Red Hat Enterprise Linux 10是美国Red Hat公司的一套面向企业用户的Linux操作系统。 Red Hat Enterprise Linux 10存在日志信息泄露漏洞,该漏洞源于nexmo.py module模块中api_key和api_secret参数被声明为no_log=True,但立即被URL编码到GET请求的查询参数中,绕过了所有日志保护,可能导致低权限攻击者通过网络访问获取敏感信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 8 | any |
unknown |
any |
unknown | ||
| Red Hat | Red Hat Enterprise Linux 9 | any |
unknown |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11807 | 9.6 CRITICAL | Eda-server: websocket missing authorization allows credential theft via activation_id spoo |
| CVE-2026-12112 | 7.8 HIGH | Foreman-mcp-server: mcp server: active session hijacking via insecure session state reuse |
| CVE-2026-10609 | 6.8 MEDIUM | Openshift/cluster-logging-operator: cluster logging operator creates and forwards servicea |
| CVE-2026-9073 | 6.2 MEDIUM | Foreman-mcp-server: mcp server: insecure sensitive http header sanitization |
| CVE-2026-11819 | 5.5 MEDIUM | Community.general: community.general keyring_info — os keyring passphrase returned in plai |
| CVE-2026-12969 | 5.3 MEDIUM | Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation |
| CVE-2026-55655 | 5.0 MEDIUM | Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat ente |
| CVE-2026-12892 | 4.4 MEDIUM | Gstreamer1-plugins-bad: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in h.264 na |
| CVE-2026-55653 | 4.3 MEDIUM | Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path du |
| CVE-2026-12891 | 4.3 MEDIUM | Gstreamer1-plugins-bad: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266 |
| CVE-2026-55654 | 3.7 LOW | Openssh: heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi in |
No comments yet