← All Advisories

CVE-2026-83596

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-83596

Key Details

CVECVE-2026-83596
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-09-30
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsRed Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7, WebKit WebKit, and WebKitGTK WebKitGTK
Classified asCWE-120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 7
WebKitWebKit
WebKitGTKWebKitGTK
SubsystemsOT Supporting Infrastructure
SectorsMultiple

What to Know

A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling. (NVD)

What to Do

Monitor Red Hat, WebKit, and WebKitGTK's web pages for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-83596
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-83596