Update infrastructure
This hub aggregates every CVE we track for Update infrastructure, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Operating Systemson-prem
7
CVEs tracked
0
Critical
3
High
0
In CISA KEV
Severity distribution
MEDIUM4HIGH3
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
3
0
0
0
2024-092026-08
Latest CVEs
The 7 most recently published vulnerabilities affecting Update infrastructure.
- CVE-2026-48864Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data7.8
- CVE-2026-9149Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file6.5
- CVE-2026-9150Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums6.5
- CVE-2023-50782Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-256597.5
- CVE-2023-50781M2crypto: bleichenbacher timing attacks in the rsa decryption api - incomplete fix for cve-2020-256577.5
- CVE-2022-3644The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.5.5
- CVE-2013-4518RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates5.5
Product normalization is registry-driven with AI assist and human review. How it works