Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Red Hat

High [CVE-2026-7320] Information disclosure due to incorrect boundary conditions in the Audio/Video component

Information disclosure due to incorrect boundary conditions in the Audio/Video component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:19370 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 8 more.

CVE-2026-7320
Unclassified
Apr 28, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-41636] Node.js skip() recursion

Node.js skip() recursion. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-776. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhacm2/acm-grafana-rhel9:1780677003. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-41636
Unclassified
Apr 28, 2026
High7.5Red Hat

High [CVE-2026-41606] Denial of Service via uncontrolled recursion

Denial of Service via uncontrolled recursion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 13 more.

CVE-2026-41606
Unclassified
Apr 28, 2026
High7.7Red Hat

High [CVE-2026-41605] Integer Overflow or Wraparound Vulnerability

Integer Overflow or Wraparound Vulnerability. Red Hat rates this important (CVSS 7.7). Weakness: CWE-190. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 13 more.

CVE-2026-41605
Unclassified
Apr 28, 2026
High8.2Red Hat

High [CVE-2026-41604] Out-of-bounds Read vulnerability

Out-of-bounds Read vulnerability. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 13 more.

CVE-2026-41604
Unclassified
Apr 28, 2026
High8.2Red Hat

High [CVE-2026-41603] Security Bypass via Improper Certificate Hostname Validation

Security Bypass via Improper Certificate Hostname Validation. Red Hat rates this important (CVSS 8.2). Weakness: CWE-295. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 7 more.

CVE-2026-41603
Unclassified
Apr 28, 2026
High7.5Red Hat

High [CVE-2026-41602] Integer Overflow in TFramedTransport Go implementation

Integer Overflow in TFramedTransport Go implementation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779925273, rhosdt/opentelemetry-collector-rhel9:1778056267, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 13 more.

CVE-2026-41602
Unclassified
Apr 28, 2026
High7.5Red Hat

High [CVE-2025-48431] Apache Thrift c_glib: Denial of Service via specially crafted requests

Apache Thrift c_glib: Denial of Service via specially crafted requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-763. Affected package(s): cryostat/cryostat-storage-rhel9:4.2.0, rhosdt/tempo-rhel9:1781589494, rhacm2/acm-grafana-rhel9:1780926805, rhacm2/acm-grafana-rhel9:1780677003. Resolved in Red Hat advisory RHSA-2026:24539 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.10.1; and 5 more.

CVE-2025-48431
Unclassified
Apr 28, 2026
High8.2Red Hat

High [CVE-2026-7353] Heap buffer overflow in Skia

Heap buffer overflow in Skia. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7353
Unclassified
Apr 28, 2026
High8.8Red Hat

High [CVE-2026-7348] Use after free in Codecs

Use after free in Codecs. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7348
Unclassified
Apr 28, 2026
High8.7Red Hat

High [CVE-2026-7360] Insufficient validation of untrusted input in Compositing

Insufficient validation of untrusted input in Compositing. Red Hat rates this important (CVSS 8.7). Weakness: CWE-1173. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7360
Unclassified
Apr 28, 2026
High8.8Red Hat

High [CVE-2026-7346] Inappropriate implementation in Tint

Inappropriate implementation in Tint. Red Hat rates this important (CVSS 8.8). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7346
Unclassified
Apr 28, 2026
High8.0Red Hat

High [CVE-2026-7345] Insufficient validation of untrusted input in Feedback

Insufficient validation of untrusted input in Feedback. Red Hat rates this important (CVSS 8). Weakness: CWE-1286. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7345
Unclassified
Apr 28, 2026
High8.2Red Hat

High [CVE-2026-40975] Weak pseudo-random number generation can lead to information disclosure.

Weak pseudo-random number generation can lead to information disclosure.. Red Hat rates this important (CVSS 8.2). Weakness: CWE-338. Affected package(s): devspaces/openvsx-rhel9:1779528224, spring-boot, devspaces/pluginregistry-rhel9:1779359423. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.28; Red Hat AMQ Clients; Red Hat build of OptaPlanner 8; Red Hat Fuse 7.

CVE-2026-40975
Unclassified
Apr 27, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-40973] Arbitrary Code Execution and Session Hijacking via predictable temporary directory

Arbitrary Code Execution and Session Hijacking via predictable temporary directory. Red Hat rates this moderate (CVSS 7). Weakness: CWE-341. Affected package(s): devspaces/openvsx-rhel9:1779528224, spring-boot, devspaces/pluginregistry-rhel9:1779359423. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40973
Unclassified
Apr 27, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-40972] Remote code execution via timing attack in DevTools remote secret comparison

Remote code execution via timing attack in DevTools remote secret comparison. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-208. Affected package(s): devspaces/openvsx-rhel9:1779528224, spring-boot, devspaces/pluginregistry-rhel9:1779359423. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40972
Unclassified
Apr 27, 2026
High8.8Red Hat

High [CVE-2026-27172] Apache Camel camel-consul: Arbitrary code execution via deserialization of untrusted data

Apache Camel camel-consul: Arbitrary code execution via deserialization of untrusted data. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27172
Unclassified
Apr 27, 2026
High8.1Red Hat

High [CVE-2026-33453] Apache Camel camel-coap: Remote code execution via CoAP URI query parameter injection

Apache Camel camel-coap: Remote code execution via CoAP URI query parameter injection. Red Hat rates this important (CVSS 8.1). Weakness: CWE-915. Affected package(s): camel-coap. Resolved in Red Hat advisory RHSA-2026:17668 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33453
Unclassified
Apr 27, 2026
High8.2Red Hat

High [CVE-2026-40022] Information disclosure and authentication bypass in embedded HTTP/management servers

Information disclosure and authentication bypass in embedded HTTP/management servers. Red Hat rates this important (CVSS 8.2). Weakness: CWE-551. Affected package(s): camel-http-starter, camel-http-common, camel-http-base, camel-http. Resolved in Red Hat advisory RHSA-2026:17668 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14.

CVE-2026-40022
Unclassified
Apr 27, 2026
High8.8Red Hat

High [CVE-2026-40858] Apache Camel camel-infinispan: Arbitrary code execution via deserialization of untrusted data

Apache Camel camel-infinispan: Arbitrary code execution via deserialization of untrusted data. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Affected package(s): camel-infinispan, camel-infinispan-common, camel-infinispan-embedded. Resolved in Red Hat advisory RHSA-2026:22453 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14; Red Hat build of Apache Camel 4 for Quarkus 3.

CVE-2026-40858
Unclassified
Apr 27, 2026

← All vendors