Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories
1225 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 785 high, 384 medium, 25 low.
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux Red Hat Enterprise Linux advisories
Critical [CVE-2026-33937] Remote Code Execution via crafted Abstract Syntax Tree object in compile()
Remote Code Execution via crafted Abstract Syntax Tree object in compile(). Red Hat rates this important (CVSS 9.8). Weakness: CWE-94. Affected package(s): cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, devspaces/code-rhel9:1776744110. Resolved in Red Hat advisory RHSA-2026:34342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.27; Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; and 1 more.
Critical [CVE-2026-33210] Denial of Service or Information Disclosure via format string injection
Denial of Service or Information Disclosure via format string injection. Red Hat rates this important (CVSS 9.1). Weakness: CWE-134. Affected package(s): ruby4.0, ruby:4.0. Resolved in Red Hat advisory RHSA-2026:20606 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
Critical [CVE-2026-33186] Authorization bypass due to improper HTTP/2 path validation
Authorization bypass due to improper HTTP/2 path validation. Red Hat rates this important (CVSS 9.1). Weakness: CWE-551. Affected package(s): rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9:1780078429, odf4/odf-csi-addons-sidecar-rhel9:1781550957, rhtas/trillian-logserver-rhel9:1776243434, openshift4/ose-cluster-olm-rhel9-operator:1779787336, rhdh/rhdh-rhel9-operator:1774544220, openshift4/ose-csi-driver-nfs-rhel9:1778242571. Resolved in Red Hat advisory RHSA-2026:27893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Container Platform 4.16; Red Hat OpenShift Container Platform 4.17; Red Hat OpenShift Container Platform 4.18; Red Hat Satellite 6.16 for RHEL 8; and 113 more.
Critical [CVE-2026-27446] org.apache.artemis:artemis-server: org.apache.activemq:artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration due to missing authentication
org.apache.artemis:artemis-server: org.apache.activemq:artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration due to missing authentication. Red Hat rates this important (CVSS 9.1). Weakness: CWE-306. Affected package(s): eap8-activemq-artemis, artemis-server. Resolved in Red Hat advisory RHSA-2026:3955 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat build of OptaPlanner 8; Red Hat Fuse 7; and 1 more.
Critical [CVE-2026-27606] Remote Code Execution via Path Traversal Vulnerability
Remote Code Execution via Path Traversal Vulnerability. Red Hat rates this important (CVSS 9.1). Weakness: CWE-22. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, automation-gateway, ansible-automation-platform, devspaces/traefik-rhel9:1776718585, automation-platform-ui, quay/quay-rhel8:1773971077. Resolved in Red Hat advisory RHSA-2026:5649 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Developer Hub 1.8; and 10 more.
Critical [CVE-2026-1615] Arbitrary Code Execution via unsafe JSON Path expression evaluation
Arbitrary Code Execution via unsafe JSON Path expression evaluation. Red Hat rates this important (CVSS 9.8). Weakness: CWE-94. Affected package(s): ansible-automation-platform, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:6309 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5; Red Hat Ansible Automation Platform 2.6; Red Hat Developer Hub 1.9; OpenShift Pipelines; and 2 more.
Critical [CVE-2026-1709] Authentication bypass allows unauthorized administrative operations due to missing client-side TLS authentication
Authentication bypass allows unauthorized administrative operations due to missing client-side TLS authentication. Red Hat rates this critical (CVSS 9.4). Weakness: CWE-322. Affected package(s): keylime. Resolved in Red Hat advisory RHSA-2026:2225 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.
Critical [CVE-2025-15467] Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing
Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing. Red Hat rates this important (CVSS 9.8). Weakness: CWE-120. Affected package(s): service-interconnect/skupper-operator-bundle:1.8.8, devspaces/dashboard-rhel9:1770764461, devspaces/pluginregistry-rhel9:1770918006, service-interconnect/skupper-controller-podman-container-rhel9:1.8.8, rhui5/rhua-rhel9:1773670137, openssl. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Container Platform 4.13; Red Hat OpenShift Container Platform 4.14; Red Hat OpenShift Container Platform 4.15; Red Hat OpenShift Container Platform 4.16; and 32 more.
Critical [CVE-2025-12543] Undertow HTTP Server Fails to Reject Malformed Host Headers Leading to Potential Cache Poisoning and SSRF
Undertow HTTP Server Fails to Reject Malformed Host Headers Leading to Potential Cache Poisoning and SSRF. Red Hat rates this important (CVSS 9.6). Weakness: CWE-20. Affected package(s): eap8-wildfly, eap8-undertow, eap8-apache-cxf, eap8-wildfly-clustering, eap8-bouncycastle, eap7-undertow. Resolved in Red Hat advisory RHSA-2026:3889 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; and 10 more.
Critical [CVE-2025-49794] Libxml: heap use after free (uaf) leads to denial of service (dos)
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.2 Advanced Update Support; and 25 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; and 20 more.
Critical [CVE-2025-49796] Libxml: type confusion leads to denial of service (dos)
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.2 Advanced Update Support; and 26 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; and 21 more.