Red Hat Linux Security Advisories & CVEs
3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-44291] Arbitrary Code Execution via prototype pollution
Arbitrary Code Execution via prototype pollution. Red Hat rates this important (CVSS 8.1). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-44290] Denial of Service via crafted schema
Denial of Service via crafted schema. Red Hat rates this important (CVSS 7.5). Weakness: CWE-915. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-44289] Denial of Service via uncontrolled recursion in protobuf decoding
Denial of Service via uncontrolled recursion in protobuf decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: OpenShift Pipelines; Red Hat Build of Podman Desktop; Red Hat Ceph Storage 9; Red Hat Enterprise Linux 8; and 4 more.
High [CVE-2026-42945] Arbitrary Code Execution Vulnerability
Arbitrary Code Execution Vulnerability. Red Hat rates this critical (CVSS 8.1). Weakness: CWE-131. Affected package(s): odf4/ocs-client-console-rhel9:1779881302, satellite/iop-gateway-rhel9:1779706797, nginx, odf4/ocs-client-console-rhel9:1779879463, odf4/ocs-client-console-rhel9:1779972138, odf4/odf-console-rhel9:1779952279. Resolved in Red Hat advisory RHSA-2026:19371 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NGINX Plus; NGINX Open Source; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; and 18 more.
High [CVE-2026-46300] "Fragnesia" is a variant of Dirty Frag vulnerability in the ESP/XFRM leading to Local Privilege Escalation (LPE) vulnerability in the Linux kernel
"Fragnesia" is a variant of Dirty Frag vulnerability in the ESP/XFRM leading to Local Privilege Escalation (LPE) vulnerability in the Linux kernel. Red Hat rates this important (CVSS 7.8). Weakness: CWE-123. Affected package(s): rhcos, kernel-rt, kernel, openshift, kpatch-patch. Resolved in Red Hat advisory RHSA-2026:23470 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NVIDIA for RHEL 10; Red Hat OpenShift Container Platform 4.21; Red Hat OpenShift Container Platform 4.12; Red Hat OpenShift Container Platform 4.13; and 64 more.
High [CVE-2026-44222] Denial of Service via malformed multimodal input or token injection
Denial of Service via malformed multimodal input or token injection. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1285. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-42338] Cross-site scripting via improper HTML escaping of untrusted input
Cross-site scripting via improper HTML escaping of untrusted input. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, nodejs24, nodejs22, openshift-service-mesh/kiali-ossmc-rhel9:1782201894, openshift-service-mesh/kiali-ossmc-rhel9:1782201696. Resolved in Red Hat advisory RHSA-2026:33160 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Ansible Automation Platform 2.6; Red Hat Developer Hub 1.10; Red Hat Developer Hub 1.9; and 23 more.
High [CVE-2026-42899] .NET: infinite loop allows an attacker to cause a denial of service
.NET: infinite loop allows an attacker to cause a denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected package(s): dotnet10.0, dotnet9.0, dotnet8.0, dotnet8, dotnet9, dotnet10. Resolved in Red Hat advisory RHSA-2026:21291 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.
High [CVE-2026-35433] .NET: improper input validation allows an attacker to elevate privileges locally
.NET: improper input validation allows an attacker to elevate privileges locally. Red Hat rates this important (CVSS 7.3). Weakness: CWE-20. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-32177] .NET: heap-based buffer overflow allows an attacker to elevate privileges locally
.NET: heap-based buffer overflow allows an attacker to elevate privileges locally. Red Hat rates this important (CVSS 7.3). Weakness: CWE-122. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-8401] Sandbox escape in the Profile Backup component
Sandbox escape in the Profile Backup component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-653. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.
High [CVE-2026-42006] Denial of Service via excessive IMAP bracing
Denial of Service via excessive IMAP bracing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; and 7 more.
High [CVE-2026-27851] SQL/LDAP injection via incorrect safe filter interpretation with variable expansion
SQL/LDAP injection via incorrect safe filter interpretation with variable expansion. Red Hat rates this important (CVSS 7.4). Weakness: CWE-89. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-8391] Other issue in the JavaScript Engine component
Other issue in the JavaScript Engine component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-475. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.
High [CVE-2026-8390] Use-after-free in the JavaScript: WebAssembly component
Use-after-free in the JavaScript: WebAssembly component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-8388] Incorrect boundary conditions in the JavaScript Engine: JIT component
Incorrect boundary conditions in the JavaScript Engine: JIT component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.
High [CVE-2026-31228] Adversarial Robustness Toolbox (ART) Kubeflow: Remote code execution via unsanitized user input
Adversarial Robustness Toolbox (ART) Kubeflow: Remote code execution via unsanitized user input. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-31230] Arbitrary Code Execution via Command-Line Argument Injection
Arbitrary Code Execution via Command-Line Argument Injection. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-31236] llm CLI tool: Arbitrary code execution via code injection in --functions argument
llm CLI tool: Arbitrary code execution via code injection in --functions argument. Red Hat rates this important (CVSS 7.3). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-2614] Arbitrary file read via bypassed source path validation
Arbitrary file read via bypassed source path validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Affected package(s): rhoai/odh-th06-cuda130-torch210-py312-rhel9:1782136276, rhoai/odh-th06-cpu-torch210-py312-rhel9:1782135464, rhoai/odh-training-cuda128-torch29-py312-rhel9:1782132240, rhoai/odh-th06-rocm64-torch291-py312-rhel9:1782135346. Resolved in Red Hat advisory RHSA-2026:34456 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4; Red Hat OpenShift AI (RHOAI).