Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4712 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Red Hat

High [CVE-2026-64646] Denial of Service via excessive memory consumption in Server Actions

Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime. This issue has been fixed in versions 15.5.21 and 16.2.11. A flaw was found in Next.js. This can lead to a denial of service (DoS) due to resource exhaustion. An Important denial of service flaw exists in Next.js applications utilizing the App Router with Server Actions configured to use the Edge runtime. This vulnerability can lead to excessive memory consumption, potentially causing service unavailability. Red Hat products that embed or deploy Next.js applications with this specific configuration are affected. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Streams for Apache Kafka 3.2.1; Red Hat Enterprise Linux AI (RHEL AI) 3; streams for Apache Kafka 2. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Trusted Artifact Signer as not affected. Red Hat fixing advisory: RHSA-2026:54435.

CVE-2026-64646
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-64644] Denial of Service via malicious image optimization

Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in /_next/image endpoints. Only config.images.remotePatterns is affected, and just the patterns in that array, whereas config.images.unoptimized: true, config.images.loader: 'custom', and Vercel are not impacted. This issue has been fixed in versions 15.5.21 and 16.2.11. This vulnerability specifically affects configurations using config.images.remotePatterns. This is an Important denial of service vulnerability in Next.js applications. This configuration is not enabled by default in Red Hat supported products, limiting exposure to environments where this specific feature has been activated. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Streams for Apache Kafka 3.2.1; streams for Apache Kafka 2. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Trusted Artifact Signer as not affected.

CVE-2026-64644
Unclassified
Jul 27, 2026
High8.2Red Hat

High [CVE-2026-64642] Authentication bypass leading to unauthorized access

Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales can bypass middleware/proxy based authentication. This issue has been fixed in version 16.2.11. This vulnerability allows for unauthorized access, leading to a high impact on confidentiality through information disclosure. This could enable unauthorized access to web applications utilizing such a configuration within Red Hat products. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N). Weakness: CWE-807. Affected Red Hat products: Red Hat Build of Keycloak; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; Red Hat Connectivity Link 1; Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7.

CVE-2026-64642
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-64641] Denial of Service via crafted requests to App Router with Server Actions

Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process. This issue has been fixed in versions 15.5.21 and 16.2.11. A remote attacker can send specially crafted requests to Next.js applications that utilize the App Router with Server Actions. This can lead to excessive CPU usage, causing the application to become unresponsive and preventing it from processing further requests, resulting in a Denial of Service (DoS). Important: A denial of service flaw exists in Next.js applications utilizing the App Router with Server Actions. Crafted requests can lead to excessive CPU consumption, potentially disrupting service availability for affected Red Hat products that embed or depend on vulnerable Next.js versions. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected products named by the advisory: Streams for Apache Kafka 3.2.1; Red Hat Build of Keycloak; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; and 7 more.

CVE-2026-64641
Unclassified
Jul 27, 2026
High8.2Red Hat

High [CVE-2026-64645] Server-Side Request Forgery vulnerability

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A redirects() rule configured this way is vulnerable to an Open Redirect. This issue has been fixed in versions 15.5.21 and 16.2.11. This vulnerability allows a remote attacker to perform Server-Side Request Forgery (SSRF) or Open Redirect attacks. Additionally, this misconfiguration can result in Open Redirects, potentially exposing users to phishing. This Important vulnerability in Next.js applications arises when `rewrites()` or `redirects()` rules construct external destination hostnames from untrusted input. The impact is contingent on the application's specific routing configuration. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N). Weakness: CWE-918. Affected Red Hat products: Streams for Apache Kafka 3.2.1; Red Hat Enterprise Linux AI (RHEL AI) 3; streams for Apache Kafka 2.

CVE-2026-64645
Unclassified
Jul 27, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-45623] Information disclosure and denial of service via crafted CSS input

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferences PATH against the local filesystem with no scheme, allowlist, or traversal check. An attacker who controls the CSS input can cause the host process to read any file readable by Node and leak the first ~10 bytes of its content through the resulting JSON.parse SyntaxError message. The bug also yields a precise file-existence oracle and a controllable-read primitive that may be combined with large-file targets for DoS. The behaviour is triggered with PostCSS's default options — no from, no map, no plugins required — and is therefore reachable from any pipeline that runs untrusted CSS through PostCSS (CMS themes, user-uploaded styles, browser-extension/userstyle processors, build pipelines for third-party packages, blog comment renderers, etc.). This issue has been fixed in version 8.5.12. A flaw was found in PostCSS, a tool that processes CSS files. An attacker who provides specially crafted CSS input containing a malicious source map comment can cause the system to read arbitrary files from the local filesystem.

CVE-2026-45623
Red Hat Enterprise Linux
Jul 27, 2026
High7.2Vendor: MediumRed Hat

High [CVE-2026-54272] Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifies an address by matching it against a table of known IPv6 special-use prefixes, returning Global unicast when nothing matches. That table had no entry for the IPv4-mapped range (::ffff:0:0/96), so every mapped address fell through to Global unicast; NAT64 addresses matched their own NAT64 … labels. The boolean checks isLoopback, isUnspecified, and isMulticast compared getType() against a fixed label and so returned false, while isLinkLocal and isULA checked only the native IPv6 ranges. The library already exposed isMapped4() and to4(), but did not apply them inside these checks, so a mapped or NAT64 address was never normalized to its embedded IPv4 address before classification. For IPv4-mapped addresses the host OS routes to the IPv4 stack, so the misclassification is reachable on any dual-stack host. For NAT64, the classification bypass is unconditional but end-to-end reachability additionally requires a NAT64/DNS64 gateway in the deployment network. This issue has been fixed in version 10.2.1. An attacker could exploit this misclassification to bypass network restrictions and potentially access or manipulate internal resources.

CVE-2026-54272
Red Hat Enterprise Linux
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-54890] Denial of Service via integer underflow in ETF decoding

Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modules) allows Forced Integer Overflow, Excessive Allocation. This vulnerability is associated with program files erts/emulator/beam/external.c, emulator/beam/external.c. The BIT_BINARY_EXT tag (77) handler in the External Term Format (ETF) decoder accepts an encoding with both length and trailing-bits fields set to zero. The subsequent computation of the bitstring size underflows an unsigned integer, producing a value of roughly 2^64 that is then passed as a memory allocation size. The allocator aborts the entire node with a message such as "Cannot allocate 2305843009213693951 bytes of memory (of type binary)". The crash is a VM-level abort, not an Erlang-level exception. It cannot be intercepted by supervision trees, by try/catch, or by passing the [safe] option to binary_to_term/2 (which only restricts atom creation and does not perform structural validation of binary encodings). Any application that decodes ETF from untrusted sources via binary_to_term/1,2 or enif_binary_to_term() is exposed. The Erlang distribution protocol also decodes incoming terms through the same code path, but distribution is expected to run on trusted networks per the OTP Secure Coding Guidelines (DSG-011). Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-54890
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-59251] Erlang/OTP public_key: Denial of Service via crafted TLS certificate chains

Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial of service by sending a crafted X.509 certificate chain during the TLS handshake. During RFC 5280 policy processing in public_key:pkix_path_validation/3, the certificate policy tree maintained by pubkey_policy_tree grows without an upper bound. When a certificate chain contains M policies per certificate and K certificates, the tree grows on the order of M^K nodes because pubkey_policy_tree:add_leaves/2 and pubkey_policy_tree:add_leaf_siblings/2 extend the tree per policy per certificate. A modest chain with many policies per certificate is enough to pin BEAM schedulers and exhaust the node's memory, taking down the entire VM. The attacker only needs to be able to present a certificate chain to the victim, which is the normal precondition for a TLS handshake, so exploitation succeeds against any incoming or outgoing TLS connection that validates the peer's chain (the default for SSL/TLS clients and mutual-TLS servers). This is the same vulnerability class as OpenSSL's X509_verify_cert policy tree DoS. This vulnerability is associated with program files lib/public_key/src/pubkey_policy_tree.erl and program routines pubkey_policy_tree:add_leaves/2 and pubkey_policy_tree:add_leaf_siblings/2.

CVE-2026-59251
Unclassified
Jul 27, 2026
High7.4Red Hat

High [CVE-2026-55953] Erlang/OTP ssl client: Authentication bypass via unoffered anonymous cipher suite acceptance

The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. The client-side tls_handshake:hello/5 handler validates the negotiated protocol version and the downgrade sentinel but hands the server-chosen suite directly to ssl_handshake:handle_server_hello_extensions/9, which installs it without a membership check. The TLS 1.3 client path performs this check (per RFC 8446), so it is not affected. An on-path attacker between the client and the intended server can respond with a ServerHello selecting an anonymous key exchange suite such as TLS_DH_anon_* or TLS_ECDH_anon_* that the client never offered. Anonymous suites do not require the server to present a certificate, so the entire verify_peer and cacerts configuration is bypassed: the attacker completes the handshake with its own ephemeral parameters, no certificate is validated, no hostname is checked, and ssl:connect returns {ok, Socket}. All subsequent application traffic is readable and modifiable by the attacker. This issue affects OTP from OTP R13B03 before OTP 27.3.4.15, from OTP 28.0 before OTP 28.5.0.4, and from OTP 29.0 before OTP 29.0.4, corresponding to ssl from 3.10.7 before 11.2.12.11, from 11.3 before 11.6.0.4, and from 11.7 before 11.7.4.

CVE-2026-55953
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-55737] Denial of Service via crafted external term format binary

Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafted Erlang external term format (ETF) binary to binary_to_term/1 to corrupt the BEAM heap pointer and crash the virtual machine. When decoding a LARGE_TUPLE_EXT term, the validation pass decoded_size() in erts/emulator/beam/external.c reads the 32-bit arity field as unsigned (get_uint32()), while the decode pass dec_term() reads the same field as a signed 32-bit integer (get_int32()) into an int. An arity wire value of 0x80000000 passes validation as 2147483648 but decodes as -2147483648, so the subsequent hp += n moves the heap allocation pointer backward. Neither pass enforces the runtime tuple-arity limit MAX_ARITYVAL. The result is an out-of-bounds heap write; in practice the VM detects an impossible heap size and aborts, denying service. The required padding is large when uncompressed but the compressed-ETF envelope shrinks it to a small payload on the wire. This issue affects OTP from OTP 25.0 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15, corresponding to erts from 13.0 before 17.0.4, 16.4.0.4 and 15.2.7.11. This manipulation of data types during processing can corrupt the system's memory, leading to an out-of-bounds write. The ultimate consequence is a denial of service (DoS), causing the Erlang virtual machine to crash.

CVE-2026-55737
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-42792] Erlang OTP epmd: Remote Denial of Service via connection exhaustion

Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminate the Erlang Port Mapper Daemon (epmd) via connection slot exhaustion. The do_accept function in erts/epmd/src/epmd_srv.c calls epmd_cleanup_exit() when accept(2) returns EMFILE (per-process file descriptor limit reached) or ENFILE (system-wide file descriptor limit reached), rather than treating these as recoverable conditions. An attacker can exhaust epmd's file descriptor slots by holding many TCP connections open while periodically sending a single byte to reset the idle timeout, then causing accept(2) to return EMFILE, which kills the daemon. epmd has no per-source-IP connection cap, making the attack feasible from a single source. On Debian/Ubuntu default packaging the impact is amplified: the systemd unit inherits a low file descriptor soft limit, and repeated daemon deaths trigger systemd's start-rate-limit, permanently failing both epmd.service and epmd.socket and requiring manual operator intervention to recover. This issue affects OTP from OTP 17.0 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15. By exhausting connection slots through holding numerous TCP connections open and periodically sending data, the attacker can force epmd to terminate, leading to a permanent Denial of Service (DoS).

CVE-2026-42792
Unclassified
Jul 27, 2026
High8.4Red Hat

High [CVE-2026-55971] Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. A remote, unauthenticated attacker can exploit a heap-based buffer overflow vulnerability without user interaction. This can lead to arbitrary code execution, allowing the attacker to gain full control over the affected system, compromise data, and cause a denial of service. Red Hat ships the affected C++ package (thrift) in RHEL AI and in the Fedora/EPEL community distributions, and it is also consumed by AIPCC's PyArrow build pipeline (tracked separately as AIPCC-28667); upgrade to Apache Thrift 0.24.0 or later to remediate. Confirmed usage in RHEL AI 3.4's GPU bootc images and in the AIPCC PyArrow build pipeline is limited to PyArrow's Parquet metadata support, which serializes structs via Thrift's TCompactProtocol directly to an in-memory buffer and does not invoke THeaderTransport. As a result, this usage does not expose the vulnerable code path to network input; it would require local access to a maliciously crafted Parquet file instead. Affected products named by the advisory: Red Hat Enterprise Linux AI 3.4 for RHEL 9; Red Hat Enterprise Linux AI 3.5 for RHEL 9; Red Hat Enterprise Linux AI 3.6 for RHEL 9; Red Hat Hardened Images; and 1 more.

CVE-2026-55971
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-55969] Denial of Service via integer overflow or wraparound

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This integer overflow or wraparound vulnerability allows a remote attacker to cause a denial of service (DoS) by sending specially crafted input. The flaw can lead to the affected service becoming unavailable. This vulnerability in Apache Thrift bindings, rated as Important, allows a remote attacker to trigger a denial of service. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-190. Affected products named by the advisory: Cryostat 4 on RHEL 9; Multicluster Global Hub 1.4.9; Multicluster Global Hub 1.5.8; Multicluster Global Hub 1.6.6; and 26 more.

CVE-2026-55969
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-55968] Apache Thrift Node.js bindings: Denial of Service due to inefficient algorithmic complexity and resource allocation

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. By exploiting this, an attacker can consume excessive resources, making the service unavailable to legitimate users. This flaw primarily impacts Red Hat OpenShift Container Platform components that utilize the vulnerable Thrift Node.js bindings, potentially leading to service unavailability. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Confidential Compute Attestation; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Update Service as not affected. Red Hat fixing advisory: RHSA-2026:49837.

CVE-2026-55968
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-49158] Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. By sending specially crafted highly compressed data, an attacker can exhaust system resources, making the service unavailable to legitimate users. This Important vulnerability in Apache Thrift Ruby bindings could allow a remote, unauthenticated attacker to trigger a denial of service. By sending specially crafted compressed data, an attacker can cause excessive resource consumption, leading to service unavailability in affected Red Hat products that utilize these bindings, such as OpenShift Container Platform components. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-409. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Confidential Compute Attestation; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Update Service as not affected. Red Hat fixing advisory: RHSA-2026:49837.

CVE-2026-49158
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-48586] Denial of Service via improper handling of highly compressed data

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This vulnerability, categorized as improper handling of highly compressed data (also known as data amplification), allows a remote attacker to cause a Denial of Service (DoS) by sending specially crafted, highly compressed data. The affected component fails to properly manage the expansion of this data, leading to resource exhaustion and system unavailability. This Important vulnerability in Apache Thrift's handling of highly compressed data can lead to a denial of service. Remote, unauthenticated attackers could exploit this flaw by sending specially crafted compressed data, causing excessive resource consumption and disrupting the availability of services utilizing vulnerable Thrift bindings in Red Hat products. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-409. Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Build of Apache Camel 4.18 for Quarkus 3.33; Multicluster Global Hub 1.4.9; Multicluster Global Hub 1.5.8; and 27 more.

CVE-2026-48586
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-45112] Denial of Service due to uncontrolled resource allocation

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This vulnerability, categorized as an Allocation of Resources Without Limits or Throttling, allows a remote attacker to cause a denial of service by exhausting system resources. The flaw occurs when the application fails to properly limit or throttle resource allocation, leading to potential system instability or unresponsiveness. This vulnerability is rated as Important. It stems from uncontrolled resource allocation in Apache Thrift Java bindings, which can lead to a denial of service. This impacts Red Hat products such as Red Hat OpenShift AI, Red Hat build of Apache Camel, Red Hat Ceph Storage, Red Hat Connectivity Link, and Cryostat, where services utilizing these vulnerable bindings could experience resource exhaustion and service disruption. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Build of Apache Camel 4.18 for Quarkus 3.33; Red Hat Hardened Images; Red Hat OpenShift AI 2.25; and 7 more.

CVE-2026-45112
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-43871] Denial of Service via infinite loop

Denial of Service via infinite loop. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835.

CVE-2026-43871
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-41608] Apache Thrift Python bindings: Denial of Service via data amplification

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. An attacker could exploit this by providing specially crafted compressed input, which may cause the application to consume excessive resources. This could potentially result in a denial of service (DoS) for affected systems. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-409. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Confidential Compute Attestation; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Update Service as not affected. Red Hat fixing advisory: RHSA-2026:49837.

CVE-2026-41608
Unclassified
Jul 27, 2026

← All vendors