Red Hat Linux Security Advisories & CVEs
5301 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-48059] Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers
Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1286. Affected package(s): netty-codec-haproxy. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1; Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat build of Quarkus 3.27.4.SP1; Red Hat build of Quarkus 3.33.2.SP1; and 14 more.
High [CVE-2026-48043] Denial of Service due to resource leak
Denial of Service due to resource leak. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected package(s): netty-codec-http2. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1; Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat build of Quarkus 3.27.4.SP1; Red Hat build of Quarkus 3.33.2.SP1; and 15 more.
High [CVE-2026-48006] Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 1 more.
High [CVE-2026-47691] Netty has Insufficient Bailiwick Validation for NS Records
Netty has Insufficient Bailiwick Validation for NS Records. Red Hat rates this important (CVSS 8.7). Weakness: CWE-346. Affected package(s): netty-resolver-dns. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1; Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat build of Quarkus 3.27.4.SP1; Red Hat build of Quarkus 3.33.2.SP1; and 16 more.
High [CVE-2026-46340] Denial of Service due to unbounded memory growth from SctpMessage fragments
Denial of Service due to unbounded memory growth from SctpMessage fragments. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 1 more.
High [CVE-2026-45674] Information disclosure and data manipulation due to improper CNAME record validation
Information disclosure and data manipulation due to improper CNAME record validation. Red Hat rates this important (CVSS 8.7). Weakness: CWE-346. Affected package(s): netty-resolver-dns. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1; Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat build of Quarkus 3.27.4.SP1; Red Hat build of Quarkus 3.33.2.SP1; and 16 more.
High [CVE-2026-47141] NodeVM observability builtins leak host process and HTTP request data
NodeVM observability builtins leak host process and HTTP request data. Red Hat rates this moderate (CVSS 8.6). Weakness: CWE-653. Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-47139] Sandbox escape via internal HTTP built-ins leading to network restriction bypass
Sandbox escape via internal HTTP built-ins leading to network restriction bypass. Red Hat rates this moderate (CVSS 8.6). Weakness: CWE-1100. Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-47135] Sandbox escape allows arbitrary code execution on the host system
Sandbox escape allows arbitrary code execution on the host system. Red Hat rates this moderate (CVSS 8.7). Weakness: CWE-1100. Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-47209] Integrity bypass via incorrect property assignment leading to potential arbitrary code execution
Integrity bypass via incorrect property assignment leading to potential arbitrary code execution. Red Hat rates this moderate (CVSS 8.6). Weakness: CWE-915. Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-45416] Denial of Service due to eager buffer allocation in TLS handshake
Denial of Service due to eager buffer allocation in TLS handshake. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): netty-handler, offline-knowledge-portal/rhokp-rhel9:1782239370. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Offline Knowledge Portal 1.2.7; OpenShift Serverless; Red Hat AMQ Broker 7; Red Hat AMQ Clients; and 19 more.
High [CVE-2026-44894] Denial of Service amplification via improper QUIC token validation
Denial of Service amplification via improper QUIC token validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-346. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat build of Apache Camel - HawtIO 4.
High [CVE-2026-44893] Denial of Service via malformed HAProxy message
Denial of Service via malformed HAProxy message. Red Hat rates this important (CVSS 7.5). Weakness: CWE-805. Affected package(s): netty-codec-haproxy. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1; Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat build of Quarkus 3.27.4.SP1; Red Hat build of Quarkus 3.33.2.SP1; and 14 more.
High [CVE-2026-50633] Arbitrary code execution via JNDI Injection
Arbitrary code execution via JNDI Injection. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat Fuse 7.
High [CVE-2026-50632] Arbitrary code execution via untrusted JMS configuration
Arbitrary code execution via untrusted JMS configuration. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; and 1 more.
High [CVE-2026-50628] Unauthorized access due to logic error in OAuthRequestFilter
Unauthorized access due to logic error in OAuthRequestFilter. Red Hat rates this important (CVSS 7.4). Weakness: CWE-358. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat Fuse 7; Red Hat JBoss Web Server 5.
High [CVE-2026-50627] Token Confusion/Routing attacks due to improper validation of JWT audience claims
Token Confusion/Routing attacks due to improper validation of JWT audience claims. Red Hat rates this important (CVSS 8.1). Weakness: CWE-303. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat Fuse 7; Red Hat JBoss Web Server 5.
High [CVE-2026-49875] Information disclosure via out-of-band external entity resolution due to missing JAXP hardening
Information disclosure via out-of-band external entity resolution due to missing JAXP hardening. Red Hat rates this important (CVSS 7.5). Weakness: CWE-611. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; and 3 more.
High [CVE-2026-53705] Heap buffer overflow in WavPack decoder via integer overflow
Heap buffer overflow in WavPack decoder via integer overflow. Red Hat rates this important (CVSS 7.6). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; and 7 more.
Medium [CVE-2026-44171] Unauthorized file creation via path traversal
Unauthorized file creation via path traversal. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-22. Affected package(s): mariadb10.11, mariadb11, galera, mariadb:11.8, mariadb11.8, mariadb:10.11. Resolved in Red Hat advisory RHSA-2026:33093 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.