Red Hat Discovery

11 known vulnerabilities in Red Hat Discovery, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-18477 CVSS 4.4 medium A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write…
  • CVE-2026-18508 CVSS 4.4 medium A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the…
  • CVE-2026-13757 CVSS 6.2 medium A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and…
  • CVE-2026-54371 CVSS 8.4 high attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to…
  • CVE-2026-54369 CVSS 8.4 high acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file()…
  • CVE-2026-48779 CVSS 7.5 high ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to…
  • CVE-2026-8643 CVSS 4.1 medium pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the…
  • CVE-2026-45736 CVSS 7.5 high ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to…
  • CVE-2026-5704 CVSS 5.5 medium A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file…
  • CVE-2025-6170 CVSS 2.5 low A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long…
  • CVE-2025-5278 CVSS 4.4 medium A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may…