Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

284 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Low3.3Red Hat

Low [CVE-2026-41990] Denial of Service or data integrity issues from missing bounds check during Dilithium signing.

Denial of Service or data integrity issues from missing bounds check during Dilithium signing.. Red Hat rates this low (CVSS 3.3). Weakness: CWE-787. Affected package(s): libgcrypt-main. Resolved in Red Hat advisory RHSA-2026:8466 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-41990
Unclassified
Apr 23, 2026
Low3.7Red Hat

Low [CVE-2026-22008] Improved Arena allocations (Oracle CPU 2026-04)

Improved Arena allocations (Oracle CPU 2026-04). Red Hat rates this low (CVSS 3.7). Weakness: CWE-122. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:9694 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-22008
Unclassified
Apr 21, 2026
Low2.9Red Hat

Low [CVE-2026-22007] Enhance crypto algorithm support (Oracle CPU 2026-04)

Enhance crypto algorithm support (Oracle CPU 2026-04). Red Hat rates this low (CVSS 2.9). Weakness: CWE-327. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:11829 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-22007
Unclassified
Apr 21, 2026
Low3.7Red Hat

Low [CVE-2026-22018] Enhance Zip file reading (Oracle CPU 2026-04)

Enhance Zip file reading (Oracle CPU 2026-04). Red Hat rates this low (CVSS 3.7). Weakness: CWE-125. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:11829 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-22018
Unclassified
Apr 21, 2026
Low2.9Red Hat

Low [CVE-2026-34268] Enhance key generation (Oracle CPU 2026-04)

Enhance key generation (Oracle CPU 2026-04). Red Hat rates this low (CVSS 2.9). Weakness: CWE-327. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:11829 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-34268
Unclassified
Apr 21, 2026
Low3.4Red Hat

Low [CVE-2026-6776] Incorrect boundary conditions in the WebRTC: Networking component

Incorrect boundary conditions in the WebRTC: Networking component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-131. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:10757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-6776
Unclassified
Apr 21, 2026
Low2.7Red Hat

Low [CVE-2026-22001] Information Schema unspecified vulnerability (CPU Apr 2026)

Information Schema unspecified vulnerability (CPU Apr 2026). Red Hat rates this low (CVSS 2.7). Weakness: CWE-538. Affected package(s): mysql:8.4, mysql, mysql8.4, mysql:8.0. Resolved in Red Hat advisory RHSA-2026:25919 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-22001
Unclassified
Apr 21, 2026
Low3.7Red Hat

Low [CVE-2026-41080] Denial of Service via hash flooding with crafted XML

Denial of Service via hash flooding with crafted XML. Red Hat rates this low (CVSS 3.7). Weakness: CWE-331. Affected package(s): expat-main. Resolved in Red Hat advisory RHSA-2026:11004 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-41080
Unclassified
Apr 16, 2026
Low3.8Red Hat

Low [CVE-2026-33948] Input validation bypass via embedded NUL bytes allows parser differential attacks

Input validation bypass via embedded NUL bytes allows parser differential attacks. Red Hat rates this low (CVSS 3.8). Weakness: CWE-170. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:8579 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33948
Unclassified
Apr 13, 2026
Low2.9Red Hat

Low [CVE-2026-40228] Unintended output to user terminals via logger command

Unintended output to user terminals via logger command. Red Hat rates this low (CVSS 2.9). Weakness: CWE-117. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40228
Unclassified
Apr 10, 2026
Low3.5Red Hat

Low [CVE-2026-33551] Privilege escalation through EC2 credential creation

Privilege escalation through EC2 credential creation. Red Hat rates this low (CVSS 3.5). Weakness: CWE-266. Affected package(s): openstack-keystone. Resolved in Red Hat advisory RHSA-2026:28044 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-33551
Unclassified
Apr 7, 2026
Low3.7Red Hat

Low [CVE-2026-28387] Arbitrary code execution due to use-after-free in DANE TLSA authentication

Arbitrary code execution due to use-after-free in DANE TLSA authentication. Red Hat rates this low (CVSS 3.7). Weakness: CWE-1341. Affected package(s): openssl-main. Resolved in Red Hat advisory RHSA-2026:7261 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-28387
Unclassified
Apr 7, 2026
Low3.7Red Hat

Low [CVE-2026-37977] Information disclosure via CORS header injection due to unvalidated JWT azp claim

Information disclosure via CORS header injection due to unvalidated JWT azp claim. Red Hat rates this low (CVSS 3.7). Weakness: CWE-346. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-37977
Unclassified
Apr 6, 2026
Low2.2Red Hat

Low [CVE-2026-35388] Low integrity impact from unconfirmed proxy-mode multiplexing sessions

Low integrity impact from unconfirmed proxy-mode multiplexing sessions. Red Hat rates this low (CVSS 2.2). Weakness: CWE-306. Affected package(s): openssh, rhaiis/model-opt-cuda-rhel9:1780681984, discovery/discovery-ui-rhel9:1778156756, rhui5/rhua-rhel9:1779798222, discovery/discovery-server-rhel9:1778101579, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-35388
Unclassified
Apr 2, 2026
Low3.1Red Hat

Low [CVE-2026-35387] Information disclosure due to unintended cryptographic algorithm usage

Information disclosure due to unintended cryptographic algorithm usage. Red Hat rates this low (CVSS 3.1). Weakness: CWE-115. Affected package(s): openssh, rhaiis/model-opt-cuda-rhel9:1780681984, rhui5/rhua-rhel9:1779798222, discovery/discovery-server-rhel9:1778101579, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-35387
Unclassified
Apr 2, 2026
Low3.6Red Hat

Low [CVE-2026-35386] Arbitrary command execution via shell metacharacters in username

Arbitrary command execution via shell metacharacters in username. Red Hat rates this low (CVSS 3.6). Weakness: CWE-78. Affected package(s): openssh, rhaiis/model-opt-cuda-rhel9:1780681984, rhui5/rhua-rhel9:1779798222, discovery/discovery-server-rhel9:1778101579, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-35386
Unclassified
Apr 2, 2026
Low3.7Red Hat

Low [CVE-2026-34073] Security bypass due to improper DNS name constraint validation

Security bypass due to improper DNS name constraint validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-295. Affected package(s): python-cryptography-main. Resolved in Red Hat advisory RHSA-2026:7295 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34073
Unclassified
Mar 31, 2026
Low3.3Red Hat

Low [CVE-2026-21715] Information disclosure due to `fs.realpathSync.native()` bypassing filesystem read restrictions

Information disclosure due to `fs.realpathSync.native()` bypassing filesystem read restrictions. Red Hat rates this low (CVSS 3.3). Weakness: CWE-425. Affected package(s): nodejs24, nodejs:24. Resolved in Red Hat advisory RHSA-2026:7350 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-21715
Unclassified
Mar 30, 2026
Low3.8Red Hat

Low [CVE-2026-21716] Permission bypass allows unauthorized modification of file permissions and ownership via incomplete security fix.

Permission bypass allows unauthorized modification of file permissions and ownership via incomplete security fix.. Red Hat rates this low (CVSS 3.8). Weakness: CWE-279. Affected package(s): nodejs20-main, nodejs25-main, nodejs24, nodejs22-main, nodejs:24, nodejs24-main. Resolved in Red Hat advisory RHSA-2026:7350 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-21716
Unclassified
Mar 30, 2026
Low3.1Red Hat

Low [CVE-2026-4874] Server-Side Request Forgery via OIDC token endpoint manipulation

Server-Side Request Forgery via OIDC token endpoint manipulation. Red Hat rates this low (CVSS 3.1). Weakness: CWE-918. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4874
Unclassified
Mar 26, 2026

← All vendors