Red Hat Linux Security Advisories & CVEs
3066 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2025-15381] Information disclosure and unauthorized data modification via unprotected tracing and assessment endpoints
Information disclosure and unauthorized data modification via unprotected tracing and assessment endpoints. Red Hat rates this important (CVSS 8.1). Weakness: CWE-425. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-28369] request smuggling via malformed http request headers
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. Request smuggling allows an attacker to bypass security mechanisms, access restricted information, or manipulate web caches, potentially leading to unauthorized actions or data exposure. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Data Grid 8; and 7 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 2 more.
High [CVE-2026-27880] Denial of Service via unbounded memory read in feature toggle evaluation
Denial of Service via unbounded memory read in feature toggle evaluation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
High [CVE-2026-27877] Information disclosure of data-source passwords via public dashboards
Information disclosure of data-source passwords via public dashboards. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected package(s): grafana. Resolved in Red Hat advisory RHSA-2026:11416 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support.
High [CVE-2026-33433] Authentication bypass via non-canonical HTTP header injection
Authentication bypass via non-canonical HTTP header injection. Red Hat rates this important (CVSS 7.7). Weakness: CWE-290. Affected package(s): devspaces/traefik-rhel9:1776718585. Resolved in Red Hat advisory RHSA-2026:10175 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat OpenShift Dev Spaces 3.27.
High [CVE-2026-32695] Cross-tenant traffic exposure and host restriction bypass via rule-syntax injection in Knative provider
Cross-tenant traffic exposure and host restriction bypass via rule-syntax injection in Knative provider. Red Hat rates this important (CVSS 7.7). Weakness: CWE-917. Affected package(s): devspaces/traefik-rhel9:1776718585. Resolved in Red Hat advisory RHSA-2026:10175 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat OpenShift Dev Spaces 3.27.
High [CVE-2026-27858] denial of service via crafted message before authentication
denial of service via crafted message before authentication. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 10 more.
High [CVE-2026-27857] denial of service via specially crafted NOOP command
denial of service via specially crafted NOOP command. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 10 more.
High [CVE-2026-27856] Full access via timing oracle attack in credential verification
Full access via timing oracle attack in credential verification. Red Hat rates this important (CVSS 7.4). Weakness: CWE-208. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 6.
High [CVE-2026-24031] Authentication bypass and user enumeration due to cleared auth_username_chars configuration
Authentication bypass and user enumeration due to cleared auth_username_chars configuration. Red Hat rates this important (CVSS 7.7). Weakness: CWE-89. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 6.
High [CVE-2025-59032] Denial of Service via crafted SASL initial response in AUTHENTICATE command
Denial of Service via crafted SASL initial response in AUTHENTICATE command. Red Hat rates this important (CVSS 7.5). Weakness: CWE-229. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 10 more.
High [CVE-2026-33747] Arbitrary file write and code execution via untrusted frontend
Arbitrary file write and code execution via untrusted frontend. Red Hat rates this moderate (CVSS 8.2). Weakness: CWE-22. Affected package(s): openshift-service-mesh/istio-proxyv2-rhel9:1776240392, quay/quay-rhel9:1779922205, multicluster-engine/must-gather-rhel9:1782158798, openshift-service-mesh/istio-proxyv2-rhel9:1776291540, openshift-service-mesh/istio-proxyv2-rhel9:1776315466, oadp/oadp-mustgather-rhel9:1779770049. Resolved in Red Hat advisory RHSA-2026:9453 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-33721] Denial of Service via crafted Styled Layer Descriptor
Denial of Service via crafted Styled Layer Descriptor. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-33701] io.opentelemetry.javaagent/opentelemetry-javaagent: OpenTelemetry Java Instrumentation: Remote code execution via deserialization vulnerability in RMI
io.opentelemetry.javaagent/opentelemetry-javaagent: OpenTelemetry Java Instrumentation: Remote code execution via deserialization vulnerability in RMI. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat JBoss Enterprise Application Platform Expansion Pack.
High [CVE-2026-27893] Remote code execution due to hardcoded trust_remote_code setting
Remote code execution due to hardcoded trust_remote_code setting. Red Hat rates this important (CVSS 8.8). Weakness: CWE-501. Affected package(s): rhaiis/vllm-cuda-rhel9:1779223654, rhelai3/bootc-azure-cuda-rhel9:1776871985, rhelai3/bootc-aws-cuda-rhel9:1776871984, rhaiis/model-opt-cuda-rhel9:1775749857, rhaiis/vllm-rocm-rhel9:1775680262, rhaiis/vllm-rocm-rhel9:1779223651. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat AI Inference Server 3.2; Red Hat AI Inference Server 3.3; Red Hat Enterprise Linux AI 3.3; Red Hat OpenShift AI 2.25; and 1 more.
High [CVE-2026-33898] Privilege escalation and unauthorized access due to improper authentication token validation in web UI
Privilege escalation and unauthorized access due to improper authentication token validation in web UI. Red Hat rates this important (CVSS 8.2). Weakness: CWE-303. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-33711] Local privilege escalation or denial of service via predictable temporary file paths
Local privilege escalation or denial of service via predictable temporary file paths. Red Hat rates this important (CVSS 8.8). Weakness: CWE-59. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-33542] Image cache poisoning due to insufficient image fingerprint validation
Image cache poisoning due to insufficient image fingerprint validation. Red Hat rates this important (CVSS 8.5). Weakness: CWE-354. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-1556] File (Field) Paths: Drupal File (Field) Paths: Information Disclosure via filename-collision uploads
File (Field) Paths: Drupal File (Field) Paths: Information Disclosure via filename-collision uploads. Red Hat rates this important (CVSS 7.7). Weakness: CWE-73. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-32285] Denial of Service via malformed JSON input
Denial of Service via malformed JSON input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1285. Affected package(s): multicluster-engine/assisted-service, syft-main, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, trivy-main, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Logging Subsystem for Red Hat OpenShift 6.4; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Hardened Images; and 13 more.