Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

RHSA-2026:42088

HighCVSS 8.8 / 10
Published Jul 23, 2026·Last modified Jul 23, 2026
Affected Components(0)

No affected components available

Description

Red Hat Security Advisory: webkit2gtk3 security update

Risk Scores
Base Score
8.8

The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker does not need any special privileges or access rights. The attacker needs the user to perform some action, like clicking a link. The impact is confined to the system where the vulnerability exists. There is a high impact on the confidentiality of the information. There is a high impact on the integrity of the data. There is a high impact on the availability of the system.

Threat Intelligence
8.1

Exploitation activity has been observed. Apply available patches or mitigations urgently.

EPSS
72.65%

The exploit probability is very high. The vulnerability is very likely to be exploited in the next 30 days.

Exploit
Not available

We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.

Related Vulnerabilities
  • CVE-2026-43731
    Upstream
  • CVE-2026-43712
    Upstream
  • CVE-2026-43663
    Upstream
  • CVE-2026-43726
    Upstream
  • CVE-2026-43725
    Upstream
  • CVE-2026-43745
    Upstream
  • CVE-2026-43713
    Upstream
  • CVE-2026-43707
    Upstream
  • CVE-2026-43721
    Upstream
  • CVE-2026-43740
    Upstream
  • CVE-2026-43742
    Upstream
  • CVE-2026-39872
    Upstream
  • CVE-2026-43699
    Upstream
  • CVE-2026-43676
    Upstream
  • CVE-2026-43734
    Upstream
  • CVE-2026-43720
    Upstream
  • CVE-2026-43701
    Upstream
  • CVE-2026-43705
    Upstream
  • CVE-2026-43727
    Upstream
  • CVE-2026-43715
    Upstream
  • CVE-2024-4367

    A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

    UpstreamEPSS 72.6%
  • CVE-2026-43716
    Upstream
  • CVE-2026-43732
    Upstream
  • EUVD-2024-1831
    Upstream
  • EUVD-2026-40183
    Upstream
  • EUVD-2026-40184
    Upstream
  • EUVD-2026-40189
    Upstream
  • EUVD-2026-40192
    Upstream
  • EUVD-2026-40193
    Upstream
  • EUVD-2026-40194
    Upstream
  • EUVD-2026-40196
    Upstream
  • EUVD-2026-40197
    Upstream
  • EUVD-2026-40199
    Upstream
  • EUVD-2026-40200
    Upstream
  • EUVD-2026-40202
    Upstream
  • EUVD-2026-40204
    Upstream
  • EUVD-2026-40205
    Upstream
  • EUVD-2026-40206
    Upstream
  • EUVD-2026-40209
    Upstream
  • EUVD-2026-40210
    Upstream
  • EUVD-2026-40211
    Upstream
  • EUVD-2026-40212
    Upstream
  • EUVD-2026-40214
    Upstream
  • EUVD-2026-40215
    Upstream
  • EUVD-2026-40217
    Upstream
  • EUVD-2026-40218
    Upstream

Browse More

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard