Known vulnerabilities in buildah (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:buildah_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 128
Public exploits: 5
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting buildah (Red Hat package) buildah (Red Hat package) is affected by 128 known vulnerabilities: 8 high, 88 medium, 32 low Critical High Medium Low

Vulnerabilities (128)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU140622 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-39822
CWE-59 Low
No
No
1.43.1-4.el9_8, 1.43.1-4.el10_2 31.07.2026 SB2026073128
SB20260731126
SB20260731127
and 8 more
#VU140600 - Improper input validation
CVE-2026-32281
CWE-20 Medium
No
No
1.33.15-1.el9_4.1, 1.43.1-2.el10_2 31.07.2026 SB2026073125
SB2026073183
SB2026073184
and 35 more
#VU140599 - Resource exhaustion
CVE-2026-32280
CWE-400 Medium
No
No
1.33.12-5.rhaos4.19.el9, 1.33.15-1.el9_4.1, 1.43.1-2.el10_2 31.07.2026 SB2026073125
SB2026073160
SB2026073161
and 70 more
#VU136680 - Dependency on Vulnerable Third-Party Component
CVE-2026-32283
CWE-1395 Medium
No
No
1.26.11-1.el9_0, 1.33.15-1.el9_4.1, 1.43.1-2.el10_2 02.07.2026 SB2026070218
SB2026070239
SB2026070240
and 61 more
#VU125945 - Improper input validation
CVE-2026-34986
CWE-20 Medium
No
No
1.29.7-1.el9_2.5, 1.33.15-1.el9_4.1 14.04.2026 SB2026041463
SB2026041464
SB2026041465
and 73 more
#VU124118 - Improper input validation
CVE-2026-25679
CWE-20 Medium
No
No
1.26.11-1.el9_0, 1.29.7-1.el9_2.5, 1.39.6-2.el9_6, 1.39.8-1.el10_0, 1.43.1-2.el10_2 19.03.2026 SB2026031903
SB2026031904
SB2026031905
and 134 more
#VU124034 - Resource exhaustion
CVE-2025-61726
CWE-400 Medium
No
No
1.26.11-1.el9_0, 1.29.7-1.el9_2.5, 1.33.12-3.rhaos4.17.el8, 1.33.12-3.rhaos4.17.el9, 1.39.6-2.el9_6, 1.39.8-1.el10_0, 1.41.8-2.el9_7, 1.41.8-2.el10_1 16.03.2026 SB2026031636
SB2026031637
SB2026031638
and 143 more
#VU123129 - Improper Certificate Validation
CVE-2025-68121
CWE-295 High
No
No
1.26.11-1.el9_0, 1.29.7-1.el9_2.5, 1.39.6-2.el9_6, 1.39.8-1.el10_0, 1.41.8-2.el9_7, 1.41.8-2.el10_1 23.02.2026 SB2026022333
SB2026030334
SB2026030343
and 116 more
#VU121565 - Resource exhaustion
CVE-2025-65637
CWE-400 Medium
No
No
1.29.5-1.el9_2.2 15.01.2026 SB2026011525
SB20260116132
SB2026011920
and 35 more
#VU119235 - Resource exhaustion
CVE-2025-61729
CWE-400 Medium
No
No
1.26.11-1.el9_0, 1.29.7-1.el9_2.5, 1.39.6-2.el9_6, 1.39.8-1.el10_0, 1.41.8-2.el9_7, 1.41.8-2.el10_1 06.12.2025 SB2025120604
SB20251210172
SB20251210173
and 146 more
#VU118717 - Improper input validation
CVE-2025-47913
CWE-20 Low
No
No
1.26.11-1.el9_0, 1.29.5-1.el9_2.2, 1.39.6-2.el9_6, 1.39.8-1.el10_0, 1.41.8-1.el10_1 24.11.2025 SB2025112448
SB2025112455
SB2025112456
and 53 more
#VU118190 - Resource exhaustion
CVE-2025-58183
CWE-400 Medium
No
No
1.29.5-1.el9_2.2, 1.39.6-1.el9_6, 1.41.6-1.el9_7, 1.41.6-1.el10_1 07.11.2025 SB2025110705
SB2025110725
SB2025110726
and 177 more
#VU118105 - UNIX Symbolic Link (Symlink) Following
CVE-2025-52881
CWE-61 Low
No
No
1.29.5-1.el9_2.2, 1.33.12-3.rhaos4.17.el8, 1.33.12-3.rhaos4.17.el9, 1.39.5-1.el9_6, 1.39.5-1.el10_0, 1.41.6-1.el9_7, 1.41.6-1.el10_1 05.11.2025 SB2025110519
SB2025110530
SB2025110545
and 62 more
#VU107019 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-22871
CWE-444 Medium
No
No
1.33.12-2.el9_4.1, 1.33.12-2.rhaos4.19.el9, 1.39.4-2.el9_6, 1.39.4-2.el10_0 05.04.2025 SB2025040507
SB2025040508
SB2025040739
and 109 more
#VU105450 - Resource exhaustion
CVE-2025-27144
CWE-400 Medium
No
No
1.39.4-1.el9_6 07.03.2025 SB2025030735
SB2025030736
SB2025030737
and 80 more
#VU103500 - Permissions, Privileges, and Access Controls
CVE-2024-11218
CWE-264 Medium
No
No
1.23.5-1.rhaos4.12.el8, 1.23.5-1.rhaos4.12.el9, 1.26.9-1.el9_0, 1.29.5-1.el9_2, 1.29.5-1.rhaos4.15.el8, 1.29.5-1.rhaos4.15.el9, 1.33.12-2.el9_4, 1.37.6-1.el9_5 03.02.2025 SB2025020321
SB2025020332
SB2025020333
and 34 more
#VU98140 - Improper input validation
CVE-2024-9407
CWE-20 Low
No
No
1.33.11-1.el9_4, 1.37.5-1.el9_5 08.10.2024 SB2024100842
SB2024100843
SB2024100848
and 24 more
#VU97965 - Improper Access Control
CVE-2024-44082
CWE-284 Low
No
No
1.23.4-8.rhaos4.12.el8, 1.23.4-8.rhaos4.12.el9 02.10.2024 SB2024100260
SB2024100261
SB2024100262
and 10 more
#VU93850 - Resource exhaustion
CVE-2024-24791
CWE-400 Medium
No
No
1.37.2-1.el9 07.07.2024 SB2024070727
SB2024070728
SB2024070729
and 86 more
#VU89685 - Improper Validation of Integrity Check Value
CVE-2024-3727
CWE-354 Medium
No
No
1.33.7-1.1.rhaos4.16.el8, 1.33.7-1.1.rhaos4.16.el9, 1.37.2-1.el9 21.05.2024 SB2024052112
SB2024052116
SB2024052117
and 68 more


Showing elements 1 - 20 out of 128