VULNERABILITY REMEDIATION

CVE remediation guides

Move from asset identification to supported remediation and post-change verification while keeping source evidence visible.

These defensive guides do not provide exploit reproduction or bypass instructions.
01

Confirm exposure first

Match the product, version, installation path, and external exposure before treating a score as an action order.

02

Prefer supported fixes

Use vendor advisories and supported update paths. An unverified fixed-version field stays visibly unresolved.

03

Verify and retain rollback

Confirm version state, service health, access paths, logs, and rollback readiness after the change.

19,042 guide candidatesPage 1132 of 1587
Review reviewHighResearch in progress
CVE-2026-27137

Go standard library crypto/x509, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support

Affected
>= 1.26.0-0 < 1.26.1, 1.26.0
Fixed
No verified fixed-version field is available yet
Review reviewHighFixed-version data
CVE-2026-25679

Go standard library net/url, Cryostat 4 on RHEL 9, Red Hat Ansible Automation Platform 2.5 for RHEL 8

Affected
< 1.25.8, >= 1.26.0-0 < 1.26.1, 1.26.0
Fixed
1.25.8
Review reviewHighFixed-version data
CVE-2026-29063

immutable-js immutable-js, Cluster Observability Operator 1.5.0, Migration Toolkit for Virtualization 2.1

Affected
>= 3.0.0 < 3.8.3, >= 4.0.0 < 4.3.7, >= 5.0.0 < 5.1.5
Fixed
3.8.3, 4.3.7, 5.1.5
Review reviewHighFixed-version data
CVE-2026-29091

locutusjs locutus, Logging Subsystem for Red Hat OpenShift

Affected
< 3.0.0
Fixed
3.0.0
Review reviewHighResearch in progress
CVE-2025-70363

ez platform

Affected
>= 2.0.0 <= 2.5.32
Fixed
No verified fixed-version field is available yet
Review reviewHighFixed-version data
CVE-2026-26018

coredns coredns, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Advanced Cluster Management for Kubernetes 2.14

Affected
< 1.14.2
Fixed
1.14.2
Review reviewHighFixed-version data
CVE-2026-29074

svg svgo, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9

Affected
>= >= 2.1.0, >= >= 3.0.0, >= = 4.0.0, >= 2.1.0 < 2.8.1, >= 3.0.0 < 3.3.3, >= 4.0.0 < 4.0.1
Fixed
2.8.1, 3.3.3, 4.0.1
Review reviewHighFixed-version data
CVE-2026-29062

FasterXML jackson-core, Red Hat Certificate System 10, Red Hat Enterprise Linux 10

Affected
>= >= 3.0.0, >= 3.0.0 < 3.1.0
Fixed
3.1.0
Review reviewHighFixed-version data
CVE-2026-28802

authlib authlib, Red Hat Ansible Automation Platform 2.6, Red Hat Quay 3.1

Affected
>= >= 1.6.5, >= 1.6.5 < 1.6.7
Fixed
1.6.7
Review reviewHighResearch in progress
CVE-2026-3047

Red Hat Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2.14, Red Hat build of Keycloak 26.4

Affected
26.2, 26.2.14, 26.4, 26.4.10
Fixed
No verified fixed-version field is available yet
Review reviewHighResearch in progress
CVE-2026-3009

Red Hat Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.4.10, Red Hat JBoss Enterprise Application Platform 8

Affected
26.4, 26.4.10, 8.0, 7.0
Fixed
No verified fixed-version field is available yet
Review reviewHighFixed-version data
CVE-2026-29054

traefik traefik, Red Hat OpenShift Dev Spaces 3.27

Affected
>= >= 2.11.9, >= >= 3.1.3, >= 2.11.9 < 2.11.38, >= 3.1.3 < 3.6.9
Fixed
2.11.38, 3.6.9