Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3066 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.0Red Hat

High [CVE-2026-32107] Privilege Escalation via improper privilege management

Privilege Escalation via improper privilege management. Red Hat rates this important (CVSS 7). Weakness: CWE-273. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-32107
Unclassified
Apr 17, 2026
High7.5Red Hat

High [CVE-2026-5807] Denial of Service via unauthenticated root token generation or rekey operations

Denial of Service via unauthenticated root token generation or rekey operations. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Openshift Data Foundation 4.

CVE-2026-5807
Unclassified
Apr 17, 2026
High7.5Red Hat

High [CVE-2026-4525] Information disclosure of authentication tokens via incorrect header handling

Information disclosure of authentication tokens via incorrect header handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Openshift Data Foundation 4.

CVE-2026-4525
Unclassified
Apr 17, 2026
High8.1Red Hat

High [CVE-2026-3605] Denial of Service due to unauthorized secret deletion via policy bypass

Denial of Service due to unauthorized secret deletion via policy bypass. Red Hat rates this important (CVSS 8.1). Weakness: CWE-639. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Openshift Data Foundation 4.

CVE-2026-3605
Unclassified
Apr 17, 2026
High7.5Red Hat

High [CVE-2026-40170] Denial of service via stack buffer overflow during QUIC handshake

Denial of service via stack buffer overflow during QUIC handshake. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120. Affected package(s): samba, ngtcp2-main. Resolved in Red Hat advisory RHSA-2026:22963 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images.

CVE-2026-40170
Unclassified
Apr 16, 2026
High7.5Red Hat

High [CVE-2025-54502] APCB SMM driver: kernel: linux-firmware: AMD APCB SMM driver: Arbitrary Code Execution via incorrect boot service use

APCB SMM driver: kernel: linux-firmware: AMD APCB SMM driver: Arbitrary Code Execution via incorrect boot service use. Red Hat rates this important (CVSS 7.5). Weakness: CWE-648. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-54502
Unclassified
Apr 16, 2026
High7.1Red Hat

High [CVE-2026-41082] path traversal via the .install field

path traversal via the.install field. Red Hat rates this important (CVSS 7.1). Weakness: CWE-24. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-41082
Unclassified
Apr 16, 2026
High7.4Red Hat

High [CVE-2026-41035] Use-after-free vulnerability in extended attribute handling

Use-after-free vulnerability in extended attribute handling. Red Hat rates this important (CVSS 7.4). Weakness: CWE-805. Affected package(s): rsync, rhcos, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:25044 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 17 more.

CVE-2026-41035
Unclassified
Apr 16, 2026
High7.3Red Hat

High [CVE-2026-12912] Heap-based buffer overflow via crafted PixarLog-compressed TIFF image

Heap-based buffer overflow via crafted PixarLog-compressed TIFF image. Red Hat rates this important (CVSS 7.3). Weakness: CWE-122. Affected package(s): libtiff-main. Resolved in Red Hat advisory RHSA-2026:34890 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; and 6 more.

CVE-2026-12912
Unclassified
Apr 16, 2026
High7.5Red Hat

High [CVE-2026-40192] Denial of Service via decompression bomb in FITS image processing

Denial of Service via decompression bomb in FITS image processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Affected package(s): ansible-automation-platform, rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1778263054, rhelai3/bootc-rocm-rhel9:1778666124, rhaiis/vllm-rocm-rhel9:1778244531, rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1778677734, rhaiis/vllm-cuda-rhel9:1778274666. Resolved in Red Hat advisory RHSA-2026:23361 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Satellite 6.16 for RHEL 8; and 19 more.

CVE-2026-40192
Unclassified
Apr 15, 2026
High8.8Red Hat

High [CVE-2026-40261] command injection via malicious Perforce source reference/url

command injection via malicious Perforce source reference/url. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Affected package(s): composer-main. Resolved in Red Hat advisory RHSA-2026:8165 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-40261
Unclassified
Apr 15, 2026
High7.8Red Hat

High [CVE-2026-40176] command injection via malicious Perforce repository definition

command injection via malicious Perforce repository definition. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78. Affected package(s): composer-main. Resolved in Red Hat advisory RHSA-2026:8165 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-40176
Unclassified
Apr 15, 2026
High7.5Red Hat

High [CVE-2025-41118] sensitive COS SecretKey exposed in plaintext via configuration API due to missing type protection

sensitive COS SecretKey exposed in plaintext via configuration API due to missing type protection. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779925273. Resolved in Red Hat advisory RHSA-2026:24503 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Ceph Storage 6.

CVE-2025-41118
Unclassified
Apr 15, 2026
High7.3Red Hat

High [CVE-2026-6384] Arbitrary code execution or denial of service via buffer overflow in GIF image processing

Arbitrary code execution or denial of service via buffer overflow in GIF image processing. Red Hat rates this important (CVSS 7.3). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8.

CVE-2026-6384
Unclassified
Apr 15, 2026
High7.4Red Hat

High [CVE-2026-33805] @fastify/reply-from: @fastify/http-proxy: Fastify Reply From and HTTP Proxy: Security bypass via Connection header manipulation

@fastify/reply-from: @fastify/http-proxy: Fastify Reply From and HTTP Proxy: Security bypass via Connection header manipulation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-444. Affected package(s): devspaces/dashboard-rhel9:1776795511. Resolved in Red Hat advisory RHSA-2026:10175 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.27; Red Hat OpenShift AI (RHOAI).

CVE-2026-33805
Unclassified
Apr 15, 2026
High7.5Red Hat

High [CVE-2026-3505] unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion

unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): eap8-bouncycastle, bcpg-jdk18on, bcpg-fips, bcpg-jdk15on. Resolved in Red Hat advisory RHSA-2026:18054 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; OpenShift Developer Tools and Services; Red Hat AMQ Clients; and 6 more.

CVE-2026-3505
Unclassified
Apr 15, 2026
High7.5Red Hat

High [CVE-2026-5588] PKIX draft CompositeVerifier accepts empty signature sequence as valid

PKIX draft CompositeVerifier accepts empty signature sequence as valid. Red Hat rates this important (CVSS 7.5). Weakness: CWE-347. Affected package(s): eap8-bouncycastle, devspaces/openvsx-rhel9:1779528224, eap8-guava-failureaccess, eap8-activemq-artemis, eap8-netty-transport-native-epoll, eap8-reactivex-rxjava. Resolved in Red Hat advisory RHSA-2026:14276 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat OpenShift Dev Spaces 3.28; OpenShift Developer Tools and Services; and 9 more.

CVE-2026-5588
Unclassified
Apr 15, 2026
High7.5Red Hat

High [CVE-2026-5598] private key leakage via non-constant time comparisons

private key leakage via non-constant time comparisons. Red Hat rates this important (CVSS 7.5). Weakness: CWE-385. Affected package(s): eap8-bouncycastle, bcprov-jdk12, eap7-bouncycastle. Resolved in Red Hat advisory RHSA-2026:18054 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; and 2 more.

CVE-2026-5598
Unclassified
Apr 15, 2026
High7.5Red Hat

High [CVE-2025-14813] GOSTCTR implementation unable to process more than 255 blocks correctly

GOSTCTR implementation unable to process more than 255 blocks correctly. Red Hat rates this important (CVSS 7.5). Weakness: CWE-327. Affected package(s): bcprov-jdk15to18, eap8-bouncycastle, devspaces/openvsx-rhel9:1779528224, bcprov-ext-jdk15on, bcprov-ext-jdk18on, devspaces/pluginregistry-rhel9:1779359423. Resolved in Red Hat advisory RHSA-2026:14276 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat OpenShift AI 2.25; and 15 more.

CVE-2025-14813
Unclassified
Apr 15, 2026
High7.5Red Hat

High [CVE-2026-33806] Schema validation bypass via malformed Content-Type header

Schema validation bypass via malformed Content-Type header. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1289. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33806
Unclassified
Apr 15, 2026

← All vendors