A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to override a more specific l
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Certificate System 9 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 7 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
unaffected |
any |
affected | ||
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Certificate System 9 | - |
cpe:/a:redhat:certificate_system:9
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92574 | 8.8 HIGH | Cri-o: cri-o checkpoint restore bypasses destination security context |
| CVE-2026-15801 | 8.0 HIGH | Cri-o: cri-o: insufficient validation during container checkpoint restore |
| CVE-2026-94449 | 7.5 HIGH | Quarkus-smallrye-fault-tolerance: quarkus-smallrye-fault-tolerance: memory leak in @applyg |
| CVE-2026-75939 | 7.4 HIGH | Openshift/oc-mirror: release signature verification: openpgp signatureerror checked before |
| CVE-2026-94368 | 7.1 HIGH | Noobaa-core: noobaa-core: presigned put url escalation to copyobject via unsigned x-amz-co |
| CVE-2026-94215 | 5.5 MEDIUM | Keycloak-services: keycloak-services: cross-realm client read/write via request-level cach |
| CVE-2026-93433 | 5.5 MEDIUM | Libstoragemgmt: libstoragemgmt: denial of service via stack buffer overflow in scsi vpd pa |
| CVE-2026-94213 | 4.9 MEDIUM | Keycloak-services: keycloak-services: authorization services policy evaluation endpoint le |
| CVE-2026-92382 | 4.1 MEDIUM | Usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads t |
| CVE-2026-94217 | 3.5 LOW | Keycloak-services: keycloak-services: uma scope merge across resource owners via resource |
| CVE-2026-94218 | 3.1 LOW | Keycloak-services: keycloak-services: 2fa setup enforcement bypass via authentication sess |
| CVE-2026-94184 | Fetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fetchmail-sa-202 |
No comments yet