Red Hat Linux Security Advisories & CVEs
3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-34487] Information disclosure via sensitive data in log files
Information disclosure via sensitive data in log files. Red Hat rates this low (CVSS 6.5). Weakness: CWE-538. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-34483] Information disclosure due to improper encoding in JsonAccessLogValve
Information disclosure due to improper encoding in JsonAccessLogValve. Red Hat rates this low (CVSS 5.4). Weakness: CWE-838. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-29145] Authentication bypass due to CLIENT_CERT soft fail misconfiguration
Authentication bypass due to CLIENT_CERT soft fail misconfiguration. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-303. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-25854] Open Redirect vulnerability via LoadBalancerDrainingValve
Open Redirect vulnerability via LoadBalancerDrainingValve. Red Hat rates this low (CVSS 4.3). Weakness: CWE-601. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-24880] HTTP Request/Response Smuggling via invalid chunk extension
HTTP Request/Response Smuggling via invalid chunk extension. Red Hat rates this low (CVSS 4.3). Weakness: CWE-444. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-34757] Information disclosure and data corruption via use-after-free vulnerability
Information disclosure and data corruption via use-after-free vulnerability. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-825. Affected package(s): libpng-main. Resolved in Red Hat advisory RHSA-2026:13719 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-2377] Server-Side Request Forgery via log export functionality
Server-Side Request Forgery via log export functionality. Red Hat rates this important (CVSS 6.5). Weakness: CWE-918. Affected package(s): quay/quay-rhel8:1779811473, quay/quay-rhel8:1779689392, quay/quay-rhel8:1779822261, quay/quay-rhel9:1779204086, quay/quay-rhel8:1779811412, quay/quay-rhel8:1780891395. Resolved in Red Hat advisory RHSA-2026:23361 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Quay 3.10; Red Hat Quay 3.12; Red Hat Quay 3.14; Red Hat Quay 3.15; and 3 more.
Medium [CVE-2025-57847] privilege escalation via excessive group writable /etc/passwd permissions
A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This vulnerability allows an attacker to add a new user with any arbitrary UID, including UID 0, gaining full root privileges within the container. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5; Red Hat Ansible Automation Platform 2.
Medium [CVE-2026-32281] Go crypto/x509: Denial of Service via inefficient certificate chain validation
Go crypto/x509: Denial of Service via inefficient certificate chain validation. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-1050. Affected package(s): grafana-pcp, skopeo, host-metering, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, openshift-service-mesh/kiali-rhel9:1779520708, quay/quay-rhel9:1779922205. Resolved in Red Hat advisory RHSA-2026:10217 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.
Medium [CVE-2026-32288] Go's archive/tar package: Denial of Service via maliciously-crafted archive
Go's archive/tar package: Denial of Service via maliciously-crafted archive. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-770. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-32289] Cross-Site Scripting (XSS) via improper context and brace depth tracking in JS template literals
Cross-Site Scripting (XSS) via improper context and brace depth tracking in JS template literals. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-32591] server-side request forgery in proxy cache upstream registry configuration
server-side request forgery in proxy cache upstream registry configuration. Red Hat rates this important (CVSS 5.2). Weakness: CWE-918. Affected package(s): quay/quay-rhel9:1780604033. Resolved in Red Hat advisory RHSA-2026:24833 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Quay 3.17; mirror registry for Red Hat OpenShift 2; Red Hat Quay 3.9; Red Hat Quay 3.16; and 4 more.
Medium [CVE-2026-34079] Arbitrary file deletion on host via improper cache file path validation
Arbitrary file deletion on host via improper cache file path validation. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-22. Affected package(s): flatpak. Resolved in Red Hat advisory RHSA-2026:21757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9.
Medium [CVE-2026-39316] Denial of Service and potential arbitrary code execution via use-after-free vulnerability when deleting temporary printers.
Denial of Service and potential arbitrary code execution via use-after-free vulnerability when deleting temporary printers.. Red Hat rates this moderate (CVSS 4). Weakness: CWE-825. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-39314] Denial of Service via integer underflow in IPP attribute handling
Denial of Service via integer underflow in IPP attribute handling. Red Hat rates this moderate (CVSS 4). Weakness: CWE-191. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-35554] Information disclosure and data corruption due to race condition in producer buffer management
Information disclosure and data corruption due to race condition in producer buffer management. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-367. Affected package(s): kafka-clients. Resolved in Red Hat advisory RHSA-2026:11721 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-31790] Information Disclosure from Uninitialized Memory via Invalid RSA Public Key
Information Disclosure from Uninitialized Memory via Invalid RSA Public Key. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-824. Affected package(s): openssl, openssl-fips-provider, rhui5/haproxy-rhel9:1779798164, openssl-main, rhui5/rhua-rhel9:1779798222, openssl-fips-provider-main. Resolved in Red Hat advisory RHSA-2026:28211 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-31789] Heap buffer overflow on 32-bit systems from large X.509 certificate processing
Heap buffer overflow on 32-bit systems from large X.509 certificate processing. Red Hat rates this low (CVSS 5.8). Weakness: CWE-190. Affected package(s): openssl-main. Resolved in Red Hat advisory RHSA-2026:7261 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-28389] Denial of Service vulnerability in CMS processing
Denial of Service vulnerability in CMS processing. Red Hat rates this low (CVSS 5.9). Weakness: CWE-166. Affected package(s): openssl-main. Resolved in Red Hat advisory RHSA-2026:7261 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-28388] Denial of Service due to NULL pointer dereference in delta CRL processing
Denial of Service due to NULL pointer dereference in delta CRL processing. Red Hat rates this low (CVSS 5.9). Weakness: CWE-476. Affected package(s): openssl-main. Resolved in Red Hat advisory RHSA-2026:7261 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.