Red Hat Linux Security Advisories & CVEs
465 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Low [CVE-2026-60589] Improve Resource Resolving (2026-08 Security Update)
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Red Hat severity: Moderate — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 18 more.
Low [CVE-2026-74797] Denial of Service via malicious zip archives
OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted.zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling.zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process. A flaw was found in OpenTofu. Exploitation requires an attacker to provide a malicious archive, necessitating user interaction or a compromised dependency supply chain, which limits the attack surface in Red Hat environments where `tofu init` is typically executed in controlled development or CI/CD pipelines. Red Hat severity: Low — CVSS 3.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L). Weakness: CWE-400. Red Hat lists Red Hat Hardened Images as not affected.
Low [CVE-2026-63650] User misidentification via ignored X.509 identity field
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field This could lead to incorrect user authentication and potential security bypasses. This flaw is rated as Low impact because it requires a remote authenticated user and high attack complexity to exploit. OpenVPN, when configured with mbedTLS, may incorrectly identify users by disregarding the X.509 identity field, potentially leading to unauthorized access under specific, complex conditions. Red Hat severity: Low — CVSS 3.1 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-303.
Low [CVE-2026-55987] Administrator-deactivated accounts can be reactivated via OAuth2 sign-in
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) A flaw was found in Gitea. An attacker can reactivate an administrator-deactivated account by signing in via OAuth2, specifically when using authentication sources that do not utilize refresh tokens. This bypasses intended security controls, allowing unauthorized access to previously deactivated accounts. Red Hat severity: Low — CVSS 3.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N). Weakness: CWE-807. Red Hat lists OpenShift Pipelines as not affected.
Low [CVE-2026-55984] Denial of Service via Null Pointer Dereference in AddTime API
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service A flaw was found in Gitea. This can lead to a denial of service (DoS), making the application unavailable to legitimate users. Red Hat severity: Low — CVSS 2.7 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-476. Red Hat lists OpenShift Pipelines as not affected.
Low [CVE-2026-6469] Incorrect ownership assignment allows unauthorized statistics modification
Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. The overall impact is limited, as standard DROP TABLE operations still correctly remove the affected objects. This flaw has a Low impact on Red Hat products. Red Hat severity: Low — CVSS 3.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L). Weakness: CWE-708. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.
Low [CVE-2026-16241] Denial of Service via integer underflow
Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. This vulnerability causes the client to overwrite a large memory region, leading to a temporary denial of service (DoS). This Low impact flaw in PostgreSQL ECPG affects client applications. The limited scope to client-side disruption and the prerequisite of elevated server privileges contribute to its lower severity. Red Hat severity: Low — CVSS 3.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L). Weakness: CWE-191. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.
Low [CVE-2026-14673] PostgreSQL amcheck: Privilege escalation via untrusted search path
Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.5, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected. By setting a malicious search path before invoking an amcheck function, an attacker can hijack execution to run arbitrary SQL functions with the elevated permissions of the expression index owner. This vulnerability is rated as Low impact because exploitation requires an attacker to already possess EXECUTE privileges on amcheck functions. The necessity of having this pre-existing, elevated database access to manipulate the search path significantly limits the likelihood of successful privilege escalation. Red Hat severity: Low — CVSS 3.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-426. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7 as not affected. Red Hat fixing advisory: RHSA-2026:54751, RHSA-2026:57198.
Low [CVE-2026-73626] Extension allowlist bypass allows unauthorized installations
JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/blocklist check was not enforced for direct callers of install(). The stock JupyterLab HTTP API and Extension Manager UI are not affected, as they perform a separate, correctly awaited check. The issue affects only deployments where a custom extension or downstream integration imports PyPIExtensionManager and calls install() directly with a package name influenced by untrusted input, an allowlist/blocklist is configured, the PyPI Extension Manager is enabled, and kernels and terminals are disabled or delegated to remote hosts. This vulnerability allows direct callers of `install()` to bypass security checks, potentially enabling the installation of unauthorized extensions. This is a Low impact flaw in JupyterLab where an allowlist bypass can occur in specific deployments. Red Hat severity: Low — CVSS 0 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N). Weakness: CWE-358. Affected Red Hat products: Migration Toolkit for Applications 8; Red Hat OpenShift AI (RHOAI). Will not fix / out of support: Migration Toolkit for Applications 8. Red Hat does not currently list a fixing RHSA for this CVE.
Low [CVE-2026-73492] Arbitrary code execution due to URI scheme bypass
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: or vbscript: URIs whose scheme is split by semicolon-less numeric character references such as:,, , or CGI.unescapeHTML leaves these references encoded, so allowed_uri? reports the URL safe even though a browser decodes an encoded colon or strips encoded whitespace and executes the resulting URI scheme. This issue affects only callers that pass HTML-encoded strings directly to allowed_uri?; Loofah's default sanitize() path is not affected. This issue is fixed in version 2.25.2. The 'allowed_uri?' function, intended to validate Uniform Resource Identifiers (URIs), does not correctly identify and reject 'javascript:' or 'vbscript:' URIs when their scheme is obscured by specific HTML-encoded numeric character references. This oversight allows a browser to decode and execute the manipulated URI, potentially leading to arbitrary code execution. This issue specifically impacts applications that directly provide HTML-encoded strings to the 'allowed_uri?' function. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N). Weakness: CWE-76. Affected Red Hat products: Red Hat 3scale API Management Platform 2; Red Hat Satellite 6.
Low [CVE-2026-73491] Cross-Site Scripting via malformed `javascript:` URI parsing
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is split or prefixed with the HTML5 named whitespace character references or CGI.unescapeHTML leaves those references intact, so allowed_uri? reports the URL safe even though a browser decodes and strips the tab or line feed and executes the resulting javascript: URL. This issue affects only callers that pass HTML-encoded strings directly to allowed_uri?; Loofah's default sanitize() path is not affected. This issue is fixed in version 2.25.2. A flaw was found in Loofah. This vulnerability allows a remote attacker to craft a malicious URI that, when processed by affected callers, is incorrectly deemed safe. Consequently, a web browser will decode and execute the embedded JavaScript code, leading to Cross-Site Scripting (XSS) and potential arbitrary code execution in the user's browser context. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N). Weakness: CWE-1289. Affected Red Hat products: Red Hat 3scale API Management Platform 2; Red Hat Satellite 6. Will not fix / out of support: Red Hat 3scale API Management Platform 2. Red Hat does not currently list a fixing RHSA for this CVE.
Low [CVE-2026-73281] ssh-agent allows remote execution of local operations
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension. This could enable a remote attacker to add PKCS#11 tokens or utilize keys with destination restrictions, bypassing intended security controls. Red Hat has determined that this vulnerability has limited impact. Exploitation requires an authenticated SSH session with agent forwarding enabled and the agent in a locked state. Red Hat Enterprise Linux 6, 7, 8, and RHEL 9 through 9.6 ship OpenSSH versions prior to 8.9 and are not affected. Red Hat may apply this fix in a future update for affected products. Red Hat severity: Low — CVSS 3.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N). Weakness: CWE-266. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: openssh.
Low [CVE-2026-73071] Denial of Service via Use-After-Free in JSON Decoding
Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer, causing the error path to read freed memory instead of reader->js_buf + reader->js_used when an invalid JSON string spans buffers. This issue is fixed in version 9.2.0844. A flaw was found in Vim. This can lead to the program attempting to read freed memory, potentially resulting in a denial of service for a local user. Fedora and Hummingbird already ship 9.2.920, which is past the fix. No Red Hat product is affected by this vulnerability. Red Hat severity: Low — CVSS 3.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-416. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4 as not affected.
Low [CVE-2026-18503] Denial of Service via super-linear regular expression work in csv.Sniffer.sniff
Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv. Sniffer.sniff(). A flaw was found in the `csv. This excessive processing consumes significant CPU resources, potentially leading to a Denial of Service (DoS) for applications that process unbounded input using this function. Red Hat has evaluated this issue and determined it has a Low security impact. Most applications are not affected as they use csv.reader() or csv. DictReader() directly without invoking the sniffing functionality. Red Hat severity: Low — CVSS 2.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L). Weakness: CWE-1333. Affected Red Hat products: Red Hat Hardened Images; Exploit Intelligence; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Enterprise Linux command line assistant; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces; Red Hat OpenShift Virtualization 4; Self-service automation portal 2. Red Hat fixing advisory: RHSA-2026:54534, RHSA-2026:54554, RHSA-2026:57010, RHSA-2026:57660, RHSA-2026:58420. Affected products named by the advisory: Red Hat package: python3.12; Red Hat package: python36; Red Hat package: python3.9.
Low [CVE-2026-66484] GNU cpio: Path Traversal allows creating hard links outside intended directory via malicious tar archives.
GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar hard-link target is passed to the link_to_name function without equivalent sanitization before calling link function. A tar archive provided by an attacker, containing a hard-link entry whose linkname is set to an absolute path outside the extraction directory, can cause cpio to create a hard link to an existing file outside the intended extraction directory, breaking the expected guarantee of --no-absolute-filenames and allowing archive-controlled linkage to external files. This issue has been fixed in commit e2b9cbdd3354d2b1569b7390d1bc15c1930559ad This vulnerability, known as Path Traversal, occurs during the extraction of tar archives in copy-in mode when the `--no-absolute-filenames` option is used. An attacker could provide a specially crafted tar archive that, when extracted with this option, creates hard links pointing to files outside the intended extraction directory, potentially leading to unauthorized file modifications. Red Hat severity: Low — CVSS 3.3 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N). Weakness: CWE-22.
Low [CVE-2026-71391] off-by-one error via a malicious font file
GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index boundary check in sfnt_vary_simple_glyph() and sfnt_vary_compound_glyph() uses a strict greater-than comparison instead of greater-than-or-equal, allowing a crafted TrueType variable font to bypass the check and trigger a heap-based out-of-bounds read via memcpy. An attacker can deliver a malicious font file via email, EWW (Emacs Web Wowser), or documents with custom faces, causing Emacs to load it. This exposes heap memory contents which can be later used to defeat ASLR. This issue was fixed in commit 95ab9ef627b212d74d321c5bbb5b56a1be7b9fbe An off-by-one error can occur when a specially crafted font file is processed due to an improper bounds check. This can cause a heap-based buffer over-read, exposing heap memory contents. To exploit this flaw, a user needs to load a malicious font file or a document with custom faces, limiting its exposure. The only security impact of this issue is an information disclosure of heap memory contents. For these reasons, this vulnerability has been rated with a low severity. Red Hat severity: Low — CVSS 3.3 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N). Weakness: CWE-193.
Low [CVE-2026-19411] shim/dp.c library: NULL-pointer dereference in is_removable_media_path when DevicePathToStr returns NULL
shim/dp.c library: NULL-pointer dereference in is_removable_media_path() when DevicePathToStr() returns NULL. Red Hat rates this low (CVSS 3.9). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Low [CVE-2026-12372] Server-Side Request Forgery via improper network URL validation
Server-Side Request Forgery via improper network URL validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-918. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).
Low [CVE-2026-61477] newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection
newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection. Red Hat rates this low (CVSS 2.3). Weakness: CWE-93. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26.
Low [CVE-2026-71326] Authenticated identity spoofing via BasicAuth key collision
Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the delimiter-free concatenation of password and secret, allowing an attacker who has a valid credential and the stored hash to authenticate as an unconfigured username when headerField trusts the forwarded identity. This issue is fixed in 3.6.25 and 3.7.10. A flaw was found in Traefik. This identity spoofing is possible when the 'headerField' is configured to trust forwarded identity information. Red Hat OpenShift Dev Spaces bundles Traefik as a reverse proxy component. No Red Hat product is affected. Red Hat severity: Low — CVSS 3.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-836.