CVE-2026-71460) * automation-controller: GitPython: Command Injection via Git option Join the discussion | GCVE Database | 09/23/2026, 21:13:48 UTC Added: 09/24/2026, 06:07:15 UTC |
The RHTAS Operator can be used with OpenShift Container Platform 4.16, 4.17, 4.18, 4.19, 4.20 and 4.21 Join the discussion | GCVE Database | 09/23/2026, 13:58:57 UTC Added: 08/14/2026, 16:37:04 UTC |
Red Hat Developer Hub (RHDH) is Red Hat's enterprise-grade, self-managed, customizable developer portal based on Backstage.io. RHDH is supported on OpenShift and other major Kubernetes clusters (AKS, EKS, GKE). The core features of RHDH include a single pane of glass, a centralized software catalog, self-service via golden path templates, and Tech Docs. RHDH is extensible by plugins. Join the discussion | GCVE Database | 09/21/2026, 07:52:01 UTC Added: 09/22/2026, 02:04:03 UTC |
0 Red Hat Lightspeed in Satellite analyzes system health and configuration by applying predefined rules to a small set of local data, such as installed packages, running services, and configuration settings. Join the discussion | GCVE Database | 09/17/2026, 21:14:20 UTC Added: 05/26/2026, 20:58:36 UTC |
The Migration Toolkit for Containers (MTC) enables you to migrate Kubernetes resources, persistent volume data, and internal container images between OpenShift Container Platform clusters, using the MTC web console or the Kubernetes API. Join the discussion | GCVE Database | 09/17/2026, 14:19:21 UTC Added: 08/05/2026, 15:30:56 UTC |
Red Hat OpenShift Logging 6.2.13 is a cluster-wide logging solution for OpenShift that collects and manages applications, infrastructure, and audit logs. Join the discussion | GCVE Database | 09/16/2026, 17:49:50 UTC Added: 09/09/2026, 13:28:58 UTC |
GCVE Database | 09/03/2026, 18:45:09 UTC Added: 08/06/2026, 18:17:21 UTC | |
The 1.5.2 release of COO. Join the discussion | GCVE Database | 08/31/2026, 07:19:28 UTC Added: 07/15/2026, 12:36:32 UTC |
0 Red Hat build of Podman Desktop is a graphical tool for managing containers using Podman. It allows users to run, manage, and configure containers and container images using a desktop GUI. Security Fix(es): * github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) * ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338) * protobufjs: protobufjs: Denial of Service via crafted JSON descriptors (CVE-2026-45740) * ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray` (CVE-2026-45736) * devalue: devalue: Excessive memory consumption via deserialization of sparse arrays (CVE-2026-42570) * tmp: path Traversal via unsanitized prefix/postfix enables directory escape (CVE-2026-44705) * form-data: form-data: Form field override via CRLF injection (CVE-2026-12143) * webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration (CVE-2026-9595) * ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments (CVE-2026-48779) * extract-zip: github.com/maxogden/extract-zip: extract-zip: Arbitrary file write and information disclosure via symlink validation bypass (CVE-2026-56876) * fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization (CVE-2026-13676) * brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149) * tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874) * tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873) * js-yaml: js-yaml: Denial of Service via crafted YAML documents (CVE-2026-59869) * protobufjs: protobufjs: Denial of Service via crafted .proto schema (CVE-2026-59877) * grpc-js: @grpc/grpc-js: Server crash via malformed HTTP/2 stream initiation (CVE-2026-48068) * linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability (CVE-2026-48801) * dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution (CVE-2026-49978) * brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257) * postcss: PostCSS: Information disclosure and denial of service via crafted CSS input (CVE-2026-45623) * postcss: PostCSS: Information disclosure via crafted sourceMappingURL (CVE-2026-69153) * brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation (CVE-2026-69152) * ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass (CVE-2026-69192) Bug Fix(es) and Enhancement(s): * Release RH Podman Desktop 1.1.2 to RHEL 10.2 Extensions (JIRA:RHEL-238929) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 08/20/2026, 16:08:12 UTC Added: 07/08/2026, 13:21:09 UTC |
0 Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network. Join the discussion | GCVE Database | 08/13/2026, 19:46:27 UTC Added: 07/11/2026, 09:36:49 UTC |
Showing 1 to 10 of 16 results