Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.5Vendor: HighRed Hat

Medium [CVE-2026-56000] GLX contextTags Use-After-Free in CommonMakeCurrent

GLX contextTags Use-After-Free in CommonMakeCurrent(). Red Hat rates this important (CVSS 6.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:38490 with package xorg-x11-server-Xwayland-0:24.1.9-4.el9_8.3, xorg-x11-server-Xwayland-0:24.1.9-4.el10_2.3. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-56000
Unclassified
Jul 8, 2026
Medium6.3Red Hat

Medium [CVE-2026-15044] Unauthenticated access to AI guardrails and orchestrator APIs

Unauthenticated access to AI guardrails and orchestrator APIs. Red Hat rates this moderate (CVSS 6.3).

CVE-2026-15044
Unclassified
Jul 8, 2026
Medium6.3Red Hat

Medium [CVE-2026-15063] Gorch port bypass when auth IS enabled

Gorch port bypass when auth IS enabled. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-306.

CVE-2026-15063
Unclassified
Jul 8, 2026
Medium5.0Red Hat

Medium [CVE-2026-14740] DBI for Perl: Out-of-bounds read in SQL comment processing

DBI for Perl: Out-of-bounds read in SQL comment processing. Red Hat rates this moderate (CVSS 5). Weakness: CWE-125.

CVE-2026-14740
Unclassified
Jul 7, 2026
Medium5.9Red Hat

Medium [CVE-2026-58472] Arbitrary code execution or denial of service via crafted HTML attribute

Arbitrary code execution or denial of service via crafted HTML attribute. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-131.

CVE-2026-58472
Unclassified
Jul 7, 2026
Medium5.9Red Hat

Medium [CVE-2026-58471] Heap buffer overflow via server-supplied filename leads to memory corruption

Heap buffer overflow via server-supplied filename leads to memory corruption. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-122.

CVE-2026-58471
Unclassified
Jul 7, 2026
Medium5.3Red Hat

Medium [CVE-2026-58470] Integer overflow in Content-Range header parsing causes download desynchronization

Integer overflow in Content-Range header parsing causes download desynchronization. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-190.

CVE-2026-58470
Unclassified
Jul 7, 2026
Medium6.5Red Hat

Medium [CVE-2026-58469] Memory corruption via crafted Metalink URL

Memory corruption via crafted Metalink URL. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125.

CVE-2026-58469
Unclassified
Jul 7, 2026
Medium4.4Red Hat

Medium [CVE-2026-14969] Static initialization vector in AES-CBC/3DES-CBC attribute encryption

Static initialization vector in AES-CBC/3DES-CBC attribute encryption. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-329.

CVE-2026-14969
Unclassified
Jul 7, 2026
Medium4.8Vendor: LowRed Hat

Medium [CVE-2026-53877] Information disclosure via heap buffer over-read in GDALRaster

Information disclosure via heap buffer over-read in GDALRaster. Red Hat rates this low (CVSS 4.8). Weakness: CWE-126.

CVE-2026-53877
Unclassified
Jul 7, 2026
Medium5.3Red Hat

Medium [CVE-2026-14940] heap-buffer-overflow in DN normalization via quoted multivalued RDN

heap-buffer-overflow in DN normalization via quoted multivalued RDN. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-122.

CVE-2026-14940
Unclassified
Jul 7, 2026
Medium6.5Red Hat

Medium [CVE-2025-12799] Jastow Cross-Site Scripting attack due to unsanitized URI

Jastow Cross-Site Scripting attack due to unsanitized URI. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:36343 with package eap8-elytron-web-0:4.1.2-1.Final_redhat_00001.1.el10eap, eap8-jboss-ejb-client-0:5.0.8-1.Final_redhat_00001.1.el10eap, eap8-jandex-0:3.2.7-1.redhat_00001.1.el10eap, eap8-javaee-security-soteria-0:3.0.3-2.redhat_00001.1.el10eap. Affected product named by the advisory: Red Hat Enterprise Linux 1.

CVE-2025-12799
Unclassified
Jul 7, 2026
Medium6.1Red Hat

Medium [CVE-2026-59710] Stored Cross-Site Scripting via unescaped table header ID attributes in markdown

Stored Cross-Site Scripting via unescaped table header ID attributes in markdown. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-79.

CVE-2026-59710
Unclassified
Jul 6, 2026
Medium6.1Red Hat

Medium [CVE-2026-59711] Cross-site scripting via unescaped metadata title allows arbitrary code execution

Cross-site scripting via unescaped metadata title allows arbitrary code execution. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-79.

CVE-2026-59711
Unclassified
Jul 6, 2026
Medium5.8Red Hat

Medium [CVE-2026-54764] Authorization bypass in ForwardAuth middleware via forged X-Forwarded-Port

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middleware, even when configured with trustForwardHeader: false, derives the X-Forwarded-Port header sent to the authentication service from the original incoming request instead of the sanitized forwarded request. As a result, an unauthenticated remote attacker can inject an X-Forwarded-Proto: https header over a plain HTTP connection and cause Traefik to forward X-Forwarded-Port: 443 to the authentication service, bypassing port-based authorization checks. This issue is fixed in versions v2.11.51, v3.6.22, and v3.7.6. This bypasses port-based authorization checks, potentially granting unauthorized access. Moderate: A flaw in Traefik's ForwardAuth middleware, as used in Red Hat OpenShift Dev Spaces, allows an unauthenticated remote attacker to bypass port-based authorization. Red Hat severity: Moderate — CVSS 5.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N). Weakness: CWE-348. Affected Red Hat products: Red Hat OpenShift Dev Spaces. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-54764
Unclassified
Jul 6, 2026
Medium6.5Red Hat

Medium [CVE-2026-55514] Denial of Service via crafted prompt in /v1/completions request

Denial of Service via crafted prompt in /v1/completions request. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-617.

CVE-2026-55514
Unclassified
Jul 6, 2026
Medium6.5Red Hat

Medium [CVE-2026-55646] Denial of Service due to excessive memory allocation via oversized audio file uploads

Denial of Service due to excessive memory allocation via oversized audio file uploads. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770.

CVE-2026-55646
Unclassified
Jul 6, 2026
Medium5.5Red Hat

Medium [CVE-2026-59089] Gimp: gimp: denial of service via integer overflow in playstation tim loader

A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calculates the size of the Color Look-Up Table (CLUT) due to an integer overflow. This occurs when multiplying num_colors and num_cluts, both 16-bit unsigned short integers, resulting in a value exceeding the maximum integer limit. An attacker could exploit this by providing a specially crafted image file, leading to undefined behavior and causing the GIMP plug-in to abort, effectively resulting in a denial of service. Conditions for Exploitation: Successful exploitation requires user interaction. An attacker must trick a user into manually opening a specially crafted, malicious PlayStation TIM image file within the GIMP application. Impact Limitations: The vulnerability is strictly limited to a localized Denial of Service (DoS) where the specific file loader plug-in aborts. It does not allow for remote code execution, data exfiltration, or privilege escalation, and it does not compromise the broader system or network security. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.

CVE-2026-59089
Red Hat Enterprise Linux
Jul 6, 2026
Medium5.9Red Hat

Medium [CVE-2026-54291] Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade

pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12. A remote attacker who can intercept a TLS (Transport Layer Security) connection can silently downgrade connections configured to require channel binding from SCRAM-SHA-256-PLUS to plain SCRAM-SHA-256. This downgrade bypasses the intended man-in-the-middle protection, allowing the attacker to potentially intercept or alter sensitive communication. The vulnerability occurs because the system fails to properly validate the channel binding when a specific type of certificate is used. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-940.

CVE-2026-54291
Unclassified
Jul 6, 2026
Medium4.5Red Hat

Medium [CVE-2026-55798] Arbitrary command injection via shell metacharacters in file paths

Arbitrary command injection via shell metacharacters in file paths. Red Hat rates this moderate (CVSS 4.5). Weakness: CWE-78.

CVE-2026-55798
Unclassified
Jul 6, 2026

← All vendors