Red Hat Linux Security Advisories & CVEs
284 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Low [CVE-2026-2297] Logging Bypass in Legacy .pyc File Handling
Logging Bypass in Legacy.pyc File Handling. Red Hat rates this low (CVSS 3.3). Weakness: CWE-778. Affected package(s): python3.12, python3, python3.14, rhui5/rhua-rhel9:1779798222, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:19019 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.
Low [CVE-2025-12150] webauthn attestation statement verification bypass
A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration. Affected products named by the advisory: Red Hat build of Keycloak 26.2; Red Hat build of Keycloak 26.4.
Low [CVE-2026-3184] Access control bypass due to improper hostname canonicalization
Access control bypass due to improper hostname canonicalization. Red Hat rates this low (CVSS 3.7). Weakness: CWE-289. Affected package(s): util-linux-main. Resolved in Red Hat advisory RHSA-2026:7180 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-2791] Mitigation bypass in the Networking: Cache component
Mitigation bypass in the Networking: Cache component. Red Hat rates this low (CVSS 3.4). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.
Low [CVE-2026-2790] Same-origin policy bypass in the Networking: JAR component
Same-origin policy bypass in the Networking: JAR component. Red Hat rates this low (CVSS 3.4). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.
Low [CVE-2026-2733] Missing Check on Disabled Client for Docker Registry Protocol
Missing Check on Disabled Client for Docker Registry Protocol. Red Hat rates this low (CVSS 3.8). Weakness: CWE-285. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.10, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:3947 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-2366] Information disclosure via authorization bypass in Admin API
Information disclosure via authorization bypass in Admin API. Red Hat rates this low (CVSS 3.1). Weakness: CWE-639. Affected package(s): rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-0965] Denial of Service via improper configuration file handling
Denial of Service via improper configuration file handling. Red Hat rates this low (CVSS 3.3). Weakness: CWE-73. Affected package(s): libssh. Resolved in Red Hat advisory RHSA-2026:18160 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Low [CVE-2026-0967] Denial of Service via inefficient regular expression processing
Denial of Service via inefficient regular expression processing. Red Hat rates this low (CVSS 2.2). Weakness: CWE-1333. Affected package(s): libssh. Resolved in Red Hat advisory RHSA-2026:18160 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Low [CVE-2026-0968] Denial of Service due to malformed SFTP message
Denial of Service due to malformed SFTP message. Red Hat rates this low (CVSS 3.1). Weakness: CWE-476. Affected package(s): libssh. Resolved in Red Hat advisory RHSA-2026:18160 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Low [CVE-2026-1703] Information disclosure via path traversal when installing crafted wheel archives
Information disclosure via path traversal when installing crafted wheel archives. Red Hat rates this low (CVSS 3.9). Weakness: CWE-22. Affected package(s): python-pip-main. Resolved in Red Hat advisory RHSA-2026:7610 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2025-13881] Limited administrator can retrieve sensitive user attributes via Admin API
Limited administrator can retrieve sensitive user attributes via Admin API. Red Hat rates this low (CVSS 2.7). Weakness: CWE-266. Affected package(s): keycloak, rhbk/keycloak-operator-bundle:26.4.9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:2366 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-1035] Keycloak Refresh Token Reuse Bypass via TOCTOU Race Condition
Keycloak Refresh Token Reuse Bypass via TOCTOU Race Condition. Red Hat rates this low (CVSS 3.1). Weakness: CWE-367. Affected package(s): rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-1190] Keycloak SAML brokering: Response delay due to unchecked NotOnOrAfter in SubjectConfirmationData
Keycloak SAML brokering: Response delay due to unchecked NotOnOrAfter in SubjectConfirmationData. Red Hat rates this low (CVSS 3.1). Weakness: CWE-112. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.10, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:3947 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-0976] proxy bypass due to improper handling of matrix parameters in url paths
A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant matrix parameters in URL path segments, while common reverse proxy configurations may ignore or mishandle them. A remote attacker can craft requests to mask path segments, potentially bypassing proxy-level path filtering. This could expose administrative or sensitive endpoints that operators believe are not externally reachable. This vulnerability is rated Low for Red Hat Keycloak. The flaw arises from Keycloak's acceptance of RFC-compliant matrix parameters in URL paths, which can be mishandled by certain reverse proxy configurations. Exploitation depends on the specific reverse proxy configuration. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-20. Affected Red Hat products: Red Hat Build of Keycloak; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack. Red Hat does not currently list a fixing RHSA for this CVE.
Low [CVE-2026-0988] Denial of Service via Integer Overflow in g_buffered_input_stream_peek()
Denial of Service via Integer Overflow in g_buffered_input_stream_peek(). Red Hat rates this low (CVSS 3.7). Weakness: CWE-190. Affected package(s): glib2-main. Resolved in Red Hat advisory RHSA-2026:7461 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-0989] Unbounded RelaxNG Include Recursion Leading to Stack Overflow
Unbounded RelaxNG Include Recursion Leading to Stack Overflow. Red Hat rates this low (CVSS 3.7). Weakness: CWE-674. Affected package(s): libxml2-main. Resolved in Red Hat advisory RHSA-2026:7519 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-0992] Denial of Service via crafted XML catalogs
Denial of Service via crafted XML catalogs. Red Hat rates this low (CVSS 2.9). Weakness: CWE-400. Affected package(s): libxml2-main. Resolved in Red Hat advisory RHSA-2026:7519 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-22036] Denial of Service via excessive decompression steps
Denial of Service via excessive decompression steps. Red Hat rates this low (CVSS 3.7). Weakness: CWE-770. Affected package(s): rhdh/rhdh-hub-rhel9:1780930740. Resolved in Red Hat advisory RHSA-2026:24841 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-0890] Spoofing issue in the DOM: Copy & Paste and Drag & Drop component
Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. Red Hat rates this low (CVSS 3.4). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:1413 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.