A vulnerability identified as critical has been detected in kovidgoyal kitty up to 0.47.1. This issue affects the function os.open. The manipulation leads to link following.
This vulnerability is referenced as CVE-2026-54055. The attack can only be performed from a local environment. No exploit is available.
You should upgrade the affected component.
A vulnerability was found in Red Hat Enterprise Linux 6/7/8. It has been classified as critical. This impacts an unknown function. This manipulation causes link following.
This vulnerability appears as CVE-2026-54230. The attack requires local access. There is no available exploit.
A vulnerability described as problematic has been identified in ninenines cowlib 2.9.0. The affected element is an unknown function of the component Matching Parser. The manipulation results in http response splitting.
This vulnerability is identified as CVE-2026-43966. The attack can be executed remotely. There is not any exploit available.
It is advisable to implement a patch to correct this issue.
A vulnerability marked as problematic has been reported in Redmine up to 5.0.13/5.1.9/6.0.6. This impacts an unknown function. The manipulation leads to storing passwords in a recoverable format.
This vulnerability is uniquely identified as CVE-2026-1836. Local access is required to approach this attack. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability was found in Moby. It has been classified as problematic. Impacted is an unknown function. Performing a manipulation results in improper neutralization of script in an error message web page.
This vulnerability was named CVE-2026-41568. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability identified as critical has been detected in form-data up to 2.5.5/3.0.4/4.0.5. Affected by this issue is some unknown functionality. Performing a manipulation results in crlf injection.
This vulnerability is identified as CVE-2026-12143. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability was found in Moby. It has been declared as critical. The affected element is an unknown function. Executing a manipulation can lead to symlink following.
The identification of this vulnerability is CVE-2026-42306. The attack can only be executed locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.6.140/6.12.90/6.18.32/7.0.9/7.1-rc3. It has been classified as critical. This impacts the function io_wq_remove_pending of the component io-wq. Performing a manipulation of the argument hash_tail[] results in null pointer dereference.
This vulnerability was named CVE-2026-46274. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability was found in Linux Kernel up to 7.1-rc4. It has been declared as critical. Affected is the function hci_uart_tty_close of the component Bluetooth. Executing a manipulation of the argument tx_skb can lead to use after free.
The identification of this vulnerability is CVE-2026-46275. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in Linux Kernel up to 6.1.174/6.6.139/6.12.87/6.18.29/7.0.6. This affects an unknown function of the component flow_dissector. The manipulation results in infinite loop.
This vulnerability is cataloged as CVE-2026-46306. The attack must originate from the local network. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in Linux Kernel up to 6.6.139/6.12.87/6.18.29/7.0.6. It has been declared as critical. Impacted is the function hfsplus_fill_super of the component hfsplus. Such manipulation of the argument max_unistr_len leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2026-46299. The attack can only be initiated within the local network. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 7.1-rc1. It has been rated as critical. The affected element is the function rock_continue of the file rock.c of the component isofs. Performing a manipulation of the argument cont_extent results in infinite loop.
This vulnerability was named CVE-2026-46303. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability identified as critical has been detected in Linux Kernel up to 7.0.8/7.1-rc2. This affects an unknown function of the component drm. The manipulation leads to privilege escalation.
This vulnerability is referenced as CVE-2026-46311. The attack needs to be initiated within the local network. No exploit is available.
You should upgrade the affected component.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.6.139/6.12.87/6.18.29/7.0.6. Affected is the function extract_iter_to_sg of the component lib. This manipulation causes memory leak.
This vulnerability is tracked as CVE-2026-46289. The attack is only possible within the local network. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability classified as critical has been found in Linux Kernel up to 7.1-rc1. Affected by this issue is the function nvmet_tcp_release_queue_work of the component nvmet. Performing a manipulation of the argument async_event_work results in deadlock.
This vulnerability is cataloged as CVE-2026-46304. The attack must originate from the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.6.139/6.12.85/6.18.26/7.0.3. It has been declared as critical. This affects the function dmirror_fops_release of the file mm/ksft_hmm.sh of the component lib. Executing a manipulation can lead to use after free.
This vulnerability is handled as CVE-2026-46280. The attack can only be done within the local network. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 7.1-rc2. The affected element is the function __ubsan_handle_out_of_bounds.cold+0x46/0x4b of the file drivers/net/wireless/ath/ath5k/base.c of the component wifi. This manipulation of the argument ts_final_idx causes out-of-bounds write.
This vulnerability is registered as CVE-2026-46307. The attack requires access to the local network. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 7.0.3. It has been rated as critical. Affected by this issue is some unknown functionality of the component mm. This manipulation of the argument folio_free causes stack-based buffer overflow.
This vulnerability is handled as CVE-2026-46277. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability was found in Linux Kernel up to 6.12.85/6.18.26/7.0.3 and classified as critical. The affected element is the function of_unittest_changeset. Such manipulation of the argument parent leads to use after free.
This vulnerability is traded as CVE-2026-46288. Access to the local network is required for this attack to succeed. There is no exploit available.
It is suggested to upgrade the affected component.