Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.1Red Hat

High [CVE-2026-47783] Username enumeration via timing side channel

Username enumeration via timing side channel. Red Hat rates this important (CVSS 8.1). Weakness: CWE-208. Affected package(s): memcached. Resolved in Red Hat advisory RHSA-2026:27862 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 1 more.

CVE-2026-47783
Unclassified
May 20, 2026
High8.1Red Hat

High [CVE-2026-43618] Remote memory disclosure via integer overflow in compressed-token decoding

Remote memory disclosure via integer overflow in compressed-token decoding. Red Hat rates this important (CVSS 8.1). Weakness: CWE-190. Affected package(s): rsync, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:26410 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 9); Red Hat Enterprise Linux BaseOS (v. 10); Red Hat Enterprise Linux BaseOS (v. 8); and 8 more.

CVE-2026-43618
Unclassified
May 20, 2026
High7.8Red Hat

High [CVE-2026-29518] TOCTOU symlink race condition allowing local privilege escalation in daemon mode without chroot.

TOCTOU symlink race condition allowing local privilege escalation in daemon mode without chroot.. Red Hat rates this important (CVSS 7.8). Weakness: CWE-367. Affected package(s): rsync, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:26410 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 9); Red Hat Enterprise Linux BaseOS (v. 10); Red Hat Enterprise Linux BaseOS (v. 8); and 8 more.

CVE-2026-29518
Unclassified
May 20, 2026
High7.5Red Hat

High [CVE-2026-42959] Unbound DNSSEC Validator Denial of Service via Incorrect Write Offset Counter in Chase-Reply Messages

Unbound DNSSEC Validator Denial of Service via Incorrect Write Offset Counter in Chase-Reply Messages. Red Hat rates this important (CVSS 7.5). Weakness: CWE-824. Affected package(s): unbound-main, unbound. Resolved in Red Hat advisory RHSA-2026:23231 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 2 more.

CVE-2026-42959
Unclassified
May 20, 2026
High7.1Red Hat

High [CVE-2026-32882] Denial of Service and Information Disclosure vulnerability

Denial of Service and Information Disclosure vulnerability. Red Hat rates this important (CVSS 7.1). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-32882
Unclassified
May 19, 2026
High7.1Red Hat

High [CVE-2026-32741] Heap buffer overflow vulnerability in image decoding

Heap buffer overflow vulnerability in image decoding. Red Hat rates this important (CVSS 7.1). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-32741
Unclassified
May 19, 2026
High8.8Red Hat

High [CVE-2026-32740] Arbitrary code execution or denial of service via crafted HEIF/AVIF file

Arbitrary code execution or denial of service via crafted HEIF/AVIF file. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-32740
Unclassified
May 19, 2026
High7.5Red Hat

High [CVE-2026-8975] Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151

Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.

CVE-2026-8975
Unclassified
May 19, 2026
High7.5Red Hat

High [CVE-2026-8973] Memory safety bugs fixed in Firefox 151

Memory safety bugs fixed in Firefox 151. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8973
Unclassified
May 19, 2026
High7.5Red Hat

High [CVE-2026-8948] Same-origin policy bypass in the DOM: Networking component

Same-origin policy bypass in the DOM: Networking component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8948
Unclassified
May 19, 2026
High7.5Red Hat

High [CVE-2026-8947] Use-after-free in the DOM: Bindings (WebIDL) component

Use-after-free in the DOM: Bindings (WebIDL) component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.

CVE-2026-8947
Unclassified
May 19, 2026
High7.5Red Hat

High [CVE-2026-8946] Incorrect boundary conditions in the Audio/Video: Web Codecs component

Incorrect boundary conditions in the Audio/Video: Web Codecs component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.

CVE-2026-8946
Unclassified
May 19, 2026
High7.5Red Hat

High [CVE-2026-8945] Sandbox escape in Firefox and Firefox Focus for Android

Sandbox escape in Firefox and Firefox Focus for Android. Red Hat rates this important (CVSS 7.5). Weakness: CWE-653. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8945
Unclassified
May 19, 2026
High8.1Red Hat

High [CVE-2026-7504] Open redirect when using wildcard valid redirect URIs in Keycloak

Open redirect when using wildcard valid redirect URIs in Keycloak. Red Hat rates this important (CVSS 8.1). Weakness: CWE-601. Affected package(s): rhbk/keycloak-rhel9-operator, rhbk/keycloak-operator-bundle:26.4.12, rhbk/keycloak-operator-bundle:26.2.16, rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-rhel9:26.2. Resolved in Red Hat advisory RHSA-2026:19594 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.2.16; Red Hat build of Keycloak 26.4.12.

CVE-2026-7504
Unclassified
May 19, 2026
High7.5Red Hat

High [CVE-2026-7507] Session fixation in OIDC login flow that can lead to account takeover

Session fixation in OIDC login flow that can lead to account takeover. Red Hat rates this important (CVSS 7.5). Weakness: CWE-290. Affected package(s): rhbk/keycloak-rhel9-operator, rhbk/keycloak-operator-bundle:26.4.12, rhbk/keycloak-operator-bundle:26.2.16, rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-rhel9:26.2. Resolved in Red Hat advisory RHSA-2026:19594 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.2.16; Red Hat build of Keycloak 26.4.12.

CVE-2026-7507
Unclassified
May 19, 2026
High7.1Vendor: MediumRed Hat

High [CVE-2026-7571] Access token disclosure and implicit flow bypass via forged client data

Access token disclosure and implicit flow bypass via forged client data. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-472. Affected package(s): rhbk/keycloak-operator-bundle:26.4.12, rhbk/keycloak-rhel9-operator, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:19596 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7571
Unclassified
May 19, 2026
High7.5Red Hat

High [CVE-2026-7307] Denial of Service via specially crafted SAML input

Denial of Service via specially crafted SAML input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1286. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.12, rhbk/keycloak-operator-bundle:26.2.16, rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-rhel9:26.2. Resolved in Red Hat advisory RHSA-2026:19594 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.2; Red Hat build of Keycloak 26.4.

CVE-2026-7307
Unclassified
May 19, 2026
High8.1Red Hat

High [CVE-2025-51427] Arbitrary code execution via crafted configuration module

Arbitrary code execution via crafted configuration module. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2025-51427
Unclassified
May 19, 2026
High8.8Red Hat

High [CVE-2026-31072] Remote Code Execution via Insecure Deserialization

Remote Code Execution via Insecure Deserialization. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-31072
Unclassified
May 19, 2026
High7.4Red Hat

High [CVE-2026-9116] Insufficient policy enforcement in ServiceWorker

Insufficient policy enforcement in ServiceWorker. Red Hat rates this important (CVSS 7.4). Weakness: CWE-346. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9116
Unclassified
May 19, 2026

← All vendors