VendorsRed Hatupdate_infrastructureall versions
Vulnerabilities

Red Hat Update Infrastructure

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2026-9256
NGINX ngx_http_rewrite_module vulnerability
Published 2026-05-22 · Modified
9.2EPSS 0.027
CVE-2026-42055
NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
Published 2026-06-17 · Modified
9.2EPSS 0.024
CVE-2026-48864
Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
Published 2026-05-26 · Modified
7.8EPSS 0.003
CVE-2023-50781
M2crypto: bleichenbacher timing attacks in the rsa decryption api - incomplete fix for cve-2020-25657
Published 2024-02-05 · Analyzed
7.5EPSS 0.011
CVE-2023-50782
Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659
Published 2024-02-05 · Modified
7.5EPSS 0.011
CVE-2026-9150
Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums
Published 2026-05-20 · Modified
6.5EPSS 0.006
CVE-2026-9149
Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file
Published 2026-05-20 · Modified
6.5EPSS 0.006
CVE-2022-3644
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
Published 2022-10-25 · Modified
5.5EPSS 0.003
CVE-2013-4518
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates
Published 2019-11-04 · Modified
5.5EPSS 0.003