cbcvebase.

Redhat Update Infrastructure vulnerabilities

9 known vulnerabilities affecting redhat/update_infrastructure.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2026-9256P2HIGHCVSS 8.1≥ 5.0, < 5.22026-05-22
CVE-2026-9256 [HIGH] CWE-122 CVE-2026-9256: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vu NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in
nvd
CVE-2026-42055P2HIGHCVSS 8.1≥ 5.0, < 5.22026-06-17
CVE-2026-42055 [HIGH] CWE-122 CVE-2026-42055: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_g NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger tha
nvd
CVE-2026-48864P3HIGHCVSS 7.8v42026-05-26
CVE-2026-48864 [HIGH] CWE-787 CVE-2026-48864: A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-c A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result
nvd
CVE-2023-50781P3HIGHCVSS 7.5v42024-02-05
CVE-2023-50781 [HIGH] CWE-203 CVE-2023-50781: A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
nvd
CVE-2023-50782P3HIGHCVSS 7.5v42024-02-05
CVE-2023-50782 [HIGH] CWE-203 CVE-2023-50782: A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decry A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
nvd
CVE-2026-9150P3MEDIUMCVSS 6.5v42026-05-20
CVE-2026-9150 [MEDIUM] CWE-121 CVE-2026-9150: A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debi A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.
nvd
CVE-2026-9149P4MEDIUMCVSS 6.5v42026-05-21
CVE-2026-9149 [MEDIUM] CWE-122 CVE-2026-9149: A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).
nvd
CVE-2022-3644P4MEDIUMCVSS 5.5v3.02022-10-25
CVE-2022-3644 [MEDIUM] CWE-256 CVE-2022-3644: The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
nvd
CVE-2013-4518P4MEDIUMCVSS 5.5v2.1.32019-11-04
CVE-2013-4518 [MEDIUM] CWE-200 CVE-2013-4518: RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates
nvd
Redhat Update Infrastructure vulnerabilities | cvebase