Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total5
Critical0
High1
Medium2
Reset
Showing 1-5 of 5 records
Threat Entry Updated 2026-01-16

CVE-2026-0990 - Red Hat Enterprise Linux 8 Plugin

A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.

PLUGIN Red Hat Enterprise Linux 8

CVE-2026-0990

MEDIUM CVSS 5.9 2026-01-15
Threat Entry Updated 2026-01-16

CVE-2026-0989 - Red Hat Enterprise Linux 8 Plugin

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.

PLUGIN Red Hat Enterprise Linux 8

CVE-2026-0989

LOW CVSS 3.7 2026-01-15
Threat Entry Updated 2026-01-16

CVE-2026-0992 - Red Hat Enterprise Linux 8 Plugin

A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.

PLUGIN Red Hat Enterprise Linux 8

CVE-2026-0992

LOW CVSS 2.9 2026-01-15
Threat Entry Updated 2026-01-14

CVE-2026-0716 - Red Hat Enterprise Linux 8 Plugin

A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup’s WebSocket support with this configuration may be impacted.

PLUGIN Red Hat Enterprise Linux 8

CVE-2026-0716

MEDIUM CVSS 4.8 2026-01-13
Threat Entry Updated 2026-02-17

CVE-2026-0719 - Red Hat Enterprise Linux 8 Plugin

A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When processing extremely long passwords, an internal size calculation can overflow due to improper use of signed integers. This results in incorrect memory allocation on the stack, followed by unsafe memory copying. As a result, applications using libsoup may crash unexpectedly, creating a denial-of-service risk.

PLUGIN Red Hat Enterprise Linux 8

CVE-2026-0719

HIGH CVSS 8.6 2026-01-08
Scroll to top