{"schema_version":1,"title":"Red Hat Trusted Artifact Signer vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 9 vulnerabilities in Red Hat Trusted Artifact Signer: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-44577, was published on 13 May 2026.","url":"https://junglewise.ai/threats/technologies/trusted-artifact-signer","json_url":"https://junglewise.ai/threats/technologies/trusted-artifact-signer.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/trusted-artifact-signer","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":8,"all_time":9,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":9},"latest":[{"cve":"CVE-2026-44577","cvss":5.9,"epss":0.0094,"slug":"cve-2026-44577-vercel-next-js-denial-of-service-in-image-optimization-api","title":"Vercel Next.js denial of service in Image Optimization API","severity":"medium","exploited":false,"published_at":"2026-05-13T17:16:23.173+00:00","url":"https://junglewise.ai/threats/cve-2026-44577-vercel-next-js-denial-of-service-in-image-optimization-api"},{"cve":"CVE-2026-44574","cvss":8.1,"epss":0.0067,"slug":"cve-2026-44574-vercel-next-js-authorization-bypass-in-dynamic-route-middleware","title":"Vercel Next.js authorization bypass in dynamic route middleware","severity":"high","exploited":false,"published_at":"2026-05-13T17:16:22.767+00:00","url":"https://junglewise.ai/threats/cve-2026-44574-vercel-next-js-authorization-bypass-in-dynamic-route-middleware"},{"cve":"CVE-2026-4660","cvss":7.5,"epss":0.0055,"slug":"cve-2026-4660-hashicorp-go-getter-arbitrary-file-read-via-argument-injection-in","title":"HashiCorp go-getter arbitrary file read via argument injection in Git URLs","severity":"high","exploited":false,"published_at":"2026-04-09T14:16:32.993+00:00","url":"https://junglewise.ai/threats/cve-2026-4660-hashicorp-go-getter-arbitrary-file-read-via-argument-injection-in"},{"cve":"CVE-2026-4926","cvss":7.5,"epss":0.0089,"slug":"cve-2026-4926-path-to-regexp-denial-of-service-via-sequential-optional-groups","title":"path-to-regexp denial of service via sequential optional groups","severity":"high","exploited":false,"published_at":"2026-03-26T19:17:08.387+00:00","url":"https://junglewise.ai/threats/cve-2026-4926-path-to-regexp-denial-of-service-via-sequential-optional-groups"},{"cve":"CVE-2026-3338","cvss":7.5,"epss":0.0038,"slug":"cve-2026-3338-aws-aws-lc-signature-verification-bypass-in-pkcs7-verify","title":"AWS AWS-LC signature verification bypass in PKCS7_verify","severity":"high","exploited":false,"published_at":"2026-03-02T22:16:32.35+00:00","url":"https://junglewise.ai/threats/cve-2026-3338-aws-aws-lc-signature-verification-bypass-in-pkcs7-verify"},{"cve":"CVE-2026-3336","cvss":7.5,"epss":0.0038,"slug":"cve-2026-3336-aws-aws-lc-certificate-chain-validation-bypass-in-pkcs7-verify","title":"AWS AWS-LC certificate chain validation bypass in PKCS7_verify","severity":"high","exploited":false,"published_at":"2026-03-02T22:16:31.277+00:00","url":"https://junglewise.ai/threats/cve-2026-3336-aws-aws-lc-certificate-chain-validation-bypass-in-pkcs7-verify"},{"cve":"CVE-2026-22775","cvss":7.5,"epss":0.0064,"slug":"cve-2026-22775-svelte-devalue-denial-of-service-via-resource-exhaustion-in-parse","title":"Svelte devalue denial of service via resource exhaustion in parse","severity":"high","exploited":false,"published_at":"2026-01-15T19:16:05.963+00:00","url":"https://junglewise.ai/threats/cve-2026-22775-svelte-devalue-denial-of-service-via-resource-exhaustion-in-parse"},{"cve":"CVE-2026-22774","cvss":7.5,"epss":0.0064,"slug":"cve-2026-22774-svelte-devalue-denial-of-service-in-devalue-parse","title":"Svelte devalue denial of service in devalue.parse","severity":"high","exploited":false,"published_at":"2026-01-15T19:16:05.813+00:00","url":"https://junglewise.ai/threats/cve-2026-22774-svelte-devalue-denial-of-service-in-devalue-parse"},{"cve":"CVE-2026-0897","cvss":7.5,"epss":0.0034,"slug":"cve-2026-0897-google-keras-denial-of-service-via-hdf5-shape-bomb-in-weight","title":"Google Keras Denial of Service via HDF5 shape bomb in weight loading","severity":"high","exploited":false,"published_at":"2026-01-15T14:16:26.89+00:00","url":"https://junglewise.ai/threats/cve-2026-0897-google-keras-denial-of-service-via-hdf5-shape-bomb-in-weight"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Red Hat Enterprise Linux 9","slug":"enterprise-linux-9","vulnerabilities":146,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-9"},{"name":"Red Hat Enterprise Linux 10","slug":"enterprise-linux-10","vulnerabilities":140,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-10"},{"name":"Red Hat Enterprise Linux 8","slug":"enterprise-linux-8","vulnerabilities":132,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-8"},{"name":"Red Hat Enterprise Linux 7","slug":"enterprise-linux-7","vulnerabilities":68,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-7"},{"name":"Red Hat Keycloak","slug":"red-hat-keycloak","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/red-hat-keycloak"},{"name":"Red Hat Enterprise Linux 6","slug":"enterprise-linux-6","vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-6"},{"name":"Red Hat Build of Keycloak","slug":"red-hat-build-of-keycloak","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/red-hat-build-of-keycloak"},{"name":"Red Hat Enterprise Linux AppStream","slug":"enterprise-linux-appstream","vulnerabilities":46,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-appstream"},{"name":"Red Hat OpenShift Container Platform 4","slug":"openshift-container-platform-4","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/openshift-container-platform-4"},{"name":"Red Hat Ansible Automation Platform","slug":"ansible-automation-platform-2","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/ansible-automation-platform-2"},{"name":"Red Hat Developer Hub","slug":"developer-hub","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/developer-hub"},{"name":"Red Hat Multicluster Global Hub","slug":"multicluster-global-hub","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/multicluster-global-hub"}],"technology":{"hub":true,"name":"Red Hat Trusted Artifact Signer","slug":"trusted-artifact-signer","vendor":{"name":"Red Hat","slug":"red-hat","url":"https://junglewise.ai/threats/vendors/red-hat"},"aliases":["red-hat-trusted-artifact-signer"],"category":"software-stack","homepage":"https://access.redhat.com/products/red-hat-trusted-artifact-signer","repo_url":"https://github.com/securesign/trusted-artifact-signer","description":"A service for signing and verifying software artifacts to ensure supply chain security.","url":"https://junglewise.ai/threats/technologies/trusted-artifact-signer"},"most_severe":[{"cve":"CVE-2026-44574","cvss":8.1,"epss":0.0067,"slug":"cve-2026-44574-vercel-next-js-authorization-bypass-in-dynamic-route-middleware","title":"Vercel Next.js authorization bypass in dynamic route middleware","severity":"high","exploited":false,"published_at":"2026-05-13T17:16:22.767+00:00","url":"https://junglewise.ai/threats/cve-2026-44574-vercel-next-js-authorization-bypass-in-dynamic-route-middleware"},{"cve":"CVE-2026-4926","cvss":7.5,"epss":0.0089,"slug":"cve-2026-4926-path-to-regexp-denial-of-service-via-sequential-optional-groups","title":"path-to-regexp denial of service via sequential optional groups","severity":"high","exploited":false,"published_at":"2026-03-26T19:17:08.387+00:00","url":"https://junglewise.ai/threats/cve-2026-4926-path-to-regexp-denial-of-service-via-sequential-optional-groups"},{"cve":"CVE-2026-22775","cvss":7.5,"epss":0.0064,"slug":"cve-2026-22775-svelte-devalue-denial-of-service-via-resource-exhaustion-in-parse","title":"Svelte devalue denial of service via resource exhaustion in parse","severity":"high","exploited":false,"published_at":"2026-01-15T19:16:05.963+00:00","url":"https://junglewise.ai/threats/cve-2026-22775-svelte-devalue-denial-of-service-via-resource-exhaustion-in-parse"},{"cve":"CVE-2026-22774","cvss":7.5,"epss":0.0064,"slug":"cve-2026-22774-svelte-devalue-denial-of-service-in-devalue-parse","title":"Svelte devalue denial of service in devalue.parse","severity":"high","exploited":false,"published_at":"2026-01-15T19:16:05.813+00:00","url":"https://junglewise.ai/threats/cve-2026-22774-svelte-devalue-denial-of-service-in-devalue-parse"},{"cve":"CVE-2026-4660","cvss":7.5,"epss":0.0055,"slug":"cve-2026-4660-hashicorp-go-getter-arbitrary-file-read-via-argument-injection-in","title":"HashiCorp go-getter arbitrary file read via argument injection in Git URLs","severity":"high","exploited":false,"published_at":"2026-04-09T14:16:32.993+00:00","url":"https://junglewise.ai/threats/cve-2026-4660-hashicorp-go-getter-arbitrary-file-read-via-argument-injection-in"},{"cve":"CVE-2026-3338","cvss":7.5,"epss":0.0038,"slug":"cve-2026-3338-aws-aws-lc-signature-verification-bypass-in-pkcs7-verify","title":"AWS AWS-LC signature verification bypass in PKCS7_verify","severity":"high","exploited":false,"published_at":"2026-03-02T22:16:32.35+00:00","url":"https://junglewise.ai/threats/cve-2026-3338-aws-aws-lc-signature-verification-bypass-in-pkcs7-verify"},{"cve":"CVE-2026-3336","cvss":7.5,"epss":0.0038,"slug":"cve-2026-3336-aws-aws-lc-certificate-chain-validation-bypass-in-pkcs7-verify","title":"AWS AWS-LC certificate chain validation bypass in PKCS7_verify","severity":"high","exploited":false,"published_at":"2026-03-02T22:16:31.277+00:00","url":"https://junglewise.ai/threats/cve-2026-3336-aws-aws-lc-certificate-chain-validation-bypass-in-pkcs7-verify"},{"cve":"CVE-2026-0897","cvss":7.5,"epss":0.0034,"slug":"cve-2026-0897-google-keras-denial-of-service-via-hdf5-shape-bomb-in-weight","title":"Google Keras Denial of Service via HDF5 shape bomb in weight loading","severity":"high","exploited":false,"published_at":"2026-01-15T14:16:26.89+00:00","url":"https://junglewise.ai/threats/cve-2026-0897-google-keras-denial-of-service-via-hdf5-shape-bomb-in-weight"},{"cve":"CVE-2026-44577","cvss":5.9,"epss":0.0094,"slug":"cve-2026-44577-vercel-next-js-denial-of-service-in-image-optimization-api","title":"Vercel Next.js denial of service in Image Optimization API","severity":"medium","exploited":false,"published_at":"2026-05-13T17:16:23.173+00:00","url":"https://junglewise.ai/threats/cve-2026-44577-vercel-next-js-denial-of-service-in-image-optimization-api"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}