Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

2993 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Red Hat

High [CVE-2026-56859] Denial of Service via XML decoding recursion depth issue

Denial of Service via XML decoding recursion depth issue. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Red Hat lists fixing advisory RHSA-2026:54836 with package golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; AWS Load Balancer Operator; Builds for Red Hat OpenShift; cert-manager Operator for Red Hat OpenShift; and 52 more. Affected products named by the advisory: Compliance Operator; Confidential Compute Attestation; Cryostat 4; Custom Metric Autoscaler operator for Red Hat Openshift; and 48 more.

CVE-2026-56859
Red Hat Enterprise Linux
Aug 13, 2026
High7.2Red Hat Updated

High [CVE-2026-73662] FreePBX Music on Hold: Arbitrary command execution by authenticated administrator

FreePBX Music on Hold: Arbitrary command execution by authenticated administrator. Red Hat rates this important (CVSS 7.2). Weakness: CWE-78.

CVE-2026-73662
Unclassified
Aug 13, 2026
High7.4Red Hat Updated

High [CVE-2026-45774] Arbitrary file read via path traversal in profile import

Arbitrary file read via path traversal in profile import. Red Hat rates this important (CVSS 7.4). Weakness: CWE-22. Affected product named by the advisory: File Integrity Operator.

CVE-2026-45774
Unclassified
Aug 13, 2026
High7.4Red Hat Updated

High [CVE-2026-45725] Arbitrary file write via path traversal in remote fetching mechanism

Arbitrary file write via path traversal in remote fetching mechanism. Red Hat rates this important (CVSS 7.4). Weakness: CWE-22. Affected product named by the advisory: File Integrity Operator.

CVE-2026-45725
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-73643] Denial of Service via exponential parsing in flow collections

Denial of Service via exponential parsing in flow collections. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Cryostat 4; Gatekeeper 3; Migration Toolkit for Applications 8; Migration Toolkit for Containers; and 31 more. Affected products named by the advisory: Network Observability Operator; Node HealthCheck Operator; OpenShift Lightspeed; OpenShift Pipelines; and 27 more.

CVE-2026-73643
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-73569] Denial of Service via repeated DOCTYPE declarations

Denial of Service via repeated DOCTYPE declarations. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected products named by the advisory: Migration Toolkit for Applications 8; Red Hat Advanced Cluster Security 4; Red Hat Openshift Data Foundation 4; Red Hat OpenShift GitOps; and 2 more. Affected products named by the advisory: Red Hat OpenShift Virtualization 4; Self-service automation portal 2.

CVE-2026-73569
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-73566] Denial of Service via crafted long-path tar archive

Denial of Service via crafted long-path tar archive. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Migration Toolkit for Containers; Node HealthCheck Operator; and 30 more. Affected products named by the advisory: OpenShift Pipelines; OpenShift Service Mesh 3; Red Hat 3scale API Management Platform 2; Red Hat Advanced Cluster Management for Kubernetes 2; and 26 more.

CVE-2026-73566
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat Updated

High [CVE-2026-58440] Information disclosure via incomplete webhook revocation

Information disclosure via incomplete webhook revocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-459. Affected product named by the advisory: OpenShift Pipelines.

CVE-2026-58440
Unclassified
Aug 13, 2026
High8.1Red Hat

High [CVE-2026-73515] Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer

Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer. Red Hat rates this important (CVSS 8.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: postgresql16-postgis; Red Hat package: postgresql18-postgis.

CVE-2026-73515
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-73556] Denial of Service via Regular Expression processing

Denial of Service via Regular Expression processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-73556
Unclassified
Aug 13, 2026
High7.1Red Hat Updated

High [CVE-2026-53785] Arbitrary file write via path traversal in --relative mode

Arbitrary file write via path traversal in --relative mode. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-53785
Red Hat Enterprise Linux
Aug 13, 2026
High7.0Red Hat Updated

High [CVE-2026-53803] Local Privilege Escalation via Symlink Following

Local Privilege Escalation via Symlink Following. Red Hat rates this important (CVSS 7). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-53803
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat Updated

High [CVE-2026-73508] Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names

Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected products named by the advisory: OpenShift Serverless; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Data Grid 8; and 7 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 3 more.

CVE-2026-73508
Unclassified
Aug 13, 2026
High7.8Red Hat

High [CVE-2026-73505] Arbitrary command execution via template injection in directory names

Arbitrary command execution via template injection in directory names. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78.

CVE-2026-73505
Unclassified
Aug 13, 2026
High7.5Red Hat Updated

High [CVE-2026-14456] Denial of Service via unbounded memory growth in QUIC server

Denial of Service via unbounded memory growth in QUIC server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:56097 with package openssl-main-3.5.6-0.5.hum1. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: openssl.

CVE-2026-14456
Red Hat Enterprise Linux
Aug 13, 2026
High7.7Red Hat Updated

High [CVE-2026-66804] authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure

authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure. Red Hat rates this important (CVSS 7.7). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:57194 with package rhacm2/console-rhel9:1786908361, multicluster-engine/console-mce-rhel9:1786911977. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66804
Unclassified
Aug 13, 2026
High7.1Vendor: MediumRed Hat Updated

High [CVE-2026-73627] Plugin manager lock-rule bypass allows unauthorized plugin control

Plugin manager lock-rule bypass allows unauthorized plugin control. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-414. Affected products named by the advisory: Migration Toolkit for Applications 8; Red Hat OpenShift AI (RHOAI).

CVE-2026-73627
Unclassified
Aug 13, 2026
High8.1Red Hat

High [CVE-2026-73624] Arbitrary File Overwrite via improper git option validation

Arbitrary File Overwrite via improper git option validation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-88. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.

CVE-2026-73624
Unclassified
Aug 13, 2026
High8.8Red Hat

High [CVE-2026-73625] Remote Code Execution via kwarg value smuggling

Remote Code Execution via kwarg value smuggling. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.

CVE-2026-73625
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-73623] Remote Code Execution via malicious Git template

Remote Code Execution via malicious Git template. Red Hat rates this important (CVSS 7.5). Weakness: CWE-78. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.

CVE-2026-73623
Unclassified
Aug 13, 2026

← All vendors