2026 CVE Vulnerabilities

47,667 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-18947HIGH8.5A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental...
CVE-2026-18942MEDIUM5.5A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. Th...
CVE-2026-18941HIGH7.7A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is...
CVE-2026-18621HIGH7.6A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security harde...
CVE-2026-18620HIGH7.1A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerab...
CVE-2026-18618HIGH7.5A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to kn...
CVE-2026-18617HIGH8.8A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the sp...
CVE-2026-18611HIGH7.5A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive...
CVE-2026-18608HIGH8.7A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permission...
CVE-2026-16456MEDIUM6.5A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can ex...
CVE-2026-15581HIGH8A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to b...
CVE-2026-15467HIGH8.1A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can e...
CVE-2026-14450CRITICAL9.9A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy...
CVE-2026-13717HIGH8.8A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serv...
CVE-2026-11810HIGH7.5The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) pars...
CVE-2026-11809LOW3.7The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z...
CVE-2026-72902CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to...
CVE-2026-72901CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-pri...
CVE-2026-72886CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.u...
CVE-2026-72885NONE0Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, dockerContextPath accepted by apps/dokp...
CVE-2026-72884HIGH8.7Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, sanitizeCommand in packages/server/src/...
CVE-2026-72883HIGH8.8Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/...
CVE-2026-72882CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can crea...
CVE-2026-72881MEDIUM6.4Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command bui...
CVE-2026-72880CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in pack...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now