Red Hat Linux Security Advisories & CVEs
4712 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-69243] HTTP Request Smuggling via WebSocket Upgrade
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If using the server-side component, an attacker may be able to execute a request smuggling vulnerability using an edge case in the WebSocket upgrade procedure. A WebSocket upgrade request with a body could cause the parser to switch protocols before the complete request body was received, leaving trailing bytes to be handled as upgraded-protocol or pipelined data rather than normal HTTP body data. This issue is fixed in version 3.14.2. This leaves trailing data to be processed incorrectly, potentially enabling an attacker to bypass security mechanisms or gain unauthorized access to resources. Moderate impact. This vulnerability in aiohttp's HTTP parser enables request smuggling when the server-side component handles WebSocket upgrade requests containing a body. An attacker could exploit an edge case during protocol switching, causing trailing data to be processed as subsequent requests or upgraded protocol data. This affects Red Hat products utilizing aiohttp in a server-side capacity. Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L). Weakness: CWE-444.
High [CVE-2026-69192] Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass
Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass. Red Hat rates this important (CVSS 8.6). Weakness: CWE-1389. Red Hat lists fixing advisory RHSA-2026:56338 with package nodejs24-1:24.18.0-5.el10_2, grafana13-1-main-13.1.1-0.5.2.hum1, ansible-automation-platform/automation-portal:1787047114, grafana13-1-main-13.1.2-0.1.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-69185] Denial of Service via memory exhaustion from crafted packets
Denial of Service via memory exhaustion from crafted packets. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.
High [CVE-2026-14257 +1] DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9. This issue is due to an incomplete mitigation of CVE-2026-14257. Any applications that pass user-controlled input to the `expand()` function are vulnerable to this issue. This flaw can result in an excessive consumption of memory that eventually terminates the process or blocks the event loop, both causing a denial of service. As this vulnerability allows a remote attacker to cause a denial of service, it has been rated with an important severity. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Enterprise Linux 10.0 Extended Update Support; and 44 more.
High [CVE-2026-69151] @angular/compiler: @angular/core: Angular: Cross-Site Scripting via internationalization event handlers
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and other i18n-on event-handler attributes, allowing a lower-trust translation file to replace a static handler with executable JavaScript. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.1. A remote attacker could exploit this by injecting malicious scripts, leading to Cross-Site Scripting (XSS). This could result in unauthorized access to sensitive information or actions performed on behalf of the user. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N). Weakness: CWE-79. Affected Red Hat products: Red Hat Ceph Storage 4; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat lists Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat build of Apicurio Registry 3; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: ceph; Red Hat package: intel-cmt-cat.
High [CVE-2026-68945] @angular/common: Angular: Cross-Request Response Reuse and State Poisoning in HttpTransferCache
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters, allowing semantically distinct HttpClient requests to use the same transfer-cache key and reuse a wrong backend response. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.2. A flaw was found in Angular's HttpTransferCache component. This component, used for caching HTTP requests during server-side rendering, incorrectly generates cache keys when repeated request parameters are present, causing semantically different requests to share the same cache key. This cache-key ambiguity can lead to cross-request response reuse and state poisoning, where a security-sensitive request might receive an incorrect or attacker-influenced cached response. This could result in an application displaying wrong information or operating with corrupted data, potentially leading to information disclosure. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N). Weakness: CWE-694. Affected Red Hat products: Red Hat build of Apicurio Registry 3; Red Hat Ceph Storage 4; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7.
High [CVE-2026-12852] Bouncy Castle for Java: Denial of Service via MLS wire decoder
In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check. A remote attacker could exploit this by providing a specially crafted message to the MLS wire decoder. This can lead to excessive memory allocation, resulting in a Denial of Service (DoS) for the application. This vulnerability targets the Messaging Layer Security (MLS) module, which in Bouncy Castle is packaged as bcmls. No Red Hat products are affected. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1284. Red Hat lists Cryostat 4; OpenShift Developer Tools and Services; Red Hat AMQ Broker 7; Red Hat AMQ Clients; Red Hat Ansible Automation Platform 2; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apicurio Registry 3; Red Hat Build of Keycloak; Red Hat build of Quarkus; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat Satellite 6; Red Hat Single Sign-On 7 as not affected.
High [CVE-2026-58062] Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series). A remote attacker could exploit this by presenting a stapled Online Certificate Status Protocol (OCSP) response that is not properly bound to the certificate being checked. This vulnerability allows for a certificate validation bypass, potentially leading to applications accepting invalid or revoked certificates. This could enable man-in-the-middle attacks or unauthorized access. Important: This vulnerability in Bouncy Castle for Java allows a remote attacker to bypass certificate validation. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-295. Affected Red Hat products: Red Hat Ceph Storage 9; Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7. Red Hat lists Red Hat AMQ Clients; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected. Will not fix / out of support: Red Hat JBoss Enterprise Application Platform 7. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-59650] Bouncy Castle for Java: Cryptographic key compromise due to unvalidated Diffie-Hellman peer value
In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. The software fails to validate Diffie-Hellman peer values during key agreement. A remote attacker can exploit this flaw to compromise cryptographic keys, potentially leading to the decryption of sensitive communications or successful impersonation. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-325. Red Hat lists Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7 as not affected.
High [CVE-2026-8763] Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series). A flaw was found in Bouncy Castle for Java, a cryptographic library. An attacker can exploit this vulnerability by manipulating rfc822Name and URI fields within X.509 certificates using a trailing dot. This bypasses Name Constraints, potentially leading to spoofing or unauthorized access. Such an exploit impacts the integrity and confidentiality of communications. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-295. Affected Red Hat products: Red Hat Ceph Storage 9; Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7. Red Hat lists Red Hat AMQ Clients; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected. Will not fix / out of support: Red Hat JBoss Enterprise Application Platform 7. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-68580] Remote code execution or denial of service via audio input integer overflow
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms. A flaw was found in FreeRDP, an open-source implementation of the Remote Desktop Protocol (RDP). This can lead to a heap-based buffer overflow, potentially enabling arbitrary code execution on systems using the ALSA backend, or a denial of service across all supported platforms. The vulnerability arises from an integer overflow in the audio input redirection channel (audin) when connecting to a malicious RDP server, which can cause a heap-based buffer overflow, particularly affecting Linux systems using the ALSA backend. Exploitation requires user interaction to connect to a compromised server. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190.
High [CVE-2026-67323] Arbitrary code execution via command injection due to unguarded Git options
GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leading-dash revision arguments, so a revision like --output= can cause Git to open and truncate an arbitrary file. Exploitation requires an application that passes attacker-controlled arguments to these methods. This vulnerability allows an attacker to inject arbitrary commands when using functions like Repo.archive() and git.ls_remote(), potentially leading to arbitrary code execution. This is an Important vulnerability because it allows for arbitrary code execution or file truncation. This could lead to a compromise of confidentiality, integrity, and availability on affected Red Hat products that utilize GitPython in such a manner. Red Hat severity: Important — CVSS 8.4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-88. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7; and 11 more.
High [CVE-2026-67326] Remote Code Execution via Newline Injection in config_writer
GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into.git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-controlled directories, achieving remote code execution when git hooks are triggered. A flaw was found in GitPython. Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-93. Affected Red Hat products: Red Hat Hardened Images. Red Hat fixing advisory: RHSA-2026:44416, RHSA-2026:45785, RHSA-2026:45940.
High [CVE-2026-67312] Denial of Service via uncontrolled recursion in form data processing
axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData with Content-Type: application/json). When an application passes attacker-controlled FormData field names, a field name with thousands of nested bracket-delimited segments causes unbounded recursion in buildPath(), exhausting the JavaScript call stack (RangeError: Maximum call stack size exceeded) and causing denial of service for that request, or process termination in applications without appropriate error handling. A flaw was found in axios, a popular JavaScript library. An attacker can exploit this vulnerability by providing malicious form data containing deeply nested field names. This input triggers uncontrolled recursion within the formDataToJSON function, which is responsible for processing form data. This vulnerability affects applications that pass attacker-controlled FormData field names to axios' FormData-to-JSON conversion. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-674. Affected products named by the advisory: Red Hat Developer Hub 1.10; Red Hat Developer Hub 1.9; Red Hat Hardened Images; Red Hat OpenShift Dev Spaces 3.30; and 4 more.
High [CVE-2026-67321] Denial of Service via object serialization bypass
axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path. A flaw was found in axios. A remote attacker could exploit an incomplete depth-limit bypass when the component serializes objects with specific top-level keys. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.11; and 20 more.
High [CVE-2026-67324] Arbitrary Code Execution via Joined Short Options Bypass
GitPython 3.1.50 fails to recognize joined short-option forms such as -u (the short form of --upload-pack=) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi_options=..., allow_unsafe_options=False), an attacker can supply -u to bypass the gate that blocks --upload-pack/-u, causing Git to execute the specified helper command during clone. Fixed in 3.1.51. A flaw was found in GitPython. This allows the attacker to bypass security checks and execute arbitrary commands during a Git clone operation. This can lead to a complete compromise of the affected system. This vulnerability is rated as Important because exploitation requires an application to invoke `Repo.clone_from()` with attacker-controlled `multi_options` while `allow_unsafe_options=False` is set. This precondition means an attacker must already have some influence over a Git-related workflow within the consuming application, rather than exploiting it through mere network access. This affects GitPython version 3.1.50. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-78.
High [CVE-2026-67298] Denial of Service via integer underflow in RAIL channel handling
Denial of Service via integer underflow in RAIL channel handling. Red Hat rates this important (CVSS 7.1). Weakness: CWE-191.
High [CVE-2026-67320] Information disclosure via Prototype Pollution in Node HTTP adapter
axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but request interceptors run after the merge; a common immutable interceptor pattern such as {...config} or Object.assign({}, config) converts the hardened config back into a regular object. axios then dispatches that object without re-hardening it, and the Node HTTP adapter reads config.proxy through the prototype chain. For plaintext HTTP requests, the proxy can observe Authorization headers, Basic auth from config.auth, method, absolute URL, Host, and request body, and can return its own response. This does not establish browser impact or HTTPS header/body disclosure under normal TLS validation. Affected versions are >=0.31.1 (fixed in 0.33.0) and >=1.15.2 (fixed in 1.18.0). This vulnerability, known as Prototype Pollution, occurs because request interceptors can revert hardened request configurations, allowing an attacker to manipulate the Object.prototype.proxy property. If successfully exploited, an attacker can route affected plaintext HTTP requests through a malicious proxy, potentially observing sensitive data such as authentication headers and request bodies, and even returning their own responses.
High [CVE-2026-67322] Environment variable exfiltration via attacker-controlled clone URL
GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking git clone. An attacker who controls the clone URL can embed $NAME or ${NAME} tokens that are expanded to the values of the hosting process's environment variables (e.g., AWS_SECRET_ACCESS_KEY or GITHUB_TOKEN). The resulting URL, now containing the secret, is transmitted over the network to an attacker-controlled host during the clone attempt, disclosing the secret. A flaw was found in GitPython. A remote attacker can exploit a vulnerability in the Repo.clone_from() method by providing a specially crafted Git repository URL. This allows the attacker to exfiltrate sensitive environment variables, such as access keys or tokens, to an attacker-controlled server during the cloning process, leading to information disclosure. This Important vulnerability in GitPython allows for sensitive environment variable exfiltration. This poses a risk of information disclosure, particularly for credentials or tokens, in Red Hat products that process untrusted clone URLs. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-214.
High [CVE-2026-67325] Command Injection via Git option prefix abbreviation
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git resolves to dangerous options and executes arbitrary commands. A flaw was found in GitPython. This allows for the execution of arbitrary commands, leading to potential arbitrary code execution. This vulnerability is rated as Important as it allows for arbitrary command execution. It arises from an incomplete command injection blocklist in GitPython, which can be bypassed by supplying abbreviated Git options. This could lead to a complete compromise of confidentiality, integrity, and availability in Red Hat products that process untrusted input as keyword arguments to GitPython's Git commands. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-78. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7; and 10 more.