Red Hat Linux Security Advisories & CVEs
3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-7320] Information disclosure due to incorrect boundary conditions in the Audio/Video component
Information disclosure due to incorrect boundary conditions in the Audio/Video component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:19370 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 8 more.
High [CVE-2026-41636] Node.js skip() recursion
Node.js skip() recursion. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-776. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhacm2/acm-grafana-rhel9:1780677003. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-41606] Denial of Service via uncontrolled recursion
Denial of Service via uncontrolled recursion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 13 more.
High [CVE-2026-41605] Integer Overflow or Wraparound Vulnerability
Integer Overflow or Wraparound Vulnerability. Red Hat rates this important (CVSS 7.7). Weakness: CWE-190. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 13 more.
High [CVE-2026-41604] Out-of-bounds Read vulnerability
Out-of-bounds Read vulnerability. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 13 more.
High [CVE-2026-41603] Security Bypass via Improper Certificate Hostname Validation
Security Bypass via Improper Certificate Hostname Validation. Red Hat rates this important (CVSS 8.2). Weakness: CWE-295. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 7 more.
High [CVE-2026-41602] Integer Overflow in TFramedTransport Go implementation
Integer Overflow in TFramedTransport Go implementation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779925273, rhosdt/opentelemetry-collector-rhel9:1778056267, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 13 more.
High [CVE-2025-48431] Apache Thrift c_glib: Denial of Service via specially crafted requests
Apache Thrift c_glib: Denial of Service via specially crafted requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-763. Affected package(s): cryostat/cryostat-storage-rhel9:4.2.0, rhosdt/tempo-rhel9:1781589494, rhacm2/acm-grafana-rhel9:1780926805, rhacm2/acm-grafana-rhel9:1780677003. Resolved in Red Hat advisory RHSA-2026:24539 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.10.1; and 5 more.
High [CVE-2026-7353] Heap buffer overflow in Skia
Heap buffer overflow in Skia. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-7348] Use after free in Codecs
Use after free in Codecs. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-7360] Insufficient validation of untrusted input in Compositing
Insufficient validation of untrusted input in Compositing. Red Hat rates this important (CVSS 8.7). Weakness: CWE-1173. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-7346] Inappropriate implementation in Tint
Inappropriate implementation in Tint. Red Hat rates this important (CVSS 8.8). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-7345] Insufficient validation of untrusted input in Feedback
Insufficient validation of untrusted input in Feedback. Red Hat rates this important (CVSS 8). Weakness: CWE-1286. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-40975] Weak pseudo-random number generation can lead to information disclosure.
Weak pseudo-random number generation can lead to information disclosure.. Red Hat rates this important (CVSS 8.2). Weakness: CWE-338. Affected package(s): devspaces/openvsx-rhel9:1779528224, spring-boot, devspaces/pluginregistry-rhel9:1779359423. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.28; Red Hat AMQ Clients; Red Hat build of OptaPlanner 8; Red Hat Fuse 7.
High [CVE-2026-40973] Arbitrary Code Execution and Session Hijacking via predictable temporary directory
Arbitrary Code Execution and Session Hijacking via predictable temporary directory. Red Hat rates this moderate (CVSS 7). Weakness: CWE-341. Affected package(s): devspaces/openvsx-rhel9:1779528224, spring-boot, devspaces/pluginregistry-rhel9:1779359423. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-40972] Remote code execution via timing attack in DevTools remote secret comparison
Remote code execution via timing attack in DevTools remote secret comparison. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-208. Affected package(s): devspaces/openvsx-rhel9:1779528224, spring-boot, devspaces/pluginregistry-rhel9:1779359423. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-27172] Apache Camel camel-consul: Arbitrary code execution via deserialization of untrusted data
Apache Camel camel-consul: Arbitrary code execution via deserialization of untrusted data. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-33453] Apache Camel camel-coap: Remote code execution via CoAP URI query parameter injection
Apache Camel camel-coap: Remote code execution via CoAP URI query parameter injection. Red Hat rates this important (CVSS 8.1). Weakness: CWE-915. Affected package(s): camel-coap. Resolved in Red Hat advisory RHSA-2026:17668 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-40022] Information disclosure and authentication bypass in embedded HTTP/management servers
Information disclosure and authentication bypass in embedded HTTP/management servers. Red Hat rates this important (CVSS 8.2). Weakness: CWE-551. Affected package(s): camel-http-starter, camel-http-common, camel-http-base, camel-http. Resolved in Red Hat advisory RHSA-2026:17668 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14.
High [CVE-2026-40858] Apache Camel camel-infinispan: Arbitrary code execution via deserialization of untrusted data
Apache Camel camel-infinispan: Arbitrary code execution via deserialization of untrusted data. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Affected package(s): camel-infinispan, camel-infinispan-common, camel-infinispan-embedded. Resolved in Red Hat advisory RHSA-2026:22453 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14; Red Hat build of Apache Camel 4 for Quarkus 3.