Skip to content
VulniPulse

Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories

1229 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 799 high, 376 medium, 20 low.

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux Red Hat Enterprise Linux advisories

High8.2Linux

High [CVE-2026-33941] Arbitrary code execution via CLI precompiler input sanitization flaw

Arbitrary code execution via CLI precompiler input sanitization flaw. Red Hat rates this important (CVSS 8.2). Weakness: CWE-94. Affected package(s): cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, devspaces/code-rhel9:1776744110. Resolved in Red Hat advisory RHSA-2026:34342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.27; Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; and 1 more.

CVE-2026-33941
Red Hat Enterprise Linux
Mar 27, 2026
High8.1Linux

High [CVE-2026-33940] Arbitrary code execution via crafted template context

Arbitrary code execution via crafted template context. Red Hat rates this important (CVSS 8.1). Weakness: CWE-94. Affected package(s): cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, devspaces/code-rhel9:1776744110. Resolved in Red Hat advisory RHSA-2026:34342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.27; Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; and 1 more.

CVE-2026-33940
Red Hat Enterprise Linux
Mar 27, 2026
High7.5Linux

High [CVE-2026-33939] Denial of Service via malformed decorator syntax in template compilation

Denial of Service via malformed decorator syntax in template compilation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-248. Affected package(s): cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, devspaces/code-rhel9:1776744110. Resolved in Red Hat advisory RHSA-2026:34342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.27; Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-33939
Red Hat Enterprise Linux
Mar 27, 2026
High8.1Linux

High [CVE-2026-33938] Arbitrary code execution via @partial-block overwrite

Arbitrary code execution via @partial-block overwrite. Red Hat rates this important (CVSS 8.1). Weakness: CWE-917. Affected package(s): cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, devspaces/code-rhel9:1776744110. Resolved in Red Hat advisory RHSA-2026:34342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.27; Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 8.

CVE-2026-33938
Red Hat Enterprise Linux
Mar 27, 2026
High7.4Linux

High [CVE-2026-33896] Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance

Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected package(s): rhdh/rhdh-hub-rhel9:1777903262, cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, automation-gateway, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9; and 8 more.

CVE-2026-33896
Red Hat Enterprise Linux
Mar 27, 2026
High7.5Linux

High [CVE-2026-33895] Authentication bypass via forged Ed25519 cryptographic signatures

Authentication bypass via forged Ed25519 cryptographic signatures. Red Hat rates this important (CVSS 7.5). Weakness: CWE-347. Affected package(s): rhdh/rhdh-hub-rhel9:1777903262, cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, automation-gateway, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9; and 6 more.

CVE-2026-33895
Red Hat Enterprise Linux
Mar 27, 2026
High7.5Linux

High [CVE-2026-33894] Signature Forgery via Weak RSASSA PKCS#1 v1.5 Verification

Signature Forgery via Weak RSASSA PKCS#1 v1.5 Verification. Red Hat rates this important (CVSS 7.5). Weakness: CWE-347. Affected package(s): quay/quay-rhel9:1779922205, quay/quay-rhel8:1779811473, rhdh/rhdh-hub-rhel9:1777903262, quay/quay-rhel8:1779689392, cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, quay/quay-rhel8:1779822261. Resolved in Red Hat advisory RHSA-2026:23361 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9; and 13 more.

CVE-2026-33894
Red Hat Enterprise Linux
Mar 27, 2026
High7.5Linux

High [CVE-2026-33891] Denial of Service via infinite loop in BigInteger.modInverse()

Denial of Service via infinite loop in BigInteger.modInverse(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Affected package(s): rhdh/rhdh-hub-rhel9:1777903262, cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, automation-platform-ui, automation-gateway, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Developer Hub 1.8; and 6 more.

CVE-2026-33891
Red Hat Enterprise Linux
Mar 27, 2026
High7.5Linux

High [CVE-2026-33871] Denial of Service via HTTP/2 CONTINUATION frame flood

Denial of Service via HTTP/2 CONTINUATION frame flood. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): eap8-netty-transport-native-epoll, rhoai/odh-modelmesh-rhel9:1776756834, cryostat/jfr-datasource-rhel9:4.2.0, netty-codec-http, eap8-netty, cryostat/cryostat-rhel9:4.2.0. Resolved in Red Hat advisory RHSA-2026:8509 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat AMQ Broker 7.12.7; Red Hat AMQ Broker 7.13.5; Red Hat AMQ Broker 7.14.0; and 27 more.

CVE-2026-33871
Red Hat Enterprise Linux
Mar 27, 2026
High7.5Linux

High [CVE-2026-33870] Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values

Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values. Red Hat rates this important (CVSS 7.5). Weakness: CWE-444. Affected package(s): eap8-netty-transport-native-epoll, devspaces/pluginregistry-rhel9:1776717247, netty-codec-http, rhoai/odh-modelmesh-rhel9:1776756834, cryostat/jfr-datasource-rhel9:4.2.0, devspaces/server-rhel9:1776796445. Resolved in Red Hat advisory RHSA-2026:8509 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat AMQ Broker 7.12.7; Red Hat AMQ Broker 7.13.5; Red Hat AMQ Broker 7.14.0; and 25 more.

CVE-2026-33870
Red Hat Enterprise Linux
Mar 27, 2026
High8.7Linux

High [CVE-2026-28369] Undertow: undertow: request smuggling via malformed http request headers

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. Request smuggling allows an attacker to bypass security mechanisms, access restricted information, or manipulate web caches, potentially leading to unauthorized actions or data exposure. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Data Grid 8; and 7 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 2 more.

CVE-2026-28369
Red Hat Enterprise Linux
Mar 27, 2026
High7.5Linux

High [CVE-2026-27880] Denial of Service via unbounded memory read in feature toggle evaluation

Denial of Service via unbounded memory read in feature toggle evaluation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-27880
Red Hat Enterprise Linux
Mar 27, 2026
High7.5Linux

High [CVE-2026-27877] Information disclosure of data-source passwords via public dashboards

Information disclosure of data-source passwords via public dashboards. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected package(s): grafana. Resolved in Red Hat advisory RHSA-2026:11416 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support.

CVE-2026-27877
Red Hat Enterprise Linux
Mar 27, 2026
High7.5Linux

High [CVE-2026-27858] denial of service via crafted message before authentication

denial of service via crafted message before authentication. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 10 more.

CVE-2026-27858
Red Hat Enterprise Linux
Mar 27, 2026
High7.5Linux

High [CVE-2026-27857] denial of service via specially crafted NOOP command

denial of service via specially crafted NOOP command. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 10 more.

CVE-2026-27857
Red Hat Enterprise Linux
Mar 27, 2026
High7.4Linux

High [CVE-2026-27856] Full access via timing oracle attack in credential verification

Full access via timing oracle attack in credential verification. Red Hat rates this important (CVSS 7.4). Weakness: CWE-208. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 6.

CVE-2026-27856
Red Hat Enterprise Linux
Mar 27, 2026
High7.7Linux

High [CVE-2026-24031] Authentication bypass and user enumeration due to cleared auth_username_chars configuration

Authentication bypass and user enumeration due to cleared auth_username_chars configuration. Red Hat rates this important (CVSS 7.7). Weakness: CWE-89. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 6.

CVE-2026-24031
Red Hat Enterprise Linux
Mar 27, 2026
High7.5Linux

High [CVE-2025-59032] Denial of Service via crafted SASL initial response in AUTHENTICATE command

Denial of Service via crafted SASL initial response in AUTHENTICATE command. Red Hat rates this important (CVSS 7.5). Weakness: CWE-229. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 10 more.

CVE-2025-59032
Red Hat Enterprise Linux
Mar 27, 2026
High8.8Linux

High [CVE-2026-27893] Remote code execution due to hardcoded trust_remote_code setting

Remote code execution due to hardcoded trust_remote_code setting. Red Hat rates this important (CVSS 8.8). Weakness: CWE-501. Affected package(s): rhaiis/vllm-cuda-rhel9:1779223654, rhelai3/bootc-azure-cuda-rhel9:1776871985, rhelai3/bootc-aws-cuda-rhel9:1776871984, rhaiis/model-opt-cuda-rhel9:1775749857, rhaiis/vllm-rocm-rhel9:1775680262, rhaiis/vllm-rocm-rhel9:1779223651. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat AI Inference Server 3.2; Red Hat AI Inference Server 3.3; Red Hat Enterprise Linux AI 3.3; Red Hat OpenShift AI 2.25; and 1 more.

CVE-2026-27893
Red Hat Enterprise Linux
Mar 26, 2026
High7.5Linux

High [CVE-2026-32286] Denial of Service via malicious PostgreSQL server

Denial of Service via malicious PostgreSQL server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1285. Affected package(s): quay/quay-rhel8:1779689392, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1779209992, multicluster-globalhub/multicluster-globalhub-manager-rhel9:1779210608, advanced-cluster-security/rhacs-scanner-v4-rhel8:1777307791, quay/quay-rhel8:1776752646. Resolved in Red Hat advisory RHSA-2026:11916 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Advanced Cluster Security for Kubernetes 4.8; Red Hat Quay 3.10; and 14 more.

CVE-2026-32286
Red Hat Enterprise Linux
Mar 26, 2026

← All Linux advisories