Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories
1641 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 35 critical, 621 high, 814 medium, 169 low.
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat RHEL & SELinux advisories
Medium [CVE-2026-15603] Log Forging via unescaped Unicode line separators
Log Forging via unescaped Unicode line separators. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-117. Affected products named by the advisory: Cryostat 4; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Fuse 7; and 6 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Openshift Data Foundation 4; Red Hat package: linux-sgx; Red Hat package: nodejs22; and 2 more.
Medium [CVE-2026-73209] Denial of Service via crafted compressed data
Denial of Service via crafted compressed data. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.
Medium [CVE-2026-52687] Denial of Service via IMAP compression memory exhaustion
Denial of Service via IMAP compression memory exhaustion. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.
Medium [CVE-2026-42395] Denial of Service via NUL byte in forwarding information
Denial of Service via NUL byte in forwarding information. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-170. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.
Medium [CVE-2026-42392] Information disclosure via invalid IMAP URLFETCH command
Information disclosure via invalid IMAP URLFETCH command. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.
Medium [CVE-2026-42008] Authentication bypass via trusted proxy forwarding
Authentication bypass via trusted proxy forwarding. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-349. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.
Medium [CVE-2026-40205] Authorization bypass via partially valid OAuth2 token
Authorization bypass via partially valid OAuth2 token. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-303. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.
Medium [CVE-2026-40017] Denial of Service via crafted IMAP message headers
Denial of Service via crafted IMAP message headers. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.
Medium [CVE-2026-40015] Denial of Service via malformed IMAP commands in imap-hibernate service
Denial of Service via malformed IMAP commands in imap-hibernate service. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.
Medium [CVE-2026-40014] Denial of Service via crafted IMAP THREAD command
Denial of Service via crafted IMAP THREAD command. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-606. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.
Medium [CVE-2026-40013] Denial of Service in ManageSieve service via crafted Sieve script
Denial of Service in ManageSieve service via crafted Sieve script. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.
Medium [CVE-2026-33607] Denial of Service via IMAP LIST command
Denial of Service via IMAP LIST command. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-606. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.
Medium [CVE-2026-33606] Unauthorized mailbox modification via dsync command injection
Unauthorized mailbox modification via dsync command injection. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.
Medium [CVE-2026-33604] SMTP smuggling vulnerability allows spoofed email injection
SMTP smuggling vulnerability allows spoofed email injection. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-93. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.
Medium [CVE-2026-37236] Access control bypass via X-HTTP-Method-Override header
Access control bypass via X-HTTP-Method-Override header. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-444. Affected products named by the advisory: Cryostat 4; Migration Toolkit for Applications 8; Multicluster Global Hub; OpenShift Serverless; and 12 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; and 8 more.
Medium [CVE-2026-80179] Denial of Service via malformed JWE tokens
A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memory, leading to a MemoryError. This issue results in a denial of service (DoS) for services that process untrusted JWE values. An attacker could provide a specially crafted malformed JWE token, causing excessive memory allocation and potentially degrading service availability. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 16.2. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: python-jwcrypto.
Medium [CVE-2026-18374] Heap buffer overflow via attacker-controlled fopen mode string
Heap buffer overflow via attacker-controlled fopen mode string. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-134. Red Hat lists fixing advisory RHSA-2026:65339 with package glibc-main-2.43-8.5.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: glibc; Red Hat package: compat-glibc.
Medium [CVE-2026-81893] invalid write in JPEG ICC profile parser on error recovery
A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. Affected version >= 2.26.4 Red Hat Product Security has rated this issue as having Moderate security impact. Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gdk-pixbuf2.
Medium [CVE-2026-59272] Information disclosure due to disabled TLS hostname verification
Information disclosure due to disabled TLS hostname verification. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-295. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat AMQ Broker 7; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 17 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; and 13 more.
Medium [CVE-2026-80213] Resolv gem: DNS allowlist and egress bypass, and cache poisoning via crafted hostnames
Resolv gem: DNS allowlist and egress bypass, and cache poisoning via crafted hostnames. Red Hat rates this moderate (CVSS 4). Weakness: CWE-130. Red Hat lists fixing advisory RHSA-2026:62563 with package ruby4-0-main-4.0.6-37.2.hum1, ruby4-0-main-4.0.6-37.3.hum1, ruby3-4-main-3.4.10-31.6.hum1, ruby3-3-main-3.3.10-23.5.hum1. Affected products named by the advisory: Red Hat Hardened Images; Lightspeed Core; Red Hat 3scale API Management Platform 2; Red Hat Enterprise Linux 10; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.