{"schema_version":1,"title":"Red Hat Enterprise Linux AppStream vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 46 vulnerabilities in Red Hat Enterprise Linux AppStream: 0 in the last 7 days and 0 in the last 90 days, 10 of them critical and 0 exploited in the wild. The most recent, CVE-2026-44673, was published on 14 May 2026.","url":"https://junglewise.ai/threats/technologies/enterprise-linux-appstream","json_url":"https://junglewise.ai/threats/technologies/enterprise-linux-appstream.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/enterprise-linux-appstream","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":33,"all_time":46,"critical":10,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":46},"latest":[{"cve":"CVE-2026-44673","cvss":7.5,"epss":0.0027,"slug":"cve-2026-44673-cesnet-libyang-heap-buffer-overflow-in-lyb-read-string","title":"CESNET libyang heap buffer overflow in lyb_read_string","severity":"high","exploited":false,"published_at":"2026-05-14T21:16:47.5+00:00","url":"https://junglewise.ai/threats/cve-2026-44673-cesnet-libyang-heap-buffer-overflow-in-lyb-read-string"},{"cve":"CVE-2026-5172","cvss":7.3,"epss":0.0065,"slug":"cve-2026-5172-dnsmasq-heap-out-of-bounds-read-in-extract-addresses","title":"dnsmasq heap out-of-bounds read in extract_addresses","severity":"high","exploited":false,"published_at":"2026-05-11T18:16:41.92+00:00","url":"https://junglewise.ai/threats/cve-2026-5172-dnsmasq-heap-out-of-bounds-read-in-extract-addresses"},{"cve":"CVE-2026-4891","cvss":5.3,"epss":0.0446,"slug":"cve-2026-4891-dnsmasq-heap-out-of-bounds-read-in-dnssec-validation","title":"dnsmasq heap out-of-bounds read in DNSSEC validation","severity":"medium","exploited":false,"published_at":"2026-05-11T18:16:41.38+00:00","url":"https://junglewise.ai/threats/cve-2026-4891-dnsmasq-heap-out-of-bounds-read-in-dnssec-validation"},{"cve":"CVE-2026-4890","cvss":7.5,"epss":0.0561,"slug":"cve-2026-4890-dnsmasq-infinite-loop-in-dnssec-nsec-parsing","title":"dnsmasq infinite loop in DNSSEC NSEC parsing","severity":"high","exploited":false,"published_at":"2026-05-11T18:16:41.273+00:00","url":"https://junglewise.ai/threats/cve-2026-4890-dnsmasq-infinite-loop-in-dnssec-nsec-parsing"},{"cve":"CVE-2026-7263","cvss":7.5,"epss":0.0027,"slug":"cve-2026-7263-php-domnode-c14n-denial-of-service-via-circular-linked-list","title":"PHP DOMNode::C14N() denial of service via circular linked list","severity":"high","exploited":false,"published_at":"2026-05-10T06:16:08.343+00:00","url":"https://junglewise.ai/threats/cve-2026-7263-php-domnode-c14n-denial-of-service-via-circular-linked-list"},{"cve":"CVE-2026-6104","cvss":9.1,"epss":0.0044,"slug":"cve-2026-6104-php-mbstring-out-of-bounds-read-in-mb-convert-encoding","title":"PHP mbstring out-of-bounds read in mb_convert_encoding","severity":"critical","exploited":false,"published_at":"2026-05-10T06:16:07.397+00:00","url":"https://junglewise.ai/threats/cve-2026-6104-php-mbstring-out-of-bounds-read-in-mb-convert-encoding"},{"cve":"CVE-2026-7568","cvss":7.5,"epss":0.0024,"slug":"cve-2026-7568-php-signed-integer-overflow-in-metaphone-function","title":"PHP signed integer overflow in metaphone function","severity":"high","exploited":false,"published_at":"2026-05-10T05:16:11.92+00:00","url":"https://junglewise.ai/threats/cve-2026-7568-php-signed-integer-overflow-in-metaphone-function"},{"cve":"CVE-2026-7262","cvss":7.5,"epss":0.0045,"slug":"cve-2026-7262-php-soap-extension-null-pointer-dereference-in-apache-map-decoder","title":"PHP SOAP extension NULL pointer dereference in apache:Map decoder","severity":"high","exploited":false,"published_at":"2026-05-10T05:16:11.78+00:00","url":"https://junglewise.ai/threats/cve-2026-7262-php-soap-extension-null-pointer-dereference-in-apache-map-decoder"},{"cve":"CVE-2026-25243","cvss":8.8,"epss":0.0137,"slug":"cve-2026-25243-redis-restore-command-invalid-memory-access-leading-to-rce","title":"Redis RESTORE command invalid memory access leading to RCE","severity":"high","exploited":false,"published_at":"2026-05-05T17:17:03.667+00:00","url":"https://junglewise.ai/threats/cve-2026-25243-redis-restore-command-invalid-memory-access-leading-to-rce"},{"cve":"CVE-2026-23631","cvss":8.1,"epss":0.0122,"slug":"cve-2026-23631-redis-use-after-free-in-lua-scripting-synchronization","title":"Redis use-after-free in Lua scripting synchronization","severity":"high","exploited":false,"published_at":"2026-05-05T17:17:03.503+00:00","url":"https://junglewise.ai/threats/cve-2026-23631-redis-use-after-free-in-lua-scripting-synchronization"},{"cve":"CVE-2026-5656","cvss":7,"epss":0.0017,"slug":"cve-2026-5656-wireshark-path-traversal-in-configuration-profile-import","title":"Wireshark path traversal in Configuration Profile import","severity":"high","exploited":false,"published_at":"2026-05-01T00:16:25.097+00:00","url":"https://junglewise.ai/threats/cve-2026-5656-wireshark-path-traversal-in-configuration-profile-import"},{"cve":"CVE-2026-42198","cvss":7.5,"epss":0.0412,"slug":"cve-2026-42198-postgresql-pgjdbc-denial-of-service-via-unbounded-scram","title":"PostgreSQL pgjdbc denial of service via unbounded SCRAM iterations","severity":"high","exploited":false,"published_at":"2026-04-29T16:16:25.427+00:00","url":"https://junglewise.ai/threats/cve-2026-42198-postgresql-pgjdbc-denial-of-service-via-unbounded-scram"},{"cve":"CVE-2026-41316","cvss":8.1,"epss":0.0131,"slug":"cve-2026-41316-ruby-erb-arbitrary-code-execution-via-deserialization-guard","title":"Ruby ERB arbitrary code execution via deserialization guard bypass","severity":"high","exploited":false,"published_at":"2026-04-24T03:16:11.897+00:00","url":"https://junglewise.ai/threats/cve-2026-41316-ruby-erb-arbitrary-code-execution-via-deserialization-guard"},{"cve":"CVE-2026-33116","cvss":7.5,"epss":0.0244,"slug":"cve-2026-33116-microsoft-net-infinite-loop-in-xmldecryptiontransform","title":"Microsoft .NET infinite loop in XmlDecryptionTransform","severity":"high","exploited":false,"published_at":"2026-04-14T18:17:33.903+00:00","url":"https://junglewise.ai/threats/cve-2026-33116-microsoft-net-infinite-loop-in-xmldecryptiontransform"},{"cve":"CVE-2026-32203","cvss":7.5,"epss":0.0244,"slug":"cve-2026-32203-microsoft-net-and-visual-studio-stack-overflow-denial-of-service","title":"Microsoft .NET and Visual Studio stack overflow denial of service","severity":"high","exploited":false,"published_at":"2026-04-14T18:17:27.7+00:00","url":"https://junglewise.ai/threats/cve-2026-32203-microsoft-net-and-visual-studio-stack-overflow-denial-of-service"},{"cve":"CVE-2026-32178","cvss":7.5,"epss":0.0209,"slug":"cve-2026-32178-microsoft-net-smtp-command-injection-in-mailaddress-parsing","title":"Microsoft .NET SMTP command injection in MailAddress parsing","severity":"high","exploited":false,"published_at":"2026-04-14T18:17:20.26+00:00","url":"https://junglewise.ai/threats/cve-2026-32178-microsoft-net-smtp-command-injection-in-mailaddress-parsing"},{"cve":"CVE-2026-26171","cvss":7.5,"epss":0.0226,"slug":"cve-2026-26171-microsoft-net-denial-of-service-via-xml-entity-expansion","title":"Microsoft .NET denial of service via XML entity expansion","severity":"high","exploited":false,"published_at":"2026-04-14T18:16:51.577+00:00","url":"https://junglewise.ai/threats/cve-2026-26171-microsoft-net-denial-of-service-via-xml-entity-expansion"},{"cve":"CVE-2026-4151","cvss":7.8,"epss":0.0059,"slug":"cve-2026-4151-gimp-ani-file-parsing-integer-overflow","title":"GIMP ANI file parsing integer overflow","severity":"high","exploited":false,"published_at":"2026-04-11T01:16:16.697+00:00","url":"https://junglewise.ai/threats/cve-2026-4151-gimp-ani-file-parsing-integer-overflow"},{"cve":"CVE-2026-34078","cvss":10,"epss":0.0164,"slug":"cve-2026-34078-flatpak-sandbox-escape-via-symlink-following-in-sandbox-expose","title":"Flatpak sandbox escape via symlink following in sandbox-expose","severity":"critical","exploited":false,"published_at":"2026-04-07T22:16:21.93+00:00","url":"https://junglewise.ai/threats/cve-2026-34078-flatpak-sandbox-escape-via-symlink-following-in-sandbox-expose"},{"cve":"CVE-2026-21413","cvss":9.8,"epss":0.0054,"slug":"cve-2026-21413-libraw-heap-buffer-overflow-in-lossless-jpeg-load-raw","title":"LibRaw heap buffer overflow in lossless_jpeg_load_raw","severity":"critical","exploited":false,"published_at":"2026-04-07T15:17:35.633+00:00","url":"https://junglewise.ai/threats/cve-2026-21413-libraw-heap-buffer-overflow-in-lossless-jpeg-load-raw"},{"cve":"CVE-2026-34588","cvss":7.8,"epss":0.0057,"slug":"cve-2026-34588-openexr-integer-overflow-in-piz-decoder-leads-to-oob-read-and","title":"OpenEXR integer overflow in PIZ decoder leads to OOB read and write","severity":"high","exploited":false,"published_at":"2026-04-06T16:16:35.893+00:00","url":"https://junglewise.ai/threats/cve-2026-34588-openexr-integer-overflow-in-piz-decoder-leads-to-oob-read-and"},{"cve":"CVE-2026-33983","cvss":6.5,"epss":0.0025,"slug":"cve-2026-33983-freerdp-denial-of-service-in-progressive-decompress-tile-upgrade","title":"FreeRDP denial of service in progressive_decompress_tile_upgrade","severity":"medium","exploited":false,"published_at":"2026-03-30T22:16:19.407+00:00","url":"https://junglewise.ai/threats/cve-2026-33983-freerdp-denial-of-service-in-progressive-decompress-tile-upgrade"},{"cve":"CVE-2026-21710","cvss":7.5,"epss":0.1307,"slug":"cve-2026-21710-node-js-denial-of-service-via-proto-header-in-req-headersdistinct","title":"Node.js denial of service via __proto__ header in req.headersDistinct","severity":"high","exploited":false,"published_at":"2026-03-30T20:16:18.21+00:00","url":"https://junglewise.ai/threats/cve-2026-21710-node-js-denial-of-service-via-proto-header-in-req-headersdistinct"},{"cve":"CVE-2026-32748","cvss":7.5,"epss":0.0273,"slug":"cve-2026-32748-squid-heap-use-after-free-in-icp-request-handling","title":"Squid heap use-after-free in ICP request handling","severity":"high","exploited":false,"published_at":"2026-03-26T01:16:26.85+00:00","url":"https://junglewise.ai/threats/cve-2026-32748-squid-heap-use-after-free-in-icp-request-handling"},{"cve":"CVE-2026-4371","cvss":7.4,"epss":0.0029,"slug":"cve-2026-4371-mozilla-thunderbird-out-of-bounds-read-in-imap-parsing","title":"Mozilla Thunderbird out of bounds read in IMAP parsing","severity":"high","exploited":false,"published_at":"2026-03-24T21:16:29.583+00:00","url":"https://junglewise.ai/threats/cve-2026-4371-mozilla-thunderbird-out-of-bounds-read-in-imap-parsing"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Red Hat Enterprise Linux 9","slug":"enterprise-linux-9","vulnerabilities":146,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-9"},{"name":"Red Hat Enterprise Linux 10","slug":"enterprise-linux-10","vulnerabilities":140,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-10"},{"name":"Red Hat Enterprise Linux 8","slug":"enterprise-linux-8","vulnerabilities":132,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-8"},{"name":"Red Hat Enterprise Linux 7","slug":"enterprise-linux-7","vulnerabilities":68,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-7"},{"name":"Red Hat Keycloak","slug":"build-of-keycloak","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/build-of-keycloak"},{"name":"Red Hat Enterprise Linux 6","slug":"enterprise-linux-6","vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-6"},{"name":"Red Hat Build of Keycloak","slug":"red-hat-build-of-keycloak","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/red-hat-build-of-keycloak"},{"name":"Red Hat OpenShift Container Platform 4","slug":"openshift-container-platform-4","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/openshift-container-platform-4"},{"name":"Red Hat Ansible Automation Platform","slug":"ansible-automation-platform-2","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/ansible-automation-platform-2"},{"name":"Red Hat Developer Hub","slug":"developer-hub","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/developer-hub"},{"name":"Red Hat Multicluster Global Hub","slug":"multicluster-global-hub","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/multicluster-global-hub"},{"name":"Red Hat AI Inference Server","slug":"ai-inference-server","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/ai-inference-server"}],"technology":{"hub":true,"name":"Red Hat Enterprise Linux AppStream","slug":"enterprise-linux-appstream","vendor":{"name":"Red Hat","slug":"red-hat","url":"https://junglewise.ai/threats/vendors/red-hat"},"aliases":[],"category":"operating-system","homepage":"https://www.redhat.com/en/technologies/linux-platforms/enterprise-linux","description":"Repository for Red Hat Enterprise Linux containing user-space applications, runtime languages, and databases.","url":"https://junglewise.ai/threats/technologies/enterprise-linux-appstream"},"most_severe":[{"cve":"CVE-2026-34078","cvss":10,"epss":0.0164,"slug":"cve-2026-34078-flatpak-sandbox-escape-via-symlink-following-in-sandbox-expose","title":"Flatpak sandbox escape via symlink following in sandbox-expose","severity":"critical","exploited":false,"published_at":"2026-04-07T22:16:21.93+00:00","url":"https://junglewise.ai/threats/cve-2026-34078-flatpak-sandbox-escape-via-symlink-following-in-sandbox-expose"},{"cve":"CVE-2026-2768","cvss":10,"epss":0.0035,"slug":"cve-2026-2768-mozilla-firefox-and-thunderbird-sandbox-escape-in-indexeddb","title":"Mozilla Firefox and Thunderbird sandbox escape in IndexedDB","severity":"critical","exploited":false,"published_at":"2026-02-24T14:16:25.183+00:00","url":"https://junglewise.ai/threats/cve-2026-2768-mozilla-firefox-and-thunderbird-sandbox-escape-in-indexeddb"},{"cve":"CVE-2026-21413","cvss":9.8,"epss":0.0054,"slug":"cve-2026-21413-libraw-heap-buffer-overflow-in-lossless-jpeg-load-raw","title":"LibRaw heap buffer overflow in lossless_jpeg_load_raw","severity":"critical","exploited":false,"published_at":"2026-04-07T15:17:35.633+00:00","url":"https://junglewise.ai/threats/cve-2026-21413-libraw-heap-buffer-overflow-in-lossless-jpeg-load-raw"},{"cve":"CVE-2026-23884","cvss":9.8,"epss":0.0054,"slug":"cve-2026-23884-freerdp-use-after-free-in-gdi-offscreen-bitmap-deletion","title":"FreeRDP use after free in GDI offscreen bitmap deletion","severity":"critical","exploited":false,"published_at":"2026-01-19T18:16:06.43+00:00","url":"https://junglewise.ai/threats/cve-2026-23884-freerdp-use-after-free-in-gdi-offscreen-bitmap-deletion"},{"cve":"CVE-2025-67268","cvss":9.8,"epss":0.0053,"slug":"cve-2025-67268-gpsd-heap-based-out-of-bounds-write-in-nmea2000-driver","title":"gpsd heap-based out-of-bounds write in NMEA2000 driver","severity":"critical","exploited":false,"published_at":"2026-01-02T16:17:00.99+00:00","url":"https://junglewise.ai/threats/cve-2025-67268-gpsd-heap-based-out-of-bounds-write-in-nmea2000-driver"},{"cve":"CVE-2026-2762","cvss":9.8,"epss":0.0052,"slug":"cve-2026-2762-mozilla-firefox-and-thunderbird-integer-overflow-in-javascript","title":"Mozilla Firefox and Thunderbird integer overflow in JavaScript Standard Library","severity":"critical","exploited":false,"published_at":"2026-02-24T14:16:24.48+00:00","url":"https://junglewise.ai/threats/cve-2026-2762-mozilla-firefox-and-thunderbird-integer-overflow-in-javascript"},{"cve":"CVE-2026-22853","cvss":9.8,"epss":0.0049,"slug":"cve-2026-22853-freerdp-heap-buffer-overflow-in-rdpear-ndr-array-reader","title":"FreeRDP heap buffer overflow in RDPEAR NDR array reader","severity":"critical","exploited":false,"published_at":"2026-01-14T18:16:42.79+00:00","url":"https://junglewise.ai/threats/cve-2026-22853-freerdp-heap-buffer-overflow-in-rdpear-ndr-array-reader"},{"cve":"CVE-2026-33210","cvss":9.1,"epss":0.0101,"slug":"cve-2026-33210-ruby-json-format-string-injection-in-json-parser","title":"Ruby JSON format string injection in JSON parser","severity":"critical","exploited":false,"published_at":"2026-03-20T23:16:46.01+00:00","url":"https://junglewise.ai/threats/cve-2026-33210-ruby-json-format-string-injection-in-json-parser"},{"cve":"CVE-2025-55130","cvss":9.1,"epss":0.0049,"slug":"cve-2025-55130-node-js-permission-model-bypass-via-crafted-symlinks","title":"Node.js permission model bypass via crafted symlinks","severity":"critical","exploited":false,"published_at":"2026-01-20T21:16:03.177+00:00","url":"https://junglewise.ai/threats/cve-2025-55130-node-js-permission-model-bypass-via-crafted-symlinks"},{"cve":"CVE-2026-6104","cvss":9.1,"epss":0.0044,"slug":"cve-2026-6104-php-mbstring-out-of-bounds-read-in-mb-convert-encoding","title":"PHP mbstring out-of-bounds read in mb_convert_encoding","severity":"critical","exploited":false,"published_at":"2026-05-10T06:16:07.397+00:00","url":"https://junglewise.ai/threats/cve-2026-6104-php-mbstring-out-of-bounds-read-in-mb-convert-encoding"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}