Red Hat Linux Security Advisories & CVEs
11617 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-91786] out-of-bounds read in remote search icon rendering due to unvalidated icon-data buffer size
out-of-bounds read in remote search icon rendering due to unvalidated icon-data buffer size. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gnome-shell.
Medium [CVE-2026-86818] Mailto header injection via percent-encoded field-name desynchronization
Mailto header injection via percent-encoded field-name desynchronization. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-838. Affected product named by the advisory: Red Hat Satellite 6.
Medium [CVE-2026-86472] Security bypass due to inconsistent host case normalization
Security bypass due to inconsistent host case normalization. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-178. Red Hat lists fixing advisory RHSA-2026:71040 with package grafana12-4-main-12.4.10-0.4.hum1, grafana13-2-main-13.2.1-0.7.hum1, grafana13-1-main-13.1.6-0.3.hum1. Affected products named by the advisory: Red Hat Hardened Images; Cost Management On Premise; Migration Toolkit for Applications 8; Migration Toolkit for Containers; and 32 more. Affected products named by the advisory: Multicluster Engine for Kubernetes; Network Observability Operator; OpenShift Lightspeed; OpenShift Pipelines; and 28 more.
Medium [CVE-2026-17495] Path Traversal via crafted non-string input to locale function
Path Traversal via crafted non-string input to locale function. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-22. Affected products named by the advisory: Multicluster Engine for Kubernetes; OpenShift Pipelines; OpenShift Service Mesh 3; Red Hat 3scale API Management Platform 2; and 31 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; Red Hat build of Apache Camel for Spring Boot 4; and 27 more.
Medium [CVE-2026-81320] TLS private key written to operator log at debug level
TLS private key written to operator log at debug level. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-532. Affected product named by the advisory: Red Hat build of Apache Camel - HawtIO 4.
Medium [CVE-2026-81303] routes/custom-host confused-deputy via spec.routeHostName
routes/custom-host confused-deputy via spec.routeHostName. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-441. Affected product named by the advisory: Red Hat build of Apache Camel - HawtIO 4.
Medium [CVE-2026-90878] Denial of Service via Jinja Template Rendering
Denial of Service via Jinja Template Rendering. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-606. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Low [CVE-2026-91739] Missing authorization in Transactions Platform
Missing authorization in Transactions Platform. Red Hat rates this low (CVSS 3.9). Weakness: CWE-1021.
Low [CVE-2026-92240] Out-of-bounds read in IMAP response parser
Out-of-bounds read in IMAP response parser. Red Hat rates this low (CVSS 3.4). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, thunderbird-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.
Low [CVE-2026-91957] Use-after-free vulnerability in smartcard RDPDR device handler leading to denial of service or potential code execution
Use-after-free vulnerability in smartcard RDPDR device handler leading to denial of service or potential code execution. Red Hat rates this low (CVSS 3.1). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.
Low [CVE-2026-92079] Mitigation bypass in the Widget: Win32 component
Mitigation bypass in the Widget: Win32 component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-807.
Low [CVE-2026-92078] Denial-of-service in the Security component
Denial-of-service in the Security component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-770.
Low [CVE-2026-92077] Denial-of-service in the SVG component
Denial-of-service in the SVG component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-770.
Low [CVE-2026-92076] Incorrect boundary conditions in the Networking component
Incorrect boundary conditions in the Networking component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-120.
Low [CVE-2026-92075] Mitigation bypass in the Networking component
Mitigation bypass in the Networking component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-305.
Low [CVE-2026-92074] Mitigation bypass in the Popup Blocker component
Mitigation bypass in the Popup Blocker component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-807.
Low [CVE-2026-92073] Privilege escalation in the Enterprise Policies component
Privilege escalation in the Enterprise Policies component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-266.
Low [CVE-2026-92072] Incorrect boundary conditions in the Safe Browsing component
Incorrect boundary conditions in the Safe Browsing component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-125.
Low [CVE-2026-92071] Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-501.
Low [CVE-2026-92070] Information disclosure in the Networking component
Information disclosure in the Networking component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-201.