Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1655 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 33 critical, 629 high, 820 medium, 171 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

High8.8Red Hat

High [CVE-2026-5674] Sandbox escape and arbitrary code execution via malicious library loading

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system. Important: This flaw in PipeWire allows for a sandbox escape, enabling arbitrary code execution outside of sandboxed environments, such as Flatpak applications, when minimal permissions are granted. Red Hat products utilizing PipeWire's PulseAudio compatibility layer are susceptible, as an attacker can load a malicious library from within a sandboxed process, bypassing isolation mechanisms. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-427. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2026-5674
Red Hat Enterprise Linux
Jul 16, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-14957] badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with no CA certificates loaded in the NSS database are not vulnerable. A flaw was found in Libreswan. An unauthenticated remote attacker can send a specially crafted X.509 certificate payload during an IKEv1 or IKEv2 exchange. This flaw occurs when Libreswan is operating in FIPS (Federal Information Processing Standards) mode and processing a certificate with an invalid public key, such as an RSA exponent of zero. This can trigger an assertion failure, leading to the termination of the daemon process and a denial of service.

CVE-2026-14957
Red Hat Enterprise Linux
Jul 15, 2026
High7.5Red Hat

High [CVE-2026-50651] SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM

Allocation of resources without limits or throttling in.NET allows an unauthorized attacker to deny service over a network..NET Denial of Service Vulnerability - HTTP/2 SETTINGS/PING ACK flood causing OOM Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images. Red Hat lists Red Hat Hardened Images as not affected. Red Hat fixing advisory: RHSA-2026:41893, RHSA-2026:41895, RHSA-2026:41897, RHSA-2026:58566, RHSA-2026:58567, RHSA-2026:41899, RHSA-2026:41900, RHSA-2026:41901, RHSA-2026:41894, RHSA-2026:41896, RHSA-2026:41898, RHSA-2026:58568, RHSA-2026:58569, RHSA-2026:58570, RHSA-2026:26638, RHSA-2026:27171, RHSA-2026:42145. Affected products named by the advisory: Red Hat package: dotnet8.0; Red Hat package: dotnet9.0; Red Hat package: dotnet10.0.

CVE-2026-50651
Red Hat Enterprise Linux
Jul 14, 2026
High7.4Red Hat

High [CVE-2026-15766] Uninitialized Use in Skia

Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) An uninitialized use flaw was found in the Skia component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N). Weakness: CWE-824. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:74084. Affected products named by the advisory: Red Hat package: webkit2gtk3; Red Hat package: webkitgtk4.

CVE-2026-15766
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-48801] Denial of Service via algorithmic complexity vulnerability

linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails. Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service triggerable by a tens-of-KB request body. This issue is fixed in version 5.0.1. This can be exploited by a remote attacker sending a specially crafted request body, leading to a worker-process denial of service (DoS) due to excessive CPU usage when synchronously rendering untrusted Markdown with linkify enabled. This Moderate impact flaw in linkify-it, a link recognition library, can lead to a denial of service in Red Hat products. The vulnerability arises from an O(N²) algorithmic complexity when processing untrusted Markdown with numerous fuzzy links or emails, potentially causing excessive CPU consumption and worker-process unavailability. This risk is present in services that synchronously render untrusted Markdown with the linkify feature enabled. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1333.

CVE-2026-48801
Red Hat Enterprise Linux
Jul 14, 2026
High8.1Red Hat

High [CVE-2026-49978] Cross-site scripting vulnerability allows code execution

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7. When performing in-place sanitization, DOMPurify could fail to properly process content within shadow DOM elements attached to a `.content`. This oversight allows an attacker to embed malicious code, such as JavaScript, which could then execute when the sanitized template is used by an application, potentially leading to unauthorized actions or information disclosure. This vulnerability in DOMPurify is rated as Important as it allows for cross-site scripting (XSS) attacks. This could lead to unauthorized actions or information disclosure in Red Hat products that utilize DOMPurify for sanitizing untrusted HTML, MathML, or SVG. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N). Weakness: CWE-79. Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat AMQ Broker 7.13.6; Red Hat AMQ Broker 7.14.1; Red Hat Data Grid 8.6.3; and 33 more.

CVE-2026-49978
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-15711] WebSocket remote denial of service via oversized control frame protocol violation

A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a payload of 125 bytes or less. A remote, unauthenticated attacker can exploit this by sending a non-compliant, oversized control frame. Because the parser handles this protocol violation improperly instead of throwing an immediate connection termination error, it triggers a internal processing crash, resulting in a remote denial of service (DoS) for applications utilizing libsoup WebSockets. This flaw poses a moderate availability risk to both client and server applications depending on libsoup for WebSocket networking. By failing to drop connections that break core protocol design rules, the library allows low-complexity remote inputs to abruptly terminate the service state machine. Exploitation requires no authentication or user interaction, allowing any hostile peer on the wire to forcibly disconnect endpoints or crash application wrapper logic by intentionally packing data into a signaling frame. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770.

CVE-2026-15711
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-15709] WebSocket permessage-deflate Unbounded Decompression Remote Denial of Service

A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compressed frame size via max_incoming_payload_size, it fails to track or limit memory allocation during decompression. A separate check for decompressed size (max_total_message_size) exists but executes only after inflation is complete, and it is entirely disabled by default for client connections. A remote, unauthenticated attacker can exploit this by sending a small, highly compressed payload (a decompression bomb), causing unbounded memory allocation that triggers an Out-of-Memory (OOM) crash and a Denial of Service (DoS). This vulnerability poses a high availability risk to both clients and servers utilizing libsoup for WebSocket communication. Because the memory exhaustion occurs during the extraction process before payload size validations are applied, standard post-decompression limits fail to mitigate the threat. A network-based attacker requires no privileges or user interaction to deliberately crash vulnerable applications or desktop services that establish connections using the default permessage-deflate configuration.

CVE-2026-15709
Red Hat Enterprise Linux
Jul 14, 2026
High7.8Red Hat

High [CVE-2026-50650] .NET Framework: Privilege escalation via code injection

Improper control of generation of code ('code injection') in.NET Framework allows an unauthorized attacker to elevate privileges locally. Successful exploitation can lead to local privilege escalation, enabling the attacker to gain higher access rights on the affected system. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-94. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images. Red Hat lists Red Hat Hardened Images; Red Hat OpenShift Dev Spaces as not affected. Red Hat fixing advisory: RHSA-2026:41893, RHSA-2026:41895, RHSA-2026:41897, RHSA-2026:58566, RHSA-2026:58567, RHSA-2026:41899, RHSA-2026:41900, RHSA-2026:41901, RHSA-2026:41894, RHSA-2026:41896, RHSA-2026:41898, RHSA-2026:58568, RHSA-2026:58569, RHSA-2026:58570, RHSA-2026:27171, RHSA-2026:42145. Affected products named by the advisory: Red Hat package: dotnet8.0; Red Hat package: dotnet9.0; Red Hat package: dotnet10.0.

CVE-2026-50650
Red Hat Enterprise Linux
Jul 14, 2026
High7.8Red Hat

High [CVE-2026-50649] .NET: Local code execution via deserialization of untrusted data

Deserialization of untrusted data in.NET allows an unauthorized attacker to execute code locally. A flaw was found in.NET. This means that if an attacker can provide specially crafted data, the.NET application may process it in a way that leads to the execution of malicious code on the system where the application is running. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-502. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images. Red Hat lists Red Hat Hardened Images; Red Hat OpenShift Dev Spaces as not affected. Red Hat fixing advisory: RHSA-2026:41893, RHSA-2026:41895, RHSA-2026:41897, RHSA-2026:58566, RHSA-2026:58567, RHSA-2026:41899, RHSA-2026:41900, RHSA-2026:41901, RHSA-2026:41894, RHSA-2026:41896, RHSA-2026:41898, RHSA-2026:58568, RHSA-2026:58569, RHSA-2026:58570, RHSA-2026:27171, RHSA-2026:42145. Affected products named by the advisory: Red Hat package: dotnet8.0; Red Hat package: dotnet9.0; Red Hat package: dotnet10.0.

CVE-2026-50649
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Red Hat

High [CVE-2026-50648] .NET Framework: Remote Denial of Service due to uncontrolled resource allocation

Allocation of resources without limits or throttling in.NET Framework allows an unauthorized attacker to deny service over a network. An unauthorized attacker can exploit this vulnerability remotely by causing the system to allocate resources without proper limits or throttling. This uncontrolled resource allocation can lead to a Denial of Service (DoS), making the affected system unresponsive or unavailable to legitimate users. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images. Red Hat lists Red Hat OpenShift Dev Spaces as not affected. Red Hat fixing advisory: RHSA-2026:41893, RHSA-2026:41895, RHSA-2026:41897, RHSA-2026:58566, RHSA-2026:58567, RHSA-2026:41899, RHSA-2026:41900, RHSA-2026:41901, RHSA-2026:41894, RHSA-2026:41896, RHSA-2026:41898, RHSA-2026:58568, RHSA-2026:58569, RHSA-2026:58570, RHSA-2026:26638, RHSA-2026:27171, RHSA-2026:42145. Affected products named by the advisory: Red Hat package: dotnet8.0; Red Hat package: dotnet9.0; Red Hat package: dotnet10.0.

CVE-2026-50648
Red Hat Enterprise Linux
Jul 14, 2026
High8.2Red Hat

High [CVE-2026-50528] .NET: Security feature bypass due to incorrect authorization

Incorrect authorization in.NET allows an unauthorized attacker to bypass a security feature over a network. This vulnerability enables an attacker to circumvent intended security controls, potentially leading to unauthorized access or actions within the affected system. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N). Weakness: CWE-551. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images. Red Hat lists Red Hat OpenShift Dev Spaces as not affected. Red Hat fixing advisory: RHSA-2026:41893, RHSA-2026:41895, RHSA-2026:41897, RHSA-2026:58566, RHSA-2026:58567, RHSA-2026:41899, RHSA-2026:41900, RHSA-2026:41901, RHSA-2026:41894, RHSA-2026:41896, RHSA-2026:41898, RHSA-2026:58568, RHSA-2026:58569, RHSA-2026:58570, RHSA-2026:26638, RHSA-2026:27171, RHSA-2026:42145. Affected products named by the advisory: Red Hat package: dotnet8.0; Red Hat package: dotnet9.0; Red Hat package: dotnet10.0.

CVE-2026-50528
Red Hat Enterprise Linux
Jul 14, 2026
High7.8Red Hat

High [CVE-2026-50646] .NET Framework: Local Code Execution via Protection Mechanism Failure

Protection mechanism failure in.NET Framework allows an unauthorized attacker to execute code locally. Successful exploitation of this vulnerability can lead to a complete compromise of the affected system. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-807. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images. Red Hat lists Red Hat Hardened Images; Red Hat OpenShift Dev Spaces as not affected. Red Hat fixing advisory: RHSA-2026:41893, RHSA-2026:41895, RHSA-2026:41897, RHSA-2026:58566, RHSA-2026:58567, RHSA-2026:41899, RHSA-2026:41900, RHSA-2026:41901, RHSA-2026:41894, RHSA-2026:41896, RHSA-2026:41898, RHSA-2026:58568, RHSA-2026:58569, RHSA-2026:58570, RHSA-2026:27171, RHSA-2026:42145. Affected products named by the advisory: Red Hat package: dotnet8.0; Red Hat package: dotnet9.0; Red Hat package: dotnet10.0.

CVE-2026-50646
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Red Hat

High [CVE-2026-50527] .NET Framework: Denial of Service via network-based buffer overflow

Stack-based buffer overflow in.NET Framework allows an unauthorized attacker to deny service over a network. Successful exploitation can lead to a denial of service (DoS), making the affected system unavailable to legitimate users. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images. Red Hat lists Red Hat OpenShift Dev Spaces as not affected. Red Hat fixing advisory: RHSA-2026:41893, RHSA-2026:41895, RHSA-2026:41897, RHSA-2026:58566, RHSA-2026:58567, RHSA-2026:41899, RHSA-2026:41900, RHSA-2026:41901, RHSA-2026:41894, RHSA-2026:41896, RHSA-2026:41898, RHSA-2026:58568, RHSA-2026:58569, RHSA-2026:58570, RHSA-2026:26638, RHSA-2026:27171, RHSA-2026:42145. Affected products named by the advisory: Red Hat package: dotnet8.0; Red Hat package: dotnet9.0; Red Hat package: dotnet10.0.

CVE-2026-50527
Red Hat Enterprise Linux
Jul 14, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-50526] .NET: Local tampering via improper link resolution

Improper link resolution before file access ('link following') in.NET allows an authorized attacker to perform tampering locally. A flaw was found in.NET. This could lead to unauthorized modification of data or system files. Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-59. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images. Red Hat lists Red Hat OpenShift Dev Spaces as not affected. Red Hat fixing advisory: RHSA-2026:41893, RHSA-2026:41895, RHSA-2026:41897, RHSA-2026:58566, RHSA-2026:58567, RHSA-2026:41899, RHSA-2026:41900, RHSA-2026:41901, RHSA-2026:41894, RHSA-2026:41896, RHSA-2026:41898, RHSA-2026:58568, RHSA-2026:58569, RHSA-2026:58570, RHSA-2026:26638, RHSA-2026:27171, RHSA-2026:42145. Affected products named by the advisory: Red Hat package: dotnet8.0; Red Hat package: dotnet9.0; Red Hat package: dotnet10.0.

CVE-2026-50526
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Red Hat

High [CVE-2026-50525] .NET: Denial of Service due to uncontrolled resource allocation

Allocation of resources without limits or throttling in.NET allows an unauthorized attacker to deny service over a network. A flaw was found in.NET where uncontrolled allocation of resources can lead to a Denial of Service (DoS). An unauthorized remote attacker could exploit this vulnerability by continuously requesting resources without limits or throttling, causing the affected system to become unresponsive or crash. This can disrupt the availability of services running on the.NET framework. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images. Red Hat lists Red Hat OpenShift Dev Spaces as not affected. Red Hat fixing advisory: RHSA-2026:41893, RHSA-2026:41895, RHSA-2026:41897, RHSA-2026:58566, RHSA-2026:58567, RHSA-2026:41899, RHSA-2026:41900, RHSA-2026:41901, RHSA-2026:41894, RHSA-2026:41896, RHSA-2026:41898, RHSA-2026:58568, RHSA-2026:58569, RHSA-2026:58570, RHSA-2026:26638, RHSA-2026:27171, RHSA-2026:42145.

CVE-2026-50525
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Red Hat

High [CVE-2026-50524] .NET Framework: Denial of Service via improper input validation

Improper validation of specified type of input in.NET Framework allows an unauthorized attacker to deny service over a network. This vulnerability can lead to a Denial of Service (DoS) condition, making the affected system unavailable to legitimate users. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1287. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images. Red Hat lists Red Hat OpenShift Dev Spaces as not affected. Red Hat fixing advisory: RHSA-2026:41893, RHSA-2026:41895, RHSA-2026:41897, RHSA-2026:58566, RHSA-2026:58567, RHSA-2026:41899, RHSA-2026:41900, RHSA-2026:41901, RHSA-2026:41894, RHSA-2026:41896, RHSA-2026:41898, RHSA-2026:58568, RHSA-2026:58569, RHSA-2026:58570, RHSA-2026:26638, RHSA-2026:27171, RHSA-2026:42145. Affected products named by the advisory: Red Hat package: dotnet8.0; Red Hat package: dotnet9.0; Red Hat package: dotnet10.0.

CVE-2026-50524
Red Hat Enterprise Linux
Jul 14, 2026
High8.8Red Hat

High [CVE-2026-47303] Privilege Elevation via Authentication Bypass

Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. This can allow the attacker to elevate their privileges within the system. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-472. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images. Red Hat lists Red Hat OpenShift Dev Spaces as not affected. Red Hat fixing advisory: RHSA-2026:41893, RHSA-2026:41895, RHSA-2026:41897, RHSA-2026:58566, RHSA-2026:58567, RHSA-2026:41899, RHSA-2026:41900, RHSA-2026:41901, RHSA-2026:41894, RHSA-2026:41896, RHSA-2026:41898, RHSA-2026:58568, RHSA-2026:58569, RHSA-2026:58570, RHSA-2026:26638, RHSA-2026:39952, RHSA-2026:42145. Affected products named by the advisory: Red Hat package: dotnet8.0; Red Hat package: dotnet9.0; Red Hat package: dotnet10.0.

CVE-2026-47303
Red Hat Enterprise Linux
Jul 14, 2026
High8.1Red Hat

High [CVE-2026-47304] .NET Security Feature Bypass Vulnerability

Improper verification of cryptographic signature in.NET allows an unauthorized attacker to bypass a security feature over a network. A flaw was found in.NET. This allows the attacker to bypass a critical security feature, potentially leading to significant compromise of confidentiality, integrity, and availability. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-347. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images. Red Hat lists Red Hat Hardened Images; Red Hat OpenShift Dev Spaces as not affected. Red Hat fixing advisory: RHSA-2026:41893, RHSA-2026:41895, RHSA-2026:41897, RHSA-2026:58566, RHSA-2026:58567, RHSA-2026:41899, RHSA-2026:41900, RHSA-2026:41901, RHSA-2026:41894, RHSA-2026:41896, RHSA-2026:41898, RHSA-2026:58568, RHSA-2026:58569, RHSA-2026:58570, RHSA-2026:39952, RHSA-2026:42145. Affected products named by the advisory: Red Hat package: dotnet8.0; Red Hat package: dotnet9.0; Red Hat package: dotnet10.0.

CVE-2026-47304
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Red Hat

High [CVE-2026-47302] .NET: Denial of Service vulnerability due to uncontrolled resource allocation

Allocation of resources without limits or throttling in.NET allows an unauthorized attacker to deny service over a network. A flaw was found in.NET where uncontrolled resource allocation can be exploited by an unauthorized attacker over a network. This vulnerability allows the attacker to exhaust available resources, leading to a Denial of Service (DoS) condition. The lack of limits or throttling mechanisms enables an attacker to disrupt the availability of the affected system. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images. Red Hat lists Red Hat OpenShift Dev Spaces as not affected. Red Hat fixing advisory: RHSA-2026:41893, RHSA-2026:41895, RHSA-2026:41897, RHSA-2026:58566, RHSA-2026:58567, RHSA-2026:41899, RHSA-2026:41900, RHSA-2026:41901, RHSA-2026:41894, RHSA-2026:41896, RHSA-2026:41898, RHSA-2026:58568, RHSA-2026:58569, RHSA-2026:58570, RHSA-2026:26638, RHSA-2026:27171, RHSA-2026:42145.

CVE-2026-47302
Red Hat Enterprise Linux
Jul 14, 2026

← All Red Hat advisories