Red Hat Linux Security Advisories & CVEs
3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-8535] Out of bounds read in Media
Out of bounds read in Media. Red Hat rates this important (CVSS 4.4). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-8516] Insufficient validation of untrusted input in DataTransfer
Insufficient validation of untrusted input in DataTransfer. Red Hat rates this critical (CVSS 6.5). Weakness: CWE-1286. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-6575] Information disclosure via buffer over-read in pg_restore_attribute_stats()
Information disclosure via buffer over-read in pg_restore_attribute_stats(). Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-805. Affected package(s): postgresql17-main, postgresql18-main. Resolved in Red Hat advisory RHSA-2026:22878 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-6475] Operating system account hijack via symlink following in pg_basebackup and pg_rewind
Operating system account hijack via symlink following in pg_basebackup and pg_rewind. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-59. Affected package(s): postgresql, postgresql:12, postgresql:18, postgresql:15, libpq, postgresql16. Resolved in Red Hat advisory RHSA-2026:26561 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
Medium [CVE-2026-6474] Information disclosure via externally-controlled format string in timeofday() function
Information disclosure via externally-controlled format string in timeofday() function. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-134. Affected package(s): postgresql18-main. Resolved in Red Hat advisory RHSA-2026:22878 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-6472] PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege
PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-862. Affected package(s): postgresql17-main, postgresql18-main. Resolved in Red Hat advisory RHSA-2026:22878 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-44431] Information disclosure via cross-origin redirects forwarding sensitive headers
Information disclosure via cross-origin redirects forwarding sensitive headers. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-201. Affected package(s): rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, satellite/iop-yuptoo-rhel9:1782380482, satellite/iop-insights-engine-rhel9:1782448455, satellite/iop-host-inventory-rhel9:1780414237, satellite/iop-puptoo-rhel9:1779792651. Resolved in Red Hat advisory RHSA-2026:26221 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
Medium [CVE-2026-40460] Authorization bypass via IP spoofing in HTTP/3 QUIC module
Authorization bypass via IP spoofing in HTTP/3 QUIC module. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-290. Affected package(s): nginx-main. Resolved in Red Hat advisory RHSA-2026:20351 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-7168] Information disclosure via incorrect Proxy-Authorization header reuse
Information disclosure via incorrect Proxy-Authorization header reuse. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-201. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:19106 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-43515] Improper Authorization allows security bypass
Improper Authorization allows security bypass. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-551. Affected package(s): tomcat11-main. Resolved in Red Hat advisory RHSA-2026:13745 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-43512] Authentication bypass via digest authentication
Authentication bypass via digest authentication. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-303. Affected package(s): tomcat10-main, tomcat11-main, devspaces/server-rhel9:1780694994. Resolved in Red Hat advisory RHSA-2026:25123 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-42498] Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication.
Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication.. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-201. Affected package(s): tomcat10-main, tomcat11-main. Resolved in Red Hat advisory RHSA-2026:13745 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-43896] stack overflow in recursive object merge
stack overflow in recursive object merge. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-674. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:29986 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-43895] embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts
embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-20. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:29986 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-43894] Arbitrary Code Execution or Denial of Service via Signed Integer Overflow
Arbitrary Code Execution or Denial of Service via Signed Integer Overflow. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-190. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:29986 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-41256] embedded NUL truncates top-level jq programs loaded with -f
embedded NUL truncates top-level jq programs loaded with -f. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-158. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:29986 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-40612] stack overflow via unbounded recursion in jv_contains
stack overflow via unbounded recursion in jv_contains. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-674. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:29986 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-41257] signed-int overflow in stack_reallocate
signed-int overflow in stack_reallocate. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-190. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:29986 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-7258] Denial of Service via improper handling of signed characters in ctype functions
Denial of Service via improper handling of signed characters in ctype functions. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-839. Affected package(s): php, php8.4, php:8.2, php:7.4, php:8.3, php-main. Resolved in Red Hat advisory RHSA-2026:22649 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-7259] NULL pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()
NULL pointer dereference in php_mb_check_encoding() via mb_ereg_search_init(). Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-476. Affected package(s): php. Resolved in Red Hat advisory RHSA-2026:33449 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.