Red Hat Cryostat
30 known vulnerabilities in Red Hat Cryostat, 7 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-10832 CVSS 5.9 medium A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability…
- CVE-2026-54513 CVSS 8.1 high jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until…
- CVE-2026-48779 CVSS 7.5 high ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to…
- CVE-2026-12143 CVSS 8.7 high form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to…
- CVE-2026-46595 CVSS 10.0 critical Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed…
- CVE-2026-39835 CVSS 5.3 medium SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by…
- CVE-2026-39830 CVSS 9.1 critical A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The…
- CVE-2026-39829 CVSS 7.5 high The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus…
- CVE-2026-39828 CVSS 6.3 medium When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently…
- CVE-2026-45736 CVSS 7.5 high ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to…
- CVE-2026-33811 CVSS 7.5 high When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
- CVE-2026-40895 CVSS 6.9 medium follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior…
- CVE-2026-5598 CVSS 8.9 high Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is…
- CVE-2026-33810 CVSS 8.2 high When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs…
- CVE-2026-32283 CVSS 7.5 high If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock…
- CVE-2026-32280 CVSS 7.5 high During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are…
- CVE-2026-33816 CVSS 9.8 critical Memory-safety vulnerability in github.com/jackc/pgx/v5.
- CVE-2026-33815 CVSS 9.8 critical Memory-safety vulnerability in github.com/jackc/pgx/v5.
- CVE-2026-4800 CVSS 9.8 critical Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in…
- CVE-2026-33896 CVSS 9.1 critical Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0…
- CVE-2026-33895 CVSS 7.5 high Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519…
- CVE-2026-33891 CVSS 7.5 high Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of…
- CVE-2026-33186 CVSS 9.1 critical gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input…
- CVE-2026-29786 CVSS 8.2 high node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the…
- CVE-2026-25679 CVSS 7.5 high url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
- CVE-2025-61726 CVSS 7.5 high The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs…
- CVE-2026-24842 CVSS 8.2 high node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses…
- CVE-2025-13465 CVSS 6.9 medium Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass…
- CVE-2026-23950 CVSS 5.9 medium node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete…
- CVE-2026-23745 CVSS 8.2 high node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries…