Red Hat Linux Security Advisories & CVEs
284 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Low [CVE-2026-41990] Denial of Service or data integrity issues from missing bounds check during Dilithium signing.
Denial of Service or data integrity issues from missing bounds check during Dilithium signing.. Red Hat rates this low (CVSS 3.3). Weakness: CWE-787. Affected package(s): libgcrypt-main. Resolved in Red Hat advisory RHSA-2026:8466 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-22008] Improved Arena allocations (Oracle CPU 2026-04)
Improved Arena allocations (Oracle CPU 2026-04). Red Hat rates this low (CVSS 3.7). Weakness: CWE-122. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:9694 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Low [CVE-2026-22007] Enhance crypto algorithm support (Oracle CPU 2026-04)
Enhance crypto algorithm support (Oracle CPU 2026-04). Red Hat rates this low (CVSS 2.9). Weakness: CWE-327. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:11829 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Low [CVE-2026-22018] Enhance Zip file reading (Oracle CPU 2026-04)
Enhance Zip file reading (Oracle CPU 2026-04). Red Hat rates this low (CVSS 3.7). Weakness: CWE-125. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:11829 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Low [CVE-2026-34268] Enhance key generation (Oracle CPU 2026-04)
Enhance key generation (Oracle CPU 2026-04). Red Hat rates this low (CVSS 2.9). Weakness: CWE-327. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:11829 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Low [CVE-2026-6776] Incorrect boundary conditions in the WebRTC: Networking component
Incorrect boundary conditions in the WebRTC: Networking component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-131. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:10757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Low [CVE-2026-22001] Information Schema unspecified vulnerability (CPU Apr 2026)
Information Schema unspecified vulnerability (CPU Apr 2026). Red Hat rates this low (CVSS 2.7). Weakness: CWE-538. Affected package(s): mysql:8.4, mysql, mysql8.4, mysql:8.0. Resolved in Red Hat advisory RHSA-2026:25919 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Low [CVE-2026-41080] Denial of Service via hash flooding with crafted XML
Denial of Service via hash flooding with crafted XML. Red Hat rates this low (CVSS 3.7). Weakness: CWE-331. Affected package(s): expat-main. Resolved in Red Hat advisory RHSA-2026:11004 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-33948] Input validation bypass via embedded NUL bytes allows parser differential attacks
Input validation bypass via embedded NUL bytes allows parser differential attacks. Red Hat rates this low (CVSS 3.8). Weakness: CWE-170. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:8579 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-40228] Unintended output to user terminals via logger command
Unintended output to user terminals via logger command. Red Hat rates this low (CVSS 2.9). Weakness: CWE-117. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-33551] Privilege escalation through EC2 credential creation
Privilege escalation through EC2 credential creation. Red Hat rates this low (CVSS 3.5). Weakness: CWE-266. Affected package(s): openstack-keystone. Resolved in Red Hat advisory RHSA-2026:28044 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9.
Low [CVE-2026-28387] Arbitrary code execution due to use-after-free in DANE TLSA authentication
Arbitrary code execution due to use-after-free in DANE TLSA authentication. Red Hat rates this low (CVSS 3.7). Weakness: CWE-1341. Affected package(s): openssl-main. Resolved in Red Hat advisory RHSA-2026:7261 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-37977] Information disclosure via CORS header injection due to unvalidated JWT azp claim
Information disclosure via CORS header injection due to unvalidated JWT azp claim. Red Hat rates this low (CVSS 3.7). Weakness: CWE-346. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-35388] Low integrity impact from unconfirmed proxy-mode multiplexing sessions
Low integrity impact from unconfirmed proxy-mode multiplexing sessions. Red Hat rates this low (CVSS 2.2). Weakness: CWE-306. Affected package(s): openssh, rhaiis/model-opt-cuda-rhel9:1780681984, discovery/discovery-ui-rhel9:1778156756, rhui5/rhua-rhel9:1779798222, discovery/discovery-server-rhel9:1778101579, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Low [CVE-2026-35387] Information disclosure due to unintended cryptographic algorithm usage
Information disclosure due to unintended cryptographic algorithm usage. Red Hat rates this low (CVSS 3.1). Weakness: CWE-115. Affected package(s): openssh, rhaiis/model-opt-cuda-rhel9:1780681984, rhui5/rhua-rhel9:1779798222, discovery/discovery-server-rhel9:1778101579, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Low [CVE-2026-35386] Arbitrary command execution via shell metacharacters in username
Arbitrary command execution via shell metacharacters in username. Red Hat rates this low (CVSS 3.6). Weakness: CWE-78. Affected package(s): openssh, rhaiis/model-opt-cuda-rhel9:1780681984, rhui5/rhua-rhel9:1779798222, discovery/discovery-server-rhel9:1778101579, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Low [CVE-2026-34073] Security bypass due to improper DNS name constraint validation
Security bypass due to improper DNS name constraint validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-295. Affected package(s): python-cryptography-main. Resolved in Red Hat advisory RHSA-2026:7295 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-21715] Information disclosure due to `fs.realpathSync.native()` bypassing filesystem read restrictions
Information disclosure due to `fs.realpathSync.native()` bypassing filesystem read restrictions. Red Hat rates this low (CVSS 3.3). Weakness: CWE-425. Affected package(s): nodejs24, nodejs:24. Resolved in Red Hat advisory RHSA-2026:7350 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Low [CVE-2026-21716] Permission bypass allows unauthorized modification of file permissions and ownership via incomplete security fix.
Permission bypass allows unauthorized modification of file permissions and ownership via incomplete security fix.. Red Hat rates this low (CVSS 3.8). Weakness: CWE-279. Affected package(s): nodejs20-main, nodejs25-main, nodejs24, nodejs22-main, nodejs:24, nodejs24-main. Resolved in Red Hat advisory RHSA-2026:7350 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Low [CVE-2026-4874] Server-Side Request Forgery via OIDC token endpoint manipulation
Server-Side Request Forgery via OIDC token endpoint manipulation. Red Hat rates this low (CVSS 3.1). Weakness: CWE-918. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.