Red hat developer tools
This hub aggregates every CVE we track for Red hat developer tools, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
13
CVEs tracked
6
Critical
3
High
0
In CISA KEV
Severity distribution
CRITICAL6HIGH3MEDIUM3LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
2024-092026-08
Latest CVEs
The 13 most recently published vulnerabilities affecting Red hat developer tools.
- CVE-2026-32281Inefficient policy validation in crypto/x5097.5
- CVE-2024-24790Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip9.8
- CVE-2024-1394Golang-fips/openssl: memory leaks in code encrypting and decrypting rsa payloads7.5
- CVE-2023-29409Large RSA keys can cause high CPU usage in crypto/tls5.3
- CVE-2023-29405Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go9.8
- CVE-2023-29404Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go9.8
- CVE-2023-24540Improper handling of JavaScript whitespace in html/template9.8
- CVE-2023-24537Infinite loop in parsing in go/scanner7.5
- CVE-2023-24538Backticks not treated as string delimiters in html/template9.8
- CVE-2022-41717Excessive memory growth in net/http and golang.org/x/net/http25.3
- CVE-2022-30629Session tickets lack random ticket_age_add in crypto/tls3.1
- CVE-2022-23806Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.9.1
- CVE-2021-28169For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. F...5.3
Product normalization is registry-driven with AI assist and human review. How it works