Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11617 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.1Red Hat

Medium [CVE-2026-91786] out-of-bounds read in remote search icon rendering due to unvalidated icon-data buffer size

out-of-bounds read in remote search icon rendering due to unvalidated icon-data buffer size. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gnome-shell.

CVE-2026-91786
Red Hat Enterprise Linux
Sep 15, 2026
Medium4.8Red Hat

Medium [CVE-2026-86818] Mailto header injection via percent-encoded field-name desynchronization

Mailto header injection via percent-encoded field-name desynchronization. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-838. Affected product named by the advisory: Red Hat Satellite 6.

CVE-2026-86818
Unclassified
Sep 15, 2026
Medium4.8Red Hat

Medium [CVE-2026-86472] Security bypass due to inconsistent host case normalization

Security bypass due to inconsistent host case normalization. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-178. Red Hat lists fixing advisory RHSA-2026:71040 with package grafana12-4-main-12.4.10-0.4.hum1, grafana13-2-main-13.2.1-0.7.hum1, grafana13-1-main-13.1.6-0.3.hum1. Affected products named by the advisory: Red Hat Hardened Images; Cost Management On Premise; Migration Toolkit for Applications 8; Migration Toolkit for Containers; and 32 more. Affected products named by the advisory: Multicluster Engine for Kubernetes; Network Observability Operator; OpenShift Lightspeed; OpenShift Pipelines; and 28 more.

CVE-2026-86472
Red Hat Enterprise Linux
Sep 15, 2026
Medium5.9Red Hat

Medium [CVE-2026-17495] Path Traversal via crafted non-string input to locale function

Path Traversal via crafted non-string input to locale function. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-22. Affected products named by the advisory: Multicluster Engine for Kubernetes; OpenShift Pipelines; OpenShift Service Mesh 3; Red Hat 3scale API Management Platform 2; and 31 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; Red Hat build of Apache Camel for Spring Boot 4; and 27 more.

CVE-2026-17495
Red Hat Enterprise Linux
Sep 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-81320] TLS private key written to operator log at debug level

TLS private key written to operator log at debug level. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-532. Affected product named by the advisory: Red Hat build of Apache Camel - HawtIO 4.

CVE-2026-81320
Unclassified
Sep 15, 2026
Medium6.3Red Hat

Medium [CVE-2026-81303] routes/custom-host confused-deputy via spec.routeHostName

routes/custom-host confused-deputy via spec.routeHostName. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-441. Affected product named by the advisory: Red Hat build of Apache Camel - HawtIO 4.

CVE-2026-81303
Unclassified
Sep 15, 2026
Medium4.3Red Hat

Medium [CVE-2026-90878] Denial of Service via Jinja Template Rendering

Denial of Service via Jinja Template Rendering. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-606. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-90878
Unclassified
Sep 15, 2026
Low3.9Red Hat

Low [CVE-2026-91739] Missing authorization in Transactions Platform

Missing authorization in Transactions Platform. Red Hat rates this low (CVSS 3.9). Weakness: CWE-1021.

CVE-2026-91739
Unclassified
Sep 15, 2026
Low3.4Red Hat

Low [CVE-2026-92240] Out-of-bounds read in IMAP response parser

Out-of-bounds read in IMAP response parser. Red Hat rates this low (CVSS 3.4). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, thunderbird-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92240
Unclassified
Sep 15, 2026
Low3.1Red Hat

Low [CVE-2026-91957] Use-after-free vulnerability in smartcard RDPDR device handler leading to denial of service or potential code execution

Use-after-free vulnerability in smartcard RDPDR device handler leading to denial of service or potential code execution. Red Hat rates this low (CVSS 3.1). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-91957
Red Hat Enterprise Linux
Sep 15, 2026
Low3.4Red Hat

Low [CVE-2026-92079] Mitigation bypass in the Widget: Win32 component

Mitigation bypass in the Widget: Win32 component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-807.

CVE-2026-92079
Unclassified
Sep 15, 2026
Low3.4Red Hat

Low [CVE-2026-92078] Denial-of-service in the Security component

Denial-of-service in the Security component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-770.

CVE-2026-92078
Unclassified
Sep 15, 2026
Low3.4Red Hat

Low [CVE-2026-92077] Denial-of-service in the SVG component

Denial-of-service in the SVG component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-770.

CVE-2026-92077
Unclassified
Sep 15, 2026
Low3.4Red Hat

Low [CVE-2026-92076] Incorrect boundary conditions in the Networking component

Incorrect boundary conditions in the Networking component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-120.

CVE-2026-92076
Unclassified
Sep 15, 2026
Low3.4Red Hat

Low [CVE-2026-92075] Mitigation bypass in the Networking component

Mitigation bypass in the Networking component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-305.

CVE-2026-92075
Unclassified
Sep 15, 2026
Low3.4Red Hat

Low [CVE-2026-92074] Mitigation bypass in the Popup Blocker component

Mitigation bypass in the Popup Blocker component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-807.

CVE-2026-92074
Unclassified
Sep 15, 2026
Low3.4Red Hat

Low [CVE-2026-92073] Privilege escalation in the Enterprise Policies component

Privilege escalation in the Enterprise Policies component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-266.

CVE-2026-92073
Unclassified
Sep 15, 2026
Low3.4Red Hat

Low [CVE-2026-92072] Incorrect boundary conditions in the Safe Browsing component

Incorrect boundary conditions in the Safe Browsing component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-125.

CVE-2026-92072
Unclassified
Sep 15, 2026
Low3.4Red Hat

Low [CVE-2026-92071] Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-501.

CVE-2026-92071
Unclassified
Sep 15, 2026
Low3.4Red Hat

Low [CVE-2026-92070] Information disclosure in the Networking component

Information disclosure in the Networking component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-201.

CVE-2026-92070
Unclassified
Sep 15, 2026

← All vendors