Red Hat Linux Security Advisories & CVEs
11617 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-91991] Cookie attribute injection via capitalized keyword arguments
Cookie attribute injection via capitalized keyword arguments. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-915. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 2 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-91986] Information disclosure and virtual host spoofing via control character injection
Information disclosure and virtual host spoofing via control character injection. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-93. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; and 2 more. Affected products named by the advisory: Red Hat package: igvm; Red Hat package: rust.
Medium [CVE-2026-91962] Remote out-of-bounds access via integer overflow in audin Apple backends
Remote out-of-bounds access via integer overflow in audin Apple backends. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.
Medium [CVE-2026-91961] Denial of Service via URBDRC control-transfer request with invalid OutputBufferSize
Denial of Service via URBDRC control-transfer request with invalid OutputBufferSize. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.
Medium [CVE-2026-91960] Denial of Service via integer overflow and double free in WinPR
Denial of Service via integer overflow and double free in WinPR. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.
Medium [CVE-2026-91959] Denial of Service due to buffer over-read in RPC gateway
Denial of Service due to buffer over-read in RPC gateway. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.
Medium [CVE-2026-91958] Denial of service and potential code execution via malicious RDP file
Denial of service and potential code execution via malicious RDP file. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.
Medium [CVE-2026-91956] Denial of Service via out-of-bounds read in URBDRC channel
Denial of Service via out-of-bounds read in URBDRC channel. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.
Medium [CVE-2026-91954] Denial of Service via crafted Surface Bits command
Denial of Service via crafted Surface Bits command. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.
Medium [CVE-2026-91952] Denial of Service via crafted AVC444 graphics updates
Denial of Service via crafted AVC444 graphics updates. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-606. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.
Medium [CVE-2026-91953] Heap buffer overflow via oversized LB_LOAD_BALANCE_INFO routing token can lead to heap corruption.
Heap buffer overflow via oversized LB_LOAD_BALANCE_INFO routing token can lead to heap corruption. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.
Medium [CVE-2026-91951] Denial of Service via out-of-bounds write in urbdrc client channel
Denial of Service via out-of-bounds write in urbdrc client channel. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.
Medium [CVE-2026-91946] Information Disclosure via RDPGFX ResetGraphics PDU
Information Disclosure via RDPGFX ResetGraphics PDU. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-824. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.
Medium [CVE-2026-91945] Denial of Service due to out-of-bounds read in smartcard response processing
Denial of Service due to out-of-bounds read in smartcard response processing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.
Medium [CVE-2024-58384] CRLF injection in CurlAsyncHTTPClient allows arbitrary header injection or new HTTP requests.
CRLF injection in CurlAsyncHTTPClient allows arbitrary header injection or new HTTP requests. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-93. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 11 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 7 more.
Medium [CVE-2026-55701] github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver: OpenTelemetry Collector Contrib githubreceiver: Unauthorized data injection via authentication bypass
github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver: OpenTelemetry Collector Contrib githubreceiver: Unauthorized data injection via authentication bypass. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:63152 with package opentelemetry-collector-contrib-main-0.160.0-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-54168] github.com/openshift-pipelines/pipelines-as-code: Pipelines-as-Code: Information disclosure via unscoped GitHub App installation token
github.com/openshift-pipelines/pipelines-as-code: Pipelines-as-Code: Information disclosure via unscoped GitHub App installation token. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-862.
Medium [CVE-2026-90439] NGINX ngx_http_v3_module: Denial of Service via TLS handshake heap buffer overflow
NGINX ngx_http_v3_module: Denial of Service via TLS handshake heap buffer overflow. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:67977 with package nginx-main-1.30.5-4.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-92059] Incorrect boundary conditions in the DOM: Editor component
Incorrect boundary conditions in the DOM: Editor component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-787.
Medium [CVE-2026-92058] Use-after-free in the Graphics component
Use-after-free in the Graphics component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825.