Red Hat Network Observability
14 known vulnerabilities in Red Hat Network Observability, 2 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-6321 CVSS 7.5 high fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal()…
- CVE-2026-42044 CVSS 9.1 critical Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a…
- CVE-2026-42043 CVSS 10.0 critical Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL…
- CVE-2026-42041 CVSS 6.5 medium Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a…
- CVE-2026-42039 CVSS 6.9 medium Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects…
- CVE-2026-42033 CVSS 7.4 high Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by…
- CVE-2026-40895 CVSS 6.9 medium follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior…
- CVE-2026-40175 CVSS 4.8 medium Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific…
- CVE-2025-62718 CVSS 6.3 medium Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname…
- CVE-2026-29063 CVSS 8.7 high Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is…
- CVE-2025-69873 CVSS 2.9 low ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is…
- CVE-2026-25639 CVSS 7.5 high Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios…
- CVE-2026-24842 CVSS 8.2 high node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses…
- CVE-2026-23745 CVSS 8.2 high node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries…