Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3066 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.1Red Hat

High [CVE-2026-1531] Man-in-the-Middle due to insecure default SSL verification

Man-in-the-Middle due to insecure default SSL verification. Red Hat rates this important (CVSS 8.1). Weakness: CWE-295. Affected package(s): foreman, rubygem-katello, rubygem-foreman_kubevirt, rubygem-fog-kubevirt, python-pulp-container, python-pulp-rpm. Resolved in Red Hat advisory RHSA-2026:5968 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Satellite 6.16 for RHEL 8; Red Hat Satellite 6.16 for RHEL 9; Red Hat Satellite 6.17 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9.

CVE-2026-1531
Unclassified
Jan 28, 2026
High8.2Red Hat

High [CVE-2026-24842] Arbitrary file creation via path traversal bypass in hardlink security check

Arbitrary file creation via path traversal bypass in hardlink security check. Red Hat rates this important (CVSS 8.2). Weakness: CWE-59. Affected package(s): network-observability/network-observability-console-plugin-rhel9:1771227650, network-observability/network-observability-console-plugin-compat-rhel9:1771227610, eap7-wildfly, rhtas/rekor-search-ui-rhel9:1773308315, linux-sgx, devspaces/dashboard-rhel9:1774476526. Resolved in Red Hat advisory RHSA-2026:18868 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7; Red Hat OpenShift Dev Spaces 3.27; and 7 more.

CVE-2026-24842
Unclassified
Jan 28, 2026
High7.8Red Hat

High [CVE-2025-57283] OS command injection in the logfile variable in lib/Local.js

OS command injection in the logfile variable in lib/Local.js. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Fuse 7.

CVE-2025-57283
Unclassified
Jan 28, 2026
High8.8Red Hat

High [CVE-2025-61140] Prototype Pollution vulnerability in the value function

Prototype Pollution vulnerability in the value function. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Affected package(s): ansible-automation-platform/automation-portal:1770282458, ansible-automation-platform, rhdh/rhdh-hub-rhel9:1774545605, rhdh/rhdh-hub-rhel9:1775140647, ansible-automation-platform/automation-portal:1770281704. Resolved in Red Hat advisory RHSA-2026:6174 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.1; Red Hat Ansible Automation Platform 2.5; Red Hat Ansible Automation Platform 2.6; Red Hat Developer Hub 1.8; and 4 more.

CVE-2025-61140
Unclassified
Jan 28, 2026
High7.1Red Hat

High [CVE-2026-24779] Server-Side Request Forgery allows internal network access

Server-Side Request Forgery allows internal network access. Red Hat rates this important (CVSS 7.1). Weakness: CWE-918. Affected package(s): rhaiis/vllm-rocm-rhel9:1782353093, rhaiis/vllm-spyre-rhel9:1782352919, rhaiis/vllm-cuda-rhel9:1782352847, rhoai/odh-vllm-gaudi-rhel9:1772093278, rhoai/odh-vllm-cpu-rhel9:1776259063, rhoai/odh-vllm-cpu-rhel9:1778264363. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat AI Inference Server 3.2; Red Hat AI Inference Server 3.3; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; and 2 more.

CVE-2026-24779
Unclassified
Jan 27, 2026
High7.8Red Hat

High [CVE-2026-24765] Arbitrary code execution via unsafe deserialization of code coverage files

Arbitrary code execution via unsafe deserialization of code coverage files. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-24765
Unclassified
Jan 27, 2026
High8.8Red Hat

High [CVE-2026-24747] Arbitrary code execution via malicious checkpoint file loading

Arbitrary code execution via malicious checkpoint file loading. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Affected package(s): rhoai/odh-vllm-gaudi-rhel9:1780069069. Resolved in Red Hat advisory RHSA-2026:24977 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat OpenShift AI 2.25.

CVE-2026-24747
Unclassified
Jan 27, 2026
High8.4Red Hat

High [CVE-2026-24882] Stack-based buffer overflow in tpm2daemon allows arbitrary code execution

Stack-based buffer overflow in tpm2daemon allows arbitrary code execution. Red Hat rates this important (CVSS 8.4). Weakness: CWE-121. Affected package(s): gnupg2. Resolved in Red Hat advisory RHSA-2026:2753 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support.

CVE-2026-24882
Unclassified
Jan 27, 2026
High8.1Red Hat

High [CVE-2026-24881] Remote code execution and denial of service via crafted CMS EnvelopedData message

Remote code execution and denial of service via crafted CMS EnvelopedData message. Red Hat rates this important (CVSS 8.1). Weakness: CWE-121. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 6.

CVE-2026-24881
Unclassified
Jan 27, 2026
High7.5Red Hat

High [CVE-2026-24869] Use-after-free in the Layout: Scrolling and Overflow component

Use-after-free in the Layout: Scrolling and Overflow component. Red Hat rates this important (CVSS 7.5). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-24869
Unclassified
Jan 27, 2026
High8.1Red Hat

High [CVE-2026-21721] Grafana Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation

Grafana Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-639. Affected package(s): grafana, rhacm2/acm-grafana-rhel9:1774950654, rhacm2/acm-grafana-rhel9:1774002166. Resolved in Red Hat advisory RHSA-2026:2920 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Advanced Cluster Management for Kubernetes 2.12; Red Hat Advanced Cluster Management for Kubernetes 2.13; and 4 more.

CVE-2026-21721
Unclassified
Jan 27, 2026
High7.5Red Hat

High [CVE-2026-21720] Denial of Service via resource exhaustion from avatar requests

Denial of Service via resource exhaustion from avatar requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-21720
Unclassified
Jan 27, 2026
High8.6Red Hat

High [CVE-2026-24486] Arbitrary file write via path traversal vulnerability

Arbitrary file write via path traversal vulnerability. Red Hat rates this important (CVSS 8.6). Weakness: CWE-22. Affected package(s): rhoai/odh-vllm-gaudi-rhel9:1772093278, rhoai/odh-vllm-cpu-rhel9:1776259063, rhoai/odh-vllm-cpu-rhel9:1778264363, rhoai/odh-vllm-gaudi-rhel9:1770956034, rhaiis/vllm-cuda-rhel9:1772160593, rhoai/odh-feature-server-rhel9:1776338381. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: python-multipart; Red Hat AI Inference Server 3.2; Red Hat Ansible Automation Platform 2.6; Red Hat OpenShift AI 2.25; and 6 more.

CVE-2026-24486
Unclassified
Jan 27, 2026
High7.4Vendor: MediumRed Hat

High [CVE-2025-69419] Arbitrary code execution due to out-of-bounds write in PKCS#12 processing

Arbitrary code execution due to out-of-bounds write in PKCS#12 processing. Red Hat rates this moderate (CVSS 7.4). Weakness: CWE-131. Affected package(s): jbcs-httpd24-mod_md, rhcos, jbcs-httpd24-mod_http2, rhui5/installer-rhel9:1770646925, jbcs-httpd24-mod_proxy_cluster, openssl-main. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2025-69419
Unclassified
Jan 27, 2026
High7.5Red Hat

High [CVE-2026-23864] Denial of Service via specially crafted HTTP requests

Denial of Service via specially crafted HTTP requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284. Affected package(s): com.github.streamshub-console. Resolved in Red Hat advisory RHSA-2026:13571 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-23864
Unclassified
Jan 26, 2026
High7.8Vendor: MediumRed Hat

High [CVE-2026-23001] fix possible UAF in macvlan_forward_source()

fix possible UAF in macvlan_forward_source(). Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-416. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:3966 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-23001
Unclassified
Jan 25, 2026
High7.3Vendor: MediumRed Hat

High [CVE-2026-23010] Linux kernel: Use-after-free in IPv6 address deletion may lead to a denial of service

Linux kernel: Use-after-free in IPv6 address deletion may lead to a denial of service. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-825. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:4723 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-23010
Unclassified
Jan 25, 2026
High7.1Vendor: MediumRed Hat

High [CVE-2026-1299] email header injection due to unquoted newlines

email header injection due to unquoted newlines. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-93. Affected package(s): discovery/discovery-server-rhel9:1775668717, python3, python3.11, python3.12, rhui5/rhua-rhel9:1773670137, rhaiis/vllm-rocm-rhel9:1775680262. Resolved in Red Hat advisory RHSA-2026:5606 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-1299
Unclassified
Jan 23, 2026
High7.5Red Hat

High [CVE-2026-0994] Denial of Service due to recursion depth bypass

Denial of Service due to recursion depth bypass. Red Hat rates this important (CVSS 7.5). Weakness: CWE-674. Affected package(s): protobuf, python3.12-protobuf, rhaiis/vllm-spyre-rhel9:1778244546, rhaiis/model-opt-cuda-rhel9:1775749857, rhaiis/vllm-rocm-rhel9:1775680262, rhaiis/vllm-cuda-rhel9:1775680192. Resolved in Red Hat advisory RHSA-2026:3958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Enterprise Linux 10.0 Extended Update Support; and 6 more.

CVE-2026-0994
Unclassified
Jan 23, 2026
High7.0Red Hat

High [CVE-2026-0775] npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability

npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. Red Hat rates this important (CVSS 7). Weakness: CWE-732. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-0775
Unclassified
Jan 23, 2026

← All vendors