Red Hat Linux Security Advisories & CVEs
11617 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Low [CVE-2026-92069] Spoofing issue in the DOM: Navigation component
Spoofing issue in the DOM: Navigation component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-601.
Low [CVE-2026-92068] Site isolation issue in the Reader Mode component
Site isolation issue in the Reader Mode component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-653.
Low [CVE-2026-92067] Use-after-free in the Widget: Gtk component
Use-after-free in the Widget: Gtk component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-364.
Low [CVE-2026-92066] Sandbox escape in the Profile Backup component
Sandbox escape in the Profile Backup component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-653.
Low [CVE-2026-92065] Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-787.
Low [CVE-2026-92063] Denial-of-service in the Audio/Video component
Denial-of-service in the Audio/Video component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-770.
Low [CVE-2026-92062] Privilege escalation in the Session Restore component
Privilege escalation in the Session Restore component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-266.
Low [CVE-2026-92061] Incorrect boundary conditions in the Security: Process Sandboxing component
Incorrect boundary conditions in the Security: Process Sandboxing component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-403.
Low [CVE-2026-92060] Use-after-free in the Internationalization component
Use-after-free in the Internationalization component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-825.
Low [CVE-2026-91926] memory leak in ntlm_decode_target_info via duplicated AV_PAIR entries in NTLM CHALLENGE
memory leak in ntlm_decode_target_info via duplicated AV_PAIR entries in NTLM CHALLENGE. Red Hat rates this low (CVSS 3.7). Weakness: CWE-401. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: gssntlmssp.
High [CVE-2026-68489] Plesk Extensions Ruby and Node.js Toolkit: Arbitrary Code Execution via Static Code Injection
Plesk Extensions Ruby and Node.js Toolkit: Arbitrary Code Execution via Static Code Injection. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces.
High [CVE-2026-53714] Information Disclosure via Unauthenticated xDS gRPC Server
Information Disclosure via Unauthenticated xDS gRPC Server. Red Hat rates this important (CVSS 7.4). Weakness: CWE-306.
High [CVE-2026-82049] Python tarfile module: File modification and content disclosure via crafted archives
Python tarfile module: File modification and content disclosure via crafted archives. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:68135 with package python3-11-main-3.11.16-1.4.hum1, python3-12-main-3.12.14-1.3.hum1, python3-10-main-3.10.21-1.3.hum1, python3-13-main-3.13.15-1.3.hum1. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-82035] Arbitrary file write via path traversal vulnerability
Arbitrary file write via path traversal vulnerability. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.
High [CVE-2026-53659] Denial of Service via unbounded gzip decompression
Denial of Service via unbounded gzip decompression. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409.
High [CVE-2026-55451] Denial of Service via Prototype Pollution
Denial of Service via Prototype Pollution. Red Hat rates this important (CVSS 8.2). Weakness: CWE-915. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat Openshift Data Foundation 4.
High [CVE-2026-84445] Denial of Service via malformed RPC requests
Denial of Service via malformed RPC requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:72884 with package rhoai/odh-kserve-agent-rhel9:1789570413, rhacm2/multicluster-role-assignment-rhel9:1790198006, cluster-observability-operator/prometheus-rhel9:1790857922, multicluster-engine/hypershift-addon-rhel9-operator:1790117675. Affected product named by the advisory: Red Hat Enterprise Linux 7.
High [CVE-2026-90947] out-of-bounds write in lighting effects plugin via crafted preset file
out-of-bounds write in lighting effects plugin via crafted preset file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:75575 with package gimp-2:3.0.4-4.el9_8.14. Affected product named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-90949] heap-based buffer overflow in PSP loader due to selection-channel geometry mismatch
heap-based buffer overflow in PSP loader due to selection-channel geometry mismatch. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.
High [CVE-2026-90948] heap-based buffer overflow in ICO loader via integer overflow in embedded PNG dimensions
heap-based buffer overflow in ICO loader via integer overflow in embedded PNG dimensions. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:75575 with package gimp-2:3.0.4-4.el9_8.14. Affected product named by the advisory: Red Hat Enterprise Linux 9.