Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

411 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Critical9.0Red Hat

Critical [CVE-2026-2651] Arbitrary code execution via unauthorized multipart upload access

Arbitrary code execution via unauthorized multipart upload access. Red Hat rates this critical (CVSS 9). Weakness: CWE-1220. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2651
Unclassified
May 25, 2026
Critical9.8Vendor: HighRed Hat

Critical [CVE-2026-8631] Arbitrary code execution and privilege escalation via integer overflow in hpcups

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path when handling crafted print data. A remote attacker who can submit print job content to the hpcups filter path may achieve arbitrary code execution or privilege escalation on systems using HPLIP for printing. Red Hat severity: Important — CVSS 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 6.

CVE-2026-8631
Unclassified
May 20, 2026
Critical9.8Red Hat

Critical [CVE-2026-47323] Remote Code Execution via header injection due to missing inbound filtering

Remote Code Execution via header injection due to missing inbound filtering. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-791. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: OpenShift Serverless.

CVE-2026-47323
Unclassified
May 19, 2026
Critical9.6Red Hat

Critical [CVE-2026-2611] Arbitrary Code Execution via Improper Origin Validation

Arbitrary Code Execution via Improper Origin Validation. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-940. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2611
Unclassified
May 19, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-9118] Use after free in XR

Use after free in XR. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9118
Unclassified
May 19, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-9120] Use after free in WebRTC

Use after free in WebRTC. Red Hat rates this important (CVSS 9.6). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9120
Unclassified
May 19, 2026
Critical9.3Vendor: HighRed Hat

Critical [CVE-2026-9115] Insufficient policy enforcement in Service Worker

Insufficient policy enforcement in Service Worker. Red Hat rates this important (CVSS 9.3). Weakness: CWE-940. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9115
Unclassified
May 19, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-9119] Heap buffer overflow in WebRTC

Heap buffer overflow in WebRTC. Red Hat rates this important (CVSS 9.6). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9119
Unclassified
May 19, 2026
Critical9.8Vendor: HighRed Hat

Critical [CVE-2026-9114] Use after free in QUIC

Use after free in QUIC. Red Hat rates this important (CVSS 9.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9114
Unclassified
May 19, 2026
Critical10.0Red Hat

Critical [CVE-2026-45829] Arbitrary code execution via pre-authentication code injection

Arbitrary code execution via pre-authentication code injection. Red Hat rates this critical (CVSS 10). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux; python.

CVE-2026-45829
Unclassified
May 18, 2026
Critical9.8Red Hat

Critical [CVE-2021-47952] Arbitrary Code Execution via Malicious JSON Deserialization

Arbitrary Code Execution via Malicious JSON Deserialization. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: python jsonpickle.

CVE-2021-47952
Unclassified
May 16, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-42327] Arbitrary code execution via specially crafted certificate

Arbitrary code execution via specially crafted certificate. Red Hat rates this important (CVSS 9.1). Weakness: CWE-475. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-42327
Unclassified
May 14, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-8554] Type Confusion in ANGLE

Type Confusion in ANGLE. Red Hat rates this important (CVSS 9). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8554
Unclassified
May 14, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-8548] Out of bounds write in Media

Out of bounds write in Media. Red Hat rates this important (CVSS 9). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8548
Unclassified
May 14, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-8547] Insufficient policy enforcement in Passwords

Insufficient policy enforcement in Passwords. Red Hat rates this important (CVSS 9). Weakness: CWE-266. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8547
Unclassified
May 14, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-8534] Integer overflow in GPU

Integer overflow in GPU. Red Hat rates this important (CVSS 9). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8534
Unclassified
May 14, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-8533] Use after free in Accessibility

Use after free in Accessibility. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8533
Unclassified
May 14, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-8531] Heap buffer overflow in WebML

Heap buffer overflow in WebML. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8531
Unclassified
May 14, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-8525] Heap buffer overflow in ANGLE

Heap buffer overflow in ANGLE. Red Hat rates this important (CVSS 9.6). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8525
Unclassified
May 14, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-8526] Out of bounds write in WebRTC

Out of bounds write in WebRTC. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8526
Unclassified
May 14, 2026

← All vendors