Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.5Red Hat

Medium [CVE-2026-43721] A malicious website may silently hijack clipboard data

A malicious website may silently hijack clipboard data. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-732. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-43721
Unclassified
Jul 10, 2026
Medium6.5Red Hat

Medium [CVE-2026-43732] Maliciously crafted web content may disclose sensitive user information

Maliciously crafted web content may disclose sensitive user information. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-43732
Unclassified
Jul 10, 2026
Medium6.5Red Hat

Medium [CVE-2026-43740] Maliciously crafted web content may disclose process memory

Maliciously crafted web content may disclose process memory. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-43740
Unclassified
Jul 10, 2026
Medium5.3Red Hat

Medium [CVE-2026-59856] Arbitrary code execution via crafted PHP file in omni-completion

Arbitrary code execution via crafted PHP file in omni-completion. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:47982 with package vim-2:8.2.2637-26.el9_8.13, vim-main-9.2.780-1.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-59856
Unclassified
Jul 9, 2026
Medium6.5Red Hat

Medium [CVE-2026-59858] Arbitrary command execution via crafted tags file in C omni-completion

Arbitrary command execution via crafted tags file in C omni-completion. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:47982 with package vim-2:8.2.2637-26.el9_8.13, vim-main-9.2.780-1.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-59858
Unclassified
Jul 9, 2026
Medium5.5Red Hat

Medium [CVE-2026-59857] Denial of Service via out-of-bounds write in spell sound-folding

Denial of Service via out-of-bounds write in spell sound-folding. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:35387 with package vim-main-9.2.780-1.hum1.

CVE-2026-59857
Unclassified
Jul 9, 2026
Medium6.8Red Hat

Medium [CVE-2026-55689] OIDC audience validation skipped when --authn-oidc-audience is unset

OIDC audience validation skipped when --authn-oidc-audience is unset. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-287.

CVE-2026-55689
Unclassified
Jul 9, 2026
Medium5.4Red Hat

Medium [CVE-2026-55170] Incorrect authorization decisions due to case-insensitive comparisons in MySQL datastore

Incorrect authorization decisions due to case-insensitive comparisons in MySQL datastore. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-178.

CVE-2026-55170
Unclassified
Jul 9, 2026
Medium4.3Red Hat

Medium [CVE-2026-15187] Prototype pollution vulnerability allows remote attackers to modify object attributes

Prototype pollution vulnerability allows remote attackers to modify object attributes. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:34975 with package rust-main-1.96.1-1.hum1.

CVE-2026-15187
Unclassified
Jul 9, 2026
Medium5.9Red Hat

Medium [CVE-2026-12590] Denial of Service via invalid limit option

Denial of Service via invalid limit option. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-770.

CVE-2026-12590
Unclassified
Jul 9, 2026
Medium6.5Red Hat

Medium [CVE-2026-38076] Denial of Service via crafted input

Denial of Service via crafted input. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-190.

CVE-2026-38076
Unclassified
Jul 9, 2026
Medium6.2Red Hat

Medium [CVE-2020-12265 +1] path traversal via indexOf containment bypass allows arbitrary file write (bypass of CVE-2020-12265 fix)

path traversal via indexOf containment bypass allows arbitrary file write (bypass of CVE-2020-12265 fix). Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:37577 with package dotnet8-0-main-8.0.128-1.1.hum1.

CVE-2020-12265CVE-2026-39245
Unclassified
Jul 9, 2026
Medium5.7Red Hat

Medium [CVE-2026-59921] CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder

A flaw was found in Netty's HttpPostRequestEncoder, a widely used Java networking library component responsible for constructing multipart HTTP request bodies. The issue arises because user-supplied filenames and field names are directly embedded into Content-Disposition MIME headers without any validation or sanitization of CRLF (\r\n) characters. Since MIME headers are delimited by CRLF sequences, an attacker who controls the filename in a multipart upload can inject arbitrary MIME headers into the request body. This may lead to limited Content-Type spoofing or header manipulation against middleware or storage layers processing the request, though the practical impact is constrained by the context in which Netty is deployed. Moderate: A CRLF injection flaw in the Netty Java networking library's multipart message encoder allows remote attackers with low privileges to inject arbitrary MIME headers. This can lead to Content-Type spoofing, stored cross-site scripting, or manipulation of downstream application logic, compromising data confidentiality and integrity without user interaction. Red Hat severity: Moderate — CVSS 5.7 (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-93. Affected products named by the advisory: Red Hat build of Quarkus 3.27.4.SP3; Red Hat build of Quarkus 3.33.2.SP3; Cryostat 4; OpenShift Serverless; and 19 more.

CVE-2026-59921
Unclassified
Jul 9, 2026
Medium5.7Red Hat

Medium [CVE-2026-56821] Improper certificate revocation check in netty-handler-ssl-ocsp

A flaw was found in netty-handler-ssl-ocsp, a component of the Netty network application framework. The Online Certificate Status Protocol (OCSP) stapling validator in this component does not properly check certificate revocation status. This can allow an attacker to use revoked certificates without detection, potentially compromising secure communications. Red Hat severity: Moderate — CVSS 5.7 (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-93. Affected Red Hat products: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Data Grid 8; Red Hat JBoss Enterprise Application Platform Expansion Pack. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-56821
Unclassified
Jul 9, 2026
Medium5.3Red Hat

Medium [CVE-2026-59898] Protocol version confusion in netty-codec-http (WebSocket)

A flaw was found in netty-codec-http. The WebSocket handshaker in this component fails to properly validate protocol version information during the WebSocket upgrade process. A remote attacker can exploit this vulnerability by manipulating the WebSocket handshake, leading to a bypass of security checks or the negotiation of unexpected protocol versions. This could potentially enable protocol-level attacks. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-358. Affected Red Hat products: Red Hat build of Quarkus 3.27.4.SP3; Red Hat build of Quarkus 3.33.2.SP3; Cryostat 4; OpenShift Serverless; Red Hat AMQ Broker 7; Red Hat AMQ Clients; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apache Camel - HawtIO 4; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; Red Hat Data Grid 8; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces; Red Hat Satellite 6; Red Hat Single Sign-On 7; streams for Apache Kafka 2; streams for Apache Kafka 3. Red Hat fixing advisory: RHSA-2026:47189, RHSA-2026:47172.

CVE-2026-59898
Unclassified
Jul 9, 2026
Medium6.5Red Hat

Medium [CVE-2026-59900] Improper header neutralization in netty-codec-http2

A flaw was found in Netty's netty-codec-http2 component. The HTTP/2 encoder does not properly handle special characters in HTTP headers. This vulnerability allows a remote attacker to craft specific HTTP/2 requests, leading to HTTP response splitting and header injection attacks. Such attacks can enable an attacker to manipulate web content or inject malicious headers. This Moderate impact flaw in Netty's HTTP/2 encoder allows attackers to inject arbitrary header content via specially crafted HTTP/2 requests. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N). Affected Red Hat products: Red Hat build of Quarkus 3.27.4.SP3; Red Hat build of Quarkus 3.33.2.SP3; Cryostat 4; OpenShift Serverless; Red Hat AMQ Broker 7; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apache Camel - HawtIO 4; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; Red Hat Data Grid 8; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces; Red Hat Single Sign-On 7; streams for Apache Kafka 2; streams for Apache Kafka 3. Red Hat fixing advisory: RHSA-2026:47189, RHSA-2026:47172.

CVE-2026-59900
Unclassified
Jul 9, 2026
Medium5.5Red Hat

Medium [CVE-2026-59919] Improper CR/LF neutralization in netty-codec-haproxy

A flaw was found in the netty-codec-haproxy component, part of the Netty network application framework. This vulnerability allows a remote attacker to perform protocol-level injection attacks by crafting malformed HAProxy protocol frames that contain embedded carriage return (CR) and line feed (LF) sequences. This can lead to the injection of arbitrary content, potentially disrupting network communication or enabling further attacks. This Moderate flaw in `netty-codec-haproxy` allows for protocol-level injection attacks due to improper neutralization of CR/LF sequences. An attacker could exploit this by crafting malformed HAProxy protocol frames to inject arbitrary content, potentially leading to unexpected behavior or further attacks within the affected application's protocol handling. This vulnerability impacts multiple Red Hat products that incorporate the `netty-codec-haproxy` component. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-93. Affected products named by the advisory: Cryostat 4; OpenShift Serverless; Red Hat AMQ Broker 7; Red Hat build of Apache Camel 4 for Quarkus 3; and 15 more.

CVE-2026-59919
Unclassified
Jul 9, 2026
Medium6.5Red Hat

Medium [CVE-2026-59920] Improper CR/LF neutralization in netty-codec-stomp

A flaw was found in the Netty STOMP (Streaming Text Oriented Messaging Protocol) decoder. This vulnerability allows a remote attacker to inject arbitrary protocol frames by crafting malformed STOMP commands that contain embedded carriage return (CR) and line feed (LF) sequences. This bypasses message boundary checks and can lead to command injection, potentially compromising the integrity of the system. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-93. Affected Red Hat products: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Data Grid 8; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7. Will not fix / out of support: Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-59920
Unclassified
Jul 9, 2026
Medium6.1Red Hat

Medium [CVE-2026-39243] File disclosure and corruption via arbitrary hardlink creation

decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. When processing hardlink entries (type === 'link'), the x.linkname field from the archive is passed directly to fs.link() without validation (index.js line 113). An attacker can craft an archive with a hardlink entry whose linkname is an absolute path to any file on the same filesystem. This creates a hardlink inside the extraction directory that shares the same inode as the target file, enabling both reading and overwriting the original file's content. Hardlinks are limited to files on the same filesystem and cannot target directories. A flaw was found in decompress. An attacker can craft a malicious archive that, when extracted, allows for arbitrary hardlink creation. This could lead to sensitive file read disclosure or file corruption on the system. This Moderate flaw in the `decompress` library allows an attacker to create arbitrary hardlinks during archive extraction. By crafting a malicious archive, an attacker could exploit this to disclose sensitive file contents or corrupt files on the same filesystem where the archive is extracted. This risk is present in Red Hat products that utilize the `decompress` library for archive handling.

CVE-2026-39243
Unclassified
Jul 9, 2026
Medium5.7Vendor: HighRed Hat

Medium [CVE-2026-15108] Integer overflow in Extensions API

Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted Chrome Extension. (Chromium security severity: High) An integer overflow flaw was found in the Extensions API component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 5.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-125.

CVE-2026-15108
Unclassified
Jul 8, 2026

← All vendors