Satellite
This hub aggregates every CVE we track for Satellite, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
224
CVEs tracked
26
Critical
56
High
4
In CISA KEV
Severity distribution
MEDIUM112HIGH56LOW30CRITICAL26
Monthly trend
0
0
2
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
3
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Satellite.
- CVE-2026-48864Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data7.8
- CVE-2026-9149Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file6.5
- CVE-2026-9150Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums6.5
- CVE-2026-0980Rubyipmi: red hat satellite: remote code execution in rubyipmi via malicious bmc username8.3
- CVE-2024-7923Puppet-pulpcore: an authentication bypass vulnerability exists in pulpcore9.8
- CVE-2024-7012Puppet-foreman: an authentication bypass vulnerability exists in foreman9.8
- CVE-2024-4812Katello: potential cross-site scripting exploit in ui4.8
- CVE-2024-3716Foreman-installer: candlepin database password being leaked to local users via the process list6.2
- CVE-2023-4320Satellite: arithmetic overflow in satellite7.6
- CVE-2023-5189Hub: insecure galaxy-importer tarfile extraction6.3
- CVE-2023-44487The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.KEV7.5
- CVE-2023-1832Improper authorization check in the server component6.8
- CVE-2023-4886Foreman: world readable file containing secrets6.7
- CVE-2022-3874Os command injection via ct_command and fcct_command8.0
- CVE-2023-0462Arbitrary code execution through yaml global parameters8.0
Product normalization is registry-driven with AI assist and human review. How it works