Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.5Vendor: LowRed Hat

Medium [CVE-2026-34487] Information disclosure via sensitive data in log files

Information disclosure via sensitive data in log files. Red Hat rates this low (CVSS 6.5). Weakness: CWE-538. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-34487
Unclassified
Apr 9, 2026
Medium5.4Vendor: LowRed Hat

Medium [CVE-2026-34483] Information disclosure due to improper encoding in JsonAccessLogValve

Information disclosure due to improper encoding in JsonAccessLogValve. Red Hat rates this low (CVSS 5.4). Weakness: CWE-838. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-34483
Unclassified
Apr 9, 2026
Medium5.9Red Hat

Medium [CVE-2026-29145] Authentication bypass due to CLIENT_CERT soft fail misconfiguration

Authentication bypass due to CLIENT_CERT soft fail misconfiguration. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-303. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-29145
Unclassified
Apr 9, 2026
Medium4.3Vendor: LowRed Hat

Medium [CVE-2026-25854] Open Redirect vulnerability via LoadBalancerDrainingValve

Open Redirect vulnerability via LoadBalancerDrainingValve. Red Hat rates this low (CVSS 4.3). Weakness: CWE-601. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-25854
Unclassified
Apr 9, 2026
Medium4.3Vendor: LowRed Hat

Medium [CVE-2026-24880] HTTP Request/Response Smuggling via invalid chunk extension

HTTP Request/Response Smuggling via invalid chunk extension. Red Hat rates this low (CVSS 4.3). Weakness: CWE-444. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-24880
Unclassified
Apr 9, 2026
Medium4.4Red Hat

Medium [CVE-2026-34757] Information disclosure and data corruption via use-after-free vulnerability

Information disclosure and data corruption via use-after-free vulnerability. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-825. Affected package(s): libpng-main. Resolved in Red Hat advisory RHSA-2026:13719 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34757
Unclassified
Apr 9, 2026
Medium6.5Vendor: HighRed Hat

Medium [CVE-2026-2377] Server-Side Request Forgery via log export functionality

Server-Side Request Forgery via log export functionality. Red Hat rates this important (CVSS 6.5). Weakness: CWE-918. Affected package(s): quay/quay-rhel8:1779811473, quay/quay-rhel8:1779689392, quay/quay-rhel8:1779822261, quay/quay-rhel9:1779204086, quay/quay-rhel8:1779811412, quay/quay-rhel8:1780891395. Resolved in Red Hat advisory RHSA-2026:23361 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Quay 3.10; Red Hat Quay 3.12; Red Hat Quay 3.14; Red Hat Quay 3.15; and 3 more.

CVE-2026-2377
Unclassified
Apr 8, 2026
Medium6.4Red Hat

Medium [CVE-2025-57847] privilege escalation via excessive group writable /etc/passwd permissions

A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This vulnerability allows an attacker to add a new user with any arbitrary UID, including UID 0, gaining full root privileges within the container. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5; Red Hat Ansible Automation Platform 2.

CVE-2025-57847
Unclassified
Apr 8, 2026
Medium5.9Red Hat

Medium [CVE-2026-32281] Go crypto/x509: Denial of Service via inefficient certificate chain validation

Go crypto/x509: Denial of Service via inefficient certificate chain validation. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-1050. Affected package(s): grafana-pcp, skopeo, host-metering, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, openshift-service-mesh/kiali-rhel9:1779520708, quay/quay-rhel9:1779922205. Resolved in Red Hat advisory RHSA-2026:10217 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.

CVE-2026-32281
Unclassified
Apr 8, 2026
Medium4.3Red Hat

Medium [CVE-2026-32288] Go's archive/tar package: Denial of Service via maliciously-crafted archive

Go's archive/tar package: Denial of Service via maliciously-crafted archive. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-770. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-32288
Unclassified
Apr 8, 2026
Medium5.4Red Hat

Medium [CVE-2026-32289] Cross-Site Scripting (XSS) via improper context and brace depth tracking in JS template literals

Cross-Site Scripting (XSS) via improper context and brace depth tracking in JS template literals. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-32289
Unclassified
Apr 8, 2026
Medium5.2Vendor: HighRed Hat

Medium [CVE-2026-32591] server-side request forgery in proxy cache upstream registry configuration

server-side request forgery in proxy cache upstream registry configuration. Red Hat rates this important (CVSS 5.2). Weakness: CWE-918. Affected package(s): quay/quay-rhel9:1780604033. Resolved in Red Hat advisory RHSA-2026:24833 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Quay 3.17; mirror registry for Red Hat OpenShift 2; Red Hat Quay 3.9; Red Hat Quay 3.16; and 4 more.

CVE-2026-32591
Unclassified
Apr 8, 2026
Medium6.7Red Hat

Medium [CVE-2026-34079] Arbitrary file deletion on host via improper cache file path validation

Arbitrary file deletion on host via improper cache file path validation. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-22. Affected package(s): flatpak. Resolved in Red Hat advisory RHSA-2026:21757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9.

CVE-2026-34079
Unclassified
Apr 7, 2026
Medium4.0Red Hat

Medium [CVE-2026-39316] Denial of Service and potential arbitrary code execution via use-after-free vulnerability when deleting temporary printers.

Denial of Service and potential arbitrary code execution via use-after-free vulnerability when deleting temporary printers.. Red Hat rates this moderate (CVSS 4). Weakness: CWE-825. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-39316
Unclassified
Apr 7, 2026
Medium4.0Red Hat

Medium [CVE-2026-39314] Denial of Service via integer underflow in IPP attribute handling

Denial of Service via integer underflow in IPP attribute handling. Red Hat rates this moderate (CVSS 4). Weakness: CWE-191. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-39314
Unclassified
Apr 7, 2026
Medium6.8Red Hat

Medium [CVE-2026-35554] Information disclosure and data corruption due to race condition in producer buffer management

Information disclosure and data corruption due to race condition in producer buffer management. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-367. Affected package(s): kafka-clients. Resolved in Red Hat advisory RHSA-2026:11721 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-35554
Unclassified
Apr 7, 2026
Medium5.9Red Hat

Medium [CVE-2026-31790] Information Disclosure from Uninitialized Memory via Invalid RSA Public Key

Information Disclosure from Uninitialized Memory via Invalid RSA Public Key. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-824. Affected package(s): openssl, openssl-fips-provider, rhui5/haproxy-rhel9:1779798164, openssl-main, rhui5/rhua-rhel9:1779798222, openssl-fips-provider-main. Resolved in Red Hat advisory RHSA-2026:28211 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-31790
Unclassified
Apr 7, 2026
Medium5.8Vendor: LowRed Hat

Medium [CVE-2026-31789] Heap buffer overflow on 32-bit systems from large X.509 certificate processing

Heap buffer overflow on 32-bit systems from large X.509 certificate processing. Red Hat rates this low (CVSS 5.8). Weakness: CWE-190. Affected package(s): openssl-main. Resolved in Red Hat advisory RHSA-2026:7261 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-31789
Unclassified
Apr 7, 2026
Medium5.9Vendor: LowRed Hat

Medium [CVE-2026-28389] Denial of Service vulnerability in CMS processing

Denial of Service vulnerability in CMS processing. Red Hat rates this low (CVSS 5.9). Weakness: CWE-166. Affected package(s): openssl-main. Resolved in Red Hat advisory RHSA-2026:7261 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-28389
Unclassified
Apr 7, 2026
Medium5.9Vendor: LowRed Hat

Medium [CVE-2026-28388] Denial of Service due to NULL pointer dereference in delta CRL processing

Denial of Service due to NULL pointer dereference in delta CRL processing. Red Hat rates this low (CVSS 5.9). Weakness: CWE-476. Affected package(s): openssl-main. Resolved in Red Hat advisory RHSA-2026:7261 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-28388
Unclassified
Apr 7, 2026

← All vendors