Red Hat Linux Security Advisories & CVEs
5812 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-53682] Unauthenticated Dogtag CA REST API exposes Security Domain Hosts
An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session. Rated Moderate because this is unauthenticated disclosure of internal host and topology metadata only; the disclosed hostnames and roles do not directly expose credentials or sensitive data, making this a reconnaissance/follow-on-attack enabler rather than a direct compromise. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-497. Affected Red Hat products: Red Hat Certificate System 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: dogtag-pki; Red Hat package: pki-core.
Medium [CVE-2026-84142] Internally found bugs fixed in Firefox 155
Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Thunderbird 155. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Weakness: CWE-787. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Medium [CVE-2026-84132] Information disclosure in the Networking: HTTP component
Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Weakness: CWE-201. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Medium [CVE-2026-84130] Information disclosure in the Graphics: WebGPU component
Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Weakness: CWE-201. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Medium [CVE-2026-84129] Site isolation issue in the DOM: Navigation component
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Weakness: CWE-501. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Medium [CVE-2026-84128] Privilege escalation in the WebDriver BiDi component
Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Weakness: CWE-266. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Medium [CVE-2026-84127] Information disclosure in WebExtensions component
Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 155. This vulnerability allows for information disclosure, potentially enabling an attacker to gain access to sensitive data. This issue only affected Firefox for Android (Fenix). Red Hat products ship desktop Firefox and are not affected. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-201. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Medium [CVE-2026-84131] Privilege escalation due to invalid pointer in the Graphics component
Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.
Medium [CVE-2026-11873] empty request to Dogtag /ca/rest/certrequests causes HTTP 500, java exception, and stacktrace disclosure
An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating a log-amplification resource exhaustion vector (disk growth and I/O contention) without requiring authentication. Rated Moderate because the flaw only discloses internal stack traces and class names rather than sensitive data, and the availability impact is limited to gradual log-driven disk/I/O pressure rather than directly crashing the service. No code execution, authentication bypass, or direct compromise results from the flaw. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L). Weakness: CWE-209. Affected Red Hat products: Red Hat Certificate System 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: dogtag-pki; Red Hat package: pki-core.
Medium [CVE-2026-19032] com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: Jackson-databind: Uncontrolled URI scheme resolution in Path deserialization
jackson-databind's deserializer for java.nio.file. Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer. NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Path from untrusted JSON should be avoided regardless of version. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; OpenShift Serverless; Red Hat AI Inference Server; and 35 more.
Medium [CVE-2026-82398] Denial of Service via inefficient handling of non-whitespace inputs
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without whitespace. The function repeatedly performs immutable bytes concatenation in a one-byte loop, causing quadratic processing cost for the long non-whitespace input. This issue is fixed in version 6.15.0. A flaw was found in pypdf. This leads to quadratic processing cost and a potential Denial of Service (DoS). Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-1046. Affected Red Hat products: Ansible Automation Orchestrator 2026; Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat Quay 3. Will not fix / out of support: Exploit Intelligence; Red Hat Ansible Automation Platform 2; Red Hat Quay 3. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-83589] Open Redirect via /\ and /\t Bypass in Post-Login Redirect
A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft. Although successful exploitation requires user interaction to navigate a specially constructed link, the proxy's role as a trusted authentication gateway significantly heightens the blast radius. Under standard OpenShift Container Platform deployments, the component is exposed to route traffic and handles post-authentication redirection routines by default. Red Hat severity: Important — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Weakness: CWE-601. Affected Red Hat products: Red Hat OpenShift Container Platform 4.20; Red Hat OpenShift Container Platform 4.21; Red Hat OpenShift Container Platform 4.22; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:74380, RHSA-2026:74383, RHSA-2026:74429.
Medium [CVE-2026-80221] Direct database connection string with embedded credentials passed as environment variable
Direct database connection string with embedded credentials passed as environment variable. Red Hat rates this important (CVSS 4.4). Weakness: CWE-312. Red Hat lists fixing advisory RHSA-2026:68515 with package multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1788376193, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1788441983, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1788375682. Affected product named by the advisory: Multicluster Global Hub.
Medium [CVE-2026-80220] pprof profiling endpoints exposed on unauthenticated metrics listener
pprof profiling endpoints exposed on unauthenticated metrics listener. Red Hat rates this important (CVSS 5.4). Weakness: CWE-200. Red Hat lists fixing advisory RHSA-2026:68515 with package multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9:1788200952, multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9:1788200121, multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9:1788200958. Affected product named by the advisory: Multicluster Global Hub.
Medium [CVE-2026-82797] Denial of Service via uncontrolled recursion with serialized data
Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51. A flaw was found in rlottie. Successful exploitation requires user interaction to process the malicious data. The rlottie library is shipped in Fedora and EPEL community distributions. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-1265.
Medium [CVE-2026-82677] Denial of Service via double free in Module Timer subsystem
A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: b349fe2821e3998534b1454c1b64a478daf8c6b7. To fix this issue, it is recommended to deploy a patch. This flaw could lead to a denial of service. Execution remains confined within the process runtime environment, mitigated by default SELinux policies and container isolation preventing host-level escalation. Red Hat severity: Moderate — CVSS 4.9 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1341. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:61884. Affected products named by the advisory: Red Hat package: valkey.
Medium [CVE-2026-82853] SMTP Command Injection allows email spoofing and phishing attacks
Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return and line feed characters, allowing attackers to inject arbitrary SMTP commands for email spoofing and phishing attacks. A flaw was found in Nodemailer. This vulnerability allows a remote attacker to inject arbitrary Simple Mail Transfer Protocol (SMTP) commands due to improper sanitization of carriage return and line feed characters in the transport name option. Moderate: This SMTP command injection vulnerability in Nodemailer allows an attacker with high privileges to inject arbitrary SMTP commands. This could lead to email spoofing and phishing attacks within affected Red Hat products that utilize Nodemailer for email transport, such as Red Hat Developer Hub and Red Hat Ansible Automation Platform, where applications allow user or external input to configure the SMTP transport name option. Red Hat severity: Moderate — CVSS 4.9 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-93. Affected Red Hat products: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Self-service automation portal 2. Red Hat lists Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-82661] Header injection via unsanitized list comment fields
Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail client behavior and message semantics. A flaw was found in Nodemailer, an email sending library. By failing to sanitize carriage return and line feed (CRLF) characters, an attacker can alter mail client behavior and message semantics, potentially leading to email spoofing or other integrity issues. This is a Moderate impact vulnerability where an attacker with control over specific input fields can inject arbitrary email headers. This could alter mail client behavior or message semantics, but it does not enable remote code execution or direct SMTP command injection. Exploitation requires an application to pass unsanitized user-controlled input to the vulnerable `list.*.comment` parameters within the Nodemailer library. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-93. Affected Red Hat products: Red Hat Developer Hub; Self-service automation portal 2. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-82662] Information disclosure due to disabled TLS certificate verification
Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised HTTPS connections. A flaw was found in Nodemailer where it disables Transport Layer Security (TLS) certificate verification. A remote attacker, positioned between the user and the server (a machine-in-the-middle attack), could exploit this by intercepting OAuth2 token requests. This flaw allows a machine-in-the-middle attacker to intercept OAuth2 token requests, leading to the disclosure of sensitive OAuth client secrets, refresh tokens, and access tokens. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N). Weakness: CWE-295. Affected Red Hat products: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Self-service automation portal 2. Red Hat lists Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: grafana.
Medium [CVE-2026-82660] Information Disclosure via jsonTransport Access Control Bypass
Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls. A flaw was found in Nodemailer, a module for sending emails. The jsonTransport component, responsible for handling message data, does not correctly enforce security options designed to prevent unauthorized file and URL access. A remote attacker could exploit this by sending specially crafted messages containing malicious file paths or URLs. This bypasses the intended security controls, potentially allowing the attacker to read sensitive local files or access external web resources, leading to unauthorized information disclosure. This Moderate impact flaw in Nodemailer's `jsonTransport` allows an attacker to bypass intended access controls. This affects Red Hat products that integrate vulnerable versions of Nodemailer. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-472. Affected Red Hat products: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Self-service automation portal 2. Red Hat lists Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE.