Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

10919 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.2Red Hat

Medium [CVE-2026-104044] Sssd: sssd: denial of service via crafted passkey kerberos authentication request

A flaw was found in sssd. A local attacker can trigger a Denial of Service (DoS) by sending a specially crafted Pluggable Authentication Module (PAM) request when passkey authentication is enabled. Due to a missing state validation check in passkey Kerberos handling, the PAM responder dereferences an uninitialized pointer and crashes. This failure disrupts authentication services on the host. This vulnerability is rated as Moderate severity because it requires local system access to communicate with the PAM responder socket and results exclusively in a service crash, with no risk of remote code execution or unauthorized data exposure. The issue is further constrained because exploitation is only possible when passkey authentication is actively enabled on the host. Under standard configurations where passkey support is not configured, or where local socket interactions are restricted, standard authentication handling across the system remains unaffected. Red Hat severity: Moderate — CVSS 6.2 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-476. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6.

CVE-2026-104044
Red Hat Enterprise Linux
Oct 6, 2026
Medium5.5Red Hat

Medium [CVE-2026-104043] Sssd: sssd: denial of service via undersized packet parsing in nss responder

A flaw was found in SSSD. A local attacker with access to the Name Service Switch (NSS) responder UNIX socket can trigger an integer underflow by sending a specially crafted request with an undersized packet header. This issue causes an out-of-bounds memory read during packet parsing, crashing the responder process and resulting in a Denial of Service (DoS). This vulnerability is rated as Moderate impact because exploitation is constrained to local users with access to the SSSD NSS UNIX domain socket, resulting in a denial of service without compromising confidentiality or integrity. On standard Red Hat Enterprise Linux systems where SSSD is active, any unprivileged local process can interact with the responder socket by default. While crashing the NSS responder interrupts identity and group resolution across the host, the flaw cannot be leveraged for privilege escalation or remote arbitrary code execution. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-104043
Red Hat Enterprise Linux
Oct 6, 2026
Medium5.5Red Hat

Medium [CVE-2026-104042] Sssd: sssd: denial of service via out-of-bounds read in pam responder

A flaw was found in sssd. A local attacker can cause a Denial of Service (DoS) by sending a crafted Pluggable Authentication Module (PAM) request containing a zero-length authentication token to the responder socket. Due to missing input validation, the service attempts to read beyond buffer boundaries when processing the token, causing the PAM responder to crash. This vulnerability is rated as having Moderate impact because it requires local host access and is confined to causing a denial of service against the SSSD PAM responder service. Successful exploitation does not facilitate remote access, privilege escalation, or unauthorized data exposure. While local unprivileged users can interact with the PAM responder socket in standard deployments, the impact remains restricted to service disruption until the responder process is restarted. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-104042
Red Hat Enterprise Linux
Oct 6, 2026
Medium5.5Red Hat

Medium [CVE-2026-104041] Sssd: sssd: denial of service via unbounded negative cache growth

A flaw was found in SSSD. An unprivileged local user can repeatedly request lookups for nonexistent entries through the Name Service Switch (NSS) responder. Because the negative cache does not limit the total number of stored entries and only removes expired records when an existing key is rechecked, the cache can grow without bound. This behavior can lead to memory exhaustion, resulting in a Denial of Service (DoS) as the responder becomes unresponsive or terminates. This vulnerability is rated as Moderate impact because exploitation is confined to authenticated local accounts capable of issuing repeated failed lookups, restricting the blast radius strictly to host service availability rather than privilege escalation or data disclosure. On Red Hat Enterprise Linux systems where SSSD handles local identity resolution, the responder socket is accessible to unprivileged users by default. While sustained, distinct lookup misses can exhaust responder memory and disrupt host name service availability, the issue cannot be triggered remotely in standard configurations and does not compromise system integrity or confidentiality. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770.

CVE-2026-104041
Red Hat Enterprise Linux
Oct 6, 2026
Medium4.4Red Hat

Medium [CVE-2026-104040] Sssd: sssd: information disclosure via odata injection in entra id lookups

A flaw was found in SSSD. When configured with the Entra ID identity provider, input lookup names containing single quotes are not properly escaped before being included in Microsoft Graph Open Data Protocol (OData) queries. A low-privileged local user can exploit this flaw by submitting a crafted search request, altering query filters to broaden user or group searches. This can lead to information disclosure by retrieving unintended directory objects, as well as a Denial of Service (DoS) through excessive processing and cache population. This vulnerability is rated as Moderate because exploitation requires local access and non-standard domain configuration using the Entra ID identity provider (`idp_type = entra_id`). In standard Red Hat Enterprise Linux deployments, SSSD does not enable this identity provider by default. An authenticated local attacker can manipulate account lookups to alter query filters, potentially exposing directory metadata or causing resource exhaustion from processing oversized responses. However, data exposure is restricted to the read permissions already granted to the Microsoft Graph client, and the flaw does not permit unauthorized directory modifications or local privilege escalation. Red Hat severity: Moderate — CVSS 4.4 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L). Weakness: CWE-140.

CVE-2026-104040
Red Hat Enterprise Linux
Oct 6, 2026
Medium4.7Red Hat

Medium [CVE-2026-104039] Sssd: sssd: denial of service via stale connection state reuse in pam gssapi responder

A flaw was found in SSSD. A local user can cause a denial of service (DoS) by disrupting system authentication services. When handling Generic Security Services Application Programming Interface (GSSAPI) authentication in the Pluggable Authentication Module (PAM) responder, cached connection state is freed upon completion without clearing the reference pointer. An attacker can exploit this by sending an additional request over the same connection, causing the service to access invalid memory and unexpectedly terminate. This vulnerability is rated as Moderate because exploitation requires local access, specific non-default configuration, and an established session, resulting solely in a denial of service. The flaw is only reachable when SSSD's PAM responder has GSSAPI authentication explicitly configured and enabled for specific services. Furthermore, triggering the condition requires an authenticated local user to complete an initial GSSAPI context handshake and subsequently submit an additional request over the same connection. Because exploitation crashes the PAM responder process without compromising system confidentiality or integrity, the overall risk is reduced. Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-825.

CVE-2026-104039
Red Hat Enterprise Linux
Oct 6, 2026
Medium5.9Red Hat

Medium [CVE-2026-104038] Sssd: sssd: denial of service via missing sid extension in certificate mapping

A flaw was found in sssd. A remote attacker can cause a denial of service (DoS) by submitting a certificate that lacks an expected Security Identifier (SID) extension. In deployments configured with SID-based certificate mapping rules, the service fails to verify the presence of the extension before processing it, causing the process to crash during authentication or lookup operations. This vulnerability is rated as Moderate impact because triggering the denial of service requires an uncommon, non-default certificate mapping configuration. SSSD deployments are only susceptible if explicitly configured to use LDAPU1 mapping rules that expand SID or RID templates. Furthermore, an attacker must supply a certificate lacking the expected Microsoft SID extension to trigger the crash, confining the operational impact to certificate-driven lookup and authentication flows. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-476. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-104038
Red Hat Enterprise Linux
Oct 6, 2026
Medium5.5Red Hat

Medium [CVE-2026-104037] Sssd: sssd: denial of service via packet length underflow in autofs responder

A flaw was found in SSSD. A local attacker can exploit this issue by sending a specially crafted request with an invalid packet length to the autofs responder UNIX socket. This causes an integer underflow and an out-of-bounds memory read, which can crash the responder process and result in a denial of service (DoS). This vulnerability is rated as Moderate because exploitation is limited to a local denial of service against the SSSD autofs responder daemon, without enabling privilege escalation or data confidentiality/integrity loss. The autofs responder is only exposed if enabled in the SSSD configuration and accessible through its local UNIX socket. Systems where SSSD does not manage automount maps or where the autofs responder is inactive are unaffected by this issue. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-104037
Red Hat Enterprise Linux
Oct 6, 2026
Medium6.8Red Hat

Medium [CVE-2026-92821] Sssd: sssd: access control bypass via premature ldap access rule evaluation

A flaw was found in SSSD. When configured to evaluate password expiration warnings before restrictive access rules in LDAP (Lightweight Directory Access Protocol) environments, an expired-password warning terminates rule evaluation early and treats the access request as successful. A remote authenticated user with an expired password using an alternative authentication method, such as SSH public key authentication, can exploit this flaw to bypass access control restrictions and gain unauthorized access to protected systems. This vulnerability is rated as Moderate severity because successful exploitation requires a specific non-default configuration where `pwd_expire_policy_warn` is ordered ahead of restrictive rules in `ldap_access_order`, combined with a valid user account possessing an expired password. In default Red Hat Enterprise Linux configurations, this access evaluation sequence is not configured, which minimizes typical exposure. While the flaw permits an authenticated user to bypass host or filter restrictions using alternate authentication methods such as SSH public keys, the prerequisites prevent remote, unauthenticated access or compromise in standard installations. Red Hat severity: Moderate — CVSS 6.8 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-393.

CVE-2026-92821
Red Hat Enterprise Linux
Oct 6, 2026
Medium5.8Red Hat

Medium [CVE-2026-104036] Sssd: sssd: denial of service via out-of-bounds write in nfs idmap plugin

A flaw was found in SSSD's NFS idmap plugin. When retrieving cached user or group names, the plugin detects if an entry exceeds the destination buffer size but fails to abort before copying data. A local attacker can trigger this vulnerability by requesting identity lookups that resolve to oversized cached entries, resulting in an out-of-bounds write. This flaw primarily leads to a Denial of Service (DoS) by crashing the identity mapping service, and may also corrupt adjacent process memory. Under these conditions, an authenticated local user capable of triggering UID or GID resolution for oversized account names may corrupt adjacent memory within the idmap daemon process. The blast radius is primarily confined to service destabilization or a local denial of service, with no reliable privilege escalation or remote execution demonstrated in typical default configurations. Red Hat severity: Moderate — CVSS 5.8 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-104036
Red Hat Enterprise Linux
Oct 6, 2026
Medium5.5Red Hat

Medium [CVE-2026-104035] Sssd: sssd: denial of service via memory exhaustion in kcm responder

A flaw was found in SSSD. An issue in the Kerberos Credential Manager (KCM) responder allows a local user to cause a Denial of Service (DoS) by maintaining a persistent connection and repeatedly storing and destroying credentials. Because the service fails to release cached objects from memory when credentials are removed, memory consumption grows continuously, ultimately exhausting available memory and rendering the service unresponsive. This vulnerability is rated as Moderate impact because exploitation is confined to a local denial-of-service condition affecting the SSSD Kerberos Credential Manager (KCM) responder without impacting data confidentiality, integrity, or elevating privileges. A local, authenticated user with access to the KCM UNIX socket can trigger unbounded memory accumulation within the responder daemon by maintaining a persistent connection while cycling credential operations. The blast radius is limited to the availability of the KCM responder process, and standard system operations or other SSSD services remain functional. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-772. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.

CVE-2026-104035
Red Hat Enterprise Linux
Oct 6, 2026
Medium4.7Red Hat

Medium [CVE-2026-104034] Sssd: sssd: denial of service via use-after-free in kcm ticket renewal

A flaw was found in SSSD. A use-after-free vulnerability exists in the Kerberos Credential Manager (KCM) responder during Kerberos ticket-granting ticket (TGT) renewal, where a deferred callback accesses memory that has already been released. An authenticated local user with a renewable Kerberos ticket can trigger this issue on systems configured with KCM renewal, causing the KCM responder service to crash and resulting in a Denial of Service (DoS). This vulnerability is rated as Moderate because exploitation requires local authenticated access and relies on an optional, non-default Kerberos Credential Manager (KCM) renewal feature configured with the secdb storage backend. Under standard Red Hat Enterprise Linux deployments, automated ticket renewal within KCM is disabled by default. Successful exploitation is limited to terminating or destabilizing the KCM responder service, resulting in a localized denial of service without exposing sensitive credential data or allowing privilege escalation. Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6.

CVE-2026-104034
Red Hat Enterprise Linux
Oct 6, 2026
Medium5.4Red Hat

Medium [CVE-2026-104033] Sssd: sssd: access control bypass via improper ldap shadow expiration check

A flaw was found in SSSD. When configured to enforce account expiration using LDAP (Lightweight Directory Access Protocol) shadow attributes, SSSD fails to treat an expiration value of zero as an expired account. A user with valid credentials for an expired account can exploit this flaw to bypass access controls and authenticate to the system. This allows unauthorized access to persist after the account was intended to be deactivated. This vulnerability is rated Moderate because it allows an expired LDAP account to authenticate without authorization, but exploitation requires pre-existing valid credentials and cannot lead to remote code execution or privilege escalation beyond the account's existing privileges. The flaw only affects environments explicitly configured to enforce shadow-based expiration through SSSD using LDAP access control policies. Systems utilizing default SSSD configurations, alternative expiration mechanisms, or centralized directory-level account lockouts are not vulnerable to this bypass. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-193. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.

CVE-2026-104033
Red Hat Enterprise Linux
Oct 6, 2026
Medium5.5Red Hat

Medium [CVE-2026-104032] Sssd: sssd: denial of service via unprivileged autofs cache invalidation

A flaw was found in SSSD. An unprivileged local user can repeatedly request master automount map updates through the autofs responder due to missing authorization checks. This triggers global cache invalidation and forces repeated lookups to backend directory providers, leading to a Denial of Service (DoS) from degraded automount availability and elevated resource consumption. Red Hat rates this vulnerability as Moderate severity because it is restricted to local denial of service without compromising system confidentiality or integrity. The issue only presents a risk on systems configured with the SSSD automount responder where untrusted local users have access to the responder socket. Under these conditions, an authenticated local attacker can degrade automount lookup performance and increase load on backend directory services by triggering frequent cache purges, but cannot gain elevated privileges. Weakness: CWE-408. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-104032
Red Hat Enterprise Linux
Oct 6, 2026
Medium5.5Red Hat

Medium [CVE-2026-104031] Sssd: sssd: denial of service via memory exhaustion in autofs responder

A flaw was found in SSSD. In configurations where the autofs responder service is enabled, memory allocated during successful request processing is not released until the client connection terminates. A local attacker can exploit this vulnerability by maintaining an open connection and repeatedly submitting valid requests, leading to memory exhaustion and a Denial of Service (DoS). Red Hat rates this vulnerability as Moderate severity because exploitation requires local access to an active SSSD autofs responder socket, and the impact is confined to memory exhaustion without compromising system confidentiality or integrity. On standard Red Hat Enterprise Linux systems, the autofs responder is not enabled by default and is only active when automount integration is explicitly configured. An attacker must maintain an open connection and repeatedly issue valid queries to consume resources, limiting the blast radius to the availability of the responder service. Weakness: CWE-772. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-104031
Red Hat Enterprise Linux
Oct 6, 2026
High8.1Red Hat Updated

High [CVE-2019-25777] Arbitrary code execution via unrestricted package variable assignment

Arbitrary code execution via unrestricted package variable assignment. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: perl-yaml.

CVE-2019-25777
Red Hat Enterprise Linux
Oct 5, 2026
High7.4Red Hat Updated

High [CVE-2017-20285] Arbitrary destructor method execution via crafted YAML document

Arbitrary destructor method execution via crafted YAML document. Red Hat rates this important (CVSS 7.4). Weakness: CWE-502. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: perl-yaml.

CVE-2017-20285
Red Hat Enterprise Linux
Oct 5, 2026
Medium5.5Red Hat

Medium [CVE-2026-105447] Quay: quay: global read-only superuser can access build trigger write credentials

A flaw was found in Quay. When handling build trigger requests, the application incorrectly exposes trigger configuration details containing repository write tokens to global read-only administrative users. An authenticated user with read-only privileges can exploit this flaw by querying the build trigger API to retrieve these delegate tokens. This issue allows a restricted user to bypass read-only limitations and push arbitrary container images to private repositories, leading to privilege escalation. This vulnerability is rated Moderate for Red Hat Quay because exploitation requires existing high-privilege authentication as an administrative user assigned to the global read-only superuser role. While the flaw allows such users to obtain build trigger webhook tokens with repository write permissions and upload container images to private repositories, it cannot be leveraged by unauthenticated users or standard repository members. Consequently, the blast radius is confined to environments where global read-only administrative access has been delegated to untrusted accounts. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N). Weakness: CWE-863. Affected Red Hat products: Red Hat Quay 3. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-105447
Unclassified
Oct 5, 2026
Medium5.5Red Hat

Medium [CVE-2026-104030] Sssd: sssd: denial of service via out-of-bounds read during passkey parsing

A flaw was found in sssd. This vulnerability allows a local user to cause a Denial of Service (DoS) by submitting a specially crafted passkey authentication token that lacks null terminators. The authentication service reads past the end of the provided memory buffer, causing the process to crash and disrupting authentication services. Red Hat has rated this vulnerability as Moderate because it enables a local attacker to cause a denial of service in the SSSD PAM responder, interrupting authentication services without allowing privilege escalation or code execution. In standard Red Hat Enterprise Linux deployments, the PAM responder socket is accessible to local unprivileged processes to facilitate user authentication. Although exploitation requires local system access to submit malformed authentication requests, the resulting service termination affects system availability. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-104030
Red Hat Enterprise Linux
Oct 5, 2026
Medium4.2Red Hat

Medium [CVE-2026-102576] Quay: quay: dom-based cross-site scripting via unvalidated redirect_url on signin page

A flaw was found in Quay. A remote attacker could trick a user into logging in through a crafted link, resulting in cross-site scripting (XSS). Because the application does not validate the redirect destination before navigating, this flaw allows the execution of arbitrary script in the context of the victim's authenticated browser session. Successful exploitation requires the target Quay deployment to use direct database authentication and the victim to complete login through the malicious URL. This flaw allows an attacker to craft a login URL that, after a user successfully authenticates, executes arbitrary JavaScript in the user's browser session. Red Hat severity: Moderate — CVSS 4.2 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N). Weakness: CWE-79. Affected Red Hat products: Red Hat Quay 3. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-102576
Unclassified
Oct 5, 2026

← All vendors