Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1641 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 35 critical, 621 high, 814 medium, 169 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

Medium5.3Red Hat

Medium [CVE-2026-15603] Log Forging via unescaped Unicode line separators

Log Forging via unescaped Unicode line separators. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-117. Affected products named by the advisory: Cryostat 4; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Fuse 7; and 6 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Openshift Data Foundation 4; Red Hat package: linux-sgx; Red Hat package: nodejs22; and 2 more.

CVE-2026-15603
Red Hat Enterprise Linux
Aug 28, 2026
Medium6.5Red Hat

Medium [CVE-2026-73209] Denial of Service via crafted compressed data

Denial of Service via crafted compressed data. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-73209
Red Hat Enterprise Linux
Aug 28, 2026
Medium6.5Red Hat

Medium [CVE-2026-52687] Denial of Service via IMAP compression memory exhaustion

Denial of Service via IMAP compression memory exhaustion. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-52687
Red Hat Enterprise Linux
Aug 28, 2026
Medium6.5Red Hat

Medium [CVE-2026-42395] Denial of Service via NUL byte in forwarding information

Denial of Service via NUL byte in forwarding information. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-170. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-42395
Red Hat Enterprise Linux
Aug 28, 2026
Medium4.3Red Hat

Medium [CVE-2026-42392] Information disclosure via invalid IMAP URLFETCH command

Information disclosure via invalid IMAP URLFETCH command. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-42392
Red Hat Enterprise Linux
Aug 28, 2026
Medium4.3Red Hat

Medium [CVE-2026-42008] Authentication bypass via trusted proxy forwarding

Authentication bypass via trusted proxy forwarding. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-349. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-42008
Red Hat Enterprise Linux
Aug 28, 2026
Medium5.9Red Hat

Medium [CVE-2026-40205] Authorization bypass via partially valid OAuth2 token

Authorization bypass via partially valid OAuth2 token. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-303. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-40205
Red Hat Enterprise Linux
Aug 28, 2026
Medium6.5Red Hat

Medium [CVE-2026-40017] Denial of Service via crafted IMAP message headers

Denial of Service via crafted IMAP message headers. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-40017
Red Hat Enterprise Linux
Aug 28, 2026
Medium4.3Red Hat

Medium [CVE-2026-40015] Denial of Service via malformed IMAP commands in imap-hibernate service

Denial of Service via malformed IMAP commands in imap-hibernate service. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-40015
Red Hat Enterprise Linux
Aug 28, 2026
Medium6.5Red Hat

Medium [CVE-2026-40014] Denial of Service via crafted IMAP THREAD command

Denial of Service via crafted IMAP THREAD command. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-606. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-40014
Red Hat Enterprise Linux
Aug 28, 2026
Medium4.3Red Hat

Medium [CVE-2026-40013] Denial of Service in ManageSieve service via crafted Sieve script

Denial of Service in ManageSieve service via crafted Sieve script. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-40013
Red Hat Enterprise Linux
Aug 28, 2026
Medium4.3Red Hat

Medium [CVE-2026-33607] Denial of Service via IMAP LIST command

Denial of Service via IMAP LIST command. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-606. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-33607
Red Hat Enterprise Linux
Aug 28, 2026
Medium5.4Red Hat

Medium [CVE-2026-33606] Unauthorized mailbox modification via dsync command injection

Unauthorized mailbox modification via dsync command injection. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-33606
Red Hat Enterprise Linux
Aug 28, 2026
Medium5.9Red Hat

Medium [CVE-2026-33604] SMTP smuggling vulnerability allows spoofed email injection

SMTP smuggling vulnerability allows spoofed email injection. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-93. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-33604
Red Hat Enterprise Linux
Aug 28, 2026
Medium5.4Red Hat

Medium [CVE-2026-37236] Access control bypass via X-HTTP-Method-Override header

Access control bypass via X-HTTP-Method-Override header. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-444. Affected products named by the advisory: Cryostat 4; Migration Toolkit for Applications 8; Multicluster Global Hub; OpenShift Serverless; and 12 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; and 8 more.

CVE-2026-37236
Red Hat Enterprise Linux
Aug 28, 2026
Medium5.9Red Hat

Medium [CVE-2026-80179] Denial of Service via malformed JWE tokens

A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memory, leading to a MemoryError. This issue results in a denial of service (DoS) for services that process untrusted JWE values. An attacker could provide a specially crafted malformed JWE token, causing excessive memory allocation and potentially degrading service availability. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 16.2. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: python-jwcrypto.

CVE-2026-80179
Red Hat Enterprise Linux
Aug 27, 2026
Medium4.9Red Hat

Medium [CVE-2026-18374] Heap buffer overflow via attacker-controlled fopen mode string

Heap buffer overflow via attacker-controlled fopen mode string. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-134. Red Hat lists fixing advisory RHSA-2026:65339 with package glibc-main-2.43-8.5.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: glibc; Red Hat package: compat-glibc.

CVE-2026-18374
Red Hat Enterprise Linux
Aug 27, 2026
Medium4.7Red Hat

Medium [CVE-2026-81893] invalid write in JPEG ICC profile parser on error recovery

A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. Affected version >= 2.26.4 Red Hat Product Security has rated this issue as having Moderate security impact. Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gdk-pixbuf2.

CVE-2026-81893
Red Hat Enterprise Linux
Aug 27, 2026
Medium6.8Red Hat

Medium [CVE-2026-59272] Information disclosure due to disabled TLS hostname verification

Information disclosure due to disabled TLS hostname verification. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-295. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat AMQ Broker 7; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 17 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; and 13 more.

CVE-2026-59272
Red Hat Enterprise Linux
Aug 27, 2026
Medium4.0Red Hat

Medium [CVE-2026-80213] Resolv gem: DNS allowlist and egress bypass, and cache poisoning via crafted hostnames

Resolv gem: DNS allowlist and egress bypass, and cache poisoning via crafted hostnames. Red Hat rates this moderate (CVSS 4). Weakness: CWE-130. Red Hat lists fixing advisory RHSA-2026:62563 with package ruby4-0-main-4.0.6-37.2.hum1, ruby4-0-main-4.0.6-37.3.hum1, ruby3-4-main-3.4.10-31.6.hum1, ruby3-3-main-3.3.10-23.5.hum1. Affected products named by the advisory: Red Hat Hardened Images; Lightspeed Core; Red Hat 3scale API Management Platform 2; Red Hat Enterprise Linux 10; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.

CVE-2026-80213
Red Hat Enterprise Linux
Aug 27, 2026

← All Red Hat advisories