Zeros312
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1717 | N/A | [NEU] [mittel] Znuny: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1717 | [NEU] [mittel] Znuny: Mehrere Schwachstellen | 2dfa5a44a1ca73f5490f0e03f020d3e0e50b53df54b6fff7dec946c1c520d26b | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1717', 'title': '[NEU] [mittel] Znuny: Mehrere Schwachstellen', 'summary': '[NEU] [mittel] Znuny: Mehrere Schwachstellen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1717'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2037 | N/A | [NEU] [mittel] libxml2: Schwachstelle ermöglicht Denial of Service | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2037 | 2026-06-23T09:06:31Z | Ein entfernter, anonymer Angreifer kann eine Schwachstelle in libxml2 ausnutzen, um einen Denial of Service Angriff durchzuführen. | d40d035d82305b8d2f47849c2f13e8f3859f04e12d90e37591be2084c59b6bdf | 2026-06-23 12:38:20.190255+03:00 | 2026-06-23 12:38:20.190255+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2037', 'title': '[NEU] [mittel] libxml2: Schwachstelle ermöglicht Denial of Service', 'summary': 'Ein entfernter, anonymer Angreifer kann eine Schwachstelle in libxml2 ausnutzen, um einen Denial of Service Angriff durchzuführen.', 'published': '2026-06-23T09:06:31Z', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2037'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2036 | N/A | [NEU] [mittel] dnsmasq: Schwachstelle ermöglicht Denial of Service | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2036 | 2026-06-23T08:46:34Z | Ein entfernter, anonymer Angreifer kann eine Schwachstelle in dnsmasq ausnutzen, um einen Denial of Service Angriff durchzuführen. | c36f7ab91976857a0ad5ce3c1abe05bf20fc4a90ed173d12fba80ad42003519e | 2026-06-23 12:38:20.190255+03:00 | 2026-06-23 12:38:20.190255+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2036', 'title': '[NEU] [mittel] dnsmasq: Schwachstelle ermöglicht Denial of Service', 'summary': 'Ein entfernter, anonymer Angreifer kann eine Schwachstelle in dnsmasq ausnutzen, um einen Denial of Service Angriff durchzuführen.', 'published': '2026-06-23T08:46:34Z', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2036'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2035 | N/A | [NEU] [hoch] MISP: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2035 | 2026-06-23T08:46:34Z | Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in MISP ausnutzen, um beliebigen Code auszuführen, Zugriffskontrollen zu umgehen, Daten zu verändern, vertrauliche Informationen offenzulegen, Benutzersitzungen zu kapern oder einen Denial-of-Service-Zustand zu verursachen. | bac04cf22677993a04fabe51cb9242ffd26fc811076b80d40c5d97846fbd93f6 | 2026-06-23 12:38:20.190255+03:00 | 2026-06-23 12:38:20.190255+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2035', 'title': '[NEU] [hoch] MISP: Mehrere Schwachstellen', 'summary': 'Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in MISP ausnutzen, um beliebigen Code auszuführen, Zugriffskontrollen zu umgehen, Daten zu verändern, vertrauliche Informationen offenzulegen, Benutzersitzungen zu kapern oder einen Denial-of-Service-Zustand zu verursachen.', 'published': '2026-06-23T08:46:34Z', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2035'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1889 | N/A | [UPDATE] [mittel] vllm: Schwachstelle ermöglicht Manipulation von Daten | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1889 | 2026-06-23T08:46:33Z | Ein entfernter, anonymer Angreifer kann eine Schwachstelle in vllm ausnutzen, um Dateien zu manipulieren. | 670928ea4f23831a82ddf461eb0f7d8dea6011aa3bcb640cde1ce08912be7f64 | 2026-06-11 16:16:05.165876+03:00 | 2026-06-23 12:38:20.190255+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1889', 'title': '[UPDATE] [mittel] vllm: Schwachstelle ermöglicht Manipulation von Daten', 'summary': 'Ein entfernter, anonymer Angreifer kann eine Schwachstelle in vllm ausnutzen, um Dateien zu manipulieren.', 'published': '2026-06-23T08:46:33Z', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1889'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2034 | N/A | [NEU] [mittel] OpenCTI: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2034 | 2026-06-23T08:41:31Z | Ein entfernter, anonymer Angreifer kann eine Schwachstelle in OpenCTI ausnutzen, um Sicherheitsvorkehrungen zu umgehen. | 45c98cbba750b45caaebdf2f445676c5d9d212ed037b1d1ed7e57b8a7012ae28 | 2026-06-23 12:38:20.190255+03:00 | 2026-06-23 12:38:20.190255+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2034', 'title': '[NEU] [mittel] OpenCTI: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen', 'summary': 'Ein entfernter, anonymer Angreifer kann eine Schwachstelle in OpenCTI ausnutzen, um Sicherheitsvorkehrungen zu umgehen.', 'published': '2026-06-23T08:41:31Z', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2034'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7100/ | CVE-2025-14930 | Red Hat AI Inference Server Model Optimization Tools: CVSS (Max): 8.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7100/ | 2026-06-26T01:26:46Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7100
Red Hat AI Inference Server Model Optimization Tools 3.3.5 (CUDA)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference Server Model Optimization Tools
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2025-14927 CVE-2026-44431
CVE-2026-4786 CVE-2026-39979 CVE-2026-40164
CVE-2026-35385 CVE-2026-4775 CVE-2026-34982
CVE-2026-10118 CVE-2026-34588 CVE-2026-37555
CVE-2025-14926 CVE-2026-6100 CVE-2025-14928
CVE-2025-14930 CVE-2026-4878
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30078
Comment: CVSS (Max): 8.8 CVE-2026-34588 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS (Max): 0.6% (41st) CVE-2026-4775 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30078 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server Model Optimization Tools 3.3.5 (cuda)
Type/Severity
Security Advisory: Important
Topic
Red Hat AI Inference Server Model Optimization Tools 3.3.5 (CUDA) is now
available.
Description
Red Hat AI Inference Server Model Optimization Tools
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-14926
o CVE-2025-14927
o CVE-2025-14928
o CVE-2025-14930
o CVE-2026-10118
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release of the security bulletin. It may
not be updated when update | 09ffddd2441f77d49d5497e4d63d2f545d3f47a6987975752932eeb8e81db018 | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7100/', 'title': 'Red Hat AI Inference Server Model Optimization Tools: CVSS (Max): 8.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7100 \n Red Hat AI Inference Server Model Optimization Tools 3.3.5 (CUDA) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference Server Model Optimization Tools \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2025-14927 CVE-2026-44431 \n CVE-2026-4786 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-35385 CVE-2026-4775 CVE-2026-34982 \n CVE-2026-10118 CVE-2026-34588 CVE-2026-37555 \n CVE-2025-14926 CVE-2026-6100 CVE-2025-14928 \n CVE-2025-14930 CVE-2026-4878 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30078\n\nComment: CVSS (Max): 8.8 CVE-2026-34588 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\n \n EPSS (Max): 0.6% (41st) CVE-2026-4775 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30078 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server Model Optimization Tools 3.3.5 (cuda)\n\nType/Severity\nSecurity Advisory: Important\n\nTopic\n\nRed Hat AI Inference Server Model Optimization Tools 3.3.5 (CUDA) is now\navailable.\n\nDescription\n\nRed Hat AI Inference Server Model Optimization Tools\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-14926\n o CVE-2025-14927\n o CVE-2025-14928\n o CVE-2025-14930\n o CVE-2026-10118\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release of the security bulletin. It may\nnot be updated when update", 'published': '2026-06-26T01:26:46Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7100/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7100/ | CVE-2026-4878 | Red Hat AI Inference Server Model Optimization Tools: CVSS (Max): 8.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7100/ | 2026-06-26T01:26:46Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7100
Red Hat AI Inference Server Model Optimization Tools 3.3.5 (CUDA)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference Server Model Optimization Tools
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2025-14927 CVE-2026-44431
CVE-2026-4786 CVE-2026-39979 CVE-2026-40164
CVE-2026-35385 CVE-2026-4775 CVE-2026-34982
CVE-2026-10118 CVE-2026-34588 CVE-2026-37555
CVE-2025-14926 CVE-2026-6100 CVE-2025-14928
CVE-2025-14930 CVE-2026-4878
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30078
Comment: CVSS (Max): 8.8 CVE-2026-34588 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS (Max): 0.6% (41st) CVE-2026-4775 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30078 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server Model Optimization Tools 3.3.5 (cuda)
Type/Severity
Security Advisory: Important
Topic
Red Hat AI Inference Server Model Optimization Tools 3.3.5 (CUDA) is now
available.
Description
Red Hat AI Inference Server Model Optimization Tools
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-14926
o CVE-2025-14927
o CVE-2025-14928
o CVE-2025-14930
o CVE-2026-10118
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release of the security bulletin. It may
not be updated when update | dfeba6c70456b47dc419b5f11c701fd209bef80b6d9e6fa6d2af9b90d97f34dc | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7100/', 'title': 'Red Hat AI Inference Server Model Optimization Tools: CVSS (Max): 8.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7100 \n Red Hat AI Inference Server Model Optimization Tools 3.3.5 (CUDA) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference Server Model Optimization Tools \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2025-14927 CVE-2026-44431 \n CVE-2026-4786 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-35385 CVE-2026-4775 CVE-2026-34982 \n CVE-2026-10118 CVE-2026-34588 CVE-2026-37555 \n CVE-2025-14926 CVE-2026-6100 CVE-2025-14928 \n CVE-2025-14930 CVE-2026-4878 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30078\n\nComment: CVSS (Max): 8.8 CVE-2026-34588 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\n \n EPSS (Max): 0.6% (41st) CVE-2026-4775 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30078 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server Model Optimization Tools 3.3.5 (cuda)\n\nType/Severity\nSecurity Advisory: Important\n\nTopic\n\nRed Hat AI Inference Server Model Optimization Tools 3.3.5 (CUDA) is now\navailable.\n\nDescription\n\nRed Hat AI Inference Server Model Optimization Tools\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-14926\n o CVE-2025-14927\n o CVE-2025-14928\n o CVE-2025-14930\n o CVE-2026-10118\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release of the security bulletin. It may\nnot be updated when update", 'published': '2026-06-26T01:26:46Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7100/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7099/ | CVE-2026-5704 | tar: CVSS (Max): 5.5 | http://portal.auscert.org.au/bulletins/ESB-2026.7099/ | 2026-06-26T01:26:27Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7099
USN-8477-1: tar vulnerability
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: tar
Publisher: Ubuntu
Operating System: Ubuntu
Resolution: Patch/Upgrade
CVE Names: CVE-2026-5704
Original Bulletin:
https://ubuntu.com/security/notices/USN-8477-1
Comment: CVSS (Max): 5.5 CVE-2026-5704 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
CVSS Source: NIST
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS (Max): 0.4% (34th) CVE-2026-5704 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
USN-8477-1: tar vulnerability
Publication date
25 June 2026
Overview
tar could be made to overwrite files if it opened a specially crafted archive.
Releases
26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS 14.04 LTS
---------------------------------------------------------------------------------
Open side navigation
Packages
o tar - GNU tar archive utility
Details
It was discovered that tar incorrectly handled certain crafted archive files.
An attacker could possibly use this to inject hidden files with
attacker-controlled content, bypassing pre-extraction inspection mechanisms.
Update instructions
The problem can be corrected by updating your system to the following package
versions:
Ubuntu Package Version
Release
26.04 LTS tar - 1.35+dfsg-4ubuntu0.1
resolute
24.04 LTS tar - 1.35+dfsg-3ubuntu0.1
noble
22.04 LTS tar - 1.34+dfsg-1ubuntu0.1.22.04.3
jammy
20.04 LTS tar - 1.30+dfsg-7ubuntu0.20.04.4+esm1 Ubuntu Pro Fix available
focal with Ubuntu Pro .
18.04 LTS tar - 1.29b-2ubuntu0.4+esm2 Ubuntu Pro Fix available with Ubuntu
bionic Pro .
16.04 LTS tar - 1.28-2.1ubuntu0.2+esm4 Ubuntu Pro Fix available with Ubuntu
xenial Pro via Legacy Support add-on.
14.04 LTS tar - 1.27.1-1ubuntu0.1+esm5 Ubuntu Pro Fix available with Ubuntu
trusty Pro via Legacy Support add-on.
---------------------------------------------------------------------------------
References
o CVE-2026-5704
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no respons | 99525c2a91755548c7c51beb17a068ed6acf8e69e485d491ba8f704aa012f443 | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7099/', 'title': 'tar: CVSS (Max): 5.5', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7099 \n USN-8477-1: tar vulnerability \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: tar \nPublisher: Ubuntu \nOperating System: Ubuntu \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-5704 \n\nOriginal Bulletin:\n https://ubuntu.com/security/notices/USN-8477-1\n\nComment: CVSS (Max): 5.5 CVE-2026-5704 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)\n CVSS Source: NIST \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N\n \n EPSS (Max): 0.4% (34th) CVE-2026-5704 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nUSN-8477-1: tar vulnerability\n\nPublication date\n\n25 June 2026\n\nOverview\n\ntar could be made to overwrite files if it opened a specially crafted archive.\n\nReleases\n\n26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS 14.04 LTS\n---------------------------------------------------------------------------------\nOpen side navigation\n\nPackages\n\n o tar - GNU tar archive utility\n\nDetails\n\nIt was discovered that tar incorrectly handled certain crafted archive files.\nAn attacker could possibly use this to inject hidden files with\nattacker-controlled content, bypassing pre-extraction inspection mechanisms.\n\nUpdate instructions\n\nThe problem can be corrected by updating your system to the following package\nversions:\n\n Ubuntu Package Version\n Release\n 26.04 LTS tar - 1.35+dfsg-4ubuntu0.1\n resolute\n 24.04 LTS tar - 1.35+dfsg-3ubuntu0.1\n noble\n 22.04 LTS tar - 1.34+dfsg-1ubuntu0.1.22.04.3\n jammy\n 20.04 LTS tar - 1.30+dfsg-7ubuntu0.20.04.4+esm1 Ubuntu Pro Fix available\n focal with Ubuntu Pro .\n 18.04 LTS tar - 1.29b-2ubuntu0.4+esm2 Ubuntu Pro Fix available with Ubuntu\n bionic Pro .\n 16.04 LTS tar - 1.28-2.1ubuntu0.2+esm4 Ubuntu Pro Fix available with Ubuntu\n xenial Pro via Legacy Support add-on.\n 14.04 LTS tar - 1.27.1-1ubuntu0.1+esm5 Ubuntu Pro Fix available with Ubuntu\n trusty Pro via Legacy Support add-on.\n\n---------------------------------------------------------------------------------\n\nReferences\n\n o CVE-2026-5704\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no respons", 'published': '2026-06-26T01:26:27Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7099/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7070/ | CVE-2026-10118 | poppler: CVSS (Max): 7.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7070/ | 2026-06-26T01:11:53Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7070
poppler security update
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: poppler
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-10118
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30044
Comment: CVSS (Max): 7.8 CVE-2026-10118 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS (Max): 0.3% (16th) CVE-2026-10118 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30044 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Poppler security update
Type/Severity
Security Advisory: Important
Topic
An update for poppler is now available for Red Hat Enterprise Linux 7 Extended
Lifecycle Support.
Red Hat Product Security has rated this update as having a security impact of
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives
a detailed severity rating, is available for each vulnerability from the CVE
link(s) in the References section.
Description
Poppler is a Portable Document Format (PDF) rendering library, used by
applications such as Evince.
Security Fix(es):
o poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill
leads to heap buffer overflow via unchecked dimension multiplication
(CVE-2026-10118)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.
Solution
For details on how to apply this update, which includes the changes described
in this advisory, refer to:
https://access.redhat.com/articles/11258
Affected Products
o Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
o Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z
Systems) 7 s390x
o Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM
Power, big endian 7 ppc64
o Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM
Power, little endian 7 ppc64le
Fixes
o BZ - 2460428 - CVE-2026-10118 poppler: Integer overflow in Poppler
SplashOutputDev::tilingPatternFill leads to heap buffer overflow via
unchecked dimension multiplication
CVEs
o CVE-2026-10118
References
o https://access.redhat.com/security/updates/classification/#important
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as | 1a7c6b30fa551449a081bb2ef2b05b4b71dbfc8174a5b1ba538f89a16731ecab | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7070/', 'title': 'poppler: CVSS (Max): 7.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7070 \n poppler security update \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: poppler \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-10118 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30044\n\nComment: CVSS (Max): 7.8 CVE-2026-10118 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\n \n EPSS (Max): 0.3% (16th) CVE-2026-10118 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30044 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nPoppler security update\n\nType/Severity\nSecurity Advisory: Important\n\nTopic\n\nAn update for poppler is now available for Red Hat Enterprise Linux 7 Extended\nLifecycle Support.\n\nRed Hat Product Security has rated this update as having a security impact of\nImportant. A Common Vulnerability Scoring System (CVSS) base score, which gives\na detailed severity rating, is available for each vulnerability from the CVE\nlink(s) in the References section.\n\nDescription\n\nPoppler is a Portable Document Format (PDF) rendering library, used by\napplications such as Evince.\n\nSecurity Fix(es):\n\n o poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill\n leads to heap buffer overflow via unchecked dimension multiplication\n (CVE-2026-10118)\n\nFor more details about the security issue(s), including the impact, a CVSS\nscore, acknowledgments, and other related information, refer to the CVE page(s)\nlisted in the References section.\n\nSolution\n\nFor details on how to apply this update, which includes the changes described\nin this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAffected Products\n\n o Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64\n o Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z\n Systems) 7 s390x\n o Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM\n Power, big endian 7 ppc64\n o Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM\n Power, little endian 7 ppc64le\n\nFixes\n\n o BZ - 2460428 - CVE-2026-10118 poppler: Integer overflow in Poppler\n SplashOutputDev::tilingPatternFill leads to heap buffer overflow via\n unchecked dimension multiplication\n\nCVEs\n\n o CVE-2026-10118\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/#important\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as ", 'published': '2026-06-26T01:11:53Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7070/'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2032 | N/A | [NEU] [mittel] Google Cloud Logging und Cloud Console App Engine: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2032 | 2026-06-23T08:31:32Z | Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Google Cloud Logging und Cloud Console App Engine ausnutzen, um Informationen offenzulegen. | d196eea55ad8493d172cfbc47bebb8daacbe911c01d3d409b5f88e34c5a6a5d2 | 2026-06-23 12:38:20.190255+03:00 | 2026-06-23 12:38:20.190255+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2032', 'title': '[NEU] [mittel] Google Cloud Logging und Cloud Console App Engine: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen', 'summary': 'Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Google Cloud Logging und Cloud Console App Engine ausnutzen, um Informationen offenzulegen.', 'published': '2026-06-23T08:31:32Z', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2032'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1715 | N/A | [NEU] [hoch] Fleet: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1715 | [NEU] [hoch] Fleet: Mehrere Schwachstellen | d84f48f69e73e955f985a415351a8d6fb4f41ff70d9081ed511019e654c40d60 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1715', 'title': '[NEU] [hoch] Fleet: Mehrere Schwachstellen', 'summary': '[NEU] [hoch] Fleet: Mehrere Schwachstellen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1715'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0568 | N/A | [UPDATE] [kritisch] Flowise: Schwachstelle ermöglicht Codeausführung | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0568 | 2026-06-26T07:26:40Z | Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Flowise ausnutzen, um beliebigen Programmcode auszuführen. | 36e789169d418ba92b8307e072da1d329563536e7a845f184a1422f86ce7bb48 | 2026-06-26 12:34:22.977075+03:00 | 2026-06-26 12:34:22.977075+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0568', 'title': '[UPDATE] [kritisch] Flowise: Schwachstelle ermöglicht Codeausführung', 'summary': 'Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Flowise ausnutzen, um beliebigen Programmcode auszuführen.', 'published': '2026-06-26T07:26:40Z', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0568'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7215/ | CVE-2025-10911 | Subscription management tool: CVSS (Max): 8.1 | http://portal.auscert.org.au/bulletins/ESB-2026.7215/ | 2026-06-30T01:12:20Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7215
A Subscription Management tool for finding and reporting Red Hat product
usage
30 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Subscription management tool
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2025-71319
CVE-2026-9256 CVE-2026-31790 CVE-2025-13151
CVE-2026-33416 CVE-2026-33636 CVE-2025-5278
CVE-2024-34459 CVE-2026-41411 CVE-2025-10911
CVE-2026-8643
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:33313
Comment: CVSS (Max): 8.1 CVE-2026-9256 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 2.6% (83rd) CVE-2026-9256 2026-06-29
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:33313 - Security Advisory
Issued: 2026-06-29
Updated: 2026-06-29
Synopsis
Subscription management tool for finding and reporting red hat product usage
Type/Severity
Security Advisory: Important
Topic
A Subscription Management tool for finding and reporting Red Hat product usage
Description
Red Hat Discovery, also known as Discovery, is an inspection and reporting tool
that finds,
identifies, and reports environment data, or facts, such as the number of
physical and virtual
systems on a network, their operating systems, and relevant configuration data
stored within
them. Discovery also identifies and reports more detailed facts for some
versions of key
Red Hat packages and products that it finds in the network.
Solution
The containers required to run Discovery can be installed through
discovery-installer
RPM. See the official documentation for more details.
Affected Products
o Red Hat Discovery
Fixes
(none)
CVEs
o CVE-2024-34459
o CVE-2025-10911
o CVE-2025-13151
o CVE-2025-5278
o CVE-2025-71319
o CVE-2026-31790
o CVE-2026-33416
o CVE-2026-33636
o CVE-2026-41411
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-8643
o CVE-2026-9256
References
o https://access.redhat.com/security/updates/classification/
o https://docs.redhat.com/en/documentation/subscription_central/1-latest/#
Discovery
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follo | 6f61419489c921eb2f02d8992e6135503dbcded42d009f0c1ff2b83cc50605b5 | 2026-06-30 06:47:27.315299+03:00 | 2026-06-30 06:47:27.315299+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7215/', 'title': 'Subscription management tool: CVSS (Max): 8.1', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7215 \n A Subscription Management tool for finding and reporting Red Hat product \n usage \n 30 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Subscription management tool \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2025-71319 \n CVE-2026-9256 CVE-2026-31790 CVE-2025-13151 \n CVE-2026-33416 CVE-2026-33636 CVE-2025-5278 \n CVE-2024-34459 CVE-2026-41411 CVE-2025-10911 \n CVE-2026-8643 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:33313\n\nComment: CVSS (Max): 8.1 CVE-2026-9256 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 2.6% (83rd) CVE-2026-9256 2026-06-29 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:33313 - Security Advisory\n\nIssued: 2026-06-29\nUpdated: 2026-06-29\n\nSynopsis\nSubscription management tool for finding and reporting red hat product usage\n\nType/Severity\nSecurity Advisory: Important\n\nTopic\n\nA Subscription Management tool for finding and reporting Red Hat product usage\n\nDescription\n\nRed Hat Discovery, also known as Discovery, is an inspection and reporting tool\nthat finds,\nidentifies, and reports environment data, or facts, such as the number of\nphysical and virtual\nsystems on a network, their operating systems, and relevant configuration data\nstored within\nthem. Discovery also identifies and reports more detailed facts for some\nversions of key\nRed Hat packages and products that it finds in the network.\n\nSolution\n\nThe containers required to run Discovery can be installed through\ndiscovery-installer\nRPM. See the official documentation for more details.\n\nAffected Products\n\n o Red Hat Discovery\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2024-34459\n o CVE-2025-10911\n o CVE-2025-13151\n o CVE-2025-5278\n o CVE-2025-71319\n o CVE-2026-31790\n o CVE-2026-33416\n o CVE-2026-33636\n o CVE-2026-41411\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-8643\n o CVE-2026-9256\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://docs.redhat.com/en/documentation/subscription_central/1-latest/#\n Discovery\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follo", 'published': '2026-06-30T01:12:20Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7215/'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1712 | N/A | [NEU] [mittel] Veeam Backup & Replication: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1712 | [NEU] [mittel] Veeam Backup & Replication: Mehrere Schwachstellen | c52b4ce2d0b60cfc78dccab385b14a4bc74b27c280c85c07e3984af7dd355a14 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1712', 'title': '[NEU] [mittel] Veeam Backup & Replication: Mehrere Schwachstellen', 'summary': '[NEU] [mittel] Veeam Backup & Replication: Mehrere Schwachstellen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1712'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0861 | N/A | [UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0861 | [UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen | 75528f587201f70e5deee7ebcabcc3b9f995798e19fa5bb942d5629c0bf11a0e | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0861', 'title': '[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen', 'summary': '[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0861'} | |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7215/ | CVE-2026-8643 | Subscription management tool: CVSS (Max): 8.1 | http://portal.auscert.org.au/bulletins/ESB-2026.7215/ | 2026-06-30T01:12:20Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7215
A Subscription Management tool for finding and reporting Red Hat product
usage
30 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Subscription management tool
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2025-71319
CVE-2026-9256 CVE-2026-31790 CVE-2025-13151
CVE-2026-33416 CVE-2026-33636 CVE-2025-5278
CVE-2024-34459 CVE-2026-41411 CVE-2025-10911
CVE-2026-8643
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:33313
Comment: CVSS (Max): 8.1 CVE-2026-9256 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 2.6% (83rd) CVE-2026-9256 2026-06-29
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:33313 - Security Advisory
Issued: 2026-06-29
Updated: 2026-06-29
Synopsis
Subscription management tool for finding and reporting red hat product usage
Type/Severity
Security Advisory: Important
Topic
A Subscription Management tool for finding and reporting Red Hat product usage
Description
Red Hat Discovery, also known as Discovery, is an inspection and reporting tool
that finds,
identifies, and reports environment data, or facts, such as the number of
physical and virtual
systems on a network, their operating systems, and relevant configuration data
stored within
them. Discovery also identifies and reports more detailed facts for some
versions of key
Red Hat packages and products that it finds in the network.
Solution
The containers required to run Discovery can be installed through
discovery-installer
RPM. See the official documentation for more details.
Affected Products
o Red Hat Discovery
Fixes
(none)
CVEs
o CVE-2024-34459
o CVE-2025-10911
o CVE-2025-13151
o CVE-2025-5278
o CVE-2025-71319
o CVE-2026-31790
o CVE-2026-33416
o CVE-2026-33636
o CVE-2026-41411
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-8643
o CVE-2026-9256
References
o https://access.redhat.com/security/updates/classification/
o https://docs.redhat.com/en/documentation/subscription_central/1-latest/#
Discovery
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follo | 0498841e1d27b143e9985e0bd0e699f894361cf5804c0a584e57c200f61822f3 | 2026-06-30 06:47:27.315299+03:00 | 2026-06-30 06:47:27.315299+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7215/', 'title': 'Subscription management tool: CVSS (Max): 8.1', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7215 \n A Subscription Management tool for finding and reporting Red Hat product \n usage \n 30 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Subscription management tool \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2025-71319 \n CVE-2026-9256 CVE-2026-31790 CVE-2025-13151 \n CVE-2026-33416 CVE-2026-33636 CVE-2025-5278 \n CVE-2024-34459 CVE-2026-41411 CVE-2025-10911 \n CVE-2026-8643 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:33313\n\nComment: CVSS (Max): 8.1 CVE-2026-9256 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 2.6% (83rd) CVE-2026-9256 2026-06-29 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:33313 - Security Advisory\n\nIssued: 2026-06-29\nUpdated: 2026-06-29\n\nSynopsis\nSubscription management tool for finding and reporting red hat product usage\n\nType/Severity\nSecurity Advisory: Important\n\nTopic\n\nA Subscription Management tool for finding and reporting Red Hat product usage\n\nDescription\n\nRed Hat Discovery, also known as Discovery, is an inspection and reporting tool\nthat finds,\nidentifies, and reports environment data, or facts, such as the number of\nphysical and virtual\nsystems on a network, their operating systems, and relevant configuration data\nstored within\nthem. Discovery also identifies and reports more detailed facts for some\nversions of key\nRed Hat packages and products that it finds in the network.\n\nSolution\n\nThe containers required to run Discovery can be installed through\ndiscovery-installer\nRPM. See the official documentation for more details.\n\nAffected Products\n\n o Red Hat Discovery\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2024-34459\n o CVE-2025-10911\n o CVE-2025-13151\n o CVE-2025-5278\n o CVE-2025-71319\n o CVE-2026-31790\n o CVE-2026-33416\n o CVE-2026-33636\n o CVE-2026-41411\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-8643\n o CVE-2026-9256\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://docs.redhat.com/en/documentation/subscription_central/1-latest/#\n Discovery\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follo", 'published': '2026-06-30T01:12:20Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7215/'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0837 | N/A | [UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0837 | [UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service | cc981f055ee94cd633882aa31737a5f726c19c3fc278843f4291a614b3242b1d | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0837', 'title': '[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service', 'summary': '[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0837'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0683 | N/A | [UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0683 | [UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen | 1b421e7751be9f88b535ac454e25c4fe0593becda231e2a0c2596625bc42fa7e | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0683', 'title': '[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen', 'summary': '[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0683'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1710 | N/A | [NEU] [hoch] ESRI ArcGIS: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1710 | [NEU] [hoch] ESRI ArcGIS: Mehrere Schwachstellen | b64a14c8438fee1f49d5561de28afe4c48aaaab2d8c79c940bca14f4d7e05b2c | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1710', 'title': '[NEU] [hoch] ESRI ArcGIS: Mehrere Schwachstellen', 'summary': '[NEU] [hoch] ESRI ArcGIS: Mehrere Schwachstellen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1710'} | |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7158/ | CVE-2026-40355 | IBM MQ Agent: CVSS (Max): None | http://portal.auscert.org.au/bulletins/ESB-2026.7158/ | 2026-06-30T00:13:04Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7158
Multiple vulnerabilities in IBM MQ Agent images
30 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: IBM MQ Agent
Publisher: IBM
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-34181
CVE-2026-34183 CVE-2026-42764 CVE-2026-42768
CVE-2026-42769 CVE-2026-42770 CVE-2026-45445
CVE-2026-45446 CVE-2024-3651 CVE-2026-40356
CVE-2026-40355 CVE-2025-14087 CVE-2025-14512
CVE-2026-4878 CVE-2026-2100 CVE-2026-45134
CVE-2026-44681 CVE-2026-45409 CVE-2026-44843
CVE-2026-48522 CVE-2026-48523 CVE-2026-48524
CVE-2026-48525 CVE-2026-28390 CVE-2026-29111
CVE-2025-15281 CVE-2025-4598 CVE-2026-4437
CVE-2026-4438 CVE-2026-34180 CVE-2026-34182
CVE-2026-42767 CVE-2026-45447 CVE-2026-7383
CVE-2026-9076 CVE-2026-48710
Original Bulletin:
https://www.ibm.com/support/pages/node/7278328
Comment: CVSS (Max): None available when published
EPSS (Max): None available when published
- --------------------------BEGIN INCLUDED TEXT--------------------
IBM Support
Document Information
Document number : 7278328
Modified date : More support for: IBM MQ Agent
Product : IBM MQ Agent
Component : -
Software version : IBM MQ Agent v2.0.0
Operating system(s): RedHat OpenShift
Security Bulletin
Summary
Multiple vulnerabilities were addressed in IBM MQ Agent images
Vulnerability Details
CVEID: CVE-2026-45134
DESCRIPTION: LangSmith Client SDKs provide SDK's for interacting with the
LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the
LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in
Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt
manifests from the LangSmith Hub. These manifests may contain serialized
LangChain objects and model configuration that affect runtime behavior. When
pulling a public prompt by owner/name identifier, the manifest content is
controlled by an external party, but prior versions of the SDK did not
distinguish this from pulling a prompt within the caller's own organization.
This vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.
CWE: CWE-502: Deserialization of Untrusted Data
CVSS Source: security-advisories@github.com
CVSS Base score: 7.1
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)
CVEID: CVE-2026-4438
DESCRIPTION: Calling gethostbyaddr or gethostbyaddr_r with a configured
nsswitch.conf that specifies the library's DNS backend in the GNU C library
version 2.34 to version 2.43 could result in an invalid DNS hostname being
returned to the caller in violation of the DNS specification.
CWE: CWE-20: Improper Input Validation
CVSS Source: CISA ADP
CVSS Base score: 5.4
CVSS Vector: (CVSS:3.1/AV:A/AC:L/P | 08920da2f835868ee124c124b6b64f633a7194b5a03a1c06920e8798f80fc75e | 2026-06-30 06:47:27.315299+03:00 | 2026-06-30 06:47:27.315299+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7158/', 'title': 'IBM MQ Agent: CVSS (Max): None', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7158 \n Multiple vulnerabilities in IBM MQ Agent images \n 30 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: IBM MQ Agent \nPublisher: IBM \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-34181 \n CVE-2026-34183 CVE-2026-42764 CVE-2026-42768 \n CVE-2026-42769 CVE-2026-42770 CVE-2026-45445 \n CVE-2026-45446 CVE-2024-3651 CVE-2026-40356 \n CVE-2026-40355 CVE-2025-14087 CVE-2025-14512 \n CVE-2026-4878 CVE-2026-2100 CVE-2026-45134 \n CVE-2026-44681 CVE-2026-45409 CVE-2026-44843 \n CVE-2026-48522 CVE-2026-48523 CVE-2026-48524 \n CVE-2026-48525 CVE-2026-28390 CVE-2026-29111 \n CVE-2025-15281 CVE-2025-4598 CVE-2026-4437 \n CVE-2026-4438 CVE-2026-34180 CVE-2026-34182 \n CVE-2026-42767 CVE-2026-45447 CVE-2026-7383 \n CVE-2026-9076 CVE-2026-48710 \n\nOriginal Bulletin:\n https://www.ibm.com/support/pages/node/7278328\n\nComment: CVSS (Max): None available when published \n \n EPSS (Max): None available when published \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nIBM Support\n\nDocument Information\n\nDocument number : 7278328\nModified date : More support for: IBM MQ Agent\nProduct : IBM MQ Agent\nComponent : -\nSoftware version : IBM MQ Agent v2.0.0\nOperating system(s): RedHat OpenShift\n\nSecurity Bulletin\n\n\nSummary\n\nMultiple vulnerabilities were addressed in IBM MQ Agent images\n\nVulnerability Details\n\nCVEID: CVE-2026-45134\nDESCRIPTION: LangSmith Client SDKs provide SDK's for interacting with the\nLangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the\nLangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in\nPython, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt\nmanifests from the LangSmith Hub. These manifests may contain serialized\nLangChain objects and model configuration that affect runtime behavior. When\npulling a public prompt by owner/name identifier, the manifest content is\ncontrolled by an external party, but prior versions of the SDK did not\ndistinguish this from pulling a prompt within the caller's own organization.\nThis vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.\nCWE: CWE-502: Deserialization of Untrusted Data\nCVSS Source: security-advisories@github.com\nCVSS Base score: 7.1\nCVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)\n\nCVEID: CVE-2026-4438\nDESCRIPTION: Calling gethostbyaddr or gethostbyaddr_r with a configured\nnsswitch.conf that specifies the library's DNS backend in the GNU C library\nversion 2.34 to version 2.43 could result in an invalid DNS hostname being\nreturned to the caller in violation of the DNS specification.\nCWE: CWE-20: Improper Input Validation\nCVSS Source: CISA ADP\nCVSS Base score: 5.4\nCVSS Vector: (CVSS:3.1/AV:A/AC:L/P", 'published': '2026-06-30T00:13:04Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7158/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7158/ | CVE-2025-14087 | IBM MQ Agent: CVSS (Max): None | http://portal.auscert.org.au/bulletins/ESB-2026.7158/ | 2026-06-30T00:13:04Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7158
Multiple vulnerabilities in IBM MQ Agent images
30 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: IBM MQ Agent
Publisher: IBM
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-34181
CVE-2026-34183 CVE-2026-42764 CVE-2026-42768
CVE-2026-42769 CVE-2026-42770 CVE-2026-45445
CVE-2026-45446 CVE-2024-3651 CVE-2026-40356
CVE-2026-40355 CVE-2025-14087 CVE-2025-14512
CVE-2026-4878 CVE-2026-2100 CVE-2026-45134
CVE-2026-44681 CVE-2026-45409 CVE-2026-44843
CVE-2026-48522 CVE-2026-48523 CVE-2026-48524
CVE-2026-48525 CVE-2026-28390 CVE-2026-29111
CVE-2025-15281 CVE-2025-4598 CVE-2026-4437
CVE-2026-4438 CVE-2026-34180 CVE-2026-34182
CVE-2026-42767 CVE-2026-45447 CVE-2026-7383
CVE-2026-9076 CVE-2026-48710
Original Bulletin:
https://www.ibm.com/support/pages/node/7278328
Comment: CVSS (Max): None available when published
EPSS (Max): None available when published
- --------------------------BEGIN INCLUDED TEXT--------------------
IBM Support
Document Information
Document number : 7278328
Modified date : More support for: IBM MQ Agent
Product : IBM MQ Agent
Component : -
Software version : IBM MQ Agent v2.0.0
Operating system(s): RedHat OpenShift
Security Bulletin
Summary
Multiple vulnerabilities were addressed in IBM MQ Agent images
Vulnerability Details
CVEID: CVE-2026-45134
DESCRIPTION: LangSmith Client SDKs provide SDK's for interacting with the
LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the
LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in
Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt
manifests from the LangSmith Hub. These manifests may contain serialized
LangChain objects and model configuration that affect runtime behavior. When
pulling a public prompt by owner/name identifier, the manifest content is
controlled by an external party, but prior versions of the SDK did not
distinguish this from pulling a prompt within the caller's own organization.
This vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.
CWE: CWE-502: Deserialization of Untrusted Data
CVSS Source: security-advisories@github.com
CVSS Base score: 7.1
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)
CVEID: CVE-2026-4438
DESCRIPTION: Calling gethostbyaddr or gethostbyaddr_r with a configured
nsswitch.conf that specifies the library's DNS backend in the GNU C library
version 2.34 to version 2.43 could result in an invalid DNS hostname being
returned to the caller in violation of the DNS specification.
CWE: CWE-20: Improper Input Validation
CVSS Source: CISA ADP
CVSS Base score: 5.4
CVSS Vector: (CVSS:3.1/AV:A/AC:L/P | 7467cb88bf1f489ca1411cf4c117da49bd1032c912627e97aadbb3a25b71fe3a | 2026-06-30 06:47:27.315299+03:00 | 2026-06-30 06:47:27.315299+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7158/', 'title': 'IBM MQ Agent: CVSS (Max): None', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7158 \n Multiple vulnerabilities in IBM MQ Agent images \n 30 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: IBM MQ Agent \nPublisher: IBM \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-34181 \n CVE-2026-34183 CVE-2026-42764 CVE-2026-42768 \n CVE-2026-42769 CVE-2026-42770 CVE-2026-45445 \n CVE-2026-45446 CVE-2024-3651 CVE-2026-40356 \n CVE-2026-40355 CVE-2025-14087 CVE-2025-14512 \n CVE-2026-4878 CVE-2026-2100 CVE-2026-45134 \n CVE-2026-44681 CVE-2026-45409 CVE-2026-44843 \n CVE-2026-48522 CVE-2026-48523 CVE-2026-48524 \n CVE-2026-48525 CVE-2026-28390 CVE-2026-29111 \n CVE-2025-15281 CVE-2025-4598 CVE-2026-4437 \n CVE-2026-4438 CVE-2026-34180 CVE-2026-34182 \n CVE-2026-42767 CVE-2026-45447 CVE-2026-7383 \n CVE-2026-9076 CVE-2026-48710 \n\nOriginal Bulletin:\n https://www.ibm.com/support/pages/node/7278328\n\nComment: CVSS (Max): None available when published \n \n EPSS (Max): None available when published \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nIBM Support\n\nDocument Information\n\nDocument number : 7278328\nModified date : More support for: IBM MQ Agent\nProduct : IBM MQ Agent\nComponent : -\nSoftware version : IBM MQ Agent v2.0.0\nOperating system(s): RedHat OpenShift\n\nSecurity Bulletin\n\n\nSummary\n\nMultiple vulnerabilities were addressed in IBM MQ Agent images\n\nVulnerability Details\n\nCVEID: CVE-2026-45134\nDESCRIPTION: LangSmith Client SDKs provide SDK's for interacting with the\nLangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the\nLangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in\nPython, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt\nmanifests from the LangSmith Hub. These manifests may contain serialized\nLangChain objects and model configuration that affect runtime behavior. When\npulling a public prompt by owner/name identifier, the manifest content is\ncontrolled by an external party, but prior versions of the SDK did not\ndistinguish this from pulling a prompt within the caller's own organization.\nThis vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.\nCWE: CWE-502: Deserialization of Untrusted Data\nCVSS Source: security-advisories@github.com\nCVSS Base score: 7.1\nCVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)\n\nCVEID: CVE-2026-4438\nDESCRIPTION: Calling gethostbyaddr or gethostbyaddr_r with a configured\nnsswitch.conf that specifies the library's DNS backend in the GNU C library\nversion 2.34 to version 2.43 could result in an invalid DNS hostname being\nreturned to the caller in violation of the DNS specification.\nCWE: CWE-20: Improper Input Validation\nCVSS Source: CISA ADP\nCVSS Base score: 5.4\nCVSS Vector: (CVSS:3.1/AV:A/AC:L/P", 'published': '2026-06-30T00:13:04Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7158/'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3251 | N/A | [UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3251 | [UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service | f1807a526a2e35d8cb644364284e6daf6923ef6c46e22650bcf5c2c9366a8fd6 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3251', 'title': '[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service', 'summary': '[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3251'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3050 | N/A | [UPDATE] [niedrig] Linux Kernel: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3050 | [UPDATE] [niedrig] Linux Kernel: Mehrere Schwachstellen | 9fdb2e739c6b48be66b4a1a19147749549eb5df13b7fee7cc99d50cade734672 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3050', 'title': '[UPDATE] [niedrig] Linux Kernel: Mehrere Schwachstellen', 'summary': '[UPDATE] [niedrig] Linux Kernel: Mehrere Schwachstellen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3050'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1607 | N/A | [UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1607 | [UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen | f1e977b55bb56b5541d8e5a46946530facd1f942e29ee6c0ddf7acae8b7aa6c5 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1607', 'title': '[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen', 'summary': '[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1607'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1259 | N/A | [UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service und unspezifischen Angriff | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1259 | [UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service und unspezifischen Angriff | 17165ab1ad189f3139c41ab64c60264eb66f6905010d9379c4ff5d2ce51091d3 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1259', 'title': '[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service und unspezifischen Angriff', 'summary': '[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service und unspezifischen Angriff', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1259'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0749 | N/A | [UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0749 | [UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen | 71495aaf27150b960d27bd1722d8ff709715f24eff39003d3fca7dda4c1bc0fe | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0749', 'title': '[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen', 'summary': '[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0749'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1869 | N/A | [UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1869 | [UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen | 39c04b75cfff6a506ec7f48c75070327cfec9eaf3db2c39577799999ea4f8828 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1869', 'title': '[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen', 'summary': '[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1869'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0435 | N/A | [UPDATE] [mittel] X.Org X11: Mehrere Schwachstellen ermöglichen nicht näher spezifizierte Auswirkungen, möglicherweise Codeausführung | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0435 | 2026-06-26T07:26:39Z | Ein lokaler Angreifer kann mehrere Schwachstellen in X.Org X11 ausnutzen, um nicht spezifizierte Effekte zu verursachen, was möglicherweise zur Ausführung von beliebigem Code führt. | 0327aa858d191d0d8d36c47ada4b1e91a70118f6ec4b5d6d6fd8dd4dd73dd2a9 | 2026-06-18 12:45:43.397785+03:00 | 2026-06-26 12:34:22.977075+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0435', 'title': '[UPDATE] [mittel] X.Org X11: Mehrere Schwachstellen ermöglichen nicht näher spezifizierte Auswirkungen, möglicherweise Codeausführung', 'summary': 'Ein lokaler Angreifer kann mehrere Schwachstellen in X.Org X11 ausnutzen, um nicht spezifizierte Effekte zu verursachen, was möglicherweise zur Ausführung von beliebigem Code führt.', 'published': '2026-06-26T07:26:39Z', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0435'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7213/ | CVE-2026-31411 | kernel: CVSS (Max): 7.1 | http://portal.auscert.org.au/bulletins/ESB-2026.7213/ | 2026-06-30T01:09:53Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7213
kernel security, bug fix, and enhancement update
30 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: kernel
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-31411 CVE-2026-43198
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:33285
Comment: CVSS (Max): 7.1 CVE-2026-31411 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
EPSS (Max): 0.4% (28th) CVE-2026-43198 2026-06-29
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:33285 - Security Advisory
Issued: 2026-06-29
Updated: 2026-06-29
Synopsis
Kernel security, bug fix, and enhancement update
Type/Severity
Security Advisory: Important
Topic
An update for kernel is now available for Red Hat Enterprise Linux 9.
Red Hat Product Security has rated this update as having a security impact of
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives
a detailed severity rating, is available for each vulnerability from the CVE
link(s) in the References section.
Description
The kernel packages contain the Linux kernel, the core of any Linux operating
system.
Security Fix(es):
o kernel: net: atm: fix crash due to unvalidated vcc pointer in sigd_send()
(CVE-2026-31411)
o kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198)
Bug Fix(es) and Enhancement(s):
o [RHEL 9.8 Bug] qla2xxx flash image validation failure [rhel-9.8.z]
(JIRA:RHEL-181886)
o crypto: testmgr - allow authenc(hmac(sha{256,384}),cts(cbc(aes))) in FIPS
mode [rhel-9.8.z] (JIRA:RHEL-182540)
o tegra-se fixes and updates [rhel-9.8.z] (JIRA:RHEL-182760)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.
Solution
For details on how to apply this update, which includes the changes described
in this advisory, refer to:
https://access.redhat.com/articles/11258
The system must be rebooted for this update to take effect.
Affected Products
o Red Hat Enterprise Linux for x86_64 9 x86_64
o Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64
o Red Hat Enterprise Linux for IBM z Systems 9 s390x
o Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8
s390x
o Red Hat Enterprise Linux for Power, little endian 9 ppc64le
o Red Hat Enterprise Linux for Power, little endian - Extended Update Support
9.8 ppc64le
o Red Hat Enterprise Linux for ARM 64 9 aarch64
o Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64
o Red Hat Enterprise Linux Server for Power LE - Update Services for SAP
Solutions 9.8 ppc64le
o Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8
x86_64
o Red Hat CodeReady Linux Builder for x86_64 9 x86_64
o Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le
o Red | 1a7c676a6ab307faeb18d3046a96bc6b9e8ee09ea57f3fbea0bc731462f77bc2 | 2026-06-30 06:47:27.315299+03:00 | 2026-06-30 06:47:27.315299+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7213/', 'title': 'kernel: CVSS (Max): 7.1', 'summary': '<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7213 \n kernel security, bug fix, and enhancement update \n 30 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: kernel \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-31411 CVE-2026-43198 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:33285\n\nComment: CVSS (Max): 7.1 CVE-2026-31411 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H\n \n EPSS (Max): 0.4% (28th) CVE-2026-43198 2026-06-29 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:33285 - Security Advisory\n\nIssued: 2026-06-29\nUpdated: 2026-06-29\n\nSynopsis\nKernel security, bug fix, and enhancement update\n\nType/Severity\nSecurity Advisory: Important\n\nTopic\n\nAn update for kernel is now available for Red Hat Enterprise Linux 9.\n\nRed Hat Product Security has rated this update as having a security impact of\nImportant. A Common Vulnerability Scoring System (CVSS) base score, which gives\na detailed severity rating, is available for each vulnerability from the CVE\nlink(s) in the References section.\n\nDescription\n\nThe kernel packages contain the Linux kernel, the core of any Linux operating\nsystem.\n\nSecurity Fix(es):\n\n o kernel: net: atm: fix crash due to unvalidated vcc pointer in sigd_send()\n (CVE-2026-31411)\n o kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198)\n\nBug Fix(es) and Enhancement(s):\n\n o [RHEL 9.8 Bug] qla2xxx flash image validation failure [rhel-9.8.z]\n (JIRA:RHEL-181886)\n o crypto: testmgr - allow authenc(hmac(sha{256,384}),cts(cbc(aes))) in FIPS\n mode [rhel-9.8.z] (JIRA:RHEL-182540)\n o tegra-se fixes and updates [rhel-9.8.z] (JIRA:RHEL-182760)\n\nFor more details about the security issue(s), including the impact, a CVSS\nscore, acknowledgments, and other related information, refer to the CVE page(s)\nlisted in the References section.\n\nSolution\n\nFor details on how to apply this update, which includes the changes described\nin this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nThe system must be rebooted for this update to take effect.\n\nAffected Products\n\n o Red Hat Enterprise Linux for x86_64 9 x86_64\n o Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64\n o Red Hat Enterprise Linux for IBM z Systems 9 s390x\n o Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8\n s390x\n o Red Hat Enterprise Linux for Power, little endian 9 ppc64le\n o Red Hat Enterprise Linux for Power, little endian - Extended Update Support\n 9.8 ppc64le\n o Red Hat Enterprise Linux for ARM 64 9 aarch64\n o Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64\n o Red Hat Enterprise Linux Server for Power LE - Update Services for SAP\n Solutions 9.8 ppc64le\n o Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8\n x86_64\n o Red Hat CodeReady Linux Builder for x86_64 9 x86_64\n o Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le\n o Red', 'published': '2026-06-30T01:09:53Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7213/'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1711 | N/A | [NEU] [mittel] n8n: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1711 | [NEU] [mittel] n8n: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen | b9821743269e30740a8e199643572fcb2421a5eeb317b982048a8bc7f7468d8a | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1711', 'title': '[NEU] [mittel] n8n: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen', 'summary': '[NEU] [mittel] n8n: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1711'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1350 | N/A | [UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1350 | [UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service | 80b051873d1ccb6a2e186419baa2661ec6a80d12cd8ec034640b88432aa4e318 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1350', 'title': '[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service', 'summary': '[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1350'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0372 | N/A | [UPDATE] [hoch] PostgreSQL: Schwachstelle ermöglicht SQL Injection und Codeausführung | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0372 | 2026-06-26T07:26:39Z | Ein entfernter, anonymer Angreifer kann eine Schwachstelle in PostgreSQL ausnutzen, um eine SQL Injection durchzuführen und in der Folge beliebigen Programmcode auszuführen. | c4ccebd00659d56aa38453af9696c6766229a6d5ff38e98fa92666996d7cff46 | 2026-06-26 12:34:22.977075+03:00 | 2026-06-26 12:34:22.977075+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0372', 'title': '[UPDATE] [hoch] PostgreSQL: Schwachstelle ermöglicht SQL Injection und Codeausführung', 'summary': 'Ein entfernter, anonymer Angreifer kann eine Schwachstelle in PostgreSQL ausnutzen, um eine SQL Injection durchzuführen und in der Folge beliebigen Programmcode auszuführen.', 'published': '2026-06-26T07:26:39Z', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0372'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1570 | N/A | [UPDATE] [mittel] vim: Mehrere Schwachstellen ermöglichen Codeausführung | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1570 | 2026-06-23T07:28:10Z | Ein Angreifer kann mehrere Schwachstellen in vim ausnutzen, um beliebigen Programmcode auszuführen. | 954668ca893496409ac991d651232c6e361eb234e0cb89d8709a9903d7ac98b8 | 2026-06-12 15:27:29.402648+03:00 | 2026-06-23 12:38:20.190255+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1570', 'title': '[UPDATE] [mittel] vim: Mehrere Schwachstellen ermöglichen Codeausführung', 'summary': 'Ein Angreifer kann mehrere Schwachstellen in vim ausnutzen, um beliebigen Programmcode auszuführen.', 'published': '2026-06-23T07:28:10Z', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1570'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7213/ | CVE-2026-43198 | kernel: CVSS (Max): 7.1 | http://portal.auscert.org.au/bulletins/ESB-2026.7213/ | 2026-06-30T01:09:53Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7213
kernel security, bug fix, and enhancement update
30 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: kernel
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-31411 CVE-2026-43198
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:33285
Comment: CVSS (Max): 7.1 CVE-2026-31411 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
EPSS (Max): 0.4% (28th) CVE-2026-43198 2026-06-29
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:33285 - Security Advisory
Issued: 2026-06-29
Updated: 2026-06-29
Synopsis
Kernel security, bug fix, and enhancement update
Type/Severity
Security Advisory: Important
Topic
An update for kernel is now available for Red Hat Enterprise Linux 9.
Red Hat Product Security has rated this update as having a security impact of
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives
a detailed severity rating, is available for each vulnerability from the CVE
link(s) in the References section.
Description
The kernel packages contain the Linux kernel, the core of any Linux operating
system.
Security Fix(es):
o kernel: net: atm: fix crash due to unvalidated vcc pointer in sigd_send()
(CVE-2026-31411)
o kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198)
Bug Fix(es) and Enhancement(s):
o [RHEL 9.8 Bug] qla2xxx flash image validation failure [rhel-9.8.z]
(JIRA:RHEL-181886)
o crypto: testmgr - allow authenc(hmac(sha{256,384}),cts(cbc(aes))) in FIPS
mode [rhel-9.8.z] (JIRA:RHEL-182540)
o tegra-se fixes and updates [rhel-9.8.z] (JIRA:RHEL-182760)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.
Solution
For details on how to apply this update, which includes the changes described
in this advisory, refer to:
https://access.redhat.com/articles/11258
The system must be rebooted for this update to take effect.
Affected Products
o Red Hat Enterprise Linux for x86_64 9 x86_64
o Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64
o Red Hat Enterprise Linux for IBM z Systems 9 s390x
o Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8
s390x
o Red Hat Enterprise Linux for Power, little endian 9 ppc64le
o Red Hat Enterprise Linux for Power, little endian - Extended Update Support
9.8 ppc64le
o Red Hat Enterprise Linux for ARM 64 9 aarch64
o Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64
o Red Hat Enterprise Linux Server for Power LE - Update Services for SAP
Solutions 9.8 ppc64le
o Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8
x86_64
o Red Hat CodeReady Linux Builder for x86_64 9 x86_64
o Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le
o Red | 4fa97b8b7a02eb6ffce2046768970ea577a954a53bd1e4491a97d5cf32d354b4 | 2026-06-30 06:47:27.315299+03:00 | 2026-06-30 06:47:27.315299+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7213/', 'title': 'kernel: CVSS (Max): 7.1', 'summary': '<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7213 \n kernel security, bug fix, and enhancement update \n 30 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: kernel \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-31411 CVE-2026-43198 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:33285\n\nComment: CVSS (Max): 7.1 CVE-2026-31411 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H\n \n EPSS (Max): 0.4% (28th) CVE-2026-43198 2026-06-29 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:33285 - Security Advisory\n\nIssued: 2026-06-29\nUpdated: 2026-06-29\n\nSynopsis\nKernel security, bug fix, and enhancement update\n\nType/Severity\nSecurity Advisory: Important\n\nTopic\n\nAn update for kernel is now available for Red Hat Enterprise Linux 9.\n\nRed Hat Product Security has rated this update as having a security impact of\nImportant. A Common Vulnerability Scoring System (CVSS) base score, which gives\na detailed severity rating, is available for each vulnerability from the CVE\nlink(s) in the References section.\n\nDescription\n\nThe kernel packages contain the Linux kernel, the core of any Linux operating\nsystem.\n\nSecurity Fix(es):\n\n o kernel: net: atm: fix crash due to unvalidated vcc pointer in sigd_send()\n (CVE-2026-31411)\n o kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198)\n\nBug Fix(es) and Enhancement(s):\n\n o [RHEL 9.8 Bug] qla2xxx flash image validation failure [rhel-9.8.z]\n (JIRA:RHEL-181886)\n o crypto: testmgr - allow authenc(hmac(sha{256,384}),cts(cbc(aes))) in FIPS\n mode [rhel-9.8.z] (JIRA:RHEL-182540)\n o tegra-se fixes and updates [rhel-9.8.z] (JIRA:RHEL-182760)\n\nFor more details about the security issue(s), including the impact, a CVSS\nscore, acknowledgments, and other related information, refer to the CVE page(s)\nlisted in the References section.\n\nSolution\n\nFor details on how to apply this update, which includes the changes described\nin this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nThe system must be rebooted for this update to take effect.\n\nAffected Products\n\n o Red Hat Enterprise Linux for x86_64 9 x86_64\n o Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64\n o Red Hat Enterprise Linux for IBM z Systems 9 s390x\n o Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8\n s390x\n o Red Hat Enterprise Linux for Power, little endian 9 ppc64le\n o Red Hat Enterprise Linux for Power, little endian - Extended Update Support\n 9.8 ppc64le\n o Red Hat Enterprise Linux for ARM 64 9 aarch64\n o Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64\n o Red Hat Enterprise Linux Server for Power LE - Update Services for SAP\n Solutions 9.8 ppc64le\n o Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8\n x86_64\n o Red Hat CodeReady Linux Builder for x86_64 9 x86_64\n o Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le\n o Red', 'published': '2026-06-30T01:09:53Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7213/'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0280 | N/A | [UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0280 | [UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen | 29dc9e041a90a7960536e5313ac8a42b9005120988148d549d24a56d500615c9 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0280', 'title': '[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen', 'summary': '[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0280'} | |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7158/ | CVE-2025-14512 | IBM MQ Agent: CVSS (Max): None | http://portal.auscert.org.au/bulletins/ESB-2026.7158/ | 2026-06-30T00:13:04Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7158
Multiple vulnerabilities in IBM MQ Agent images
30 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: IBM MQ Agent
Publisher: IBM
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-34181
CVE-2026-34183 CVE-2026-42764 CVE-2026-42768
CVE-2026-42769 CVE-2026-42770 CVE-2026-45445
CVE-2026-45446 CVE-2024-3651 CVE-2026-40356
CVE-2026-40355 CVE-2025-14087 CVE-2025-14512
CVE-2026-4878 CVE-2026-2100 CVE-2026-45134
CVE-2026-44681 CVE-2026-45409 CVE-2026-44843
CVE-2026-48522 CVE-2026-48523 CVE-2026-48524
CVE-2026-48525 CVE-2026-28390 CVE-2026-29111
CVE-2025-15281 CVE-2025-4598 CVE-2026-4437
CVE-2026-4438 CVE-2026-34180 CVE-2026-34182
CVE-2026-42767 CVE-2026-45447 CVE-2026-7383
CVE-2026-9076 CVE-2026-48710
Original Bulletin:
https://www.ibm.com/support/pages/node/7278328
Comment: CVSS (Max): None available when published
EPSS (Max): None available when published
- --------------------------BEGIN INCLUDED TEXT--------------------
IBM Support
Document Information
Document number : 7278328
Modified date : More support for: IBM MQ Agent
Product : IBM MQ Agent
Component : -
Software version : IBM MQ Agent v2.0.0
Operating system(s): RedHat OpenShift
Security Bulletin
Summary
Multiple vulnerabilities were addressed in IBM MQ Agent images
Vulnerability Details
CVEID: CVE-2026-45134
DESCRIPTION: LangSmith Client SDKs provide SDK's for interacting with the
LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the
LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in
Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt
manifests from the LangSmith Hub. These manifests may contain serialized
LangChain objects and model configuration that affect runtime behavior. When
pulling a public prompt by owner/name identifier, the manifest content is
controlled by an external party, but prior versions of the SDK did not
distinguish this from pulling a prompt within the caller's own organization.
This vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.
CWE: CWE-502: Deserialization of Untrusted Data
CVSS Source: security-advisories@github.com
CVSS Base score: 7.1
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)
CVEID: CVE-2026-4438
DESCRIPTION: Calling gethostbyaddr or gethostbyaddr_r with a configured
nsswitch.conf that specifies the library's DNS backend in the GNU C library
version 2.34 to version 2.43 could result in an invalid DNS hostname being
returned to the caller in violation of the DNS specification.
CWE: CWE-20: Improper Input Validation
CVSS Source: CISA ADP
CVSS Base score: 5.4
CVSS Vector: (CVSS:3.1/AV:A/AC:L/P | 71d4a0865b5bc6c1ab00487247792cc68dcddbb984bb2196f409b42e35b6bf66 | 2026-06-30 06:47:27.315299+03:00 | 2026-06-30 06:47:27.315299+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7158/', 'title': 'IBM MQ Agent: CVSS (Max): None', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7158 \n Multiple vulnerabilities in IBM MQ Agent images \n 30 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: IBM MQ Agent \nPublisher: IBM \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-34181 \n CVE-2026-34183 CVE-2026-42764 CVE-2026-42768 \n CVE-2026-42769 CVE-2026-42770 CVE-2026-45445 \n CVE-2026-45446 CVE-2024-3651 CVE-2026-40356 \n CVE-2026-40355 CVE-2025-14087 CVE-2025-14512 \n CVE-2026-4878 CVE-2026-2100 CVE-2026-45134 \n CVE-2026-44681 CVE-2026-45409 CVE-2026-44843 \n CVE-2026-48522 CVE-2026-48523 CVE-2026-48524 \n CVE-2026-48525 CVE-2026-28390 CVE-2026-29111 \n CVE-2025-15281 CVE-2025-4598 CVE-2026-4437 \n CVE-2026-4438 CVE-2026-34180 CVE-2026-34182 \n CVE-2026-42767 CVE-2026-45447 CVE-2026-7383 \n CVE-2026-9076 CVE-2026-48710 \n\nOriginal Bulletin:\n https://www.ibm.com/support/pages/node/7278328\n\nComment: CVSS (Max): None available when published \n \n EPSS (Max): None available when published \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nIBM Support\n\nDocument Information\n\nDocument number : 7278328\nModified date : More support for: IBM MQ Agent\nProduct : IBM MQ Agent\nComponent : -\nSoftware version : IBM MQ Agent v2.0.0\nOperating system(s): RedHat OpenShift\n\nSecurity Bulletin\n\n\nSummary\n\nMultiple vulnerabilities were addressed in IBM MQ Agent images\n\nVulnerability Details\n\nCVEID: CVE-2026-45134\nDESCRIPTION: LangSmith Client SDKs provide SDK's for interacting with the\nLangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the\nLangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in\nPython, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt\nmanifests from the LangSmith Hub. These manifests may contain serialized\nLangChain objects and model configuration that affect runtime behavior. When\npulling a public prompt by owner/name identifier, the manifest content is\ncontrolled by an external party, but prior versions of the SDK did not\ndistinguish this from pulling a prompt within the caller's own organization.\nThis vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.\nCWE: CWE-502: Deserialization of Untrusted Data\nCVSS Source: security-advisories@github.com\nCVSS Base score: 7.1\nCVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)\n\nCVEID: CVE-2026-4438\nDESCRIPTION: Calling gethostbyaddr or gethostbyaddr_r with a configured\nnsswitch.conf that specifies the library's DNS backend in the GNU C library\nversion 2.34 to version 2.43 could result in an invalid DNS hostname being\nreturned to the caller in violation of the DNS specification.\nCWE: CWE-20: Improper Input Validation\nCVSS Source: CISA ADP\nCVSS Base score: 5.4\nCVSS Vector: (CVSS:3.1/AV:A/AC:L/P", 'published': '2026-06-30T00:13:04Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7158/'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0194 | N/A | [UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Service | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0194 | [UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Service | 1c772ac0f4f087abb11dbadd19282ca1815e870ab1015a4c6bba95bd3805b00d | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0194', 'title': '[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Service', 'summary': '[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Service', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0194'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0184 | N/A | [UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Service | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0184 | [UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Service | 84ec9969202d8f16dd2a88465cb3f7f019f4b6ef0f4e75fab50f09349006991f | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0184', 'title': '[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Service', 'summary': '[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Service', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0184'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0009 | N/A | [UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0009 | [UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service | 8caa06898878e2e12fdde60f733ecd589b065c52a90195684a8ce13c07cb9da7 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0009', 'title': '[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service', 'summary': '[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0009'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2929 | N/A | [UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2929 | [UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen | 6d6a3559d34a7c03334cc47af4fc1d751bd687ba72fccf81c7ee49617ace25fb | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2929', 'title': '[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen', 'summary': '[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2929'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2914 | N/A | [UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2914 | [UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service | 1f1fe6a0d4affdfe1ddc5f612346d457192ebf3ba3ee6e92d71dc467d8f2964b | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2914', 'title': '[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service', 'summary': '[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2914'} | |
cisa | /node/24914 | N/A | ABB B&R PCs | https://www.cisa.gov/news-events/ics-advisories/icsa-26-141-02 | ABB B&R PCs | 9e8bedcae0437e74f23372c04ae27101802fbb5163a03bd13e2de28d228cf6e5 | 2026-05-29 02:12:33.029194+03:00 | 2026-05-29 02:12:33.029194+03:00 | {'link': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-141-02', 'title': 'ABB B&R PCs', 'summary': 'ABB B&R PCs', 'published': '', 'advisory_id': '/node/24914'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3475 | N/A | [UPDATE] [hoch] PostgreSQL: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3475 | 2026-06-26T07:26:38Z | Ein entfernter Angreifer kann mehrere Schwachstellen in PostgreSQL ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder vertrauliche Informationen preiszugeben. | 0c33d593c2f2be4305f2e5f45e0973c49dc2f3f60e5284600e5ae6639fdcfef0 | 2026-06-26 12:34:22.977075+03:00 | 2026-06-26 12:34:22.977075+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3475', 'title': '[UPDATE] [hoch] PostgreSQL: Mehrere Schwachstellen', 'summary': 'Ein entfernter Angreifer kann mehrere Schwachstellen in PostgreSQL ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder vertrauliche Informationen preiszugeben.', 'published': '2026-06-26T07:26:38Z', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3475'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1709 | N/A | [NEU] [hoch] Webmin: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1709 | [NEU] [hoch] Webmin: Mehrere Schwachstellen | 0b483207260490d3ae8bfa74ba59fb1faa68f5111345e3cf8fb41e1ebd52709c | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1709', 'title': '[NEU] [hoch] Webmin: Mehrere Schwachstellen', 'summary': '[NEU] [hoch] Webmin: Mehrere Schwachstellen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1709'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1531 | N/A | [UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1531 | 2026-06-24T08:57:34Z | Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht näher spezifizierte Auswirkungen zu erzielen. | 8d53a6b06dfbed7fee76329da125cd06e45aa13751a01792a6a2a9fb246d6cd4 | 2026-05-29 02:12:30.351260+03:00 | 2026-06-24 13:38:15.877417+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1531', 'title': '[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen', 'summary': 'Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht näher spezifizierte Auswirkungen zu erzielen.', 'published': '2026-06-24T08:57:34Z', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1531'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1530 | N/A | [UPDATE] [hoch] Linux Kernel (Fragnesia): Schwachstelle ermöglicht Erlangen von Administratorrechten | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1530 | 2026-06-30T11:51:01Z | Ein lokaler Angreifer kann eine Schwachstelle in Linux Kernel ausnutzen, um Administratorrechte zu erlangen. | 9bd437e9a315e3071605eb9b0c95bd9f2dacaa2d461fdd19c645fba4a7a721fb | 2026-05-29 02:12:30.351260+03:00 | 2026-06-30 19:35:57.730876+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1530', 'title': '[UPDATE] [hoch] Linux Kernel (Fragnesia): Schwachstelle ermöglicht Erlangen von Administratorrechten', 'summary': 'Ein lokaler Angreifer kann eine Schwachstelle in Linux Kernel ausnutzen, um Administratorrechte zu erlangen.', 'published': '2026-06-30T11:51:01Z', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1530'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1707 | N/A | [NEU] [hoch] Jenkins Plugins: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1707 | [NEU] [hoch] Jenkins Plugins: Mehrere Schwachstellen | 21e2aaa706a880879b9c4f1581b8c109f9634cde0e335eb7b4cb20e5a9e39c15 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1707', 'title': '[NEU] [hoch] Jenkins Plugins: Mehrere Schwachstellen', 'summary': '[NEU] [hoch] Jenkins Plugins: Mehrere Schwachstellen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1707'} | |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.5797/ | CVE-2026-27143 | OpenShift Container Platform 4.19.32: CVSS (Max): 9.1 | http://portal.auscert.org.au/bulletins/ESB-2026.5797/ | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.5797
OpenShift Container Platform 4.19.32 bug fix and security update
28 May 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: OpenShift Container Platform 4.19.32
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-35469 CVE-2025-61726 CVE-2026-33186
CVE-2026-40175 CVE-2026-4800 CVE-2025-66031
CVE-2026-27143 CVE-2026-27144 CVE-2026-29063
CVE-2026-25679 CVE-2026-22029 CVE-2026-34986
CVE-2026-34043 CVE-2025-12816
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:20041
Comment: CVSS (Max): 9.1 CVE-2026-33186 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS (Max): 0.1% (23rd) CVE-2026-29063 2026-05-27
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:20041 - Security Advisory
Issued: 2026-05-27
Updated: 2026-05-27
Synopsis
Container platform 4.19.32 bug fix and security update
Type/Severity
Security Advisory: Important
Topic
Red Hat OpenShift Container Platform release 4.19.32 is now available with
updates to packages and images that fix several bugs and add enhancements.
This release includes a security update for Red Hat OpenShift Container
Platform 4.19.
Red Hat Product Security has rated this update as having a security impact of
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives
a detailed severity rating, is available for each vulnerability from the CVE
link(s) in the References section.
Description
Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes
application platform solution designed for on-premise or private cloud
deployments.
This advisory contains the container images for Red Hat OpenShift Container
Platform 4.19.32. See the following advisory for the RPM packages for this
release:
https://access.redhat.com/errata/RHBA-2026:20039
Space precludes documenting all of the container images in this advisory. See
the following Release Notes documentation, which will be updated shortly for
this release, for details about these changes:
https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html
/release_notes/
Solution
For OpenShift Container Platform 4.19 see the following documentation, which
will be updated shortly for this release, for important instructions on how to
upgrade your cluster and fully apply this asynchronous errata update:
https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html
/release_notes/
You may download the oc tool and use it to inspect release image metadata for
x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be
found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.
The sha values for the release are as follows:
(For x86_64 architecture)
The image digest is
sha256:1bd5ad0745f446a798a4038e4d04cf651213f71bc4e76dd9349f5c6968135f9b
(For s390x architec | b7f27a40038a6f4b32bbd19a52dd6240ea50e9bf359346b42df25562e23406b5 | 2026-05-29 02:12:38.557132+03:00 | 2026-05-29 02:12:38.557132+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.5797/', 'title': 'OpenShift Container Platform 4.19.32: CVSS (Max): 9.1', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.5797 \n OpenShift Container Platform 4.19.32 bug fix and security update \n 28 May 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: OpenShift Container Platform 4.19.32 \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-35469 CVE-2025-61726 CVE-2026-33186 \n CVE-2026-40175 CVE-2026-4800 CVE-2025-66031 \n CVE-2026-27143 CVE-2026-27144 CVE-2026-29063 \n CVE-2026-25679 CVE-2026-22029 CVE-2026-34986 \n CVE-2026-34043 CVE-2025-12816 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:20041\n\nComment: CVSS (Max): 9.1 CVE-2026-33186 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N\n \n EPSS (Max): 0.1% (23rd) CVE-2026-29063 2026-05-27 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:20041 - Security Advisory\n\nIssued: 2026-05-27\nUpdated: 2026-05-27\n\nSynopsis\nContainer platform 4.19.32 bug fix and security update\n\nType/Severity\nSecurity Advisory: Important\n\nTopic\n\nRed Hat OpenShift Container Platform release 4.19.32 is now available with\nupdates to packages and images that fix several bugs and add enhancements.\n\nThis release includes a security update for Red Hat OpenShift Container\nPlatform 4.19.\n\nRed Hat Product Security has rated this update as having a security impact of\nImportant. A Common Vulnerability Scoring System (CVSS) base score, which gives\na detailed severity rating, is available for each vulnerability from the CVE\nlink(s) in the References section.\n\nDescription\n\nRed Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes\napplication platform solution designed for on-premise or private cloud\ndeployments.\n\nThis advisory contains the container images for Red Hat OpenShift Container\nPlatform 4.19.32. See the following advisory for the RPM packages for this\nrelease:\n\nhttps://access.redhat.com/errata/RHBA-2026:20039\n\nSpace precludes documenting all of the container images in this advisory. See\nthe following Release Notes documentation, which will be updated shortly for\nthis release, for details about these changes:\n\nhttps://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html\n/release_notes/\n\nSolution\n\nFor OpenShift Container Platform 4.19 see the following documentation, which\nwill be updated shortly for this release, for important instructions on how to\nupgrade your cluster and fully apply this asynchronous errata update:\n\nhttps://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html\n/release_notes/\n\nYou may download the oc tool and use it to inspect release image metadata for\nx86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be\nfound at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.\n\nThe sha values for the release are as follows:\n\n(For x86_64 architecture)\nThe image digest is\nsha256:1bd5ad0745f446a798a4038e4d04cf651213f71bc4e76dd9349f5c6968135f9b\n\n(For s390x architec", 'published': '', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.5797/'} | |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7093/ | CVE-2026-42271 | ALERT Red Hat OpenShift AI: CVSS (Max): 9.1 | http://portal.auscert.org.au/bulletins/ESB-2026.7093/ | 2026-06-26T01:23:25Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7093
RHOAI 3.3.4 - Red Hat OpenShift AI
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat OpenShift AI
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-40217 CVE-2026-35029 CVE-2026-35030
CVE-2026-42271
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30056
Comment: CVSS (Max): 9.1 CVE-2026-35030 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The following are listed in the CISA Known Exploited Vulnerabilities (KEV) Catalog:
CISA KEV CVE(s): CVE-2026-42271
CISA KEV URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
EPSS (Max): 75.0% (99th) CVE-2026-42271 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30056 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
3.3.4 - Red Hat OpenShift AI
Type/Severity
Security Advisory: Important
Topic
Updated images are now available for Red Hat OpenShift AI.
Description
Release of RHOAI 3.3.4 provides these changes:
Solution
For Red Hat OpenShift AI 3.3.4 see the following documentation, which will be
updated shortly for this release, for important instructions on how to upgrade
your cluster and fully apply this errata update:
https://docs.redhat.com/en/documentation/red_hat_openshift_ai/
Affected Products
o Red Hat OpenShift AI
Fixes
(none)
CVEs
o CVE-2026-35029
o CVE-2026-35030
o CVE-2026-40217
o CVE-2026-42271
References
o https://access.redhat.com/security/updates/classification/
o https://docs.redhat.com/en/documentation/red_hat_openshift_ai/
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release of the security bulletin. It may
not be updated when updates to the origi | 0e3e309c0b1fb4092374d3f0e36e1ea34094de12a78de8f6587731da1c7cb125 | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7093/', 'title': 'ALERT Red Hat OpenShift AI: CVSS (Max): 9.1', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7093 \n RHOAI 3.3.4 - Red Hat OpenShift AI \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat OpenShift AI \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-40217 CVE-2026-35029 CVE-2026-35030 \n CVE-2026-42271 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30056\n\nComment: CVSS (Max): 9.1 CVE-2026-35030 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N\n \n The following are listed in the CISA Known Exploited Vulnerabilities (KEV) Catalog:\n CISA KEV CVE(s): CVE-2026-42271 \n CISA KEV URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog\n \n EPSS (Max): 75.0% (99th) CVE-2026-42271 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30056 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\n3.3.4 - Red Hat OpenShift AI\n\nType/Severity\nSecurity Advisory: Important\n\nTopic\n\nUpdated images are now available for Red Hat OpenShift AI.\n\nDescription\n\nRelease of RHOAI 3.3.4 provides these changes:\n\nSolution\n\nFor Red Hat OpenShift AI 3.3.4 see the following documentation, which will be\nupdated shortly for this release, for important instructions on how to upgrade\nyour cluster and fully apply this errata update:\n\nhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/\n\nAffected Products\n\n o Red Hat OpenShift AI\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2026-35029\n o CVE-2026-35030\n o CVE-2026-40217\n o CVE-2026-42271\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://docs.redhat.com/en/documentation/red_hat_openshift_ai/\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release of the security bulletin. It may\nnot be updated when updates to the origi", 'published': '2026-06-26T01:23:25Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7093/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | CVE-2026-44432 | Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | 2026-06-26T01:22:47Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7092
Red Hat AI Inference Server 3.3.5 (Spyre)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference (RHAI) Server
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786
CVE-2025-62164 CVE-2026-10118 CVE-2026-4878
CVE-2026-6100 CVE-2026-22773 CVE-2026-22778
CVE-2026-22807 CVE-2026-24779 CVE-2026-34588
CVE-2026-37555 CVE-2026-35385 CVE-2026-4775
CVE-2025-66448 CVE-2026-39979 CVE-2026-40164
CVE-2026-34982 CVE-2026-48818
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30087
Comment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30087 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server 3.3.5 (spyre)
Type/Severity
Security Advisory: Critical
Topic
Red Hat AI Inference Server 3.3.5 (Spyre) is now available.
Description
Red Hat AI Inference Server
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-62164
o CVE-2025-66448
o CVE-2026-10118
o CVE-2026-22773
o CVE-2026-22778
o CVE-2026-22807
o CVE-2026-24779
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-48818
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release o | e3a907b0d85bb592a65145a0d12e834e75337d7981d57445b253cdb6ccfff9f3 | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/', 'title': 'Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7092 \n Red Hat AI Inference Server 3.3.5 (Spyre) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference (RHAI) Server \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786 \n CVE-2025-62164 CVE-2026-10118 CVE-2026-4878 \n CVE-2026-6100 CVE-2026-22773 CVE-2026-22778 \n CVE-2026-22807 CVE-2026-24779 CVE-2026-34588 \n CVE-2026-37555 CVE-2026-35385 CVE-2026-4775 \n CVE-2025-66448 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-34982 CVE-2026-48818 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30087\n\nComment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30087 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server 3.3.5 (spyre)\n\nType/Severity\nSecurity Advisory: Critical\n\nTopic\n\nRed Hat AI Inference Server 3.3.5 (Spyre) is now available.\n\nDescription\n\nRed Hat AI Inference Server\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-62164\n o CVE-2025-66448\n o CVE-2026-10118\n o CVE-2026-22773\n o CVE-2026-22778\n o CVE-2026-22807\n o CVE-2026-24779\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-48818\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release o", 'published': '2026-06-26T01:22:47Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | CVE-2026-44431 | Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | 2026-06-26T01:22:47Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7092
Red Hat AI Inference Server 3.3.5 (Spyre)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference (RHAI) Server
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786
CVE-2025-62164 CVE-2026-10118 CVE-2026-4878
CVE-2026-6100 CVE-2026-22773 CVE-2026-22778
CVE-2026-22807 CVE-2026-24779 CVE-2026-34588
CVE-2026-37555 CVE-2026-35385 CVE-2026-4775
CVE-2025-66448 CVE-2026-39979 CVE-2026-40164
CVE-2026-34982 CVE-2026-48818
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30087
Comment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30087 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server 3.3.5 (spyre)
Type/Severity
Security Advisory: Critical
Topic
Red Hat AI Inference Server 3.3.5 (Spyre) is now available.
Description
Red Hat AI Inference Server
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-62164
o CVE-2025-66448
o CVE-2026-10118
o CVE-2026-22773
o CVE-2026-22778
o CVE-2026-22807
o CVE-2026-24779
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-48818
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release o | 0d9ab4ce69372a747ba5fb7c828c3a519e6268b8206717f3680939887626d402 | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/', 'title': 'Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7092 \n Red Hat AI Inference Server 3.3.5 (Spyre) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference (RHAI) Server \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786 \n CVE-2025-62164 CVE-2026-10118 CVE-2026-4878 \n CVE-2026-6100 CVE-2026-22773 CVE-2026-22778 \n CVE-2026-22807 CVE-2026-24779 CVE-2026-34588 \n CVE-2026-37555 CVE-2026-35385 CVE-2026-4775 \n CVE-2025-66448 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-34982 CVE-2026-48818 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30087\n\nComment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30087 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server 3.3.5 (spyre)\n\nType/Severity\nSecurity Advisory: Critical\n\nTopic\n\nRed Hat AI Inference Server 3.3.5 (Spyre) is now available.\n\nDescription\n\nRed Hat AI Inference Server\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-62164\n o CVE-2025-66448\n o CVE-2026-10118\n o CVE-2026-22773\n o CVE-2026-22778\n o CVE-2026-22807\n o CVE-2026-24779\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-48818\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release o", 'published': '2026-06-26T01:22:47Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1706 | N/A | [NEU] [mittel] Jabra Direct: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1706 | [NEU] [mittel] Jabra Direct: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff | 544867c793a680cd5c2fded2abe80b8dedce058d59ef3fe10c3204f935491629 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1706', 'title': '[NEU] [mittel] Jabra Direct: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff', 'summary': '[NEU] [mittel] Jabra Direct: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1706'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1704 | N/A | [NEU] [hoch] GitLab: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1704 | [NEU] [hoch] GitLab: Mehrere Schwachstellen | 86861e7f1347627be658a276e1e7db45a0b5bc5fe7e5988b81c5b120b5361c48 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1704', 'title': '[NEU] [hoch] GitLab: Mehrere Schwachstellen', 'summary': '[NEU] [hoch] GitLab: Mehrere Schwachstellen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1704'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1703 | N/A | [NEU] [hoch] SolarWinds Web Help Desk: Schwachstelle ermöglicht Denial of Service | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1703 | [NEU] [hoch] SolarWinds Web Help Desk: Schwachstelle ermöglicht Denial of Service | 5d3a09f010b5e21487f25b19e3d4e89f12860f29ecb13cdd00b1f1498f8f72c2 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1703', 'title': '[NEU] [hoch] SolarWinds Web Help Desk: Schwachstelle ermöglicht Denial of Service', 'summary': '[NEU] [hoch] SolarWinds Web Help Desk: Schwachstelle ermöglicht Denial of Service', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1703'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1702 | N/A | [NEU] [hoch] Drupal AlternativeCommerce (Basket): Schwachstelle ermöglicht Codeausführung | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1702 | [NEU] [hoch] Drupal AlternativeCommerce (Basket): Schwachstelle ermöglicht Codeausführung | 3361087c6bf8bef386943d7b6199ed643f1ec466b464a88a03252d4a9d2f3a2e | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1702', 'title': '[NEU] [hoch] Drupal AlternativeCommerce (Basket): Schwachstelle ermöglicht Codeausführung', 'summary': '[NEU] [hoch] Drupal AlternativeCommerce (Basket): Schwachstelle ermöglicht Codeausführung', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1702'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1701 | N/A | [NEU] [mittel] Checkmk Windows-Agent-Plugins: Schwachstelle ermöglicht Denial of Service | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1701 | [NEU] [mittel] Checkmk Windows-Agent-Plugins: Schwachstelle ermöglicht Denial of Service | 45cac4d17d7eab60e18d4144552dfeccc52890c19e5f33b99c4879d569f901f9 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1701', 'title': '[NEU] [mittel] Checkmk Windows-Agent-Plugins: Schwachstelle ermöglicht Denial of Service', 'summary': '[NEU] [mittel] Checkmk Windows-Agent-Plugins: Schwachstelle ermöglicht Denial of Service', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1701'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2045 | N/A | [NEU] [mittel] rsyslog: Schwachstelle ermöglicht Denial of Service | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2045 | 2026-06-24T10:26:32Z | Ein entfernter, anonymer Angreifer kann eine Schwachstelle in rsyslog ausnutzen, um einen Denial of Service Angriff durchzuführen. | 2c5819acd6cb2e0e83beab1c6fc993430ec46b6049f100b421d208d0f9404b44 | 2026-06-24 13:38:15.877417+03:00 | 2026-06-24 13:38:15.877417+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2045', 'title': '[NEU] [mittel] rsyslog: Schwachstelle ermöglicht Denial of Service', 'summary': 'Ein entfernter, anonymer Angreifer kann eine Schwachstelle in rsyslog ausnutzen, um einen Denial of Service Angriff durchzuführen.', 'published': '2026-06-24T10:26:32Z', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2045'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1698 | N/A | [NEU] [hoch] Gladinet Triofox: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1698 | [NEU] [hoch] Gladinet Triofox: Mehrere Schwachstellen | da27b54bece93e25aab2b681db825a37130a025cad9f0ea5da1fdf2c95409a62 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1698', 'title': '[NEU] [hoch] Gladinet Triofox: Mehrere Schwachstellen', 'summary': '[NEU] [hoch] Gladinet Triofox: Mehrere Schwachstellen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1698'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1800 | N/A | [UPDATE] [hoch] PostgreSQL: Schwachstelle ermöglicht Privilegieneskalation | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1800 | 2026-06-26T07:26:37Z | Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in PostgreSQL ausnutzen, um seine Privilegien zu erhöhen. | 74b96e8fa91355d445ace6030487e9ad88a4ca2804e8c85a7587db7827c57da3 | 2026-06-26 12:34:22.977075+03:00 | 2026-06-26 12:34:22.977075+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1800', 'title': '[UPDATE] [hoch] PostgreSQL: Schwachstelle ermöglicht Privilegieneskalation', 'summary': 'Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in PostgreSQL ausnutzen, um seine Privilegien zu erhöhen.', 'published': '2026-06-26T07:26:37Z', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1800'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7158/ | CVE-2026-4878 | IBM MQ Agent: CVSS (Max): None | http://portal.auscert.org.au/bulletins/ESB-2026.7158/ | 2026-06-30T00:13:04Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7158
Multiple vulnerabilities in IBM MQ Agent images
30 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: IBM MQ Agent
Publisher: IBM
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-34181
CVE-2026-34183 CVE-2026-42764 CVE-2026-42768
CVE-2026-42769 CVE-2026-42770 CVE-2026-45445
CVE-2026-45446 CVE-2024-3651 CVE-2026-40356
CVE-2026-40355 CVE-2025-14087 CVE-2025-14512
CVE-2026-4878 CVE-2026-2100 CVE-2026-45134
CVE-2026-44681 CVE-2026-45409 CVE-2026-44843
CVE-2026-48522 CVE-2026-48523 CVE-2026-48524
CVE-2026-48525 CVE-2026-28390 CVE-2026-29111
CVE-2025-15281 CVE-2025-4598 CVE-2026-4437
CVE-2026-4438 CVE-2026-34180 CVE-2026-34182
CVE-2026-42767 CVE-2026-45447 CVE-2026-7383
CVE-2026-9076 CVE-2026-48710
Original Bulletin:
https://www.ibm.com/support/pages/node/7278328
Comment: CVSS (Max): None available when published
EPSS (Max): None available when published
- --------------------------BEGIN INCLUDED TEXT--------------------
IBM Support
Document Information
Document number : 7278328
Modified date : More support for: IBM MQ Agent
Product : IBM MQ Agent
Component : -
Software version : IBM MQ Agent v2.0.0
Operating system(s): RedHat OpenShift
Security Bulletin
Summary
Multiple vulnerabilities were addressed in IBM MQ Agent images
Vulnerability Details
CVEID: CVE-2026-45134
DESCRIPTION: LangSmith Client SDKs provide SDK's for interacting with the
LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the
LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in
Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt
manifests from the LangSmith Hub. These manifests may contain serialized
LangChain objects and model configuration that affect runtime behavior. When
pulling a public prompt by owner/name identifier, the manifest content is
controlled by an external party, but prior versions of the SDK did not
distinguish this from pulling a prompt within the caller's own organization.
This vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.
CWE: CWE-502: Deserialization of Untrusted Data
CVSS Source: security-advisories@github.com
CVSS Base score: 7.1
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)
CVEID: CVE-2026-4438
DESCRIPTION: Calling gethostbyaddr or gethostbyaddr_r with a configured
nsswitch.conf that specifies the library's DNS backend in the GNU C library
version 2.34 to version 2.43 could result in an invalid DNS hostname being
returned to the caller in violation of the DNS specification.
CWE: CWE-20: Improper Input Validation
CVSS Source: CISA ADP
CVSS Base score: 5.4
CVSS Vector: (CVSS:3.1/AV:A/AC:L/P | 28c7bd6d6555df47ec786c995c46b57ff6670881c3d3495566430cb58303b582 | 2026-06-30 06:47:27.315299+03:00 | 2026-06-30 06:47:27.315299+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7158/', 'title': 'IBM MQ Agent: CVSS (Max): None', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7158 \n Multiple vulnerabilities in IBM MQ Agent images \n 30 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: IBM MQ Agent \nPublisher: IBM \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-34181 \n CVE-2026-34183 CVE-2026-42764 CVE-2026-42768 \n CVE-2026-42769 CVE-2026-42770 CVE-2026-45445 \n CVE-2026-45446 CVE-2024-3651 CVE-2026-40356 \n CVE-2026-40355 CVE-2025-14087 CVE-2025-14512 \n CVE-2026-4878 CVE-2026-2100 CVE-2026-45134 \n CVE-2026-44681 CVE-2026-45409 CVE-2026-44843 \n CVE-2026-48522 CVE-2026-48523 CVE-2026-48524 \n CVE-2026-48525 CVE-2026-28390 CVE-2026-29111 \n CVE-2025-15281 CVE-2025-4598 CVE-2026-4437 \n CVE-2026-4438 CVE-2026-34180 CVE-2026-34182 \n CVE-2026-42767 CVE-2026-45447 CVE-2026-7383 \n CVE-2026-9076 CVE-2026-48710 \n\nOriginal Bulletin:\n https://www.ibm.com/support/pages/node/7278328\n\nComment: CVSS (Max): None available when published \n \n EPSS (Max): None available when published \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nIBM Support\n\nDocument Information\n\nDocument number : 7278328\nModified date : More support for: IBM MQ Agent\nProduct : IBM MQ Agent\nComponent : -\nSoftware version : IBM MQ Agent v2.0.0\nOperating system(s): RedHat OpenShift\n\nSecurity Bulletin\n\n\nSummary\n\nMultiple vulnerabilities were addressed in IBM MQ Agent images\n\nVulnerability Details\n\nCVEID: CVE-2026-45134\nDESCRIPTION: LangSmith Client SDKs provide SDK's for interacting with the\nLangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the\nLangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in\nPython, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt\nmanifests from the LangSmith Hub. These manifests may contain serialized\nLangChain objects and model configuration that affect runtime behavior. When\npulling a public prompt by owner/name identifier, the manifest content is\ncontrolled by an external party, but prior versions of the SDK did not\ndistinguish this from pulling a prompt within the caller's own organization.\nThis vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.\nCWE: CWE-502: Deserialization of Untrusted Data\nCVSS Source: security-advisories@github.com\nCVSS Base score: 7.1\nCVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)\n\nCVEID: CVE-2026-4438\nDESCRIPTION: Calling gethostbyaddr or gethostbyaddr_r with a configured\nnsswitch.conf that specifies the library's DNS backend in the GNU C library\nversion 2.34 to version 2.43 could result in an invalid DNS hostname being\nreturned to the caller in violation of the DNS specification.\nCWE: CWE-20: Improper Input Validation\nCVSS Source: CISA ADP\nCVSS Base score: 5.4\nCVSS Vector: (CVSS:3.1/AV:A/AC:L/P", 'published': '2026-06-30T00:13:04Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7158/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7158/ | CVE-2026-2100 | IBM MQ Agent: CVSS (Max): None | http://portal.auscert.org.au/bulletins/ESB-2026.7158/ | 2026-06-30T00:13:04Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7158
Multiple vulnerabilities in IBM MQ Agent images
30 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: IBM MQ Agent
Publisher: IBM
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-34181
CVE-2026-34183 CVE-2026-42764 CVE-2026-42768
CVE-2026-42769 CVE-2026-42770 CVE-2026-45445
CVE-2026-45446 CVE-2024-3651 CVE-2026-40356
CVE-2026-40355 CVE-2025-14087 CVE-2025-14512
CVE-2026-4878 CVE-2026-2100 CVE-2026-45134
CVE-2026-44681 CVE-2026-45409 CVE-2026-44843
CVE-2026-48522 CVE-2026-48523 CVE-2026-48524
CVE-2026-48525 CVE-2026-28390 CVE-2026-29111
CVE-2025-15281 CVE-2025-4598 CVE-2026-4437
CVE-2026-4438 CVE-2026-34180 CVE-2026-34182
CVE-2026-42767 CVE-2026-45447 CVE-2026-7383
CVE-2026-9076 CVE-2026-48710
Original Bulletin:
https://www.ibm.com/support/pages/node/7278328
Comment: CVSS (Max): None available when published
EPSS (Max): None available when published
- --------------------------BEGIN INCLUDED TEXT--------------------
IBM Support
Document Information
Document number : 7278328
Modified date : More support for: IBM MQ Agent
Product : IBM MQ Agent
Component : -
Software version : IBM MQ Agent v2.0.0
Operating system(s): RedHat OpenShift
Security Bulletin
Summary
Multiple vulnerabilities were addressed in IBM MQ Agent images
Vulnerability Details
CVEID: CVE-2026-45134
DESCRIPTION: LangSmith Client SDKs provide SDK's for interacting with the
LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the
LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in
Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt
manifests from the LangSmith Hub. These manifests may contain serialized
LangChain objects and model configuration that affect runtime behavior. When
pulling a public prompt by owner/name identifier, the manifest content is
controlled by an external party, but prior versions of the SDK did not
distinguish this from pulling a prompt within the caller's own organization.
This vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.
CWE: CWE-502: Deserialization of Untrusted Data
CVSS Source: security-advisories@github.com
CVSS Base score: 7.1
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)
CVEID: CVE-2026-4438
DESCRIPTION: Calling gethostbyaddr or gethostbyaddr_r with a configured
nsswitch.conf that specifies the library's DNS backend in the GNU C library
version 2.34 to version 2.43 could result in an invalid DNS hostname being
returned to the caller in violation of the DNS specification.
CWE: CWE-20: Improper Input Validation
CVSS Source: CISA ADP
CVSS Base score: 5.4
CVSS Vector: (CVSS:3.1/AV:A/AC:L/P | 6581118b8e09c7e786d8a6fc6b00bd03c620b35615f4aa90914106e16a7b59de | 2026-06-30 06:47:27.315299+03:00 | 2026-06-30 06:47:27.315299+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7158/', 'title': 'IBM MQ Agent: CVSS (Max): None', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7158 \n Multiple vulnerabilities in IBM MQ Agent images \n 30 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: IBM MQ Agent \nPublisher: IBM \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-34181 \n CVE-2026-34183 CVE-2026-42764 CVE-2026-42768 \n CVE-2026-42769 CVE-2026-42770 CVE-2026-45445 \n CVE-2026-45446 CVE-2024-3651 CVE-2026-40356 \n CVE-2026-40355 CVE-2025-14087 CVE-2025-14512 \n CVE-2026-4878 CVE-2026-2100 CVE-2026-45134 \n CVE-2026-44681 CVE-2026-45409 CVE-2026-44843 \n CVE-2026-48522 CVE-2026-48523 CVE-2026-48524 \n CVE-2026-48525 CVE-2026-28390 CVE-2026-29111 \n CVE-2025-15281 CVE-2025-4598 CVE-2026-4437 \n CVE-2026-4438 CVE-2026-34180 CVE-2026-34182 \n CVE-2026-42767 CVE-2026-45447 CVE-2026-7383 \n CVE-2026-9076 CVE-2026-48710 \n\nOriginal Bulletin:\n https://www.ibm.com/support/pages/node/7278328\n\nComment: CVSS (Max): None available when published \n \n EPSS (Max): None available when published \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nIBM Support\n\nDocument Information\n\nDocument number : 7278328\nModified date : More support for: IBM MQ Agent\nProduct : IBM MQ Agent\nComponent : -\nSoftware version : IBM MQ Agent v2.0.0\nOperating system(s): RedHat OpenShift\n\nSecurity Bulletin\n\n\nSummary\n\nMultiple vulnerabilities were addressed in IBM MQ Agent images\n\nVulnerability Details\n\nCVEID: CVE-2026-45134\nDESCRIPTION: LangSmith Client SDKs provide SDK's for interacting with the\nLangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the\nLangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in\nPython, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt\nmanifests from the LangSmith Hub. These manifests may contain serialized\nLangChain objects and model configuration that affect runtime behavior. When\npulling a public prompt by owner/name identifier, the manifest content is\ncontrolled by an external party, but prior versions of the SDK did not\ndistinguish this from pulling a prompt within the caller's own organization.\nThis vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.\nCWE: CWE-502: Deserialization of Untrusted Data\nCVSS Source: security-advisories@github.com\nCVSS Base score: 7.1\nCVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)\n\nCVEID: CVE-2026-4438\nDESCRIPTION: Calling gethostbyaddr or gethostbyaddr_r with a configured\nnsswitch.conf that specifies the library's DNS backend in the GNU C library\nversion 2.34 to version 2.43 could result in an invalid DNS hostname being\nreturned to the caller in violation of the DNS specification.\nCWE: CWE-20: Improper Input Validation\nCVSS Source: CISA ADP\nCVSS Base score: 5.4\nCVSS Vector: (CVSS:3.1/AV:A/AC:L/P", 'published': '2026-06-30T00:13:04Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7158/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7158/ | CVE-2026-45134 | IBM MQ Agent: CVSS (Max): None | http://portal.auscert.org.au/bulletins/ESB-2026.7158/ | 2026-06-30T00:13:04Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7158
Multiple vulnerabilities in IBM MQ Agent images
30 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: IBM MQ Agent
Publisher: IBM
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-34181
CVE-2026-34183 CVE-2026-42764 CVE-2026-42768
CVE-2026-42769 CVE-2026-42770 CVE-2026-45445
CVE-2026-45446 CVE-2024-3651 CVE-2026-40356
CVE-2026-40355 CVE-2025-14087 CVE-2025-14512
CVE-2026-4878 CVE-2026-2100 CVE-2026-45134
CVE-2026-44681 CVE-2026-45409 CVE-2026-44843
CVE-2026-48522 CVE-2026-48523 CVE-2026-48524
CVE-2026-48525 CVE-2026-28390 CVE-2026-29111
CVE-2025-15281 CVE-2025-4598 CVE-2026-4437
CVE-2026-4438 CVE-2026-34180 CVE-2026-34182
CVE-2026-42767 CVE-2026-45447 CVE-2026-7383
CVE-2026-9076 CVE-2026-48710
Original Bulletin:
https://www.ibm.com/support/pages/node/7278328
Comment: CVSS (Max): None available when published
EPSS (Max): None available when published
- --------------------------BEGIN INCLUDED TEXT--------------------
IBM Support
Document Information
Document number : 7278328
Modified date : More support for: IBM MQ Agent
Product : IBM MQ Agent
Component : -
Software version : IBM MQ Agent v2.0.0
Operating system(s): RedHat OpenShift
Security Bulletin
Summary
Multiple vulnerabilities were addressed in IBM MQ Agent images
Vulnerability Details
CVEID: CVE-2026-45134
DESCRIPTION: LangSmith Client SDKs provide SDK's for interacting with the
LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the
LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in
Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt
manifests from the LangSmith Hub. These manifests may contain serialized
LangChain objects and model configuration that affect runtime behavior. When
pulling a public prompt by owner/name identifier, the manifest content is
controlled by an external party, but prior versions of the SDK did not
distinguish this from pulling a prompt within the caller's own organization.
This vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.
CWE: CWE-502: Deserialization of Untrusted Data
CVSS Source: security-advisories@github.com
CVSS Base score: 7.1
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)
CVEID: CVE-2026-4438
DESCRIPTION: Calling gethostbyaddr or gethostbyaddr_r with a configured
nsswitch.conf that specifies the library's DNS backend in the GNU C library
version 2.34 to version 2.43 could result in an invalid DNS hostname being
returned to the caller in violation of the DNS specification.
CWE: CWE-20: Improper Input Validation
CVSS Source: CISA ADP
CVSS Base score: 5.4
CVSS Vector: (CVSS:3.1/AV:A/AC:L/P | d8c8c060527df710daf3fab2f649f0a8fe58ce524238b73d24b3cc46d90fbf78 | 2026-06-30 06:47:27.315299+03:00 | 2026-06-30 06:47:27.315299+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7158/', 'title': 'IBM MQ Agent: CVSS (Max): None', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7158 \n Multiple vulnerabilities in IBM MQ Agent images \n 30 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: IBM MQ Agent \nPublisher: IBM \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-34181 \n CVE-2026-34183 CVE-2026-42764 CVE-2026-42768 \n CVE-2026-42769 CVE-2026-42770 CVE-2026-45445 \n CVE-2026-45446 CVE-2024-3651 CVE-2026-40356 \n CVE-2026-40355 CVE-2025-14087 CVE-2025-14512 \n CVE-2026-4878 CVE-2026-2100 CVE-2026-45134 \n CVE-2026-44681 CVE-2026-45409 CVE-2026-44843 \n CVE-2026-48522 CVE-2026-48523 CVE-2026-48524 \n CVE-2026-48525 CVE-2026-28390 CVE-2026-29111 \n CVE-2025-15281 CVE-2025-4598 CVE-2026-4437 \n CVE-2026-4438 CVE-2026-34180 CVE-2026-34182 \n CVE-2026-42767 CVE-2026-45447 CVE-2026-7383 \n CVE-2026-9076 CVE-2026-48710 \n\nOriginal Bulletin:\n https://www.ibm.com/support/pages/node/7278328\n\nComment: CVSS (Max): None available when published \n \n EPSS (Max): None available when published \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nIBM Support\n\nDocument Information\n\nDocument number : 7278328\nModified date : More support for: IBM MQ Agent\nProduct : IBM MQ Agent\nComponent : -\nSoftware version : IBM MQ Agent v2.0.0\nOperating system(s): RedHat OpenShift\n\nSecurity Bulletin\n\n\nSummary\n\nMultiple vulnerabilities were addressed in IBM MQ Agent images\n\nVulnerability Details\n\nCVEID: CVE-2026-45134\nDESCRIPTION: LangSmith Client SDKs provide SDK's for interacting with the\nLangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the\nLangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in\nPython, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt\nmanifests from the LangSmith Hub. These manifests may contain serialized\nLangChain objects and model configuration that affect runtime behavior. When\npulling a public prompt by owner/name identifier, the manifest content is\ncontrolled by an external party, but prior versions of the SDK did not\ndistinguish this from pulling a prompt within the caller's own organization.\nThis vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.\nCWE: CWE-502: Deserialization of Untrusted Data\nCVSS Source: security-advisories@github.com\nCVSS Base score: 7.1\nCVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)\n\nCVEID: CVE-2026-4438\nDESCRIPTION: Calling gethostbyaddr or gethostbyaddr_r with a configured\nnsswitch.conf that specifies the library's DNS backend in the GNU C library\nversion 2.34 to version 2.43 could result in an invalid DNS hostname being\nreturned to the caller in violation of the DNS specification.\nCWE: CWE-20: Improper Input Validation\nCVSS Source: CISA ADP\nCVSS Base score: 5.4\nCVSS Vector: (CVSS:3.1/AV:A/AC:L/P", 'published': '2026-06-30T00:13:04Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7158/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7158/ | CVE-2026-44681 | IBM MQ Agent: CVSS (Max): None | http://portal.auscert.org.au/bulletins/ESB-2026.7158/ | 2026-06-30T00:13:04Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7158
Multiple vulnerabilities in IBM MQ Agent images
30 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: IBM MQ Agent
Publisher: IBM
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-34181
CVE-2026-34183 CVE-2026-42764 CVE-2026-42768
CVE-2026-42769 CVE-2026-42770 CVE-2026-45445
CVE-2026-45446 CVE-2024-3651 CVE-2026-40356
CVE-2026-40355 CVE-2025-14087 CVE-2025-14512
CVE-2026-4878 CVE-2026-2100 CVE-2026-45134
CVE-2026-44681 CVE-2026-45409 CVE-2026-44843
CVE-2026-48522 CVE-2026-48523 CVE-2026-48524
CVE-2026-48525 CVE-2026-28390 CVE-2026-29111
CVE-2025-15281 CVE-2025-4598 CVE-2026-4437
CVE-2026-4438 CVE-2026-34180 CVE-2026-34182
CVE-2026-42767 CVE-2026-45447 CVE-2026-7383
CVE-2026-9076 CVE-2026-48710
Original Bulletin:
https://www.ibm.com/support/pages/node/7278328
Comment: CVSS (Max): None available when published
EPSS (Max): None available when published
- --------------------------BEGIN INCLUDED TEXT--------------------
IBM Support
Document Information
Document number : 7278328
Modified date : More support for: IBM MQ Agent
Product : IBM MQ Agent
Component : -
Software version : IBM MQ Agent v2.0.0
Operating system(s): RedHat OpenShift
Security Bulletin
Summary
Multiple vulnerabilities were addressed in IBM MQ Agent images
Vulnerability Details
CVEID: CVE-2026-45134
DESCRIPTION: LangSmith Client SDKs provide SDK's for interacting with the
LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the
LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in
Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt
manifests from the LangSmith Hub. These manifests may contain serialized
LangChain objects and model configuration that affect runtime behavior. When
pulling a public prompt by owner/name identifier, the manifest content is
controlled by an external party, but prior versions of the SDK did not
distinguish this from pulling a prompt within the caller's own organization.
This vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.
CWE: CWE-502: Deserialization of Untrusted Data
CVSS Source: security-advisories@github.com
CVSS Base score: 7.1
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)
CVEID: CVE-2026-4438
DESCRIPTION: Calling gethostbyaddr or gethostbyaddr_r with a configured
nsswitch.conf that specifies the library's DNS backend in the GNU C library
version 2.34 to version 2.43 could result in an invalid DNS hostname being
returned to the caller in violation of the DNS specification.
CWE: CWE-20: Improper Input Validation
CVSS Source: CISA ADP
CVSS Base score: 5.4
CVSS Vector: (CVSS:3.1/AV:A/AC:L/P | 783664865a08039cccd3c53bb7cff95247aebe8b2a819f0e88d8690dff0c0c66 | 2026-06-30 06:47:27.315299+03:00 | 2026-06-30 06:47:27.315299+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7158/', 'title': 'IBM MQ Agent: CVSS (Max): None', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7158 \n Multiple vulnerabilities in IBM MQ Agent images \n 30 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: IBM MQ Agent \nPublisher: IBM \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-34181 \n CVE-2026-34183 CVE-2026-42764 CVE-2026-42768 \n CVE-2026-42769 CVE-2026-42770 CVE-2026-45445 \n CVE-2026-45446 CVE-2024-3651 CVE-2026-40356 \n CVE-2026-40355 CVE-2025-14087 CVE-2025-14512 \n CVE-2026-4878 CVE-2026-2100 CVE-2026-45134 \n CVE-2026-44681 CVE-2026-45409 CVE-2026-44843 \n CVE-2026-48522 CVE-2026-48523 CVE-2026-48524 \n CVE-2026-48525 CVE-2026-28390 CVE-2026-29111 \n CVE-2025-15281 CVE-2025-4598 CVE-2026-4437 \n CVE-2026-4438 CVE-2026-34180 CVE-2026-34182 \n CVE-2026-42767 CVE-2026-45447 CVE-2026-7383 \n CVE-2026-9076 CVE-2026-48710 \n\nOriginal Bulletin:\n https://www.ibm.com/support/pages/node/7278328\n\nComment: CVSS (Max): None available when published \n \n EPSS (Max): None available when published \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nIBM Support\n\nDocument Information\n\nDocument number : 7278328\nModified date : More support for: IBM MQ Agent\nProduct : IBM MQ Agent\nComponent : -\nSoftware version : IBM MQ Agent v2.0.0\nOperating system(s): RedHat OpenShift\n\nSecurity Bulletin\n\n\nSummary\n\nMultiple vulnerabilities were addressed in IBM MQ Agent images\n\nVulnerability Details\n\nCVEID: CVE-2026-45134\nDESCRIPTION: LangSmith Client SDKs provide SDK's for interacting with the\nLangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the\nLangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in\nPython, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt\nmanifests from the LangSmith Hub. These manifests may contain serialized\nLangChain objects and model configuration that affect runtime behavior. When\npulling a public prompt by owner/name identifier, the manifest content is\ncontrolled by an external party, but prior versions of the SDK did not\ndistinguish this from pulling a prompt within the caller's own organization.\nThis vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.\nCWE: CWE-502: Deserialization of Untrusted Data\nCVSS Source: security-advisories@github.com\nCVSS Base score: 7.1\nCVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)\n\nCVEID: CVE-2026-4438\nDESCRIPTION: Calling gethostbyaddr or gethostbyaddr_r with a configured\nnsswitch.conf that specifies the library's DNS backend in the GNU C library\nversion 2.34 to version 2.43 could result in an invalid DNS hostname being\nreturned to the caller in violation of the DNS specification.\nCWE: CWE-20: Improper Input Validation\nCVSS Source: CISA ADP\nCVSS Base score: 5.4\nCVSS Vector: (CVSS:3.1/AV:A/AC:L/P", 'published': '2026-06-30T00:13:04Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7158/'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1695 | N/A | [NEU] [mittel] IBM i: Schwachstelle ermöglicht Denial of Service | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1695 | [NEU] [mittel] IBM i: Schwachstelle ermöglicht Denial of Service | 2ae6145ba3140d769971ad6e3bf0105450864d897dca31ba48212f5201a4a318 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1695', 'title': '[NEU] [mittel] IBM i: Schwachstelle ermöglicht Denial of Service', 'summary': '[NEU] [mittel] IBM i: Schwachstelle ermöglicht Denial of Service', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1695'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1694 | N/A | [NEU] [mittel] HP ScanJet: Schwachstelle ermöglicht Offenlegung von Informationen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1694 | [NEU] [mittel] HP ScanJet: Schwachstelle ermöglicht Offenlegung von Informationen | ec9e9c49a56a523b285d45a08692e93fcd2ec05cc2c582f7106781962995e84a | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1694', 'title': '[NEU] [mittel] HP ScanJet: Schwachstelle ermöglicht Offenlegung von Informationen', 'summary': '[NEU] [mittel] HP ScanJet: Schwachstelle ermöglicht Offenlegung von Informationen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1694'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2298 | N/A | [UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2298 | [UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen | eb9c53de5c05f00320c3070f30869c962e7428b75ecc9655235edeaa08c6c79c | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2298', 'title': '[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen', 'summary': '[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2298'} | |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | CVE-2026-4786 | Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | 2026-06-26T01:22:47Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7092
Red Hat AI Inference Server 3.3.5 (Spyre)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference (RHAI) Server
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786
CVE-2025-62164 CVE-2026-10118 CVE-2026-4878
CVE-2026-6100 CVE-2026-22773 CVE-2026-22778
CVE-2026-22807 CVE-2026-24779 CVE-2026-34588
CVE-2026-37555 CVE-2026-35385 CVE-2026-4775
CVE-2025-66448 CVE-2026-39979 CVE-2026-40164
CVE-2026-34982 CVE-2026-48818
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30087
Comment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30087 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server 3.3.5 (spyre)
Type/Severity
Security Advisory: Critical
Topic
Red Hat AI Inference Server 3.3.5 (Spyre) is now available.
Description
Red Hat AI Inference Server
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-62164
o CVE-2025-66448
o CVE-2026-10118
o CVE-2026-22773
o CVE-2026-22778
o CVE-2026-22807
o CVE-2026-24779
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-48818
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release o | 1285be849fa4b698087d98042cc375b8b64ba0c39b6a27947aa4e8132090554f | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/', 'title': 'Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7092 \n Red Hat AI Inference Server 3.3.5 (Spyre) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference (RHAI) Server \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786 \n CVE-2025-62164 CVE-2026-10118 CVE-2026-4878 \n CVE-2026-6100 CVE-2026-22773 CVE-2026-22778 \n CVE-2026-22807 CVE-2026-24779 CVE-2026-34588 \n CVE-2026-37555 CVE-2026-35385 CVE-2026-4775 \n CVE-2025-66448 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-34982 CVE-2026-48818 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30087\n\nComment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30087 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server 3.3.5 (spyre)\n\nType/Severity\nSecurity Advisory: Critical\n\nTopic\n\nRed Hat AI Inference Server 3.3.5 (Spyre) is now available.\n\nDescription\n\nRed Hat AI Inference Server\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-62164\n o CVE-2025-66448\n o CVE-2026-10118\n o CVE-2026-22773\n o CVE-2026-22778\n o CVE-2026-22807\n o CVE-2026-24779\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-48818\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release o", 'published': '2026-06-26T01:22:47Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1564 | N/A | [UPDATE] [hoch] Budibase: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1564 | [UPDATE] [hoch] Budibase: Mehrere Schwachstellen | 03965b1b13fa7e5692ee315872e06d42fea3b464959f5dc7916bbd2a3d16732b | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1564', 'title': '[UPDATE] [hoch] Budibase: Mehrere Schwachstellen', 'summary': '[UPDATE] [hoch] Budibase: Mehrere Schwachstellen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1564'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1557 | N/A | [UPDATE] [hoch] Budibase: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1557 | [UPDATE] [hoch] Budibase: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen | d04e1e84fc30d666bf7290183af115d4d7380aca89bd6387718c195a54a4e7d2 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1557', 'title': '[UPDATE] [hoch] Budibase: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen', 'summary': '[UPDATE] [hoch] Budibase: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1557'} | |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | CVE-2025-62164 | Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | 2026-06-26T01:22:47Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7092
Red Hat AI Inference Server 3.3.5 (Spyre)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference (RHAI) Server
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786
CVE-2025-62164 CVE-2026-10118 CVE-2026-4878
CVE-2026-6100 CVE-2026-22773 CVE-2026-22778
CVE-2026-22807 CVE-2026-24779 CVE-2026-34588
CVE-2026-37555 CVE-2026-35385 CVE-2026-4775
CVE-2025-66448 CVE-2026-39979 CVE-2026-40164
CVE-2026-34982 CVE-2026-48818
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30087
Comment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30087 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server 3.3.5 (spyre)
Type/Severity
Security Advisory: Critical
Topic
Red Hat AI Inference Server 3.3.5 (Spyre) is now available.
Description
Red Hat AI Inference Server
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-62164
o CVE-2025-66448
o CVE-2026-10118
o CVE-2026-22773
o CVE-2026-22778
o CVE-2026-22807
o CVE-2026-24779
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-48818
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release o | 6482a50900ea064ee4189a29538bf6a663779394fb70083b3d0fbdd042033ac3 | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/', 'title': 'Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7092 \n Red Hat AI Inference Server 3.3.5 (Spyre) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference (RHAI) Server \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786 \n CVE-2025-62164 CVE-2026-10118 CVE-2026-4878 \n CVE-2026-6100 CVE-2026-22773 CVE-2026-22778 \n CVE-2026-22807 CVE-2026-24779 CVE-2026-34588 \n CVE-2026-37555 CVE-2026-35385 CVE-2026-4775 \n CVE-2025-66448 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-34982 CVE-2026-48818 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30087\n\nComment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30087 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server 3.3.5 (spyre)\n\nType/Severity\nSecurity Advisory: Critical\n\nTopic\n\nRed Hat AI Inference Server 3.3.5 (Spyre) is now available.\n\nDescription\n\nRed Hat AI Inference Server\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-62164\n o CVE-2025-66448\n o CVE-2026-10118\n o CVE-2026-22773\n o CVE-2026-22778\n o CVE-2026-22807\n o CVE-2026-24779\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-48818\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release o", 'published': '2026-06-26T01:22:47Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/'} |
cert_pl | tag:cert.pl,2026-05-19:/en/posts/2026/05/CVE-2026-42096/ | CVE-2026-42096 | Vulnerabilities in Sparx Systems products | https://cert.pl/en/posts/2026/05/CVE-2026-42096/ | 2026-05-19T09:55:00Z | CERT Polska has received a report about 5 vulnerabilities (from CVE-2026-42096 to CVE-2026-42100) found in Sparx Systems products: Pro Cloud Server and Enterprise Architect. | 3079b0d35aca7bbac178a55e1ee9dbb3226edc366723693bcba06dc16c65920e | 2026-05-29 02:12:35.327921+03:00 | 2026-06-22 18:33:39.304927+03:00 | {'link': 'https://cert.pl/en/posts/2026/05/CVE-2026-42096/', 'title': 'Vulnerabilities in Sparx Systems products', 'summary': 'CERT Polska has received a report about 5 vulnerabilities (from CVE-2026-42096 to CVE-2026-42100) found in Sparx Systems products: Pro Cloud Server and Enterprise Architect.', 'published': '2026-05-19T09:55:00Z', 'advisory_id': 'tag:cert.pl,2026-05-19:/en/posts/2026/05/CVE-2026-42096/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | CVE-2026-10118 | Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | 2026-06-26T01:22:47Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7092
Red Hat AI Inference Server 3.3.5 (Spyre)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference (RHAI) Server
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786
CVE-2025-62164 CVE-2026-10118 CVE-2026-4878
CVE-2026-6100 CVE-2026-22773 CVE-2026-22778
CVE-2026-22807 CVE-2026-24779 CVE-2026-34588
CVE-2026-37555 CVE-2026-35385 CVE-2026-4775
CVE-2025-66448 CVE-2026-39979 CVE-2026-40164
CVE-2026-34982 CVE-2026-48818
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30087
Comment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30087 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server 3.3.5 (spyre)
Type/Severity
Security Advisory: Critical
Topic
Red Hat AI Inference Server 3.3.5 (Spyre) is now available.
Description
Red Hat AI Inference Server
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-62164
o CVE-2025-66448
o CVE-2026-10118
o CVE-2026-22773
o CVE-2026-22778
o CVE-2026-22807
o CVE-2026-24779
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-48818
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release o | e4a91c56d4a87dba9dbd446821767287fadbe6cb6a29c2dfacb9b905e95d11b2 | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/', 'title': 'Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7092 \n Red Hat AI Inference Server 3.3.5 (Spyre) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference (RHAI) Server \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786 \n CVE-2025-62164 CVE-2026-10118 CVE-2026-4878 \n CVE-2026-6100 CVE-2026-22773 CVE-2026-22778 \n CVE-2026-22807 CVE-2026-24779 CVE-2026-34588 \n CVE-2026-37555 CVE-2026-35385 CVE-2026-4775 \n CVE-2025-66448 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-34982 CVE-2026-48818 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30087\n\nComment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30087 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server 3.3.5 (spyre)\n\nType/Severity\nSecurity Advisory: Critical\n\nTopic\n\nRed Hat AI Inference Server 3.3.5 (Spyre) is now available.\n\nDescription\n\nRed Hat AI Inference Server\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-62164\n o CVE-2025-66448\n o CVE-2026-10118\n o CVE-2026-22773\n o CVE-2026-22778\n o CVE-2026-22807\n o CVE-2026-24779\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-48818\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release o", 'published': '2026-06-26T01:22:47Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | CVE-2026-4878 | Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | 2026-06-26T01:22:47Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7092
Red Hat AI Inference Server 3.3.5 (Spyre)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference (RHAI) Server
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786
CVE-2025-62164 CVE-2026-10118 CVE-2026-4878
CVE-2026-6100 CVE-2026-22773 CVE-2026-22778
CVE-2026-22807 CVE-2026-24779 CVE-2026-34588
CVE-2026-37555 CVE-2026-35385 CVE-2026-4775
CVE-2025-66448 CVE-2026-39979 CVE-2026-40164
CVE-2026-34982 CVE-2026-48818
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30087
Comment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30087 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server 3.3.5 (spyre)
Type/Severity
Security Advisory: Critical
Topic
Red Hat AI Inference Server 3.3.5 (Spyre) is now available.
Description
Red Hat AI Inference Server
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-62164
o CVE-2025-66448
o CVE-2026-10118
o CVE-2026-22773
o CVE-2026-22778
o CVE-2026-22807
o CVE-2026-24779
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-48818
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release o | 1c486e5ce8d1b680b77fd3435221047a7571a3a4addd9cc4a5609eb7dd8924c2 | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/', 'title': 'Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7092 \n Red Hat AI Inference Server 3.3.5 (Spyre) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference (RHAI) Server \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786 \n CVE-2025-62164 CVE-2026-10118 CVE-2026-4878 \n CVE-2026-6100 CVE-2026-22773 CVE-2026-22778 \n CVE-2026-22807 CVE-2026-24779 CVE-2026-34588 \n CVE-2026-37555 CVE-2026-35385 CVE-2026-4775 \n CVE-2025-66448 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-34982 CVE-2026-48818 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30087\n\nComment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30087 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server 3.3.5 (spyre)\n\nType/Severity\nSecurity Advisory: Critical\n\nTopic\n\nRed Hat AI Inference Server 3.3.5 (Spyre) is now available.\n\nDescription\n\nRed Hat AI Inference Server\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-62164\n o CVE-2025-66448\n o CVE-2026-10118\n o CVE-2026-22773\n o CVE-2026-22778\n o CVE-2026-22807\n o CVE-2026-24779\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-48818\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release o", 'published': '2026-06-26T01:22:47Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | CVE-2026-6100 | Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | 2026-06-26T01:22:47Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7092
Red Hat AI Inference Server 3.3.5 (Spyre)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference (RHAI) Server
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786
CVE-2025-62164 CVE-2026-10118 CVE-2026-4878
CVE-2026-6100 CVE-2026-22773 CVE-2026-22778
CVE-2026-22807 CVE-2026-24779 CVE-2026-34588
CVE-2026-37555 CVE-2026-35385 CVE-2026-4775
CVE-2025-66448 CVE-2026-39979 CVE-2026-40164
CVE-2026-34982 CVE-2026-48818
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30087
Comment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30087 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server 3.3.5 (spyre)
Type/Severity
Security Advisory: Critical
Topic
Red Hat AI Inference Server 3.3.5 (Spyre) is now available.
Description
Red Hat AI Inference Server
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-62164
o CVE-2025-66448
o CVE-2026-10118
o CVE-2026-22773
o CVE-2026-22778
o CVE-2026-22807
o CVE-2026-24779
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-48818
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release o | 9aeadffc90ec1e55baf8b8d31bcd42caa6a496c411212315f044fd4bd58f4f19 | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/', 'title': 'Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7092 \n Red Hat AI Inference Server 3.3.5 (Spyre) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference (RHAI) Server \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786 \n CVE-2025-62164 CVE-2026-10118 CVE-2026-4878 \n CVE-2026-6100 CVE-2026-22773 CVE-2026-22778 \n CVE-2026-22807 CVE-2026-24779 CVE-2026-34588 \n CVE-2026-37555 CVE-2026-35385 CVE-2026-4775 \n CVE-2025-66448 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-34982 CVE-2026-48818 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30087\n\nComment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30087 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server 3.3.5 (spyre)\n\nType/Severity\nSecurity Advisory: Critical\n\nTopic\n\nRed Hat AI Inference Server 3.3.5 (Spyre) is now available.\n\nDescription\n\nRed Hat AI Inference Server\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-62164\n o CVE-2025-66448\n o CVE-2026-10118\n o CVE-2026-22773\n o CVE-2026-22778\n o CVE-2026-22807\n o CVE-2026-24779\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-48818\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release o", 'published': '2026-06-26T01:22:47Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | CVE-2026-22773 | Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | 2026-06-26T01:22:47Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7092
Red Hat AI Inference Server 3.3.5 (Spyre)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference (RHAI) Server
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786
CVE-2025-62164 CVE-2026-10118 CVE-2026-4878
CVE-2026-6100 CVE-2026-22773 CVE-2026-22778
CVE-2026-22807 CVE-2026-24779 CVE-2026-34588
CVE-2026-37555 CVE-2026-35385 CVE-2026-4775
CVE-2025-66448 CVE-2026-39979 CVE-2026-40164
CVE-2026-34982 CVE-2026-48818
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30087
Comment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30087 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server 3.3.5 (spyre)
Type/Severity
Security Advisory: Critical
Topic
Red Hat AI Inference Server 3.3.5 (Spyre) is now available.
Description
Red Hat AI Inference Server
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-62164
o CVE-2025-66448
o CVE-2026-10118
o CVE-2026-22773
o CVE-2026-22778
o CVE-2026-22807
o CVE-2026-24779
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-48818
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release o | aa020260f8a6ee3ec05c7b7e61a5e4cc5859b5ec68c4c68bac6303f0147e652b | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/', 'title': 'Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7092 \n Red Hat AI Inference Server 3.3.5 (Spyre) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference (RHAI) Server \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786 \n CVE-2025-62164 CVE-2026-10118 CVE-2026-4878 \n CVE-2026-6100 CVE-2026-22773 CVE-2026-22778 \n CVE-2026-22807 CVE-2026-24779 CVE-2026-34588 \n CVE-2026-37555 CVE-2026-35385 CVE-2026-4775 \n CVE-2025-66448 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-34982 CVE-2026-48818 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30087\n\nComment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30087 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server 3.3.5 (spyre)\n\nType/Severity\nSecurity Advisory: Critical\n\nTopic\n\nRed Hat AI Inference Server 3.3.5 (Spyre) is now available.\n\nDescription\n\nRed Hat AI Inference Server\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-62164\n o CVE-2025-66448\n o CVE-2026-10118\n o CVE-2026-22773\n o CVE-2026-22778\n o CVE-2026-22807\n o CVE-2026-24779\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-48818\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release o", 'published': '2026-06-26T01:22:47Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | CVE-2026-22778 | Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | 2026-06-26T01:22:47Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7092
Red Hat AI Inference Server 3.3.5 (Spyre)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference (RHAI) Server
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786
CVE-2025-62164 CVE-2026-10118 CVE-2026-4878
CVE-2026-6100 CVE-2026-22773 CVE-2026-22778
CVE-2026-22807 CVE-2026-24779 CVE-2026-34588
CVE-2026-37555 CVE-2026-35385 CVE-2026-4775
CVE-2025-66448 CVE-2026-39979 CVE-2026-40164
CVE-2026-34982 CVE-2026-48818
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30087
Comment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30087 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server 3.3.5 (spyre)
Type/Severity
Security Advisory: Critical
Topic
Red Hat AI Inference Server 3.3.5 (Spyre) is now available.
Description
Red Hat AI Inference Server
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-62164
o CVE-2025-66448
o CVE-2026-10118
o CVE-2026-22773
o CVE-2026-22778
o CVE-2026-22807
o CVE-2026-24779
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-48818
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release o | aefea5724958ea6969811fd57b8e139554a9bc68b5fea33b62a2f531603ddf20 | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/', 'title': 'Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7092 \n Red Hat AI Inference Server 3.3.5 (Spyre) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference (RHAI) Server \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786 \n CVE-2025-62164 CVE-2026-10118 CVE-2026-4878 \n CVE-2026-6100 CVE-2026-22773 CVE-2026-22778 \n CVE-2026-22807 CVE-2026-24779 CVE-2026-34588 \n CVE-2026-37555 CVE-2026-35385 CVE-2026-4775 \n CVE-2025-66448 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-34982 CVE-2026-48818 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30087\n\nComment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30087 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server 3.3.5 (spyre)\n\nType/Severity\nSecurity Advisory: Critical\n\nTopic\n\nRed Hat AI Inference Server 3.3.5 (Spyre) is now available.\n\nDescription\n\nRed Hat AI Inference Server\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-62164\n o CVE-2025-66448\n o CVE-2026-10118\n o CVE-2026-22773\n o CVE-2026-22778\n o CVE-2026-22807\n o CVE-2026-24779\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-48818\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release o", 'published': '2026-06-26T01:22:47Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1477 | N/A | [UPDATE] [hoch] Budibase: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1477 | [UPDATE] [hoch] Budibase: Mehrere Schwachstellen | ca26e8d6b7e5ead547eafd448d69fefd598217a3b110e279065dc5a115ef4585 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1477', 'title': '[UPDATE] [hoch] Budibase: Mehrere Schwachstellen', 'summary': '[UPDATE] [hoch] Budibase: Mehrere Schwachstellen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1477'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1482 | N/A | [UPDATE] [hoch] AMD Prozessor: Mehrere Schwachstellen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1482 | 2026-06-25T09:08:30Z | Ein Angreifer kann mehrere Schwachstellen in AMD Prozessor ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen – sogar mit Administratorrechten –, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand herbeizuführen. | c3163b0af87e2b05582b5c484029de2ea8fe8910cee58ba11467523c529f5d6b | 2026-05-29 02:12:30.351260+03:00 | 2026-06-25 13:41:03.462994+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1482', 'title': '[UPDATE] [hoch] AMD Prozessor: Mehrere Schwachstellen', 'summary': 'Ein Angreifer kann mehrere Schwachstellen in AMD Prozessor ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen – sogar mit Administratorrechten –, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand herbeizuführen.', 'published': '2026-06-25T09:08:30Z', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1482'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1455 | N/A | [UPDATE] [mittel] Budibase: Schwachstelle ermöglicht Offenlegung von Informationen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1455 | [UPDATE] [mittel] Budibase: Schwachstelle ermöglicht Offenlegung von Informationen | 9671a627ad4cd2e5dd9624d4dcd1207d3625e393b041cee8ea2c816c899d51fb | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1455', 'title': '[UPDATE] [mittel] Budibase: Schwachstelle ermöglicht Offenlegung von Informationen', 'summary': '[UPDATE] [mittel] Budibase: Schwachstelle ermöglicht Offenlegung von Informationen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1455'} | |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | CVE-2026-22807 | Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | 2026-06-26T01:22:47Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7092
Red Hat AI Inference Server 3.3.5 (Spyre)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference (RHAI) Server
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786
CVE-2025-62164 CVE-2026-10118 CVE-2026-4878
CVE-2026-6100 CVE-2026-22773 CVE-2026-22778
CVE-2026-22807 CVE-2026-24779 CVE-2026-34588
CVE-2026-37555 CVE-2026-35385 CVE-2026-4775
CVE-2025-66448 CVE-2026-39979 CVE-2026-40164
CVE-2026-34982 CVE-2026-48818
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30087
Comment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30087 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server 3.3.5 (spyre)
Type/Severity
Security Advisory: Critical
Topic
Red Hat AI Inference Server 3.3.5 (Spyre) is now available.
Description
Red Hat AI Inference Server
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-62164
o CVE-2025-66448
o CVE-2026-10118
o CVE-2026-22773
o CVE-2026-22778
o CVE-2026-22807
o CVE-2026-24779
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-48818
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release o | cfa10a3eca202c3ce9d391aaa68d2278aada04b3d4d2397ad278dec622f3111f | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/', 'title': 'Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7092 \n Red Hat AI Inference Server 3.3.5 (Spyre) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference (RHAI) Server \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786 \n CVE-2025-62164 CVE-2026-10118 CVE-2026-4878 \n CVE-2026-6100 CVE-2026-22773 CVE-2026-22778 \n CVE-2026-22807 CVE-2026-24779 CVE-2026-34588 \n CVE-2026-37555 CVE-2026-35385 CVE-2026-4775 \n CVE-2025-66448 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-34982 CVE-2026-48818 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30087\n\nComment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30087 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server 3.3.5 (spyre)\n\nType/Severity\nSecurity Advisory: Critical\n\nTopic\n\nRed Hat AI Inference Server 3.3.5 (Spyre) is now available.\n\nDescription\n\nRed Hat AI Inference Server\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-62164\n o CVE-2025-66448\n o CVE-2026-10118\n o CVE-2026-22773\n o CVE-2026-22778\n o CVE-2026-22807\n o CVE-2026-24779\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-48818\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release o", 'published': '2026-06-26T01:22:47Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.5797/ | CVE-2026-27144 | OpenShift Container Platform 4.19.32: CVSS (Max): 9.1 | http://portal.auscert.org.au/bulletins/ESB-2026.5797/ | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.5797
OpenShift Container Platform 4.19.32 bug fix and security update
28 May 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: OpenShift Container Platform 4.19.32
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-35469 CVE-2025-61726 CVE-2026-33186
CVE-2026-40175 CVE-2026-4800 CVE-2025-66031
CVE-2026-27143 CVE-2026-27144 CVE-2026-29063
CVE-2026-25679 CVE-2026-22029 CVE-2026-34986
CVE-2026-34043 CVE-2025-12816
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:20041
Comment: CVSS (Max): 9.1 CVE-2026-33186 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS (Max): 0.1% (23rd) CVE-2026-29063 2026-05-27
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:20041 - Security Advisory
Issued: 2026-05-27
Updated: 2026-05-27
Synopsis
Container platform 4.19.32 bug fix and security update
Type/Severity
Security Advisory: Important
Topic
Red Hat OpenShift Container Platform release 4.19.32 is now available with
updates to packages and images that fix several bugs and add enhancements.
This release includes a security update for Red Hat OpenShift Container
Platform 4.19.
Red Hat Product Security has rated this update as having a security impact of
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives
a detailed severity rating, is available for each vulnerability from the CVE
link(s) in the References section.
Description
Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes
application platform solution designed for on-premise or private cloud
deployments.
This advisory contains the container images for Red Hat OpenShift Container
Platform 4.19.32. See the following advisory for the RPM packages for this
release:
https://access.redhat.com/errata/RHBA-2026:20039
Space precludes documenting all of the container images in this advisory. See
the following Release Notes documentation, which will be updated shortly for
this release, for details about these changes:
https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html
/release_notes/
Solution
For OpenShift Container Platform 4.19 see the following documentation, which
will be updated shortly for this release, for important instructions on how to
upgrade your cluster and fully apply this asynchronous errata update:
https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html
/release_notes/
You may download the oc tool and use it to inspect release image metadata for
x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be
found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.
The sha values for the release are as follows:
(For x86_64 architecture)
The image digest is
sha256:1bd5ad0745f446a798a4038e4d04cf651213f71bc4e76dd9349f5c6968135f9b
(For s390x architec | a4c72c7653ff9c62cf11bf6d94a91960d3ebb9ecbf4ab2fee0d883da10d861a5 | 2026-05-29 02:12:38.557132+03:00 | 2026-05-29 02:12:38.557132+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.5797/', 'title': 'OpenShift Container Platform 4.19.32: CVSS (Max): 9.1', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.5797 \n OpenShift Container Platform 4.19.32 bug fix and security update \n 28 May 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: OpenShift Container Platform 4.19.32 \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-35469 CVE-2025-61726 CVE-2026-33186 \n CVE-2026-40175 CVE-2026-4800 CVE-2025-66031 \n CVE-2026-27143 CVE-2026-27144 CVE-2026-29063 \n CVE-2026-25679 CVE-2026-22029 CVE-2026-34986 \n CVE-2026-34043 CVE-2025-12816 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:20041\n\nComment: CVSS (Max): 9.1 CVE-2026-33186 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N\n \n EPSS (Max): 0.1% (23rd) CVE-2026-29063 2026-05-27 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:20041 - Security Advisory\n\nIssued: 2026-05-27\nUpdated: 2026-05-27\n\nSynopsis\nContainer platform 4.19.32 bug fix and security update\n\nType/Severity\nSecurity Advisory: Important\n\nTopic\n\nRed Hat OpenShift Container Platform release 4.19.32 is now available with\nupdates to packages and images that fix several bugs and add enhancements.\n\nThis release includes a security update for Red Hat OpenShift Container\nPlatform 4.19.\n\nRed Hat Product Security has rated this update as having a security impact of\nImportant. A Common Vulnerability Scoring System (CVSS) base score, which gives\na detailed severity rating, is available for each vulnerability from the CVE\nlink(s) in the References section.\n\nDescription\n\nRed Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes\napplication platform solution designed for on-premise or private cloud\ndeployments.\n\nThis advisory contains the container images for Red Hat OpenShift Container\nPlatform 4.19.32. See the following advisory for the RPM packages for this\nrelease:\n\nhttps://access.redhat.com/errata/RHBA-2026:20039\n\nSpace precludes documenting all of the container images in this advisory. See\nthe following Release Notes documentation, which will be updated shortly for\nthis release, for details about these changes:\n\nhttps://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html\n/release_notes/\n\nSolution\n\nFor OpenShift Container Platform 4.19 see the following documentation, which\nwill be updated shortly for this release, for important instructions on how to\nupgrade your cluster and fully apply this asynchronous errata update:\n\nhttps://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html\n/release_notes/\n\nYou may download the oc tool and use it to inspect release image metadata for\nx86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be\nfound at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.\n\nThe sha values for the release are as follows:\n\n(For x86_64 architecture)\nThe image digest is\nsha256:1bd5ad0745f446a798a4038e4d04cf651213f71bc4e76dd9349f5c6968135f9b\n\n(For s390x architec", 'published': '', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.5797/'} | |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | CVE-2026-24779 | Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | 2026-06-26T01:22:47Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7092
Red Hat AI Inference Server 3.3.5 (Spyre)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference (RHAI) Server
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786
CVE-2025-62164 CVE-2026-10118 CVE-2026-4878
CVE-2026-6100 CVE-2026-22773 CVE-2026-22778
CVE-2026-22807 CVE-2026-24779 CVE-2026-34588
CVE-2026-37555 CVE-2026-35385 CVE-2026-4775
CVE-2025-66448 CVE-2026-39979 CVE-2026-40164
CVE-2026-34982 CVE-2026-48818
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30087
Comment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30087 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server 3.3.5 (spyre)
Type/Severity
Security Advisory: Critical
Topic
Red Hat AI Inference Server 3.3.5 (Spyre) is now available.
Description
Red Hat AI Inference Server
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-62164
o CVE-2025-66448
o CVE-2026-10118
o CVE-2026-22773
o CVE-2026-22778
o CVE-2026-22807
o CVE-2026-24779
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-48818
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release o | ba8e6047ba60195ca031341c4366c6086f7d96e4e8b4ad96755b5c7887e32312 | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/', 'title': 'Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7092 \n Red Hat AI Inference Server 3.3.5 (Spyre) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference (RHAI) Server \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786 \n CVE-2025-62164 CVE-2026-10118 CVE-2026-4878 \n CVE-2026-6100 CVE-2026-22773 CVE-2026-22778 \n CVE-2026-22807 CVE-2026-24779 CVE-2026-34588 \n CVE-2026-37555 CVE-2026-35385 CVE-2026-4775 \n CVE-2025-66448 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-34982 CVE-2026-48818 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30087\n\nComment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30087 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server 3.3.5 (spyre)\n\nType/Severity\nSecurity Advisory: Critical\n\nTopic\n\nRed Hat AI Inference Server 3.3.5 (Spyre) is now available.\n\nDescription\n\nRed Hat AI Inference Server\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-62164\n o CVE-2025-66448\n o CVE-2026-10118\n o CVE-2026-22773\n o CVE-2026-22778\n o CVE-2026-22807\n o CVE-2026-24779\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-48818\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release o", 'published': '2026-06-26T01:22:47Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | CVE-2026-34588 | Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | 2026-06-26T01:22:47Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7092
Red Hat AI Inference Server 3.3.5 (Spyre)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference (RHAI) Server
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786
CVE-2025-62164 CVE-2026-10118 CVE-2026-4878
CVE-2026-6100 CVE-2026-22773 CVE-2026-22778
CVE-2026-22807 CVE-2026-24779 CVE-2026-34588
CVE-2026-37555 CVE-2026-35385 CVE-2026-4775
CVE-2025-66448 CVE-2026-39979 CVE-2026-40164
CVE-2026-34982 CVE-2026-48818
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30087
Comment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30087 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server 3.3.5 (spyre)
Type/Severity
Security Advisory: Critical
Topic
Red Hat AI Inference Server 3.3.5 (Spyre) is now available.
Description
Red Hat AI Inference Server
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-62164
o CVE-2025-66448
o CVE-2026-10118
o CVE-2026-22773
o CVE-2026-22778
o CVE-2026-22807
o CVE-2026-24779
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-48818
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release o | 19d63710aff1527d4c204323ce6bbc868e7ea43999f7f5c79e87d3918bb62981 | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/', 'title': 'Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7092 \n Red Hat AI Inference Server 3.3.5 (Spyre) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference (RHAI) Server \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786 \n CVE-2025-62164 CVE-2026-10118 CVE-2026-4878 \n CVE-2026-6100 CVE-2026-22773 CVE-2026-22778 \n CVE-2026-22807 CVE-2026-24779 CVE-2026-34588 \n CVE-2026-37555 CVE-2026-35385 CVE-2026-4775 \n CVE-2025-66448 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-34982 CVE-2026-48818 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30087\n\nComment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30087 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server 3.3.5 (spyre)\n\nType/Severity\nSecurity Advisory: Critical\n\nTopic\n\nRed Hat AI Inference Server 3.3.5 (Spyre) is now available.\n\nDescription\n\nRed Hat AI Inference Server\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-62164\n o CVE-2025-66448\n o CVE-2026-10118\n o CVE-2026-22773\n o CVE-2026-22778\n o CVE-2026-22807\n o CVE-2026-24779\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-48818\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release o", 'published': '2026-06-26T01:22:47Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | CVE-2026-37555 | Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | 2026-06-26T01:22:47Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7092
Red Hat AI Inference Server 3.3.5 (Spyre)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference (RHAI) Server
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786
CVE-2025-62164 CVE-2026-10118 CVE-2026-4878
CVE-2026-6100 CVE-2026-22773 CVE-2026-22778
CVE-2026-22807 CVE-2026-24779 CVE-2026-34588
CVE-2026-37555 CVE-2026-35385 CVE-2026-4775
CVE-2025-66448 CVE-2026-39979 CVE-2026-40164
CVE-2026-34982 CVE-2026-48818
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30087
Comment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30087 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server 3.3.5 (spyre)
Type/Severity
Security Advisory: Critical
Topic
Red Hat AI Inference Server 3.3.5 (Spyre) is now available.
Description
Red Hat AI Inference Server
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-62164
o CVE-2025-66448
o CVE-2026-10118
o CVE-2026-22773
o CVE-2026-22778
o CVE-2026-22807
o CVE-2026-24779
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-48818
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release o | d7d162f3cb2565acd3a422af91db624f51dbb674c8e360db5cdf59168d535265 | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/', 'title': 'Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7092 \n Red Hat AI Inference Server 3.3.5 (Spyre) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference (RHAI) Server \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786 \n CVE-2025-62164 CVE-2026-10118 CVE-2026-4878 \n CVE-2026-6100 CVE-2026-22773 CVE-2026-22778 \n CVE-2026-22807 CVE-2026-24779 CVE-2026-34588 \n CVE-2026-37555 CVE-2026-35385 CVE-2026-4775 \n CVE-2025-66448 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-34982 CVE-2026-48818 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30087\n\nComment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30087 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server 3.3.5 (spyre)\n\nType/Severity\nSecurity Advisory: Critical\n\nTopic\n\nRed Hat AI Inference Server 3.3.5 (Spyre) is now available.\n\nDescription\n\nRed Hat AI Inference Server\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-62164\n o CVE-2025-66448\n o CVE-2026-10118\n o CVE-2026-22773\n o CVE-2026-22778\n o CVE-2026-22807\n o CVE-2026-24779\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-48818\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release o", 'published': '2026-06-26T01:22:47Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | CVE-2026-35385 | Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | 2026-06-26T01:22:47Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7092
Red Hat AI Inference Server 3.3.5 (Spyre)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference (RHAI) Server
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786
CVE-2025-62164 CVE-2026-10118 CVE-2026-4878
CVE-2026-6100 CVE-2026-22773 CVE-2026-22778
CVE-2026-22807 CVE-2026-24779 CVE-2026-34588
CVE-2026-37555 CVE-2026-35385 CVE-2026-4775
CVE-2025-66448 CVE-2026-39979 CVE-2026-40164
CVE-2026-34982 CVE-2026-48818
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30087
Comment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30087 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server 3.3.5 (spyre)
Type/Severity
Security Advisory: Critical
Topic
Red Hat AI Inference Server 3.3.5 (Spyre) is now available.
Description
Red Hat AI Inference Server
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-62164
o CVE-2025-66448
o CVE-2026-10118
o CVE-2026-22773
o CVE-2026-22778
o CVE-2026-22807
o CVE-2026-24779
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-48818
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release o | 682f0bebda531f62194d9e85e57504c2ff63dcc734f00db7417ec5dc6b969455 | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/', 'title': 'Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7092 \n Red Hat AI Inference Server 3.3.5 (Spyre) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference (RHAI) Server \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786 \n CVE-2025-62164 CVE-2026-10118 CVE-2026-4878 \n CVE-2026-6100 CVE-2026-22773 CVE-2026-22778 \n CVE-2026-22807 CVE-2026-24779 CVE-2026-34588 \n CVE-2026-37555 CVE-2026-35385 CVE-2026-4775 \n CVE-2025-66448 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-34982 CVE-2026-48818 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30087\n\nComment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30087 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server 3.3.5 (spyre)\n\nType/Severity\nSecurity Advisory: Critical\n\nTopic\n\nRed Hat AI Inference Server 3.3.5 (Spyre) is now available.\n\nDescription\n\nRed Hat AI Inference Server\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-62164\n o CVE-2025-66448\n o CVE-2026-10118\n o CVE-2026-22773\n o CVE-2026-22778\n o CVE-2026-22807\n o CVE-2026-24779\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-48818\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release o", 'published': '2026-06-26T01:22:47Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | CVE-2026-4775 | Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | 2026-06-26T01:22:47Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7092
Red Hat AI Inference Server 3.3.5 (Spyre)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference (RHAI) Server
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786
CVE-2025-62164 CVE-2026-10118 CVE-2026-4878
CVE-2026-6100 CVE-2026-22773 CVE-2026-22778
CVE-2026-22807 CVE-2026-24779 CVE-2026-34588
CVE-2026-37555 CVE-2026-35385 CVE-2026-4775
CVE-2025-66448 CVE-2026-39979 CVE-2026-40164
CVE-2026-34982 CVE-2026-48818
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30087
Comment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30087 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server 3.3.5 (spyre)
Type/Severity
Security Advisory: Critical
Topic
Red Hat AI Inference Server 3.3.5 (Spyre) is now available.
Description
Red Hat AI Inference Server
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-62164
o CVE-2025-66448
o CVE-2026-10118
o CVE-2026-22773
o CVE-2026-22778
o CVE-2026-22807
o CVE-2026-24779
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-48818
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release o | 7bf8480f52e7c56ace08af72ee85c819c0985000283b67b4a8ebc16c2327100e | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/', 'title': 'Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7092 \n Red Hat AI Inference Server 3.3.5 (Spyre) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference (RHAI) Server \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786 \n CVE-2025-62164 CVE-2026-10118 CVE-2026-4878 \n CVE-2026-6100 CVE-2026-22773 CVE-2026-22778 \n CVE-2026-22807 CVE-2026-24779 CVE-2026-34588 \n CVE-2026-37555 CVE-2026-35385 CVE-2026-4775 \n CVE-2025-66448 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-34982 CVE-2026-48818 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30087\n\nComment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30087 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server 3.3.5 (spyre)\n\nType/Severity\nSecurity Advisory: Critical\n\nTopic\n\nRed Hat AI Inference Server 3.3.5 (Spyre) is now available.\n\nDescription\n\nRed Hat AI Inference Server\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-62164\n o CVE-2025-66448\n o CVE-2026-10118\n o CVE-2026-22773\n o CVE-2026-22778\n o CVE-2026-22807\n o CVE-2026-24779\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-48818\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release o", 'published': '2026-06-26T01:22:47Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | CVE-2025-66448 | Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | 2026-06-26T01:22:47Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7092
Red Hat AI Inference Server 3.3.5 (Spyre)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference (RHAI) Server
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786
CVE-2025-62164 CVE-2026-10118 CVE-2026-4878
CVE-2026-6100 CVE-2026-22773 CVE-2026-22778
CVE-2026-22807 CVE-2026-24779 CVE-2026-34588
CVE-2026-37555 CVE-2026-35385 CVE-2026-4775
CVE-2025-66448 CVE-2026-39979 CVE-2026-40164
CVE-2026-34982 CVE-2026-48818
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30087
Comment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30087 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server 3.3.5 (spyre)
Type/Severity
Security Advisory: Critical
Topic
Red Hat AI Inference Server 3.3.5 (Spyre) is now available.
Description
Red Hat AI Inference Server
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-62164
o CVE-2025-66448
o CVE-2026-10118
o CVE-2026-22773
o CVE-2026-22778
o CVE-2026-22807
o CVE-2026-24779
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-48818
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release o | 803438d90a85919940bf70df685909c1eb82c1d118dff8557a90e0c368380ed4 | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/', 'title': 'Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7092 \n Red Hat AI Inference Server 3.3.5 (Spyre) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference (RHAI) Server \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786 \n CVE-2025-62164 CVE-2026-10118 CVE-2026-4878 \n CVE-2026-6100 CVE-2026-22773 CVE-2026-22778 \n CVE-2026-22807 CVE-2026-24779 CVE-2026-34588 \n CVE-2026-37555 CVE-2026-35385 CVE-2026-4775 \n CVE-2025-66448 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-34982 CVE-2026-48818 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30087\n\nComment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30087 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server 3.3.5 (spyre)\n\nType/Severity\nSecurity Advisory: Critical\n\nTopic\n\nRed Hat AI Inference Server 3.3.5 (Spyre) is now available.\n\nDescription\n\nRed Hat AI Inference Server\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-62164\n o CVE-2025-66448\n o CVE-2026-10118\n o CVE-2026-22773\n o CVE-2026-22778\n o CVE-2026-22807\n o CVE-2026-24779\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-48818\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release o", 'published': '2026-06-26T01:22:47Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | CVE-2026-39979 | Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | 2026-06-26T01:22:47Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7092
Red Hat AI Inference Server 3.3.5 (Spyre)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference (RHAI) Server
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786
CVE-2025-62164 CVE-2026-10118 CVE-2026-4878
CVE-2026-6100 CVE-2026-22773 CVE-2026-22778
CVE-2026-22807 CVE-2026-24779 CVE-2026-34588
CVE-2026-37555 CVE-2026-35385 CVE-2026-4775
CVE-2025-66448 CVE-2026-39979 CVE-2026-40164
CVE-2026-34982 CVE-2026-48818
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30087
Comment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30087 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server 3.3.5 (spyre)
Type/Severity
Security Advisory: Critical
Topic
Red Hat AI Inference Server 3.3.5 (Spyre) is now available.
Description
Red Hat AI Inference Server
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-62164
o CVE-2025-66448
o CVE-2026-10118
o CVE-2026-22773
o CVE-2026-22778
o CVE-2026-22807
o CVE-2026-24779
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-48818
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release o | f3ad514799e4a2e9b16209a1f437fcc54ad7984bfe5ccc4e711ebb0ae9dbc1ee | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/', 'title': 'Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7092 \n Red Hat AI Inference Server 3.3.5 (Spyre) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference (RHAI) Server \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786 \n CVE-2025-62164 CVE-2026-10118 CVE-2026-4878 \n CVE-2026-6100 CVE-2026-22773 CVE-2026-22778 \n CVE-2026-22807 CVE-2026-24779 CVE-2026-34588 \n CVE-2026-37555 CVE-2026-35385 CVE-2026-4775 \n CVE-2025-66448 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-34982 CVE-2026-48818 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30087\n\nComment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30087 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server 3.3.5 (spyre)\n\nType/Severity\nSecurity Advisory: Critical\n\nTopic\n\nRed Hat AI Inference Server 3.3.5 (Spyre) is now available.\n\nDescription\n\nRed Hat AI Inference Server\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-62164\n o CVE-2025-66448\n o CVE-2026-10118\n o CVE-2026-22773\n o CVE-2026-22778\n o CVE-2026-22807\n o CVE-2026-24779\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-48818\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release o", 'published': '2026-06-26T01:22:47Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | CVE-2026-40164 | Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8 | http://portal.auscert.org.au/bulletins/ESB-2026.7092/ | 2026-06-26T01:22:47Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7092
Red Hat AI Inference Server 3.3.5 (Spyre)
26 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: Red Hat AI Inference (RHAI) Server
Publisher: Red Hat
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786
CVE-2025-62164 CVE-2026-10118 CVE-2026-4878
CVE-2026-6100 CVE-2026-22773 CVE-2026-22778
CVE-2026-22807 CVE-2026-24779 CVE-2026-34588
CVE-2026-37555 CVE-2026-35385 CVE-2026-4775
CVE-2025-66448 CVE-2026-39979 CVE-2026-40164
CVE-2026-34982 CVE-2026-48818
Original Bulletin:
https://access.redhat.com/errata/RHSA-2026:30087
Comment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25
- --------------------------BEGIN INCLUDED TEXT--------------------
RHSA-2026:30087 - Security Advisory
Issued: 2026-06-25
Updated: 2026-06-25
Synopsis
Red Hat AI Inference Server 3.3.5 (spyre)
Type/Severity
Security Advisory: Critical
Topic
Red Hat AI Inference Server 3.3.5 (Spyre) is now available.
Description
Red Hat AI Inference Server
Solution
Affected Products
o Red Hat AI Inference Server
Fixes
(none)
CVEs
o CVE-2025-62164
o CVE-2025-66448
o CVE-2026-10118
o CVE-2026-22773
o CVE-2026-22778
o CVE-2026-22807
o CVE-2026-24779
o CVE-2026-34588
o CVE-2026-34982
o CVE-2026-35385
o CVE-2026-37555
o CVE-2026-39979
o CVE-2026-40164
o CVE-2026-44431
o CVE-2026-44432
o CVE-2026-4775
o CVE-2026-4786
o CVE-2026-4878
o CVE-2026-48818
o CVE-2026-6100
References
o https://access.redhat.com/security/updates/classification/
o https://www.redhat.com/en/products/ai/inference-server
- --------------------------END INCLUDED TEXT----------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AUSCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AUSCERT's members. As
AUSCERT did not write the document quoted above, AUSCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AUSCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release o | 77828519d06796a632ff1fb107c327f2f0a7c584f5a0ae27c5c803af15f1e0bd | 2026-06-26 04:55:13.496816+03:00 | 2026-06-26 04:55:13.496816+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/', 'title': 'Red Hat AI Inference (RHAI) Server: CVSS (Max): 9.8', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7092 \n Red Hat AI Inference Server 3.3.5 (Spyre) \n 26 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: Red Hat AI Inference (RHAI) Server \nPublisher: Red Hat \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-4786 \n CVE-2025-62164 CVE-2026-10118 CVE-2026-4878 \n CVE-2026-6100 CVE-2026-22773 CVE-2026-22778 \n CVE-2026-22807 CVE-2026-24779 CVE-2026-34588 \n CVE-2026-37555 CVE-2026-35385 CVE-2026-4775 \n CVE-2025-66448 CVE-2026-39979 CVE-2026-40164 \n CVE-2026-34982 CVE-2026-48818 \n\nOriginal Bulletin:\n https://access.redhat.com/errata/RHSA-2026:30087\n\nComment: CVSS (Max): 9.8 CVE-2026-22778 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)\n CVSS Source: Red Hat \n Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n \n EPSS (Max): 3.3% (86th) CVE-2026-22778 2026-06-25 \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nRHSA-2026:30087 - Security Advisory\n\nIssued: 2026-06-25\nUpdated: 2026-06-25\n\nSynopsis\nRed Hat AI Inference Server 3.3.5 (spyre)\n\nType/Severity\nSecurity Advisory: Critical\n\nTopic\n\nRed Hat AI Inference Server 3.3.5 (Spyre) is now available.\n\nDescription\n\nRed Hat AI Inference Server\n\nSolution\n\nAffected Products\n\n o Red Hat AI Inference Server\n\nFixes\n\n(none)\n\nCVEs\n\n o CVE-2025-62164\n o CVE-2025-66448\n o CVE-2026-10118\n o CVE-2026-22773\n o CVE-2026-22778\n o CVE-2026-22807\n o CVE-2026-24779\n o CVE-2026-34588\n o CVE-2026-34982\n o CVE-2026-35385\n o CVE-2026-37555\n o CVE-2026-39979\n o CVE-2026-40164\n o CVE-2026-44431\n o CVE-2026-44432\n o CVE-2026-4775\n o CVE-2026-4786\n o CVE-2026-4878\n o CVE-2026-48818\n o CVE-2026-6100\n\nReferences\n\n o https://access.redhat.com/security/updates/classification/\n o https://www.redhat.com/en/products/ai/inference-server\n\n- --------------------------END INCLUDED TEXT----------------------\n\nYou have received this e-mail bulletin as a result of your organisation's\nregistration with AUSCERT. The mailing list you are subscribed to is\nmaintained within your organisation, so if you do not wish to continue\nreceiving these bulletins you should contact your local IT manager. If\nyou do not know who that is, please send an email to auscert@auscert.org.au\nand we will forward your request to the appropriate person.\n\nNOTE: Third Party Rights\nThis security bulletin is provided as a service to AUSCERT's members. As\nAUSCERT did not write the document quoted above, AUSCERT has had no control\nover its content. The decision to follow or act on information or advice\ncontained in this security bulletin is the responsibility of each user or\norganisation, and should be considered in accordance with your organisation's\nsite policies and procedures. AUSCERT takes no responsibility for consequences\nwhich may arise from following or acting on information or advice contained in\nthis security bulletin.\n\nNOTE: This is only the original release o", 'published': '2026-06-26T01:22:47Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7092/'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0789 | N/A | [UPDATE] [mittel] HTTP/2: Mehrere Schwachstellen ermöglichen Denial of Service | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0789 | 2026-06-26T07:26:35Z | Ein entfernter, anonymer Angreifer kann eine Schwachstellen in verschiedenen http/2 Implementierungen ausnutzen, um einen Denial of Service Angriff durchzuführen. | 499ab4e3c3f60bd80aa813107f5616126aa781fe3477fe1d200479f24ea9aeba | 2026-06-18 12:45:43.397785+03:00 | 2026-06-26 12:34:22.977075+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0789', 'title': '[UPDATE] [mittel] HTTP/2: Mehrere Schwachstellen ermöglichen Denial of Service', 'summary': 'Ein entfernter, anonymer Angreifer kann eine Schwachstellen in verschiedenen http/2 Implementierungen ausnutzen, um einen Denial of Service Angriff durchzuführen.', 'published': '2026-06-26T07:26:35Z', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0789'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1431 | N/A | [UPDATE] [mittel] IBM MQ: Schwachstelle ermöglicht Offenlegung von Informationen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1431 | [UPDATE] [mittel] IBM MQ: Schwachstelle ermöglicht Offenlegung von Informationen | a068651beb5b7e0cc7ecd4effbb7880658f715a1180361d13aa3dd7d4904baf3 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1431', 'title': '[UPDATE] [mittel] IBM MQ: Schwachstelle ermöglicht Offenlegung von Informationen', 'summary': '[UPDATE] [mittel] IBM MQ: Schwachstelle ermöglicht Offenlegung von Informationen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1431'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1402 | N/A | [UPDATE] [mittel] Budibase: Schwachstelle ermöglicht Offenlegung von Informationen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1402 | [UPDATE] [mittel] Budibase: Schwachstelle ermöglicht Offenlegung von Informationen | c2872d3460283b8ac447edb80e244d1b61f19fa30732a8c52a5af5fc8c5db2ea | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1402', 'title': '[UPDATE] [mittel] Budibase: Schwachstelle ermöglicht Offenlegung von Informationen', 'summary': '[UPDATE] [mittel] Budibase: Schwachstelle ermöglicht Offenlegung von Informationen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1402'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1403 | N/A | [UPDATE] [mittel] IBM App Connect Enterprise: Schwachstelle ermöglicht Offenlegung von Informationen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1403 | [UPDATE] [mittel] IBM App Connect Enterprise: Schwachstelle ermöglicht Offenlegung von Informationen | 53c11ef360998eb89a30e27fd1687c13e41af773ca07ec8e8d8b2f3ccebadb46 | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1403', 'title': '[UPDATE] [mittel] IBM App Connect Enterprise: Schwachstelle ermöglicht Offenlegung von Informationen', 'summary': '[UPDATE] [mittel] IBM App Connect Enterprise: Schwachstelle ermöglicht Offenlegung von Informationen', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1403'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1367 | N/A | [UPDATE] [hoch] Red Hat Advanced Cluster Management und Multicluster engine for Kubernetes: Schwachstelle ermöglicht Codeausführung oder DoS | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1367 | [UPDATE] [hoch] Red Hat Advanced Cluster Management und Multicluster engine for Kubernetes: Schwachstelle ermöglicht Codeausführung oder DoS | 9d213f0ef99f45b2ccde58edaf57e8bb2a6560e97e3c08a1531c7376c964daee | 2026-05-29 02:12:30.351260+03:00 | 2026-05-29 02:12:30.351260+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1367', 'title': '[UPDATE] [hoch] Red Hat Advanced Cluster Management und Multicluster engine for Kubernetes: Schwachstelle ermöglicht Codeausführung oder DoS', 'summary': '[UPDATE] [hoch] Red Hat Advanced Cluster Management und Multicluster engine for Kubernetes: Schwachstelle ermöglicht Codeausführung oder DoS', 'published': '', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1367'} | |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1326 | N/A | [UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1326 | 2026-06-23T07:27:41Z | Ein lokaler Angreifer kann eine Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsvorkehrungen zu umgehen. | 97c119c8593aebe672b55e41ffdad259a61864b87653e9307ffbbc32578eda1e | 2026-06-23 12:38:20.190255+03:00 | 2026-06-23 12:38:20.190255+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1326', 'title': '[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen', 'summary': 'Ein lokaler Angreifer kann eine Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsvorkehrungen zu umgehen.', 'published': '2026-06-23T07:27:41Z', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1326'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7158/ | CVE-2026-45409 | IBM MQ Agent: CVSS (Max): None | http://portal.auscert.org.au/bulletins/ESB-2026.7158/ | 2026-06-30T00:13:04Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7158
Multiple vulnerabilities in IBM MQ Agent images
30 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: IBM MQ Agent
Publisher: IBM
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-34181
CVE-2026-34183 CVE-2026-42764 CVE-2026-42768
CVE-2026-42769 CVE-2026-42770 CVE-2026-45445
CVE-2026-45446 CVE-2024-3651 CVE-2026-40356
CVE-2026-40355 CVE-2025-14087 CVE-2025-14512
CVE-2026-4878 CVE-2026-2100 CVE-2026-45134
CVE-2026-44681 CVE-2026-45409 CVE-2026-44843
CVE-2026-48522 CVE-2026-48523 CVE-2026-48524
CVE-2026-48525 CVE-2026-28390 CVE-2026-29111
CVE-2025-15281 CVE-2025-4598 CVE-2026-4437
CVE-2026-4438 CVE-2026-34180 CVE-2026-34182
CVE-2026-42767 CVE-2026-45447 CVE-2026-7383
CVE-2026-9076 CVE-2026-48710
Original Bulletin:
https://www.ibm.com/support/pages/node/7278328
Comment: CVSS (Max): None available when published
EPSS (Max): None available when published
- --------------------------BEGIN INCLUDED TEXT--------------------
IBM Support
Document Information
Document number : 7278328
Modified date : More support for: IBM MQ Agent
Product : IBM MQ Agent
Component : -
Software version : IBM MQ Agent v2.0.0
Operating system(s): RedHat OpenShift
Security Bulletin
Summary
Multiple vulnerabilities were addressed in IBM MQ Agent images
Vulnerability Details
CVEID: CVE-2026-45134
DESCRIPTION: LangSmith Client SDKs provide SDK's for interacting with the
LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the
LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in
Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt
manifests from the LangSmith Hub. These manifests may contain serialized
LangChain objects and model configuration that affect runtime behavior. When
pulling a public prompt by owner/name identifier, the manifest content is
controlled by an external party, but prior versions of the SDK did not
distinguish this from pulling a prompt within the caller's own organization.
This vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.
CWE: CWE-502: Deserialization of Untrusted Data
CVSS Source: security-advisories@github.com
CVSS Base score: 7.1
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)
CVEID: CVE-2026-4438
DESCRIPTION: Calling gethostbyaddr or gethostbyaddr_r with a configured
nsswitch.conf that specifies the library's DNS backend in the GNU C library
version 2.34 to version 2.43 could result in an invalid DNS hostname being
returned to the caller in violation of the DNS specification.
CWE: CWE-20: Improper Input Validation
CVSS Source: CISA ADP
CVSS Base score: 5.4
CVSS Vector: (CVSS:3.1/AV:A/AC:L/P | 613f24ef7349acee5403c623c5b5c3c59bf8ac3f518a75e96279e8bcf3b790a1 | 2026-06-30 06:47:27.315299+03:00 | 2026-06-30 06:47:27.315299+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7158/', 'title': 'IBM MQ Agent: CVSS (Max): None', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7158 \n Multiple vulnerabilities in IBM MQ Agent images \n 30 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: IBM MQ Agent \nPublisher: IBM \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-34181 \n CVE-2026-34183 CVE-2026-42764 CVE-2026-42768 \n CVE-2026-42769 CVE-2026-42770 CVE-2026-45445 \n CVE-2026-45446 CVE-2024-3651 CVE-2026-40356 \n CVE-2026-40355 CVE-2025-14087 CVE-2025-14512 \n CVE-2026-4878 CVE-2026-2100 CVE-2026-45134 \n CVE-2026-44681 CVE-2026-45409 CVE-2026-44843 \n CVE-2026-48522 CVE-2026-48523 CVE-2026-48524 \n CVE-2026-48525 CVE-2026-28390 CVE-2026-29111 \n CVE-2025-15281 CVE-2025-4598 CVE-2026-4437 \n CVE-2026-4438 CVE-2026-34180 CVE-2026-34182 \n CVE-2026-42767 CVE-2026-45447 CVE-2026-7383 \n CVE-2026-9076 CVE-2026-48710 \n\nOriginal Bulletin:\n https://www.ibm.com/support/pages/node/7278328\n\nComment: CVSS (Max): None available when published \n \n EPSS (Max): None available when published \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nIBM Support\n\nDocument Information\n\nDocument number : 7278328\nModified date : More support for: IBM MQ Agent\nProduct : IBM MQ Agent\nComponent : -\nSoftware version : IBM MQ Agent v2.0.0\nOperating system(s): RedHat OpenShift\n\nSecurity Bulletin\n\n\nSummary\n\nMultiple vulnerabilities were addressed in IBM MQ Agent images\n\nVulnerability Details\n\nCVEID: CVE-2026-45134\nDESCRIPTION: LangSmith Client SDKs provide SDK's for interacting with the\nLangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the\nLangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in\nPython, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt\nmanifests from the LangSmith Hub. These manifests may contain serialized\nLangChain objects and model configuration that affect runtime behavior. When\npulling a public prompt by owner/name identifier, the manifest content is\ncontrolled by an external party, but prior versions of the SDK did not\ndistinguish this from pulling a prompt within the caller's own organization.\nThis vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.\nCWE: CWE-502: Deserialization of Untrusted Data\nCVSS Source: security-advisories@github.com\nCVSS Base score: 7.1\nCVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)\n\nCVEID: CVE-2026-4438\nDESCRIPTION: Calling gethostbyaddr or gethostbyaddr_r with a configured\nnsswitch.conf that specifies the library's DNS backend in the GNU C library\nversion 2.34 to version 2.43 could result in an invalid DNS hostname being\nreturned to the caller in violation of the DNS specification.\nCWE: CWE-20: Improper Input Validation\nCVSS Source: CISA ADP\nCVSS Base score: 5.4\nCVSS Vector: (CVSS:3.1/AV:A/AC:L/P", 'published': '2026-06-30T00:13:04Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7158/'} |
bsi | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1352 | N/A | [UPDATE] [niedrig] Postfix: Schwachstelle ermöglicht Denial of Service | https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1352 | 2026-06-25T09:08:05Z | Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Postfix ausnutzen, um einen Denial of Service Angriff durchzuführen. | 4113ce0e27be70afd9d2ebeaa6a5dd941ade5b5e3abb063406e66bb85d927bfb | 2026-06-15 19:56:10.514200+03:00 | 2026-06-25 13:41:03.462994+03:00 | {'link': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1352', 'title': '[UPDATE] [niedrig] Postfix: Schwachstelle ermöglicht Denial of Service', 'summary': 'Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Postfix ausnutzen, um einen Denial of Service Angriff durchzuführen.', 'published': '2026-06-25T09:08:05Z', 'advisory_id': 'https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1352'} |
cert_pl | tag:cert.pl,2026-05-15:/en/posts/2026/05/CVE-2026-7182/ | CVE-2026-7182 | Vulnerabilities in DHTMLX software | https://cert.pl/en/posts/2026/05/CVE-2026-7182/ | 2026-05-15T11:55:00Z | CERT Polska has received a report about 3 vulnerabilities (CVE-2026-7182, CVE-2026-41552 and CVE-2026-41553) found in DHTMLX software. | e610f181b6759ae8b80644e9842bd9769d88cf146255ace875873f3e7ca565be | 2026-05-29 02:12:35.327921+03:00 | 2026-06-22 18:33:39.304927+03:00 | {'link': 'https://cert.pl/en/posts/2026/05/CVE-2026-7182/', 'title': 'Vulnerabilities in DHTMLX software', 'summary': 'CERT Polska has received a report about 3 vulnerabilities (CVE-2026-7182, CVE-2026-41552 and CVE-2026-41553) found in DHTMLX software.', 'published': '2026-05-15T11:55:00Z', 'advisory_id': 'tag:cert.pl,2026-05-15:/en/posts/2026/05/CVE-2026-7182/'} |
auscert | http://portal.auscert.org.au/bulletins/ESB-2026.7158/ | CVE-2026-44843 | IBM MQ Agent: CVSS (Max): None | http://portal.auscert.org.au/bulletins/ESB-2026.7158/ | 2026-06-30T00:13:04Z | <pre>===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2026.7158
Multiple vulnerabilities in IBM MQ Agent images
30 June 2026
===========================================================================
AUSCERT Security Bulletin Summary
---------------------------------
Product: IBM MQ Agent
Publisher: IBM
Operating System: Red Hat
Resolution: Patch/Upgrade
CVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-34181
CVE-2026-34183 CVE-2026-42764 CVE-2026-42768
CVE-2026-42769 CVE-2026-42770 CVE-2026-45445
CVE-2026-45446 CVE-2024-3651 CVE-2026-40356
CVE-2026-40355 CVE-2025-14087 CVE-2025-14512
CVE-2026-4878 CVE-2026-2100 CVE-2026-45134
CVE-2026-44681 CVE-2026-45409 CVE-2026-44843
CVE-2026-48522 CVE-2026-48523 CVE-2026-48524
CVE-2026-48525 CVE-2026-28390 CVE-2026-29111
CVE-2025-15281 CVE-2025-4598 CVE-2026-4437
CVE-2026-4438 CVE-2026-34180 CVE-2026-34182
CVE-2026-42767 CVE-2026-45447 CVE-2026-7383
CVE-2026-9076 CVE-2026-48710
Original Bulletin:
https://www.ibm.com/support/pages/node/7278328
Comment: CVSS (Max): None available when published
EPSS (Max): None available when published
- --------------------------BEGIN INCLUDED TEXT--------------------
IBM Support
Document Information
Document number : 7278328
Modified date : More support for: IBM MQ Agent
Product : IBM MQ Agent
Component : -
Software version : IBM MQ Agent v2.0.0
Operating system(s): RedHat OpenShift
Security Bulletin
Summary
Multiple vulnerabilities were addressed in IBM MQ Agent images
Vulnerability Details
CVEID: CVE-2026-45134
DESCRIPTION: LangSmith Client SDKs provide SDK's for interacting with the
LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the
LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in
Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt
manifests from the LangSmith Hub. These manifests may contain serialized
LangChain objects and model configuration that affect runtime behavior. When
pulling a public prompt by owner/name identifier, the manifest content is
controlled by an external party, but prior versions of the SDK did not
distinguish this from pulling a prompt within the caller's own organization.
This vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.
CWE: CWE-502: Deserialization of Untrusted Data
CVSS Source: security-advisories@github.com
CVSS Base score: 7.1
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)
CVEID: CVE-2026-4438
DESCRIPTION: Calling gethostbyaddr or gethostbyaddr_r with a configured
nsswitch.conf that specifies the library's DNS backend in the GNU C library
version 2.34 to version 2.43 could result in an invalid DNS hostname being
returned to the caller in violation of the DNS specification.
CWE: CWE-20: Improper Input Validation
CVSS Source: CISA ADP
CVSS Base score: 5.4
CVSS Vector: (CVSS:3.1/AV:A/AC:L/P | 705f9c5d14c8bd8324047de5983ca8b2f9ab3f1a8952ff10ecb58bef05593104 | 2026-06-30 06:47:27.315299+03:00 | 2026-06-30 06:47:27.315299+03:00 | {'link': 'http://portal.auscert.org.au/bulletins/ESB-2026.7158/', 'title': 'IBM MQ Agent: CVSS (Max): None', 'summary': "<pre>===========================================================================\n AUSCERT External Security Bulletin Redistribution \n \n ESB-2026.7158 \n Multiple vulnerabilities in IBM MQ Agent images \n 30 June 2026 \n \n===========================================================================\n\n AUSCERT Security Bulletin Summary\n ---------------------------------\n\nProduct: IBM MQ Agent \nPublisher: IBM \nOperating System: Red Hat \nResolution: Patch/Upgrade \nCVE Names: CVE-2026-44432 CVE-2026-44431 CVE-2026-34181 \n CVE-2026-34183 CVE-2026-42764 CVE-2026-42768 \n CVE-2026-42769 CVE-2026-42770 CVE-2026-45445 \n CVE-2026-45446 CVE-2024-3651 CVE-2026-40356 \n CVE-2026-40355 CVE-2025-14087 CVE-2025-14512 \n CVE-2026-4878 CVE-2026-2100 CVE-2026-45134 \n CVE-2026-44681 CVE-2026-45409 CVE-2026-44843 \n CVE-2026-48522 CVE-2026-48523 CVE-2026-48524 \n CVE-2026-48525 CVE-2026-28390 CVE-2026-29111 \n CVE-2025-15281 CVE-2025-4598 CVE-2026-4437 \n CVE-2026-4438 CVE-2026-34180 CVE-2026-34182 \n CVE-2026-42767 CVE-2026-45447 CVE-2026-7383 \n CVE-2026-9076 CVE-2026-48710 \n\nOriginal Bulletin:\n https://www.ibm.com/support/pages/node/7278328\n\nComment: CVSS (Max): None available when published \n \n EPSS (Max): None available when published \n\n\n- --------------------------BEGIN INCLUDED TEXT--------------------\n\nIBM Support\n\nDocument Information\n\nDocument number : 7278328\nModified date : More support for: IBM MQ Agent\nProduct : IBM MQ Agent\nComponent : -\nSoftware version : IBM MQ Agent v2.0.0\nOperating system(s): RedHat OpenShift\n\nSecurity Bulletin\n\n\nSummary\n\nMultiple vulnerabilities were addressed in IBM MQ Agent images\n\nVulnerability Details\n\nCVEID: CVE-2026-45134\nDESCRIPTION: LangSmith Client SDKs provide SDK's for interacting with the\nLangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the\nLangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in\nPython, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt\nmanifests from the LangSmith Hub. These manifests may contain serialized\nLangChain objects and model configuration that affect runtime behavior. When\npulling a public prompt by owner/name identifier, the manifest content is\ncontrolled by an external party, but prior versions of the SDK did not\ndistinguish this from pulling a prompt within the caller's own organization.\nThis vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.\nCWE: CWE-502: Deserialization of Untrusted Data\nCVSS Source: security-advisories@github.com\nCVSS Base score: 7.1\nCVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)\n\nCVEID: CVE-2026-4438\nDESCRIPTION: Calling gethostbyaddr or gethostbyaddr_r with a configured\nnsswitch.conf that specifies the library's DNS backend in the GNU C library\nversion 2.34 to version 2.43 could result in an invalid DNS hostname being\nreturned to the caller in violation of the DNS specification.\nCWE: CWE-20: Improper Input Validation\nCVSS Source: CISA ADP\nCVSS Base score: 5.4\nCVSS Vector: (CVSS:3.1/AV:A/AC:L/P", 'published': '2026-06-30T00:13:04Z', 'advisory_id': 'http://portal.auscert.org.au/bulletins/ESB-2026.7158/'} |