Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4426 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Red Hat

High [CVE-2026-68911] Denial of Service via decompression bomb in peer messages

Denial of Service via decompression bomb in peer messages. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409.

CVE-2026-68911
Unclassified
Sep 29, 2026
High7.5Red Hat

High [CVE-2026-63209] Denial of Service via integer overflow in dictionary processing

Denial of Service via integer overflow in dictionary processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-823. Red Hat lists fixing advisory RHSA-2026:72492 with package nats-server2-12-main-2.12.15-0.1.hum1, podman-main-6.1.2-1.hum1, helm4-main-4.3.0-0.2.hum1, k6v1-main-1.8.1-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-63209
Unclassified
Sep 29, 2026
High7.5Red Hat

High [CVE-2026-102496] Denial of Service (DoS) via deeply nested schema structures

Denial of Service (DoS) via deeply nested schema structures. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; and 4 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat OpenShift AI (RHOAI); Red Hat Single Sign-On 7.

CVE-2026-102496
Unclassified
Sep 29, 2026
High7.5Red Hat

High [CVE-2026-102495] Denial of Service via unbounded recursion during schema parsing

Denial of Service via unbounded recursion during schema parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; and 4 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat OpenShift AI (RHOAI); Red Hat Single Sign-On 7.

CVE-2026-102495
Unclassified
Sep 29, 2026
High7.1Vendor: MediumRed Hat Updated

High [CVE-2026-95520] integer overflow in iterReadArchiveNext leads to heap-based buffer overflow when parsing untrusted RPM packages

integer overflow in iterReadArchiveNext() leads to heap-based buffer overflow when parsing untrusted RPM packages. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 1 more. Affected products named by the advisory: Red Hat package: rpm.

CVE-2026-95520
Red Hat Enterprise Linux
Sep 29, 2026
High7.3Red Hat Updated

High [CVE-2026-19547] Local privilege escalation via predictable resource search path

Local privilege escalation via predictable resource search path. Red Hat rates this important (CVSS 7.3). Weakness: CWE-427.

CVE-2026-19547
Unclassified
Sep 29, 2026
High7.8Red Hat

High [CVE-2026-95389] Heap-based Buffer Overflow in Wireshark

Heap-based Buffer Overflow in Wireshark. Red Hat rates this important (CVSS 7.8). Weakness: CWE-122. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.

CVE-2026-95389
Red Hat Enterprise Linux
Sep 29, 2026
High8.1Red Hat Updated

High [CVE-2026-95387] Denial of Service via heap-based buffer overflow in SPDY dissector

Denial of Service via heap-based buffer overflow in SPDY dissector. Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: wireshark.

CVE-2026-95387
Red Hat Enterprise Linux
Sep 29, 2026
High8.8Red Hat Updated

High [CVE-2026-91012] org.apache.karaf.config/org.apache.karaf.config.core: Apache Karaf: Privilege escalation via path traversal in configuration service

org.apache.karaf.config/org.apache.karaf.config.core: Apache Karaf: Privilege escalation via path traversal in configuration service. Red Hat rates this important (CVSS 8.8). Weakness: CWE-22.

CVE-2026-91012
Unclassified
Sep 29, 2026
High7.1Red Hat Updated

High [CVE-2026-97024] Arbitrary write in root context via path traversal in deploy directory files/etc

Arbitrary write in root context via path traversal in deploy directory files/etc. Red Hat rates this important (CVSS 7.1). Weakness: CWE-61. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: flatpak.

CVE-2026-97024
Red Hat Enterprise Linux
Sep 29, 2026
High7.4Red Hat

High [CVE-2026-84782] Information disclosure via DTLS handshake retransmission

Information disclosure via DTLS handshake retransmission. Red Hat rates this important (CVSS 7.4). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:74162 with package ruby3-4-main-3.4.10-31.7.hum1, rust-bootupd-main-0.3.2-1.hum1, openssl-main-3.5.9-0.1.hum1, openssl3-main-3.5.9-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Ansible Automation Orchestrator 2026; Confidential Cluster Operator; Confidential Compute Attestation; and 53 more. Affected products named by the advisory: Lightspeed Core; Logging Subsystem for Red Hat OpenShift; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 49 more.

CVE-2026-84782
Red Hat Enterprise Linux
Sep 29, 2026
High7.5Red Hat Updated

High [CVE-2026-102278] Denial of Service via uncontrolled recursion in nested brace patterns

Denial of Service via uncontrolled recursion in nested brace patterns. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:73916 with package nodejs22-main-10.9.9-1.22.23.3.2.3.2.2.hum1, nodejs26-main-11.19.1-1.26.10.0.0.3.hum1, nodejs24-main-11.19.0-1.24.21.0.1.1.hum1, nodejs26-main-11.19.1-1.26.10.0.0.2.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-102278
Unclassified
Sep 28, 2026
High7.5Red Hat Updated

High [CVE-2026-102276] Denial of Service via stack exhaustion from crafted brace patterns

Denial of Service via stack exhaustion from crafted brace patterns. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:74168 with package nodejs22-main-10.9.9-1.22.23.3.2.3.2.2.hum1, nodejs26-main-11.19.1-1.26.10.0.0.3.hum1, nodejs24-main-11.19.0-1.24.21.0.1.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Red Hat 3scale API Management Platform 2; Red Hat build of Apache Camel - HawtIO 4; and 11 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat Build of Keycloak; Red Hat Ceph Storage 4; Red Hat Connectivity Link 1; and 7 more.

CVE-2026-102276
Unclassified
Sep 28, 2026
High7.4Red Hat Updated

High [CVE-2026-102273] Token forgery via acceptance of public JWK containers as HMAC secrets

Token forgery via acceptance of public JWK containers as HMAC secrets. Red Hat rates this important (CVSS 7.4). Weakness: CWE-347. Affected products named by the advisory: Ansible Automation Orchestrator 2026; Confidential Compute Attestation; Fence Agents Remediation Operator; Lightspeed Core; and 11 more. Affected products named by the advisory: Migration Toolkit for Applications 8; OpenShift Lightspeed; Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; and 7 more.

CVE-2026-102273
Unclassified
Sep 28, 2026
High7.4Red Hat Updated

High [CVE-2026-102272] Token forgery via improper Unicode byte-order mark handling

Token forgery via improper Unicode byte-order mark handling. Red Hat rates this important (CVSS 7.4). Weakness: CWE-347.

CVE-2026-102272
Unclassified
Sep 28, 2026
High7.4Red Hat Updated

High [CVE-2026-102271] Authentication bypass via acceptance of DER public keys as HMAC secrets

Authentication bypass via acceptance of DER public keys as HMAC secrets. Red Hat rates this important (CVSS 7.4). Weakness: CWE-347.

CVE-2026-102271
Unclassified
Sep 28, 2026
High7.4Red Hat Updated

High [CVE-2026-102267] Verification key substitution via unvalidated JWKS redirects

Verification key substitution via unvalidated JWKS redirects. Red Hat rates this important (CVSS 7.4). Weakness: CWE-346.

CVE-2026-102267
Unclassified
Sep 28, 2026
High7.4Red Hat Updated

High [CVE-2026-102266] Authentication bypass via empty HMAC key acceptance

Authentication bypass via empty HMAC key acceptance. Red Hat rates this important (CVSS 7.4). Weakness: CWE-347.

CVE-2026-102266
Unclassified
Sep 28, 2026
High7.4Red Hat Updated

High [CVE-2026-101916] Authentication bypass via improper peer certificate validation

Authentication bypass via improper peer certificate validation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift Dev Spaces; and 1 more. Affected products named by the advisory: Self-service automation portal 2.

CVE-2026-101916
Unclassified
Sep 28, 2026
High7.5Red Hat Updated

High [CVE-2026-96760] Signature verification bypass via deserialize_json

Signature verification bypass via deserialize_json. Red Hat rates this important (CVSS 7.5). Weakness: CWE-347. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 4 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux command line assistant; Red Hat OpenShift Virtualization 4; Red Hat Satellite 6.

CVE-2026-96760
Unclassified
Sep 28, 2026

← All vendors