Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.8Red Hat

High [CVE-2026-8532] Integer overflow in XML

Integer overflow in XML. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8532
Unclassified
May 14, 2026
High7.9Red Hat

High [CVE-2026-8528] Insufficient validation of untrusted input in SiteIsolation

Insufficient validation of untrusted input in SiteIsolation. Red Hat rates this important (CVSS 7.9). Weakness: CWE-1286. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8528
Unclassified
May 14, 2026
High8.8Red Hat

High [CVE-2026-8529] Heap buffer overflow in Codecs

Heap buffer overflow in Codecs. Red Hat rates this important (CVSS 8.8). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8529
Unclassified
May 14, 2026
High8.8Red Hat

High [CVE-2026-8527] Insufficient validation of untrusted input in Downloads

Insufficient validation of untrusted input in Downloads. Red Hat rates this important (CVSS 8.8). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8527
Unclassified
May 14, 2026
High8.8Red Hat

High [CVE-2026-8558] Out of bounds write in Fonts

Out of bounds write in Fonts. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8558
Unclassified
May 14, 2026
High7.5Vendor: CriticalRed Hat

High [CVE-2026-8521] Use after free in Tab Groups

Use after free in Tab Groups. Red Hat rates this critical (CVSS 7.5). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8521
Unclassified
May 14, 2026
High8.8Vendor: CriticalRed Hat

High [CVE-2026-8522] Use after free in Downloads

Use after free in Downloads. Red Hat rates this critical (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8522
Unclassified
May 14, 2026
High8.3Vendor: CriticalRed Hat

High [CVE-2026-8520] Race in Payments

Race in Payments. Red Hat rates this critical (CVSS 8.3). Weakness: CWE-368. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8520
Unclassified
May 14, 2026
High8.8Vendor: CriticalRed Hat

High [CVE-2026-8519] Integer overflow in ANGLE

Integer overflow in ANGLE. Red Hat rates this critical (CVSS 8.8). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8519
Unclassified
May 14, 2026
High8.0Vendor: CriticalRed Hat

High [CVE-2026-8513] Use after free in Input

Use after free in Input. Red Hat rates this critical (CVSS 8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8513
Unclassified
May 14, 2026
High8.0Vendor: CriticalRed Hat

High [CVE-2026-8510] Integer overflow in Skia

Integer overflow in Skia. Red Hat rates this critical (CVSS 8). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8510
Unclassified
May 14, 2026
High8.8Red Hat

High [CVE-2026-44513] Arbitrary remote code execution via `trust_remote_code` bypass

Arbitrary remote code execution via `trust_remote_code` bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-358. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-44513
Unclassified
May 14, 2026
High7.5Red Hat

High [CVE-2026-44216] Denial of Service via large WebAssembly table allocation

Denial of Service via large WebAssembly table allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-44216
Unclassified
May 14, 2026
High8.2Red Hat

High [CVE-2026-6478] Credential recovery via covert timing channel in MD5 password comparison

Credential recovery via covert timing channel in MD5 password comparison. Red Hat rates this important (CVSS 8.2). Weakness: CWE-385. Affected package(s): postgresql, postgresql:12, postgresql:18, postgresql:15, libpq, postgresql:13. Resolved in Red Hat advisory RHSA-2026:26561 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 9 more.

CVE-2026-6478
Unclassified
May 14, 2026
High8.4Red Hat

High [CVE-2026-6477] PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory

PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory. Red Hat rates this important (CVSS 8.4). Weakness: CWE-120. Affected package(s): postgresql, postgresql:12, postgresql:18, postgresql:15, libpq, postgresql16. Resolved in Red Hat advisory RHSA-2026:26561 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-6477
Unclassified
May 14, 2026
High8.8Red Hat

High [CVE-2026-6473] integer overflow can cause an undersized allocation and an out-of-bounds write

integer overflow can cause an undersized allocation and an out-of-bounds write. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190. Affected package(s): postgresql, postgresql:12, postgresql:18, postgresql:15, libpq, postgresql16. Resolved in Red Hat advisory RHSA-2026:26561 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-6473
Unclassified
May 14, 2026
High7.5Red Hat

High [CVE-2026-42561] Denial of Service via excessive multipart part headers

Denial of Service via excessive multipart part headers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: python-multipart; Red Hat OpenShift AI 3.3; Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; and 6 more.

CVE-2026-42561
Unclassified
May 13, 2026
High7.5Red Hat

High [CVE-2026-44248] Denial of Service due to excessive resource consumption from crafted MQTT 5 header

Denial of Service due to excessive resource consumption from crafted MQTT 5 header. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat AMQ Broker 7; Red Hat Fuse 7; Red Hat Process Automation 7; and 2 more.

CVE-2026-44248
Unclassified
May 13, 2026
High7.5Red Hat

High [CVE-2026-42587] Denial of Service via unbounded memory allocation in HTTP content decompression

Denial of Service via unbounded memory allocation in HTTP content decompression. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): devspaces/pluginregistry-rhel9:1780696380, cryostat/jfr-datasource-rhel9:4.2.0, netty-codec-http, devspaces/openvsx-rhel9:1780948325, devspaces/server-rhel9:1780694994, cryostat/cryostat-reports-rhel9:4.2.0. Resolved in Red Hat advisory RHSA-2026:23808 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat build of Quarkus 3.27.4; Red Hat OpenShift Dev Spaces 3.28; and 19 more.

CVE-2026-42587
Unclassified
May 13, 2026
High7.3Red Hat

High [CVE-2026-42584] Incorrect HTTP response parsing leads to data confusion

Incorrect HTTP response parsing leads to data confusion. Red Hat rates this important (CVSS 7.3). Weakness: CWE-444. Affected package(s): devspaces/pluginregistry-rhel9:1780696380, cryostat/jfr-datasource-rhel9:4.2.0, netty-codec-http, devspaces/openvsx-rhel9:1780948325, devspaces/server-rhel9:1780694994, cryostat/cryostat-reports-rhel9:4.2.0. Resolved in Red Hat advisory RHSA-2026:23808 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat build of Quarkus 3.27.4; Red Hat OpenShift Dev Spaces 3.28; and 20 more.

CVE-2026-42584
Unclassified
May 13, 2026

← All vendors