Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5443 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.5Linux

High [CVE-2026-46592] Remote attacker can execute unintended operations via header manipulation

Remote attacker can execute unintended operations via header manipulation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-639.

CVE-2026-46592
Unclassified
Jul 6, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-46584] Credential exposure and information disclosure via improper input validation of mail headers

Credential exposure and information disclosure via improper input validation of mail headers. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-918.

CVE-2026-46584
Unclassified
Jul 6, 2026
High8.1Linux

High [CVE-2026-40859] Apache Camel (camel-vertx-http): Remote Code Execution via Deserialization of Untrusted Data

Apache Camel (camel-vertx-http): Remote Code Execution via Deserialization of Untrusted Data. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502.

CVE-2026-40859
Unclassified
Jul 6, 2026
Medium6.1Linux

Medium [CVE-2026-59710] Stored Cross-Site Scripting via unescaped table header ID attributes in markdown

Stored Cross-Site Scripting via unescaped table header ID attributes in markdown. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-79.

CVE-2026-59710
Unclassified
Jul 6, 2026
Medium6.1Linux

Medium [CVE-2026-59711] Cross-site scripting via unescaped metadata title allows arbitrary code execution

Cross-site scripting via unescaped metadata title allows arbitrary code execution. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-79.

CVE-2026-59711
Unclassified
Jul 6, 2026
Medium5.8Linux

Medium [CVE-2026-54764] Authorization bypass in ForwardAuth middleware via forged X-Forwarded-Port

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middleware, even when configured with trustForwardHeader: false, derives the X-Forwarded-Port header sent to the authentication service from the original incoming request instead of the sanitized forwarded request. As a result, an unauthenticated remote attacker can inject an X-Forwarded-Proto: https header over a plain HTTP connection and cause Traefik to forward X-Forwarded-Port: 443 to the authentication service, bypassing port-based authorization checks. This issue is fixed in versions v2.11.51, v3.6.22, and v3.7.6. This bypasses port-based authorization checks, potentially granting unauthorized access. Moderate: A flaw in Traefik's ForwardAuth middleware, as used in Red Hat OpenShift Dev Spaces, allows an unauthenticated remote attacker to bypass port-based authorization. Red Hat severity: Moderate — CVSS 5.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N). Weakness: CWE-348. Affected Red Hat products: Red Hat OpenShift Dev Spaces. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-54764
Unclassified
Jul 6, 2026
Medium6.5Linux

Medium [CVE-2026-55514] Denial of Service via crafted prompt in /v1/completions request

Denial of Service via crafted prompt in /v1/completions request. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-617.

CVE-2026-55514
Unclassified
Jul 6, 2026
Medium6.5Linux

Medium [CVE-2026-55646] Denial of Service due to excessive memory allocation via oversized audio file uploads

Denial of Service due to excessive memory allocation via oversized audio file uploads. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770.

CVE-2026-55646
Unclassified
Jul 6, 2026
Medium5.9Linux

Medium [CVE-2026-54291] Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade

pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12. A remote attacker who can intercept a TLS (Transport Layer Security) connection can silently downgrade connections configured to require channel binding from SCRAM-SHA-256-PLUS to plain SCRAM-SHA-256. This downgrade bypasses the intended man-in-the-middle protection, allowing the attacker to potentially intercept or alter sensitive communication. The vulnerability occurs because the system fails to properly validate the channel binding when a specific type of certificate is used. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-940.

CVE-2026-54291
Unclassified
Jul 6, 2026
Medium4.5Linux

Medium [CVE-2026-55798] Arbitrary command injection via shell metacharacters in file paths

Arbitrary command injection via shell metacharacters in file paths. Red Hat rates this moderate (CVSS 4.5). Weakness: CWE-78.

CVE-2026-55798
Unclassified
Jul 6, 2026
Medium5.3Linux

Medium [CVE-2026-13122] From CVEorg collector

From CVEorg collector. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-617.

CVE-2026-13122
Unclassified
Jul 6, 2026
Medium5.0Linux

Medium [CVE-2026-59152] Information Disclosure via Arbitrary Server-Side File Read

Information Disclosure via Arbitrary Server-Side File Read. Red Hat rates this moderate (CVSS 5).

CVE-2026-59152
Unclassified
Jul 6, 2026
Medium5.3Linux

Medium [CVE-2026-58203] NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size

NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-22.

CVE-2026-58203
Unclassified
Jul 6, 2026
Medium4.9Linux

Medium [CVE-2026-13698] From CVEorg collector

From CVEorg collector. Red Hat rates this moderate (CVSS 4.9).

CVE-2026-13698
Unclassified
Jul 6, 2026
Medium5.3Linux

Medium [CVE-2026-56139] Information disclosure via error messages containing sensitive data

Information disclosure via error messages containing sensitive data. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-209.

CVE-2026-56139
Unclassified
Jul 6, 2026
Medium5.3Vendor: HighLinux

Medium [CVE-2026-49365] Information disclosure via error messages containing sensitive data

Information disclosure via error messages containing sensitive data. Red Hat rates this important (CVSS 5.3). Weakness: CWE-209.

CVE-2026-49365
Unclassified
Jul 6, 2026
Medium6.5Linux

Medium [CVE-2026-49098] Message redirection and injection via header manipulation

Message redirection and injection via header manipulation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-20.

CVE-2026-49098
Unclassified
Jul 6, 2026
Medium6.5Linux

Medium [CVE-2026-40047] CLI argument injection and path traversal

CLI argument injection and path traversal. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-78.

CVE-2026-40047
Unclassified
Jul 6, 2026
Low0.0Linux

Low [CVE-2026-56140] Apache Camel AWS SNS Component: Defense-in-depth hardening due to improper input validation

Apache Camel AWS SNS Component: Defense-in-depth hardening due to improper input validation. Red Hat rates this low.

CVE-2026-56140
Unclassified
Jul 6, 2026
Low3.3Linux

Low [CVE-2026-14788] Denial of Service via use-after-free in r_core_bin_load function

Denial of Service via use-after-free in r_core_bin_load function. Red Hat rates this low (CVSS 3.3). Weakness: CWE-825.

CVE-2026-14788
Unclassified
Jul 6, 2026

← All vendors