Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories
1635 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 619 high, 814 medium, 169 low.
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat RHEL & SELinux advisories
Low [CVE-2026-80230] Public key pinning bypass allows unauthenticated connections
When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected. A flaw was found in libcurl, a client-side URL transfer library. This bypass enables unauthenticated connections that should have been rejected, potentially compromising the integrity of the connection. This Low impact flaw in curl arises when public key pinning is enabled alongside explicitly disabled SSL/TLS peer verification. In such an atypical and insecure configuration, libcurl fails to enforce the public key pinning, allowing unauthenticated connections to proceed without proper certificate validation. Red Hat products typically employ secure default configurations that enable full peer verification, thus reducing exposure to this issue. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-303. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 4 more.
Low [CVE-2026-18924] Use-after-free in HTTP/2 Server Push with shared connections
Use-after-free in HTTP/2 Server Push with shared connections. Red Hat rates this low (CVSS 3.7). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:63161 with package curl-main-8.22.0-0.1.hum1, rust-main-1.98.0-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Confidential Compute Attestation; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; and 11 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; and 7 more.
Low [CVE-2026-13608] Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack
A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation. A flaw was found in libcurl's SASL (Simple Authentication and Security Layer) negotiation for LDAP (Lightweight Directory Access Protocol) authentication when using the OpenLDAP backend. This Low impact flaw in libcurl's SASL negotiation for LDAP authentication could allow an attacker to bypass peer validation through a Man-in-the-Middle (MITM) attack. Exploitation requires an active network attacker to inject a premature response during the authentication handshake. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-923. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Satellite 6. Red Hat fixing advisory: RHSA-2026:63161, RHSA-2026:63514. Affected products named by the advisory: Red Hat package: curl.
Low [CVE-2026-18540] HTTP response splitting via retry interceptor
HTTP response splitting via retry interceptor. Red Hat rates this low (CVSS 3.7). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:66008 with package nodejs26-main-26.8.2-0.1.hum1, grafana12-4-main-12.4.10-0.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.
Low [CVE-2026-85008] Integrity failure due to caching of unsafe HTTP method responses
Integrity failure due to caching of unsafe HTTP method responses. Red Hat rates this low (CVSS 3.7). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.
Low [CVE-2026-4897 +1] Regression in CVE-2026-4897 fix (polkit read_cookie) - stack buffer underflow
Regression in CVE-2026-4897 fix (polkit read_cookie()) - stack buffer underflow. Red Hat rates this low (CVSS 3.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:66287 with package polkit-main-127-5.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 7 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: polkit-pkla-compat; and 3 more.
Low [CVE-2026-77465] Denial of Service via uncontrolled recursion in TOML parsing
Denial of Service via uncontrolled recursion in TOML parsing. Red Hat rates this low (CVSS 3.5). Weakness: CWE-606. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: cockpit-image-builder.
Low [CVE-2026-63376] Arbitrary Code Execution via Prototype Pollution in TOML Parsing
Arbitrary Code Execution via Prototype Pollution in TOML Parsing. Red Hat rates this low (CVSS 3.7). Weakness: CWE-915. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: cockpit-image-builder.
Low [CVE-2026-84641] Information disclosure due to malicious IMAP server response
Information disclosure due to malicious IMAP server response. Red Hat rates this low (CVSS 3.4). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: thunderbird.
Low [CVE-2026-84368] @hapi/joi: joi: Prototype pollution via untrusted input in schema configuration
@hapi/joi: joi: Prototype pollution via untrusted input in schema configuration. Red Hat rates this low (CVSS 3.7). Weakness: CWE-915. Affected products named by the advisory: Gatekeeper 3; Migration Toolkit for Containers; Red Hat Build of Podman Desktop; Red Hat Data Grid 8; and 9 more. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; and 5 more.
Low [CVE-2026-83608] @xmldom/xmldom: xmldom: XML Markup Injection via DocType Name Bypass
@xmldom/xmldom: xmldom: XML Markup Injection via DocType Name Bypass. Red Hat rates this important (CVSS 3.1). Weakness: CWE-91. Red Hat lists fixing advisory RHSA-2026:69248 with package rhdh/rhdh-hub-rhel9:1789554285. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 4 more. Affected products named by the advisory: Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Red Hat package: grafana.
Low [CVE-2026-18743] Popt-devel: popt-static: short realloc in poptconfigfiletostring
A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service). This Low impact heap overflow in `popt` occurs when processing specially crafted configuration files through an explicit call to `poptConfigFileToString()`. Red Hat products are less exposed as this function is not utilized by internal sources, limiting the attack surface to scenarios where untrusted `popt` configuration content is explicitly loaded. Red Hat severity: Low — CVSS 2.5 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-131. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:56984. Affected products named by the advisory: Red Hat package: popt.
Low [CVE-2026-82631] Use-after-free vulnerability in Blocked-on-keys subsystem
A security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlockedOnKey of the file src/blocked.c of the component Blocked-on-keys Subsystem. The manipulation results in use after free. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit has been released to the public and may be used for attacks. The patch is identified as b2fb0e13f5b4c8c2fb63dcfc2c37a067a0d6d20b. Applying a patch is advised to resolve this issue. A flaw was found in Valkey. A remote attacker could exploit this flaw, leading to a denial of service. The complexity of exploiting this vulnerability is high. Red Hat severity: Low. Weakness: CWE-825. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:61884. Affected products named by the advisory: Red Hat package: valkey.
Low [CVE-2026-82562] Denial of Service via array limit bypass in query string parsing
Denial of Service via array limit bypass in query string parsing. Red Hat rates this low (CVSS 3.7). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:63164 with package grafana13-1-main-13.1.3-0.4.hum1, grafana13-2-main-13.2.1-0.1.hum1, grafana12-4-main-12.4.9-0.4.hum1. Affected products named by the advisory: Red Hat Hardened Images; Cost Management On Premise; Cryostat 4; Gatekeeper 3; and 47 more. Affected products named by the advisory: Migration Toolkit for Applications 8; Migration Toolkit for Containers; Multicluster Engine for Kubernetes; Node HealthCheck Operator; and 43 more.
Low [CVE-2026-52681] Denial of Service via Sieve script manipulation
Denial of Service via Sieve script manipulation. Red Hat rates this low (CVSS 3.1). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: dovecot.
Low [CVE-2026-42393] Information disclosure via timing attack on `doveadm` password/API key comparison
Information disclosure via timing attack on `doveadm` password/API key comparison. Red Hat rates this low (CVSS 3.1). Weakness: CWE-208. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.
Low [CVE-2026-40204] lda_mailbox_autocreate can bypass acl restrictions
lda_mailbox_autocreate can bypass acl restrictions. Red Hat rates this low (CVSS 3.1). Weakness: CWE-1220. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.
Low [CVE-2026-40203] Information disclosure via IMAP compression side-channel
Information disclosure via IMAP compression side-channel. Red Hat rates this low (CVSS 3.7). Weakness: CWE-205. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.
Low [CVE-2026-79112] Out of bounds read in Skia
Out of bounds read in Skia. Red Hat rates this low (CVSS 3.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: firefox; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Low [CVE-2026-75803] AEAD forgeries possible with empty ciphertext in EVP_Cipher
Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and expecting the call to check the AEAD tag may accept forged messages. CWE: CWE-354 (Improper Validation of Integrity Check Value) Description: The EVP_Cipher() API call for AEAD ciphers behaves like a one shot encryption and decryption call. However for AES-OCB and ChaCha20-Poly1305 ciphers it skipped the AEAD tag verification when an empty ciphertext was passed to the function. The callers of this function might believe that a successful return indicates a valid AEAD tag for these ciphers, even when that has not truly been validated in this case. FIPS impact: no The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE as the affected algorithms are not FIPS approved and thus not implemented in the FIPS module. This allows remote attackers to submit forged messages that affected applications incorrectly accept as valid. Red Hat rates this as Low since exploitation requires a rare API misuse pattern using EVP_Cipher() with empty ChaCha20-Poly1305 or AES-OCB ciphertexts.