Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Red Hat

High [CVE-2026-42440] Denial of Service via unbounded array allocation in crafted model files

Denial of Service via unbounded array allocation in crafted model files. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform Expansion Pack.

CVE-2026-42440
Unclassified
May 4, 2026
High8.1Red Hat

High [CVE-2026-24781] Arbitrary code execution via sandbox breakout through inspect function

Arbitrary code execution via sandbox breakout through inspect function. Red Hat rates this important (CVSS 8.1). Weakness: CWE-653. Affected package(s): rhdh/rhdh-hub-rhel9:1781187342. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.10; Red Hat Developer Hub 1.9.

CVE-2026-24781
Unclassified
May 4, 2026
High7.5Vendor: LowRed Hat

High [CVE-2026-29169] NULL pointer dereference via specially crafted request

NULL pointer dereference via specially crafted request. Red Hat rates this low (CVSS 7.5). Weakness: CWE-476. Affected package(s): jbcs-httpd24-httpd, httpd, httpd-main, mod_dav_lock.so. Resolved in Red Hat advisory RHSA-2026:27200 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-29169
Unclassified
May 4, 2026
High8.8Red Hat

High [CVE-2026-23918] Remote Code Execution via Double Free in HTTP/2 Protocol

Remote Code Execution via Double Free in HTTP/2 Protocol. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1341. Affected package(s): httpd-main. Resolved in Red Hat advisory RHSA-2026:13938 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-23918
Unclassified
May 4, 2026
High8.3Red Hat

High [CVE-2026-6266] Account hijacking and unauthorized access via unverified email linking

Account hijacking and unauthorized access via unverified email linking. Red Hat rates this important (CVSS 8.3). Weakness: CWE-305. Affected package(s): automation-gateway, automation-controller, python3.12-django-ansible-base, ansible-automation-platform. Resolved in Red Hat advisory RHSA-2026:13508 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9.

CVE-2026-6266
Unclassified
May 4, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-33857] off-by-one out-of-bounds reads in AJP getter functions

off-by-one out-of-bounds reads in AJP getter functions. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-125. Affected package(s): httpd, httpd:2.4, jbcs-httpd24-httpd, httpd-main, mod_proxy_ajp.so. Resolved in Red Hat advisory RHSA-2026:27200 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-33857
Unclassified
May 4, 2026
High8.2Vendor: MediumRed Hat

High [CVE-2026-34032] heap-based buffer over-read due to missing null-termination check

heap-based buffer over-read due to missing null-termination check. Red Hat rates this moderate (CVSS 8.2). Weakness: CWE-170. Affected package(s): httpd, httpd:2.4, jbcs-httpd24-httpd, httpd-main, mod_proxy_ajp.so. Resolved in Red Hat advisory RHSA-2026:27200 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-34032
Unclassified
May 4, 2026
High8.2Vendor: MediumRed Hat

High [CVE-2026-34059] heap-based buffer over-read and memory disclosure in ajp_parse_data()

heap-based buffer over-read and memory disclosure in ajp_parse_data(). Red Hat rates this moderate (CVSS 8.2). Weakness: CWE-126. Affected package(s): httpd, httpd:2.4, jbcs-httpd24-httpd, httpd-main, mod_proxy_ajp.so. Resolved in Red Hat advisory RHSA-2026:27200 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-34059
Unclassified
May 4, 2026
High7.5Red Hat

High [CVE-2026-33846] Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly

Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly. Red Hat rates this important (CVSS 7.5). Weakness: CWE-130. Affected package(s): rhui5/installer-rhel9:1781525693, libtasn1, gnutls, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 37 more.

CVE-2026-33846
Unclassified
May 4, 2026
High7.5Red Hat

High [CVE-2026-7737] osrg GoBGP: Denial of service via out-of-bounds read in BMP Parser

osrg GoBGP: Denial of service via out-of-bounds read in BMP Parser. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7737
Unclassified
May 4, 2026
High7.5Red Hat

High [CVE-2026-7736] osrg GoBGP: Integer underflow via manipulation in parseRibEntry function

osrg GoBGP: Integer underflow via manipulation in parseRibEntry function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7736
Unclassified
May 4, 2026
High8.2Red Hat

High [CVE-2026-39852] io.quarkus:quarkus-vertx-http: io.quarkus:quarkus-vertx-http: Authorization bypass via semicolons in HTTP requests

io.quarkus:quarkus-vertx-http: io.quarkus:quarkus-vertx-http: Authorization bypass via semicolons in HTTP requests. Red Hat rates this important (CVSS 8.2). Weakness: CWE-551. Affected package(s): cryostat/jfr-datasource-rhel9:4.2.0, quarkus-vertx-http, cryostat/cryostat-reports-rhel9:4.2.0, cryostat/cryostat-rhel9:4.2.0. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Build of Apache Camel 4.14 for Quarkus 3.27; Red Hat build of Quarkus 3.20.6.SP1; OpenShift Serverless; and 8 more.

CVE-2026-39852
Unclassified
May 4, 2026
High7.5Red Hat

High [CVE-2025-70069] Denial of Service via FBXConverter.cpp and ConvertMeshMultiMaterial() method

Denial of Service via FBXConverter.cpp and ConvertMeshMultiMaterial() method. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2025-70069
Unclassified
May 4, 2026
High7.5Red Hat

High [CVE-2025-70071] Denial of Service via FBXParser.cpp ParseVectorDataArray() function

Denial of Service via FBXParser.cpp ParseVectorDataArray() function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2025-70071
Unclassified
May 4, 2026
High7.5Red Hat

High [CVE-2026-37459] denial of service via crafted BGP UPDATE message

denial of service via crafted BGP UPDATE message. Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. Affected package(s): frr10, frr. Resolved in Red Hat advisory RHSA-2026:24370 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-37459
Unclassified
May 4, 2026
High7.8Red Hat

High [CVE-2026-54228] TOCTOU race condition in abrt-dbus SetElement allows arbitrary file writes to dump directories

TOCTOU race condition in abrt-dbus SetElement allows arbitrary file writes to dump directories. Red Hat rates this important (CVSS 7.8). Weakness: CWE-367. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 3 more.

CVE-2026-54228
Unclassified
May 4, 2026
High7.0Red Hat

High [CVE-2026-54229] ChownProblemDir succeeds during active post-create event processing due to inadequate locking

ChownProblemDir succeeds during active post-create event processing due to inadequate locking. Red Hat rates this important (CVSS 7). Weakness: CWE-362. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 3 more.

CVE-2026-54229
Unclassified
May 4, 2026
High7.0Red Hat

High [CVE-2026-54230] event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites

event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites. Red Hat rates this important (CVSS 7). Weakness: CWE-59. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.

CVE-2026-54230
Unclassified
May 4, 2026
High7.4Red Hat

High [CVE-2026-39805] HTTP Request Smuggling via Duplicate Content-Length Headers

HTTP Request Smuggling via Duplicate Content-Length Headers. Red Hat rates this important (CVSS 7.4). Weakness: CWE-444. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-39805
Unclassified
May 1, 2026
High7.5Red Hat

High [CVE-2026-39804] Denial of Service due to memory exhaustion via WebSocket permessage-deflate compression

Denial of Service due to memory exhaustion via WebSocket permessage-deflate compression. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-39804
Unclassified
May 1, 2026

← All vendors