Red Hat Linux Security Advisories & CVEs
3066 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-2315] Inappropriate implementation in WebGPU
Inappropriate implementation in WebGPU. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-2314] Heap buffer overflow in Codecs
Heap buffer overflow in Codecs. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-25639] Axios affected by Denial of Service via __proto__ Key in mergeConfig
Axios affected by Denial of Service via __proto__ Key in mergeConfig. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1287. Affected package(s): rhoai/odh-mod-arch-gen-ai-rhel9:1778473763, rhoai/odh-dashboard-rhel9:1779189627, multicluster-engine/console-mce-rhel9:1776223790, ansible-automation-platform, openshift-service-mesh/kiali-ossmc-rhel9:1771372942, rhoai/odh-dashboard-rhel9:1776742021. Resolved in Red Hat advisory RHSA-2026:3107 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.12; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; and 35 more.
High [CVE-2026-1609] Unauthorized Access via JWT authorization grant with disabled users
Unauthorized Access via JWT authorization grant with disabled users. Red Hat rates this important (CVSS 8.1). Weakness: CWE-284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-1486] Disabled identity providers are still accepted for JWT Authorization Grant
Disabled identity providers are still accepted for JWT Authorization Grant. Red Hat rates this important (CVSS 8.8). Weakness: CWE-358. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:2366 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat build of Keycloak 26.4.
High [CVE-2026-1529] Unauthorized organization registration via improper invitation token validation
Unauthorized organization registration via improper invitation token validation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-347. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.2.13, rhbk/keycloak-operator-bundle:26.4.9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:2366 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.2; Red Hat build of Keycloak 26.4.
High [CVE-2025-66630] Predictable UUIDs from randomness source errors can lead to security bypasses
Predictable UUIDs from randomness source errors can lead to security bypasses. Red Hat rates this important (CVSS 7.7). Weakness: CWE-331. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-1584] Remote Denial of Service via crafted ClientHello with invalid PSK binder
Remote Denial of Service via crafted ClientHello with invalid PSK binder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Affected package(s): gnutls-main. Resolved in Red Hat advisory RHSA-2026:7477 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-25793] Blocklist evasion via ECDSA Signature Malleability
Blocklist evasion via ECDSA Signature Malleability. Red Hat rates this important (CVSS 8.1). Weakness: CWE-347. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-25749] Arbitrary code execution via 'helpfile' option processing
Arbitrary code execution via 'helpfile' option processing. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-120. Affected package(s): rhcos, rhaiis/vllm-rocm-rhel9:1778244531, rhui5/haproxy-rhel9:1776868744, rhui5/installer-rhel9:1776868772, vim, rhui5/cds-rhel9:1776868774. Resolved in Red Hat advisory RHSA-2026:4715 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
High [CVE-2026-25580] Information disclosure via Server-Side Request Forgery (SSRF) through malicious URLs in message history.
Information disclosure via Server-Side Request Forgery (SSRF) through malicious URLs in message history.. Red Hat rates this important (CVSS 8.6). Weakness: CWE-918. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.
High [CVE-2026-25731] Arbitrary Code Execution via malicious custom template file during ebook conversion
Arbitrary Code Execution via malicious custom template file during ebook conversion. Red Hat rates this important (CVSS 7.8). Weakness: CWE-917. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-25635] Remote Code Execution via path traversal in CHM reader
Remote Code Execution via path traversal in CHM reader. Red Hat rates this important (CVSS 8.6). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-25636] Arbitrary file corruption via path traversal in EPUB conversion
Arbitrary file corruption via path traversal in EPUB conversion. Red Hat rates this important (CVSS 8.2). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-25640] Arbitrary code execution and information disclosure via path traversal in web UI
Arbitrary code execution and information disclosure via path traversal in web UI. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.
High [CVE-2026-23740] Arbitrary code execution and file overwrite as root via insecure ast_coredumper file handling
Arbitrary code execution and file overwrite as root via insecure ast_coredumper file handling. Red Hat rates this important (CVSS 7.8). Weakness: CWE-379. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2025-68121] Incorrect certificate validation during TLS session resumption
Incorrect certificate validation during TLS session resumption. Red Hat rates this moderate (CVSS 7.4). Affected package(s): openshift4/openshift-route-controller-manager-rhel8:1781867531, openshift4/ose-gcp-cloud-controller-manager-rhel9:1781927538, openshift4/ose-csi-livenessprobe-rhel8:1776999947, openshift4/oc-mirror-plugin-rhel8:1781822901, openshift4/ose-csi-external-snapshotter-rhel8:1776999951, openshift4/ose-prometheus-node-exporter-rhel9:1774294099. Resolved in Red Hat advisory RHSA-2026:5968 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2025-61732] Go cgo: Code smuggling due to comment parsing discrepancy
Go cgo: Code smuggling due to comment parsing discrepancy. Red Hat rates this important (CVSS 7.4). Affected package(s): openshift4/ose-csi-livenessprobe-rhel8:1776999947, openshift4/ose-csi-external-snapshotter-rhel8:1776999951, openshift4/ose-prometheus-node-exporter-rhel9:1774294099, openshift4/ose-azure-file-csi-driver-operator-rhel9:1773363768, openshift4/ose-multus-route-override-cni-rhel8:1777001628, openshift4/ose-tests:1777002345. Resolved in Red Hat advisory RHSA-2026:3469 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 8); Red Hat Enterprise Linux AppStream AUS (v. 8.2); and 41 more.
High [CVE-2026-25536] @modelcontextprotocol/sdk: @modelcontextprotocol/sdk cross-client data leak
@modelcontextprotocol/sdk: @modelcontextprotocol/sdk cross-client data leak. Red Hat rates this important (CVSS 7.1). Weakness: CWE-367. Affected package(s): ansible-automation-platform-tech-preview/mcp-server-rhel9:1772196222. Resolved in Red Hat advisory RHSA-2026:3960 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Ansible Automation Platform 2.6.
High [CVE-2026-23074] Linux kernel: Use-after-free in teql queueing discipline can lead to privilege escalation
Linux kernel: Use-after-free in teql queueing discipline can lead to privilege escalation. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:3634 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 6 more.