Red Hat Linux Security Advisories & CVEs
11820 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-76654] Subpath symlinking on Windows nodes permits NTLM coercion
Subpath symlinking on Windows nodes permits NTLM coercion. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-59. Affected product named by the advisory: Red Hat OpenShift for Windows Containers.
Medium [CVE-2026-2270] StatefulSet and ControllerRevision write permissions allow cross-namespace pod creation
StatefulSet and ControllerRevision write permissions allow cross-namespace pod creation. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-1220. Affected products named by the advisory: Logical Volume Manager Storage; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Edge Manager 1; Red Hat Hardened Images; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat OpenShift GitOps.
Medium [CVE-2026-91992] Credential leak via HTTP client handle reuse
Credential leak via HTTP client handle reuse. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-524. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 11 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 7 more.
Medium [CVE-2026-91991] Cookie attribute injection via capitalized keyword arguments
Cookie attribute injection via capitalized keyword arguments. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-915. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 2 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-91986] Information disclosure and virtual host spoofing via control character injection
Information disclosure and virtual host spoofing via control character injection. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-93. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; and 2 more. Affected products named by the advisory: Red Hat package: igvm; Red Hat package: rust.
Medium [CVE-2026-91962] Remote out-of-bounds access via integer overflow in audin Apple backends
Remote out-of-bounds access via integer overflow in audin Apple backends. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.
Medium [CVE-2026-91961] Denial of Service via URBDRC control-transfer request with invalid OutputBufferSize
Denial of Service via URBDRC control-transfer request with invalid OutputBufferSize. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.
Medium [CVE-2026-91960] Denial of Service via integer overflow and double free in WinPR
Denial of Service via integer overflow and double free in WinPR. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.
Medium [CVE-2026-91959] Denial of Service due to buffer over-read in RPC gateway
Denial of Service due to buffer over-read in RPC gateway. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.
Medium [CVE-2026-91958] Denial of service and potential code execution via malicious RDP file
Denial of service and potential code execution via malicious RDP file. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.
Medium [CVE-2026-91956] Denial of Service via out-of-bounds read in URBDRC channel
Denial of Service via out-of-bounds read in URBDRC channel. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.
Medium [CVE-2026-91954] Denial of Service via crafted Surface Bits command
Denial of Service via crafted Surface Bits command. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.
Medium [CVE-2026-91952] Denial of Service via crafted AVC444 graphics updates
Denial of Service via crafted AVC444 graphics updates. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-606. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.
Medium [CVE-2026-91953] Heap buffer overflow via oversized LB_LOAD_BALANCE_INFO routing token can lead to heap corruption.
Heap buffer overflow via oversized LB_LOAD_BALANCE_INFO routing token can lead to heap corruption. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.
Medium [CVE-2026-91951] Denial of Service via out-of-bounds write in urbdrc client channel
Denial of Service via out-of-bounds write in urbdrc client channel. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.
Medium [CVE-2026-91946] Information Disclosure via RDPGFX ResetGraphics PDU
Information Disclosure via RDPGFX ResetGraphics PDU. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-824. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.
Medium [CVE-2026-91945] Denial of Service due to out-of-bounds read in smartcard response processing
Denial of Service due to out-of-bounds read in smartcard response processing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.
Medium [CVE-2024-58384] CRLF injection in CurlAsyncHTTPClient allows arbitrary header injection or new HTTP requests.
CRLF injection in CurlAsyncHTTPClient allows arbitrary header injection or new HTTP requests. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-93. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 11 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 7 more.
Medium [CVE-2026-55701] github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver: OpenTelemetry Collector Contrib githubreceiver: Unauthorized data injection via authentication bypass
github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver: OpenTelemetry Collector Contrib githubreceiver: Unauthorized data injection via authentication bypass. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:63152 with package opentelemetry-collector-contrib-main-0.160.0-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-54168] github.com/openshift-pipelines/pipelines-as-code: Pipelines-as-Code: Information disclosure via unscoped GitHub App installation token
github.com/openshift-pipelines/pipelines-as-code: Pipelines-as-Code: Information disclosure via unscoped GitHub App installation token. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-862.