Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3066 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.8Red Hat

High [CVE-2026-3061] Out of bounds read in Media

Out of bounds read in Media. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3061
Unclassified
Feb 23, 2026
High8.8Red Hat

High [CVE-2026-3063] Inappropriate implementation in DevTools

Inappropriate implementation in DevTools. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3063
Unclassified
Feb 23, 2026
High8.1Red Hat

High [CVE-2026-27134] Unauthorized authentication via misconfigured mTLS CA chain

Unauthorized authentication via misconfigured mTLS CA chain. Red Hat rates this important (CVSS 8.1). Weakness: CWE-295. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27134
Unclassified
Feb 20, 2026
High7.3Red Hat

High [CVE-2026-2635] MLflow Use of Default Password Authentication Bypass Vulnerability

MLflow Use of Default Password Authentication Bypass Vulnerability. Red Hat rates this important (CVSS 7.3). Weakness: CWE-798. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2635
Unclassified
Feb 20, 2026
High7.8Red Hat

High [CVE-2026-2048] Remote Code Execution via XWD file parsing vulnerability

Remote Code Execution via XWD file parsing vulnerability. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:5391 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 8 more.

CVE-2026-2048
Unclassified
Feb 20, 2026
High7.8Red Hat

High [CVE-2026-2047] Remote code execution via heap-based buffer overflow in ICNS file parsing

Remote code execution via heap-based buffer overflow in ICNS file parsing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. Affected package(s): gimp. Resolved in Red Hat advisory RHSA-2026:4173 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-2047
Unclassified
Feb 20, 2026
High7.3Red Hat

High [CVE-2026-2045] Remote Code Execution via out-of-bounds write in XWD file parsing

Remote Code Execution via out-of-bounds write in XWD file parsing. Red Hat rates this important (CVSS 7.3). Weakness: CWE-787. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:5391 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 8 more.

CVE-2026-2045
Unclassified
Feb 20, 2026
High8.8Red Hat

High [CVE-2026-2044] Remote Code Execution via uninitialized memory in PGM file parsing

Remote Code Execution via uninitialized memory in PGM file parsing. Red Hat rates this important (CVSS 8.8). Weakness: CWE-908. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:5391 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 8 more.

CVE-2026-2044
Unclassified
Feb 20, 2026
High7.8Red Hat

High [CVE-2026-2492] Local privilege escalation via uncontrolled search path for plugins

Local privilege escalation via uncontrolled search path for plugins. Red Hat rates this important (CVSS 7.8). Weakness: CWE-427. Affected package(s): rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9:1776243249, rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1776319453. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat OpenShift AI 2.25.

CVE-2026-2492
Unclassified
Feb 20, 2026
High7.3Red Hat

High [CVE-2026-2033] MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. Red Hat rates this important (CVSS 7.3). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2033
Unclassified
Feb 20, 2026
High8.8Red Hat

High [CVE-2026-0797] Remote Code Execution via ICO File Parsing Vulnerability

Remote Code Execution via ICO File Parsing Vulnerability. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:5391 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 8 more.

CVE-2026-0797
Unclassified
Feb 20, 2026
High7.1Red Hat

High [CVE-2026-25896] Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling

Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling. Red Hat rates this important (CVSS 7.1). Weakness: CWE-79. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.8; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9; and 8 more.

CVE-2026-25896
Unclassified
Feb 20, 2026
High8.1Red Hat

High [CVE-2026-2472] Arbitrary code execution via Stored Cross-Site Scripting (XSS)

Arbitrary code execution via Stored Cross-Site Scripting (XSS). Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. Affected package(s): rhoai/odh-llama-stack-core-rhel9:1775144403. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Vertex AI SDK for Python; Red Hat OpenShift AI 2.25.

CVE-2026-2472
Unclassified
Feb 20, 2026
High7.1Red Hat

High [CVE-2026-2818] org.springframework.data/spring-data-geode: Spring Data Geode: Path traversal vulnerability allows arbitrary file write via import snapshot functionality.

org.springframework.data/spring-data-geode: Spring Data Geode: Path traversal vulnerability allows arbitrary file write via import snapshot functionality.. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2818
Unclassified
Feb 20, 2026
High7.1Vendor: MediumRed Hat

High [CVE-2026-26960] Arbitrary file read/write via malicious archive hardlink creation

Arbitrary file read/write via malicious archive hardlink creation. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-22. Affected package(s): rhtas/rekor-search-ui-rhel9:1773308315, network-observability/network-observability-console-plugin-rhel9:1774431617, devspaces/dashboard-rhel9:1774476526, devspaces/code-rhel9:1774448966. Resolved in Red Hat advisory RHSA-2026:5447 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-26960
Unclassified
Feb 20, 2026
High8.4Red Hat

High [CVE-2026-26967] Arbitrary code execution via H.264 unpacketizer heap-based buffer overflow

Arbitrary code execution via H.264 unpacketizer heap-based buffer overflow. Red Hat rates this important (CVSS 8.4). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-26967
Unclassified
Feb 20, 2026
High7.4Red Hat

High [CVE-2024-7730 +1] heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for CVE-2024-7730)

heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for CVE-2024-7730). Red Hat rates this important (CVSS 7.4). Weakness: CWE-122. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2024-7730CVE-2026-3195
Unclassified
Feb 20, 2026
High8.8Red Hat

High [CVE-2026-26318] Arbitrary code execution via unsanitized `locate` output

Arbitrary code execution via unsanitized `locate` output. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Developer Hub.

CVE-2026-26318
Unclassified
Feb 19, 2026
High8.4Red Hat

High [CVE-2026-26280] Arbitrary command execution via unsanitized network interface parameter

Arbitrary command execution via unsanitized network interface parameter. Red Hat rates this important (CVSS 8.4). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Developer Hub.

CVE-2026-26280
Unclassified
Feb 19, 2026
High7.5Red Hat

High [CVE-2026-26278] Denial of Service via unlimited XML entity expansion

Denial of Service via unlimited XML entity expansion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.8; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9; and 8 more.

CVE-2026-26278
Unclassified
Feb 19, 2026

← All vendors