{"schema_version":1,"title":"Red Hat Self-service automation portal vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 14 vulnerabilities in Red Hat Self-service automation portal: 0 in the last 7 days and 0 in the last 90 days, 10 of them critical and 0 exploited in the wild. The most recent, CVE-2026-45411, was published on 13 May 2026.","url":"https://junglewise.ai/threats/technologies/self-service-automation-portal","json_url":"https://junglewise.ai/threats/technologies/self-service-automation-portal.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/self-service-automation-portal","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":14,"critical":10,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":14},"latest":[{"cve":"CVE-2026-45411","cvss":9.8,"epss":0.009,"slug":"cve-2026-45411-patriksimek-vm2-sandbox-escape-via-async-generator-yield","title":"patriksimek vm2 sandbox escape via async generator yield* expression","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:19.427+00:00","url":"https://junglewise.ai/threats/cve-2026-45411-patriksimek-vm2-sandbox-escape-via-async-generator-yield"},{"cve":"CVE-2026-44009","cvss":9.8,"epss":0.0071,"slug":"cve-2026-44009-patriksimek-vm2-sandbox-breakout-via-null-prototype-exception","title":"patriksimek vm2 sandbox breakout via null prototype exception","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:17.803+00:00","url":"https://junglewise.ai/threats/cve-2026-44009-patriksimek-vm2-sandbox-breakout-via-null-prototype-exception"},{"cve":"CVE-2026-44008","cvss":9.8,"epss":0.009,"slug":"cve-2026-44008-patriksimek-vm2-sandbox-escape-in-neutralizearrayspeciesbatch","title":"patriksimek vm2 sandbox escape in neutralizeArraySpeciesBatch","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:17.667+00:00","url":"https://junglewise.ai/threats/cve-2026-44008-patriksimek-vm2-sandbox-escape-in-neutralizearrayspeciesbatch"},{"cve":"CVE-2026-44007","cvss":9.1,"epss":0.0061,"slug":"cve-2026-44007-patriksimek-vm2-sandbox-escape-via-nested-nodevm-bypass","title":"patriksimek vm2 sandbox escape via nested NodeVM bypass","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:17.527+00:00","url":"https://junglewise.ai/threats/cve-2026-44007-patriksimek-vm2-sandbox-escape-via-nested-nodevm-bypass"},{"cve":"CVE-2026-44006","cvss":10,"epss":0.0077,"slug":"cve-2026-44006-patriksimek-vm2-sandbox-escape-via-arbitrary-prototype-access","title":"patriksimek vm2 sandbox escape via arbitrary prototype access","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:17.387+00:00","url":"https://junglewise.ai/threats/cve-2026-44006-patriksimek-vm2-sandbox-escape-via-arbitrary-prototype-access"},{"cve":"CVE-2026-44005","cvss":10,"epss":0.0083,"slug":"cve-2026-44005-patriksimek-vm2-sandbox-escape-via-host-prototype-mutation","title":"patriksimek vm2 sandbox escape via host prototype mutation","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:17.257+00:00","url":"https://junglewise.ai/threats/cve-2026-44005-patriksimek-vm2-sandbox-escape-via-host-prototype-mutation"},{"cve":"CVE-2026-44004","cvss":7.5,"epss":0.0067,"slug":"cve-2026-44004-patriksimek-vm2-denial-of-service-via-host-memory-exhaustion-in","title":"patriksimek vm2 denial of service via host memory exhaustion in Buffer.alloc","severity":"high","exploited":false,"published_at":"2026-05-13T18:16:17.123+00:00","url":"https://junglewise.ai/threats/cve-2026-44004-patriksimek-vm2-denial-of-service-via-host-memory-exhaustion-in"},{"cve":"CVE-2026-43999","cvss":9.9,"epss":0.0097,"slug":"cve-2026-43999-patriksimek-vm2-remote-code-execution-via-nodevm-allowlist-bypass","title":"patriksimek vm2 remote code execution via NodeVM allowlist bypass","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:16.45+00:00","url":"https://junglewise.ai/threats/cve-2026-43999-patriksimek-vm2-remote-code-execution-via-nodevm-allowlist-bypass"},{"cve":"CVE-2026-43998","cvss":8.5,"epss":0.0085,"slug":"cve-2026-43998-patriksimek-vm2-remote-code-execution-via-symlink-traversal-in","title":"patriksimek vm2 remote code execution via symlink traversal in NodeVM","severity":"high","exploited":false,"published_at":"2026-05-13T18:16:16.317+00:00","url":"https://junglewise.ai/threats/cve-2026-43998-patriksimek-vm2-remote-code-execution-via-symlink-traversal-in"},{"cve":"CVE-2026-43997","cvss":10,"epss":0.0077,"slug":"cve-2026-43997-patriksimek-vm2-sandbox-escape-via-host-object-leakage","title":"patriksimek vm2 sandbox escape via host object leakage","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:16.177+00:00","url":"https://junglewise.ai/threats/cve-2026-43997-patriksimek-vm2-sandbox-escape-via-host-object-leakage"},{"cve":"CVE-2026-26332","cvss":9.8,"epss":0.0074,"slug":"cve-2026-26332-patriksimek-vm2-sandbox-escape-via-suppressederror","title":"patriksimek vm2 sandbox escape via SuppressedError","severity":"critical","exploited":false,"published_at":"2026-05-04T17:16:22.403+00:00","url":"https://junglewise.ai/threats/cve-2026-26332-patriksimek-vm2-sandbox-escape-via-suppressederror"},{"cve":"CVE-2026-24118","cvss":9.8,"epss":0.0091,"slug":"cve-2026-24118-patriksimek-vm2-sandbox-breakout-via-descriptor-chain-bypass","title":"patriksimek vm2 sandbox breakout via descriptor-chain bypass","severity":"critical","exploited":false,"published_at":"2026-05-04T17:16:21.643+00:00","url":"https://junglewise.ai/threats/cve-2026-24118-patriksimek-vm2-sandbox-breakout-via-descriptor-chain-bypass"},{"cve":"CVE-2026-39983","cvss":8.6,"epss":0.028,"slug":"cve-2026-39983-patrickjuchli-basic-ftp-ftp-command-injection-via-crlf-sequences","title":"patrickjuchli basic-ftp FTP command injection via CRLF sequences","severity":"high","exploited":false,"published_at":"2026-04-09T18:17:02.503+00:00","url":"https://junglewise.ai/threats/cve-2026-39983-patrickjuchli-basic-ftp-ftp-command-injection-via-crlf-sequences"},{"cve":"CVE-2026-26278","cvss":7.5,"epss":0.0097,"slug":"cve-2026-26278-naturalintelligence-fast-xml-parser-denial-of-service-via-entity","title":"NaturalIntelligence fast-xml-parser denial of service via entity expansion","severity":"high","exploited":false,"published_at":"2026-02-19T20:25:43.717+00:00","url":"https://junglewise.ai/threats/cve-2026-26278-naturalintelligence-fast-xml-parser-denial-of-service-via-entity"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Red Hat Enterprise Linux 9","slug":"enterprise-linux-9","vulnerabilities":146,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-9"},{"name":"Red Hat Enterprise Linux 10","slug":"enterprise-linux-10","vulnerabilities":140,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-10"},{"name":"Red Hat Enterprise Linux 8","slug":"enterprise-linux-8","vulnerabilities":132,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-8"},{"name":"Red Hat Enterprise Linux 7","slug":"enterprise-linux-7","vulnerabilities":68,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-7"},{"name":"Red Hat Keycloak","slug":"red-hat-keycloak","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/red-hat-keycloak"},{"name":"Red Hat Enterprise Linux 6","slug":"enterprise-linux-6","vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-6"},{"name":"Red Hat Build of Keycloak","slug":"red-hat-build-of-keycloak","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/red-hat-build-of-keycloak"},{"name":"Red Hat Enterprise Linux AppStream","slug":"enterprise-linux-appstream","vulnerabilities":46,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-appstream"},{"name":"Red Hat OpenShift Container Platform 4","slug":"openshift-container-platform-4","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/openshift-container-platform-4"},{"name":"Red Hat Ansible Automation Platform","slug":"ansible-automation-platform-2","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/ansible-automation-platform-2"},{"name":"Red Hat Developer Hub","slug":"developer-hub","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/developer-hub"},{"name":"Red Hat Multicluster Global Hub","slug":"multicluster-global-hub","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/multicluster-global-hub"}],"technology":{"hub":true,"name":"Red Hat Self-service automation portal","slug":"self-service-automation-portal","vendor":{"name":"Red Hat","slug":"red-hat","url":"https://junglewise.ai/threats/vendors/red-hat"},"aliases":[],"category":"web-application","homepage":"https://www.redhat.com/","repo_url":"https://github.com/RedHatOfficial/self-service-automation-portal","description":"A web-based interface for managing automated IT service delivery and resource provisioning.","url":"https://junglewise.ai/threats/technologies/self-service-automation-portal"},"most_severe":[{"cve":"CVE-2026-44005","cvss":10,"epss":0.0083,"slug":"cve-2026-44005-patriksimek-vm2-sandbox-escape-via-host-prototype-mutation","title":"patriksimek vm2 sandbox escape via host prototype mutation","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:17.257+00:00","url":"https://junglewise.ai/threats/cve-2026-44005-patriksimek-vm2-sandbox-escape-via-host-prototype-mutation"},{"cve":"CVE-2026-44006","cvss":10,"epss":0.0077,"slug":"cve-2026-44006-patriksimek-vm2-sandbox-escape-via-arbitrary-prototype-access","title":"patriksimek vm2 sandbox escape via arbitrary prototype access","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:17.387+00:00","url":"https://junglewise.ai/threats/cve-2026-44006-patriksimek-vm2-sandbox-escape-via-arbitrary-prototype-access"},{"cve":"CVE-2026-43997","cvss":10,"epss":0.0077,"slug":"cve-2026-43997-patriksimek-vm2-sandbox-escape-via-host-object-leakage","title":"patriksimek vm2 sandbox escape via host object leakage","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:16.177+00:00","url":"https://junglewise.ai/threats/cve-2026-43997-patriksimek-vm2-sandbox-escape-via-host-object-leakage"},{"cve":"CVE-2026-43999","cvss":9.9,"epss":0.0097,"slug":"cve-2026-43999-patriksimek-vm2-remote-code-execution-via-nodevm-allowlist-bypass","title":"patriksimek vm2 remote code execution via NodeVM allowlist bypass","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:16.45+00:00","url":"https://junglewise.ai/threats/cve-2026-43999-patriksimek-vm2-remote-code-execution-via-nodevm-allowlist-bypass"},{"cve":"CVE-2026-24118","cvss":9.8,"epss":0.0091,"slug":"cve-2026-24118-patriksimek-vm2-sandbox-breakout-via-descriptor-chain-bypass","title":"patriksimek vm2 sandbox breakout via descriptor-chain bypass","severity":"critical","exploited":false,"published_at":"2026-05-04T17:16:21.643+00:00","url":"https://junglewise.ai/threats/cve-2026-24118-patriksimek-vm2-sandbox-breakout-via-descriptor-chain-bypass"},{"cve":"CVE-2026-45411","cvss":9.8,"epss":0.009,"slug":"cve-2026-45411-patriksimek-vm2-sandbox-escape-via-async-generator-yield","title":"patriksimek vm2 sandbox escape via async generator yield* expression","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:19.427+00:00","url":"https://junglewise.ai/threats/cve-2026-45411-patriksimek-vm2-sandbox-escape-via-async-generator-yield"},{"cve":"CVE-2026-44008","cvss":9.8,"epss":0.009,"slug":"cve-2026-44008-patriksimek-vm2-sandbox-escape-in-neutralizearrayspeciesbatch","title":"patriksimek vm2 sandbox escape in neutralizeArraySpeciesBatch","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:17.667+00:00","url":"https://junglewise.ai/threats/cve-2026-44008-patriksimek-vm2-sandbox-escape-in-neutralizearrayspeciesbatch"},{"cve":"CVE-2026-26332","cvss":9.8,"epss":0.0074,"slug":"cve-2026-26332-patriksimek-vm2-sandbox-escape-via-suppressederror","title":"patriksimek vm2 sandbox escape via SuppressedError","severity":"critical","exploited":false,"published_at":"2026-05-04T17:16:22.403+00:00","url":"https://junglewise.ai/threats/cve-2026-26332-patriksimek-vm2-sandbox-escape-via-suppressederror"},{"cve":"CVE-2026-44009","cvss":9.8,"epss":0.0071,"slug":"cve-2026-44009-patriksimek-vm2-sandbox-breakout-via-null-prototype-exception","title":"patriksimek vm2 sandbox breakout via null prototype exception","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:17.803+00:00","url":"https://junglewise.ai/threats/cve-2026-44009-patriksimek-vm2-sandbox-breakout-via-null-prototype-exception"},{"cve":"CVE-2026-44007","cvss":9.1,"epss":0.0061,"slug":"cve-2026-44007-patriksimek-vm2-sandbox-escape-via-nested-nodevm-bypass","title":"patriksimek vm2 sandbox escape via nested NodeVM bypass","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:17.527+00:00","url":"https://junglewise.ai/threats/cve-2026-44007-patriksimek-vm2-sandbox-escape-via-nested-nodevm-bypass"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}