Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

465 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Low3.7Red Hat

Low [CVE-2026-57817] Authorization Code Substitution via missing c_hash validation

The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue. Such an attack could lead to unauthorized access or session hijacking. This vulnerability has a Low impact on Red Hat products. Exploitation requires a specific misconfiguration of the external IdP. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N). Weakness: CWE-303. Affected Red Hat products: Red Hat build of Apache Camel for Spring Boot 4; Red Hat JBoss Web Server 5. Will not fix / out of support: Red Hat JBoss Web Server 5. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-57817
Unclassified
Aug 6, 2026
Low2.2Red Hat

Low [CVE-2026-18839] size_t underflow in singleOptionHelp

size_t underflow in singleOptionHelp. Red Hat rates this low (CVSS 2.2). Weakness: CWE-191. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.

CVE-2026-18839
Unclassified
Aug 5, 2026
Low3.8Red Hat

Low [CVE-2026-70430] Privilege escalation via unrestricted object instantiation in project naming strategy configuration

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators. A flaw was found in Jenkins. This includes types typically reserved for administrators, potentially leading to unauthorized configuration changes or other administrative actions within the Jenkins environment. Red Hat ships Jenkins as part of OpenShift Developer Tools and Services (ocp-tools). This weakens the separation between the Overall/Manage and Overall/Administer permissions. Exploitation requires an authenticated user who already holds the Overall/Manage permission, which is not granted by default and is typically reserved for trusted operators, limiting the practical impact. Fixed upstream in Jenkins 2.576 (weekly) and LTS 2.568.2. Red Hat severity: Low — CVSS 3.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-502. Will not fix / out of support: OpenShift Developer Tools and Services. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-70430
Unclassified
Aug 5, 2026
Low2.5Red Hat

Low [CVE-2026-18739] Off-by-one in poptStuffArgs

A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data. Exploitation is only possible if the host application then unsafely processes the corrupted `poptContext` data, such as sinking it into `exec`, `system`, `popen`, or `dlopen`. Red Hat severity: Low — CVSS 2.5 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-787. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:56984. Affected products named by the advisory: Red Hat package: popt.

CVE-2026-18739
Red Hat Enterprise Linux
Aug 3, 2026
Low3.3Red Hat

Low [CVE-2026-68744] NSS responder uninitialized heap disclosure in initgroups reply

A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process. This issue can only be triggered by a local attacker who can connect to the SSSD NSS responder unix socket. Credentials, hashes, and tickets reside in separate sssd_pam and sssd_be processes and are not exposed by this flaw. Much of the directory data may already be obtainable via legitimate NSS queries depending on the deployment. The primary security concern is disclosure of heap pointers that could assist ASLR bypass if chained with a separate memory-corruption vulnerability. Red Hat severity: Low — CVSS 3.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-908. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 6 as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: sssd.

CVE-2026-68744
Red Hat Enterprise Linux
Aug 3, 2026
Low2.1Red Hat

Low [CVE-2026-66401] Denial of Service via out-of-bounds read in UVC H.264 parser

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera can trigger a heap read beyond allocated bounds during camera stream setup, causing denial of service. A flaw was found in FreeRDP. This can lead to a denial of service (DoS), making the application unavailable. Red Hat severity: Low — CVSS 2.1 (CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-66401
Red Hat Enterprise Linux
Aug 1, 2026
Low3.7Red Hat

Low [CVE-2026-67316] Prototype Pollution allows unauthorized data transmission and network redirection

axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method aliases (axios.get(), axios.delete(), axios.head(), axios.options()), inherited data is read via (config || {}).data before config normalization, causing an attacker-controlled body to be sent on requests that did not set one. Additional low-level paths, only reachable when calling exported adapters/helpers (e.g. lib/adapters/http.js, unsafe/helpers/resolveConfig.js) directly with plain configs and no own proxy or paramsSerializer, can inherit polluted proxy values (routing requests through an attacker-controlled proxy) or paramsSerializer values (attacker-controlled URL serialization). These low-level gadgets do not reproduce through normal high-level axios calls on 1.15.2+. The issue is fixed in axios 1.18.0 and 0.33.0. A flaw was found in axios, a widely used JavaScript library for making web requests. This vulnerability, known as prototype pollution, allows an attacker to subtly alter how network requests are built if another part of the system has already been compromised. This could lead to an attacker injecting unauthorized data into requests that were not intended to have a body.

CVE-2026-67316
Red Hat Enterprise Linux
Aug 1, 2026
Low3.7Red Hat

Low [CVE-2026-67294] Server certificate validation bypass via improper Extended Key Usage (EKU) validation

FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication. In x509_utils_verify(), when server-purpose (X509_PURPOSE_SSL_SERVER) verification fails, the code falls back to client-purpose and any-purpose verification, so a trusted, hostname-matching certificate valid only for clientAuth can be accepted as the RDP server certificate. In environments relying on EKU separation between client and server certificates, this allows a clientAuth-only certificate issued by a trusted CA to bypass server certificate purpose validation. A flaw was found in FreeRDP. This vulnerability allows a certificate intended only for client authentication to be accepted as a server certificate, bypassing critical server certificate purpose validation. This could lead to an attacker presenting a clientAuth-only certificate from a trusted Certificate Authority (CA) to impersonate a legitimate server. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-295. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-67294
Red Hat Enterprise Linux
Aug 1, 2026
Low3.1Red Hat

Low [CVE-2026-54787] Signature bypass allows acceptance of bundles signed with expired keys

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1. A flaw was found in sigstore-go, a software library used for verifying digital signatures. This vulnerability specifically affects the workflow for self-managed long-lived signing keys that do not use certificates. An attacker who possesses an expired signing key can exploit this by creating and signing software bundles that the system will incorrectly accept as valid. This bypasses the intended security checks, potentially leading to the acceptance of unauthorized or malicious software. Red Hat severity: Low — CVSS 3.1 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N). Weakness: CWE-347. Affected Red Hat products: Red Hat Hardened Images. Red Hat fixing advisory: RHSA-2026:44162, RHSA-2026:44451, RHSA-2026:47889, RHSA-2026:47891.

CVE-2026-54787
Unclassified
Jul 31, 2026
Low3.7Red Hat

Low [CVE-2026-18569] OIDC backchannel logout accepts unsigned forged logout tokens

A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to skip signature validation. In this specific setup, the system incorrectly accepts logout requests that have no cryptographic signature. An attacker who knows certain technical details about a user's session can use this flaw to force that user to be logged out, potentially disrupting their work. The Red Hat Product Security team has assessed the severity of this vulnerability as Low, given that it requires a non-default insecure configuration and knowledge of specific session identifiers to exploit. Successful exploitation allows an attacker to force-logout targeted brokered users, leading to a limited denial of service for those individuals. The vulnerability's root cause is the failure to enforce signature validation on backchannel logout tokens when the identity provider's signature validation setting is disabled. Weakness: CWE-347. Affected Red Hat products: Red Hat Build of Keycloak. Red Hat lists Red Hat Data Grid 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7 as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-18569
Unclassified
Jul 31, 2026
Low3.4Red Hat

Low [CVE-2026-18209] OIDC redirect_uri fragment bypass in HTTP parameter pollution check

A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a redirect URL and ignores the fragment portion. When a client is configured with a wildcard redirect URI, an attacker can use this to inject duplicate security parameters into the login response. If a client application is not configured correctly, it might trust the attacker's injected data instead of the real security information from Keycloak, leading to session fixation or account confusion. The Red Hat Product Security team has assessed the severity of this vulnerability as Low, given that it requires a specific client configuration and a non-conformant relying party to be successful. The vulnerability's root cause is an incomplete validation check in RedirectUtils that fails to inspect the URI fragment for forbidden parameters. Weakness: CWE-1288. Affected Red Hat products: Red Hat Build of Keycloak. Red Hat lists Red Hat Data Grid 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7 as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-18209
Unclassified
Jul 31, 2026
Low3.7Red Hat

Low [CVE-2026-18206] Client policy source-host wildcard domain matching bypass

A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a wildcard domain (like *.example.com) to restrict which hosts can register or update clients. Due to improper validation, the system accepts any hostname that ends with the specified domain suffix, even if it is not a legitimate subdomain. An attacker who can control the reverse DNS of their connection can bypass these host-based restrictions, potentially allowing unauthorized client modifications. The Red Hat Product Security team has assessed the severity of this vulnerability as Low, given that exploitation requires a specific administrative configuration and attacker control over reverse DNS resolution. Successful exploitation allows an attacker to bypass host-based restrictions for client registration and update operations. The vulnerability's root cause is improper validation of wildcard domain matches in the keycloak-services component, which fails to enforce proper subdomain boundaries. Weakness: CWE-20. Affected Red Hat products: Red Hat Build of Keycloak. Red Hat lists Red Hat Data Grid 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7 as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-18206
Unclassified
Jul 31, 2026
Low3.4Vendor: MediumRed Hat

Low [CVE-2026-18217] SAML HTTP-Redirect binding response preserves query string leading to parameter pollution

A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect binding. If a client is configured with a wildcard redirect URL, an attacker can craft a request that includes malicious parameters. When a user authenticates, Keycloak appends its legitimate response to the attacker's parameters. This can cause some service providers to process the attacker's data instead of the real login information, potentially leading to a user being logged into the wrong account. The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that exploitation requires a specific client configuration (wildcard redirect URIs) and a downstream service provider that incorrectly handles duplicate HTTP parameters. Successful exploitation allows an attacker to perform login CSRF or session swapping on the affected service provider. The vulnerability's root cause is the improper handling of the query string in the SAML HTTP-Redirect binding response, which fails to strip or validate pre-existing SAML parameters. Weakness: CWE-20. Affected Red Hat products: Red Hat Build of Keycloak.

CVE-2026-18217
Unclassified
Jul 31, 2026
Low3.3Red Hat

Low [CVE-2026-56847] Permission Model flaw allows trace logs to bypass filesystem write restrictions

Permission Model flaw allows trace logs to bypass filesystem write restrictions. Red Hat rates this low (CVSS 3.3). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.

CVE-2026-56847
Unclassified
Jul 30, 2026
Low2.8Red Hat

Low [CVE-2026-18018] Inappropriate implementation in Updater

Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low) An inappropriate implementation flaw was found in the Updater component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Low — CVSS 2.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N).

CVE-2026-18018
Unclassified
Jul 30, 2026
Low0.0Red Hat

Low [CVE-2026-18014] Insufficient validation of untrusted input in DevTools

Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Weakness: CWE-434.

CVE-2026-18014
Unclassified
Jul 30, 2026
Low0.0Red Hat

Low [CVE-2026-18010] Inappropriate implementation in Passwords

Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low) An inappropriate implementation flaw was found in the Passwords component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Low — CVSS 0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N). Weakness: CWE-1021.

CVE-2026-18010
Unclassified
Jul 30, 2026
Low0.0Red Hat

Low [CVE-2026-18007] Inappropriate implementation in Input

Inappropriate implementation in Input in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) An inappropriate implementation flaw was found in the Input component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Low — CVSS 0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N). Weakness: CWE-79.

CVE-2026-18007
Unclassified
Jul 30, 2026
Low3.2Red Hat

Low [CVE-2026-18004] Insufficient policy enforcement in Speech

Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Weakness: CWE-346.

CVE-2026-18004
Unclassified
Jul 30, 2026
Low3.1Red Hat

Low [CVE-2026-18001] Inappropriate implementation in WebGL

Inappropriate implementation in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low) An inappropriate implementation flaw was found in the WebGL component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Low — CVSS 3.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N). Weakness: CWE-825.

CVE-2026-18001
Unclassified
Jul 30, 2026

← All vendors