Skip to content
VulniPulse

Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories

1232 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 789 high, 387 medium, 25 low.

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux Red Hat Enterprise Linux advisories

High8.8Vendor: MediumLinux Updated

High [CVE-2026-15718] Invalid pointer in the JavaScript: WebAssembly component

Invalid pointer in the JavaScript: WebAssembly component. Red Hat rates this moderate (CVSS 8.8). Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-15718
Red Hat Enterprise Linux
Jul 14, 2026
High7.8Linux Updated

High [CVE-2026-64600] XFS data corruption using reflink

XFS data corruption using reflink. Red Hat rates this important (CVSS 7.8). Weakness: CWE-362. Red Hat lists fixing advisory RHSA-2026:47981 with package kernel-0:6.12.0-55.89.1.el10_0, kernel-0:4.18.0-553.144.1.el8_10, kpatch-patch, kernel-0:5.14.0-284.182.1.el9_2. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-64600
Red Hat Enterprise Linux
Jul 14, 2026
Medium6.5Linux Updated

Medium [CVE-2026-50659] .NET:.NET: Network Spoofing Vulnerability

.NET:.NET: Network Spoofing Vulnerability. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-838. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet9-0-main-9.0.119-1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50659
Red Hat Enterprise Linux
Jul 14, 2026
Medium6.5Linux Updated

Medium [CVE-2026-59888] com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4. Consequently, an untrusted client could set internal or privileged components from external input, potentially leading to unauthorized modification or disclosure of sensitive data. Moderate impact. This flaw in jackson-databind allows an attacker to bypass the @JsonIgnore annotation when deserializing Java Records that utilize a PropertyNamingStrategy. Red Hat products using affected versions of jackson-databind for deserialization of external input into Java Records with PropertyNamingStrategy are susceptible. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-915. Affected products named by the advisory: OpenShift Serverless; Red Hat AI Inference Server; Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; and 13 more.

CVE-2026-59888
Red Hat Enterprise Linux
Jul 14, 2026
Medium4.8Linux

Medium [CVE-2026-0716 +1] Libsoup: incomplete fix for CVE-2026-0716: out-of-bounds read in libsoup websocket frame processing (unmasked path)

The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious WebSocket server can send a crafted unmasked frame with a payload length near UINT64_MAX to trigger an OOB read in a libsoup-based client when max_incoming_payload_size is set to 0. This vulnerability is rated Moderate for Red Hat because it requires a non-default configuration where max_incoming_payload_size is explicitly set to 0 or unset in libsoup's WebSocket frame processing. In typical Red Hat deployments, this configuration is not enabled by default, limiting the exposure to memory disclosure or application instability. Red Hat severity: Moderate — CVSS 4.8 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-0716CVE-2026-12478
Red Hat Enterprise Linux
Jul 14, 2026
Low3.8Linux Updated

Low [CVE-2026-59084] Insufficient documentation for EncryptInterceptor may lead to insecure configurations

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue. Insufficient technical documentation regarding the secure configuration of the EncryptInterceptor component may lead to deployments with insecure settings. This vulnerability could allow an attacker to exploit misconfigurations that arise from unclear guidance, potentially compromising the confidentiality or integrity of data processed by the affected system. Without clear guidance on secure configuration, administrators might inadvertently deploy the interceptor in a way that weakens security, rather than a direct code flaw. This issue affects Red Hat products utilizing Apache Tomcat, including Red Hat Enterprise Linux and Red Hat JBoss Web Server. Red Hat severity: Low — CVSS 3.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-1188. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.

CVE-2026-59084
Red Hat Enterprise Linux
Jul 14, 2026
Low3.7Linux Updated

Low [CVE-2026-59083] Security constraint bypass via improper URL encoding in rewrite valve

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue. A remote attacker could exploit this to bypass security constraints in certain configurations, potentially gaining unauthorized access or performing actions that should be restricted. Exploitation requires specific configurations and has high attack complexity, limiting its overall risk to Red Hat products. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-807. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat JBoss Web Server 5. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat fixing advisory: RHSA-2026:36872, RHSA-2026:37767.

CVE-2026-59083
Red Hat Enterprise Linux
Jul 14, 2026
High7.1Linux Updated

High [CVE-2026-43701] A malicious website may process restricted web content outside the sandbox

A malicious website may process restricted web content outside the sandbox. Red Hat rates this important (CVSS 7.1). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-43701
Red Hat Enterprise Linux
Jul 10, 2026
High8.8Linux Updated

High [CVE-2026-43705] Maliciously crafted web content may lead to memory corruption

Maliciously crafted web content may lead to memory corruption. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-43705
Red Hat Enterprise Linux
Jul 10, 2026
High8.8Linux Updated

High [CVE-2026-43715] Maliciously crafted web content may lead to memory corruption

Maliciously crafted web content may lead to memory corruption. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-43715
Red Hat Enterprise Linux
Jul 10, 2026
High7.1Linux Updated

High [CVE-2026-43725] A malicious website may process restricted web content outside the sandbox

A malicious website may process restricted web content outside the sandbox. Red Hat rates this important (CVSS 7.1). Weakness: CWE-20. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-43725
Red Hat Enterprise Linux
Jul 10, 2026
Medium5.9Linux Updated

Medium [CVE-2026-49844] Malformed JSON output due to improper encoding of floating-point values

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing. Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values. This can corrupt log records or disrupt downstream log ingestion and parsing, potentially leading to a Denial of Service (DoS) or information integrity issues.

CVE-2026-49844
Red Hat Enterprise Linux
Jul 10, 2026
Medium6.5Linux Updated

Medium [CVE-2026-39872] Maliciously crafted web content may cause unexpected process crash

Maliciously crafted web content may cause unexpected process crash. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-39872
Red Hat Enterprise Linux
Jul 10, 2026
Medium6.5Linux Updated

Medium [CVE-2026-43676] Maliciously crafted web content may cause unexpected process crash

Maliciously crafted web content may cause unexpected process crash. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-43676
Red Hat Enterprise Linux
Jul 10, 2026
Medium6.5Linux Updated

Medium [CVE-2026-43707] Maliciously crafted web content may cause unexpected process crash

Maliciously crafted web content may cause unexpected process crash. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-119. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-43707
Red Hat Enterprise Linux
Jul 10, 2026
Medium6.5Linux Updated

Medium [CVE-2026-43712] Maliciously crafted web content may cause unexpected process crash

Maliciously crafted web content may cause unexpected process crash. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-43712
Red Hat Enterprise Linux
Jul 10, 2026
Medium6.5Linux Updated

Medium [CVE-2026-43713] Visiting a website may leak sensitive data

Visiting a website may leak sensitive data. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-43713
Red Hat Enterprise Linux
Jul 10, 2026
Medium6.5Linux Updated

Medium [CVE-2026-43721] A malicious website may silently hijack clipboard data

A malicious website may silently hijack clipboard data. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-732. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-43721
Red Hat Enterprise Linux
Jul 10, 2026
Medium6.5Linux Updated

Medium [CVE-2026-43732] Maliciously crafted web content may disclose sensitive user information

Maliciously crafted web content may disclose sensitive user information. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-43732
Red Hat Enterprise Linux
Jul 10, 2026
Medium6.5Linux Updated

Medium [CVE-2026-43740] Maliciously crafted web content may disclose process memory

Maliciously crafted web content may disclose process memory. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-43740
Red Hat Enterprise Linux
Jul 10, 2026

← All Linux advisories