Known vulnerabilities in yggdrasil (Red Hat package)
Vendor:
Red Hat Inc.
Software:
yggdrasil (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:yggdrasil_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
14
Public exploits:
1
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (14)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU140607 - Time-of-check Time-of-use (TOCTOU) Race Condition CVE-2026-32282 |
CWE-367 | Low | 0.4.8-5.el10_1, 0.4.9-5.el10_2 | 31.07.2026 |
SB2026073125 SB2026073160 SB2026073161 and 49 more |
||
| #VU140600 - Improper input validation CVE-2026-32281 |
CWE-20 | Medium | 0.4.9-5.el10_2 | 31.07.2026 |
SB2026073125 SB2026073183 SB2026073184 and 34 more |
||
| #VU140599 - Resource exhaustion CVE-2026-32280 |
CWE-400 | Medium | 0.4.9-5.el10_2 | 31.07.2026 |
SB2026073125 SB2026073160 SB2026073161 and 65 more |
||
| #VU136680 - Dependency on Vulnerable Third-Party Component CVE-2026-32283 |
CWE-1395 | Medium | 0.4.7-4.el10_0, 0.4.8-5.el10_1 | 02.07.2026 |
SB2026070218 SB2026070239 SB2026070240 and 59 more |
||
| #VU124118 - Improper input validation CVE-2026-25679 |
CWE-20 | Medium | 0.4.7-3.el10_0, 0.4.8-4.el10_1 | 19.03.2026 |
SB2026031903 SB2026031904 SB2026031905 and 130 more |
||
| #VU124034 - Resource exhaustion CVE-2025-61726 |
CWE-400 | Medium | 0.4.7-2.el10_0, 0.4.8-3.el10_1 | 16.03.2026 |
SB2026031636 SB2026031637 SB2026031638 and 142 more |
||
| #VU123129 - Improper Certificate Validation CVE-2025-68121 |
CWE-295 | High | 0.4.7-2.el10_0, 0.4.8-3.el10_1 | 23.02.2026 |
SB2026022333 SB2026030334 SB2026030343 and 112 more |
||
| #VU119235 - Resource exhaustion CVE-2025-61729 |
CWE-400 | Medium | 0.4.7-2.el10_0, 0.4.8-3.el10_1 | 06.12.2025 |
SB2025120604 SB20251210172 SB20251210173 and 146 more |
||
| #VU112437 - Permissions, Privileges, and Access Controls CVE-2025-3931 |
CWE-264 | Low | 0.4.5-3.el10_0 | 07.07.2025 |
SB2025070754 SB2025070757 |
||
| #VU82064 - Resource exhaustion CVE-2023-39325 |
CWE-400 | Medium | 0.2.3-1.el7sat, 0.2.3-1.el8sat, 0.2.3-1.el9sat | 16.10.2023 |
SB2023101651 SB2023101652 SB2023101653 and 341 more |
||
| #VU81728 - Resource exhaustion CVE-2023-44487 |
CWE-400 | High | 0.2.3-1.el7sat, 0.2.3-1.el8sat, 0.2.3-1.el9sat | 10.10.2023 |
SB2023101023 SB2023101024 SB2023101037 and 649 more |
||
| #VU70334 - Allocation of Resources Without Limits or Throttling CVE-2022-41717 |
CWE-770 | Medium | 0.2.3-1.el7sat, 0.2.3-1.el8sat, 0.2.3-1.el9sat | 14.12.2022 |
SB2022121432 SB2022121433 SB2022121435 and 185 more |
||
| #VU64559 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2022-2068 |
CWE-78 | Medium | 0.2.3-1.el7sat, 0.2.3-1.el8sat, 0.2.3-1.el9sat | 21.06.2022 |
SB2022062120 SB2022062125 SB2022062236 and 135 more |
||
| #VU62765 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2022-1292 |
CWE-78 | Medium | 0.2.3-1.el7sat, 0.2.3-1.el8sat, 0.2.3-1.el9sat | 03.05.2022 |
SB2022050315 SB2022050436 SB2022050503 and 141 more |