Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5812 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium4.3Red Hat

Medium [CVE-2026-84330] UI misrepresentation in FullScreen

UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium) An ui misrepresentation flaw was found in the FullScreen component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N). Weakness: CWE-1021.

CVE-2026-84330
Unclassified
Sep 1, 2026
Medium5.9Red Hat

Medium [CVE-2026-84328] Missing authorization in FileSystem

Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N). Weakness: CWE-346.

CVE-2026-84328
Unclassified
Sep 1, 2026
Medium6.8Red Hat

Medium [CVE-2026-84359] Information leak in Skia

Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 6.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N). Weakness: CWE-346. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: webkit2gtk3.

CVE-2026-84359
Red Hat Enterprise Linux
Sep 1, 2026
Medium6.1Red Hat

Medium [CVE-2026-84640] One byte overflow read in mail parser

A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. A remote attacker could exploit this vulnerability by sending a maliciously constructed mail header. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: thunderbird.

CVE-2026-84640
Red Hat Enterprise Linux
Sep 1, 2026
Medium5.9Red Hat

Medium [CVE-2026-84373] Arbitrary File Read via Path Traversal in HMR WebSocket

Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin exports in packages/mocker/src/node/interceptorPlugin.ts register the vitest:interceptor:register handler on Vite's unauthenticated HMR WebSocket without validating redirect targets against the file-serving allowlist. The implementation processes event.redirect without enforcing server.fs.allow and server.fs.deny through isFileLoadingAllowed. A remote client that can reach an exposed development server can submit an opaque URL scheme preserving.. segments, causing join(server.config.root, redirectUrl.pathname) to resolve outside the project root. The plugin's load hook then returns readFile(mock.redirect, 'utf-8') as module source, disclosing local files readable by the dev-server process. Vitest browser mode uses a token-authenticated RPC and is not remotely unauthenticated by default, although the same boundary check was missing on that path. This issue is fixed in versions 4.1.11 and 5.0.0-rc.2. A remote attacker, able to reach an exposed development server, could exploit an issue in the mockerPlugin and interceptorPlugin exports. By submitting a specially crafted URL with path traversal segments, an attacker could read arbitrary local files accessible by the development server process, leading to information disclosure.

CVE-2026-84373
Red Hat Enterprise Linux
Sep 1, 2026
Medium6.4Red Hat

Medium [CVE-2026-84470] Bulk Job Launch checks instance_groups at read level instead of use level, allowing execution-placement authorization bypass

A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard single-job launch path requires use-level permission on the same field. A principal that holds read (but not use) permission on an instance group -- for example the built-in read-only System Auditor role -- together with execute permission on a job template can launch bulk jobs onto instance groups they are not authorized to use, bypassing execution-placement isolation. Red Hat severity: Moderate — CVSS 6.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L). Weakness: CWE-862. Affected Red Hat products: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.6; Red Hat Ansible Automation Platform 2.7. Red Hat fixing advisory: RHSA-2026:71114, RHSA-2026:71113, RHSA-2026:71179, RHSA-2026:71177.

CVE-2026-84470
Unclassified
Sep 1, 2026
Medium5.4Red Hat

Medium [CVE-2026-84371] stored XSS via SVG SMIL URI-list scheme-policy bypass

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor, animateMotion, animateTransform, or set elements, a values list can begin with a safe fragment and contain a later executable destination that survives allowedSchemesAppliedToAttributes checking. When the sanitized SVG is rendered, the browser can copy that later destination into the live link, and a victim who activates the link can execute script in the application's origin. This issue is fixed in version 2.17.7. Improper validation of the animation value attributes in SVG files allows an attacker to bypass scheme filters and embed a malicious script destination within a list of values. When a user interacts with the rendered SVG animation, the embedded script executes in the context of the application, leading to Cross-Site Scripting (XSS). To exploit this flaw, an attacker needs to trick a user into clicking or interacting with a malicious rendered SVG file, reducing the likelihood of exploitation.

CVE-2026-84371
Red Hat Enterprise Linux
Sep 1, 2026
Medium5.5Red Hat

Medium [CVE-2026-84311] Denial of Service via crafted PDF XForm objects

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of reused form XObjects in which each form invokes a child multiple times, creating exponentially many traversal paths and causing long runtimes and large memory consumption. This issue is fixed in version 6.16.1. A remote attacker can exploit this vulnerability by crafting a malicious PDF document containing specially structured XForm objects. Processing this document can lead to excessive iteration, causing the application to consume significant memory and CPU resources, resulting in a Denial of Service (DoS). A flaw was found in pypdf's text extraction logic (_extract_text and extract_xform_text) within PageObject. A remote, unauthenticated attacker could trick a user or automated system into processing a specially crafted PDF containing a directed acyclic graph (DAG) of reused form XObjects. Invoking nested child forms repeatedly causes exponential expansion during traversal, triggering unbounded CPU execution and high memory consumption. Default Red Hat process sandboxing limits system-wide impact, though application workers extracting text remain susceptible to resource exhaustion.

CVE-2026-84311
Unclassified
Sep 1, 2026
Medium5.5Red Hat

Medium [CVE-2026-84310] Denial of Service via crafted PDF outlines

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines with large numbers of entries or deeply nested reused paths because the traversal lacked global entry-count and nesting-depth limits. This issue is fixed in version 6.16.1. A flaw was found in pypdf. A remote attacker could craft a malicious PDF document with specially designed outlines. Processing this document would cause the pypdf library to consume excessive processing time and memory, leading to a Denial of Service (DoS) condition. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Ansible Automation Orchestrator 2026; Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat Quay 3. Will not fix / out of support: Exploit Intelligence; Red Hat Ansible Automation Platform 2; Red Hat Quay 3. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-84310
Unclassified
Sep 1, 2026
Medium5.5Red Hat

Medium [CVE-2026-84309] Denial of Service via crafted PDF with cyclic tree structure

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a writing code path inserts a child, producing an infinite loop. This issue is fixed in version 6.16.0. A flaw was found in pypdf. This can result in a denial of service (DoS) due to resource exhaustion. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected Red Hat products: Ansible Automation Orchestrator 2026; Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat Quay 3. Will not fix / out of support: Exploit Intelligence; Red Hat Ansible Automation Platform 2; Red Hat Quay 3. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-84309
Unclassified
Sep 1, 2026
Medium4.3Red Hat

Medium [CVE-2026-84270] Gvfs: mtp: out-of-bounds read in do_read

A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, do_read() in gvfsbackendmtp.c trusts the data length returned by the device without limiting it to the original size requested by the client. If a malicious MTP device responds with more bytes than requested, this unrestricted length is passed directly to memcpy(). This causes the operation to read memory outside the intended boundaries. This allows an attacker who plugs in a malicious MTP device to cause a segmentation fault when a file is read and crash the gvfsd-mtp process, resulting in a denial of service. To exploit this issue, an attacker needs to plug in a malicious MTP device, limiting its exposure. Furthermore, the direct security impact of this flaw is a denial of service due to the out-of-bounds read. There is no information disclosure. For these reasons, this vulnerability has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gvfs.

CVE-2026-84270
Red Hat Enterprise Linux
Sep 1, 2026
Medium6.5Red Hat

Medium [CVE-2026-84269] Gvfs: afp: heap-based buffer overflow in dsi read path

A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the intended boundaries. This issue allows a malicious server to overflow a heap buffer and crash the gvfsd-afp process, resulting in a denial of service. To exploit this issue, an attacker needs a user to connect to a malicious AFP share (for example, by clicking a crafted afp:// link), limiting its exposure. Furthermore, the direct security impact of this flaw is a denial of service due to the heap-based buffer overflow. For these reasons, this vulnerability has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-122. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gvfs.

CVE-2026-84269
Red Hat Enterprise Linux
Sep 1, 2026
Medium4.3Red Hat

Medium [CVE-2026-84267] Gvfs: sftp: uninitialized heap disclosure in read_string

A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the function does not verify that the buffer is completely filled, leaving the remainder of the buffer containing uninitialized heap contents. If the server sends a short FXP_HANDLE reply, these uninitialized bytes are taken as the file handle. The client will then echo these uninitialized bytes back to the server on all subsequent requests using that handle. With a length of 128 bytes, this issue allows the malicious server to deterministically read uninitialized heap memory from the gvfsd-sftp process, leaking its heap base and the load address of the libgio library, resulting in a deterministic defeat of Address Space Layout Randomization (ASLR). To exploit this issue, an attacker needs a user to connect to a malicious SFTP share (for example, by clicking a crafted sftp:// link or intercepting an unverified connection), limiting its exposure. Furthermore, the direct security impact of this flaw is limited to an information disclosure of specific memory contents, specifically the heap base of the gvfsd-sftp process and the load address of the libgio library but it does not expose any user data. For these reasons, this vulnerability has been rated with a moderate severity.

CVE-2026-84267
Red Hat Enterprise Linux
Sep 1, 2026
Medium5.4Red Hat

Medium [CVE-2026-84232] Stored cross-site scripting via inline rendering of uploaded HTML/SVG content

A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for.html files, image/svg+xml for.svg files) and without a Content-Disposition: attachment header when using local filesystem storage. An authenticated user or attacker with content upload permissions can upload a specially crafted HTML or SVG file containing JavaScript, which executes in the browser of any user who visits the file URL, resulting in stored cross-site scripting (XSS) in the context of the host application. Red Hat Product Security has assessed this issue as a Moderate severity vulnerability. The confidentiality and integrity impact is limited because the session cookie in the host application (Foreman/Satellite) is set with the HttpOnly attribute, which prevents direct session token theft via JavaScript. The attacker's script can read visible page content and make authenticated API requests on behalf of the victim through the browser, but cannot exfiltrate the session itself or gain persistent access beyond the victim's active browser session. There is no availability impact. ``` In Red Hat Satellite, the /pulp/content/ path shares the same origin (protocol, hostname, and port) as the Satellite web UI, making the XSS effective against Satellite sessions.

CVE-2026-84232
Unclassified
Sep 1, 2026
Medium5.6Red Hat

Medium [CVE-2026-83557] com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: Path traversal via incomplete type validation

DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of "unsafe base types", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang. Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument.

CVE-2026-83557
Red Hat Enterprise Linux
Sep 1, 2026
Medium5.3Red Hat

Medium [CVE-2026-70409] Denial of Service via long LDAP referral URL port

Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to degrade availability by returning a referral URL whose port component is a very long run of digits. eldap:parse_port/2 passes the port substring straight to list_to_integer/1 with no length bound. The surrounding try... catch only rejects a value that fails to parse, so a syntactically valid port of up to roughly 1.26 million digits converts successfully and costs the caller hundreds of milliseconds of arbitrary-precision arithmetic per referral. The conversion function itself is documented to accept integers of any size, so bounding the input is the caller's responsibility. Reaching the flaw requires the application to pass a server-supplied referral to eldap:parse_ldap_url/1, which eldap never calls itself: referral strings are returned to the caller unparsed. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to eldap from 1.0.3 before 1.2.14.2, from 1.2.15 before 1.2.16.1, and from 1.3 before 1.3.1. A malicious or compromised Lightweight Directory Access Protocol (LDAP) server could exploit this vulnerability by returning a referral Uniform Resource Locator (URL) with an excessively long port number.

CVE-2026-70409
Unclassified
Sep 1, 2026
Medium6.5Red Hat

Medium [CVE-2026-74994] inets httpd mod_auth: Authentication Bypass via Directory Namespace Collapse

The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one protected directory is accepted as valid for all other protected directories on the same server instance. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Moderate: The `mod_auth` module in the `inets` httpd server, as shipped in Red Hat Hardened Images, is vulnerable to an authentication bypass. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-1220. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Cryostat 4; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat OpenShift Dev Spaces as not affected. Red Hat fixing advisory: RHSA-2026:62531.

CVE-2026-74994
Unclassified
Sep 1, 2026
Medium5.4Vendor: LowRed Hat

Medium [CVE-2026-73276] OTP inets httpd: HTTP Request Smuggling vulnerability via malformed headers

OTP inets httpd: HTTP Request Smuggling vulnerability via malformed headers. Red Hat rates this low (CVSS 5.4). Weakness: CWE-444. Affected products named by the advisory: Cryostat 4; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat OpenShift Dev Spaces.

CVE-2026-73276
Unclassified
Sep 1, 2026
Medium5.3Red Hat

Medium [CVE-2026-83611] Malformed XML end tag parsing leads to content discard and security bypass

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, DOMParser.parseFromString() can silently accept an end tag such as, close the element, and discard the trailing content. On 0.9.x, the lib/sax.js end-tag validator inherits the multiline flag from reg(), allowing the first line to satisfy the anchored XML ETag production; older lines have no equivalent residue validation. This parser differential can bypass a parse-before-trust well-formedness gate, although it does not inject the discarded content; onError on 0.9.x and errorHandler on 0.8.x are the relevant reporting interfaces. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom. The DOMParser.parseFromString() function can silently accept malformed XML end tags that include a line break and additional content. This unexpected parsing behavior causes the parser to close the element prematurely and discard the trailing content. This could potentially bypass security checks that rely on strict XML well-formedness, leading to data loss or misinterpretation in applications processing untrusted XML input. A flaw was found in the xmldom JavaScript package.

CVE-2026-83611
Red Hat Enterprise Linux
Sep 1, 2026
Medium5.3Red Hat

Medium [CVE-2026-83610] @xmldom/xmldom: xmldom: XML fragment injection via invalid EntityReference serialization

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createEntityReference(name) accepts an invalid name and the ENTITY_REFERENCE_NODE serializer emits the resulting nodeName directly in &name; form. Directly serializing the node or fragment with XMLSerializer.serializeToString() and requireWellFormed: true can therefore break the entity-reference boundary and produce attacker-controlled XML markup when reparsed. The parser does not ordinarily create these nodes, and element-child insertion is rejected, so exploitation requires an application to create and directly serialize an EntityReference. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom. The Document.createEntityReference function incorrectly accepts invalid names, which are then directly emitted during serialization. This vulnerability allows an attacker to inject arbitrary XML fragments when an application creates and directly serializes an EntityReference with specific settings. This can lead to the manipulation of XML data when the output is subsequently re-parsed. This Moderate flaw in xmldom allows for XML fragment injection.

CVE-2026-83610
Red Hat Enterprise Linux
Sep 1, 2026

← All vendors