Red Hat Linux Security Advisories & CVEs
3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-9704] Privilege escalation due to oversized subject_token JWT
Privilege escalation due to oversized subject_token JWT. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-1284. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-2340] vfs_worm does not block directory modification
vfs_worm does not block directory modification. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-280. Affected package(s): samba, rhcos. Resolved in Red Hat advisory RHSA-2026:29863 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; and 6 more.
Medium [CVE-2026-9689] http parameter pollution in oidc redirect uri allows response parameter duplication - #ghi-604
A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the client application might incorrectly prioritize attacker-controlled information over legitimate data. This vulnerability, known as HTTP parameter pollution, could allow an attacker to bypass security measures or gain unauthorized access to resources. Affected products named by the advisory: Red Hat build of Keycloak 26.4; Red Hat build of Keycloak 26.6.
Medium [CVE-2026-9980] Insufficient validation of untrusted input in Printing
Insufficient validation of untrusted input in Printing. Red Hat rates this important (CVSS 6.7). Weakness: CWE-1286. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-9917] Uninitialized Use in WebGL
Uninitialized Use in WebGL. Red Hat rates this important (CVSS 6.5). Weakness: CWE-824. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-10004] Insufficient validation of untrusted input in Passwords
Insufficient validation of untrusted input in Passwords. Red Hat rates this important (CVSS 5.4). Weakness: CWE-1173. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-9959] Race in WebRTC
Race in WebRTC. Red Hat rates this important (CVSS 6.5). Weakness: CWE-366. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-9986] Insufficient validation of untrusted input in OptimizationGuide
Insufficient validation of untrusted input in OptimizationGuide. Red Hat rates this important (CVSS 5.7). Weakness: CWE-1289. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-9920] Uninitialized Use in GPU
Uninitialized Use in GPU. Red Hat rates this important (CVSS 5.8). Weakness: CWE-824. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-9985] Insufficient validation of untrusted input in Media
Insufficient validation of untrusted input in Media. Red Hat rates this important (CVSS 4.8). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-10008] Uninitialized Use in GPU
Uninitialized Use in GPU. Red Hat rates this important (CVSS 6.5). Weakness: CWE-824. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-9944] Uninitialized Use in ANGLE
Uninitialized Use in ANGLE. Red Hat rates this important (CVSS 6.8). Weakness: CWE-824. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-9996] Out of bounds read in WebRTC
Out of bounds read in WebRTC. Red Hat rates this important (CVSS 6.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-9981] Inappropriate implementation in Skia
Inappropriate implementation in Skia. Red Hat rates this important (CVSS 6.5). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-10011] Inappropriate implementation in Skia
Inappropriate implementation in Skia. Red Hat rates this important (CVSS 6.8). Weakness: CWE-346. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-9929] Inappropriate implementation in WebGL
Inappropriate implementation in WebGL. Red Hat rates this important (CVSS 6.5). Weakness: CWE-346. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-9935] Uninitialized Use in ANGLE
Uninitialized Use in ANGLE. Red Hat rates this important (CVSS 6.5). Weakness: CWE-824. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-9911] Integer overflow in ANGLE
Integer overflow in ANGLE. Red Hat rates this important (CVSS 6.5). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-9912] Inappropriate implementation in GPU
Inappropriate implementation in GPU. Red Hat rates this important (CVSS 6.5). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-10010] Inappropriate implementation in Input
Inappropriate implementation in Input. Red Hat rates this important (CVSS 5.8). Weakness: CWE-653. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.