Red Hat Linux Security Advisories & CVEs
10918 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-95354] Use after free in Verifier
Use after free in Verifier. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-416.
High [CVE-2026-95351] Use after free in Views
Use after free in Views. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416.
High [CVE-2026-95304] Out of bounds write in V8
Out of bounds write in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.
High [CVE-2026-95373] Use after free in DevTools
Use after free in DevTools. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416.
High [CVE-2026-95282] Use after free in Platform
Use after free in Platform. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416.
High [CVE-2026-95315] Use after free in Aura
Use after free in Aura. Red Hat rates this important (CVSS 7.3). Weakness: CWE-416.
High [CVE-2026-95355] Incorrect authorization in Navigation
Incorrect authorization in Navigation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-863.
High [CVE-2026-95301] Missing authorization in Extensions
Missing authorization in Extensions. Red Hat rates this important (CVSS 8.1). Weakness: CWE-862.
High [CVE-2026-102560] Libsoup: libsoup: heap buffer overflow during outgoing permessage-deflate buffer growth
A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calculations used for GByteArray growth could wrap, causing zlib to write past the allocated buffer and resulting in a heap buffer overflow. This issue is rated Important. Applications that enable WebSocket deflate with untrusted or unbounded message sizes are affected. Impact is heap corruption or denial of service. Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3.
High [CVE-2026-102559] Libsoup: libsoup: heap buffer overflow during websocket client-frame masking
A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation APIs could be truncated while the masking routine still used the full length, causing a heap buffer overflow. This issue is rated Important. Triggering requires causing a libsoup WebSocket client (or client-role connection) to send an extremely large message. That may be reachable when application-level message size is attacker-influenced. Impact is heap corruption or denial of service in the sending process. Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3.
High [CVE-2026-102558] Libsoup: libsoup: heap buffer overflow during websocket receive-buffer growth
A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the length wrapped, causing a heap buffer overflow while reading frame data. This issue is rated Important. A remote WebSocket peer can cause heap corruption or denial of service, especially when applications leave incoming payload size unlimited. Default configurations that set a finite max-incoming-payload-size reduce exposure but the vulnerable code path remains relevant for applications that disable the limit. Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3.
High [CVE-2026-102555] Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri base64 decoding
A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded NUL bytes, the decoded length could remain uninitialized and be used as the size of the returned GBytes. This can lead to an out-of-bounds read or application crash when processing a crafted data URI. This issue is rated Important. Impact depends on how the application consumes the returned GBytes. Red Hat Enterprise Linux ships libsoup/libsoup3 widely used by GNOME and other HTTP clients; applications that decode untrusted data URIs are in scope. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3.
High [CVE-2026-102676] Privilege escalation via unauthorized Node.js integration in web workers
Privilege escalation via unauthorized Node.js integration in web workers. Red Hat rates this important (CVSS 8.3). Weakness: CWE-266. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Enterprise Linux 10; Red Hat package: podman-desktop; Red Hat package: rh-podman-desktop.
High [CVE-2026-102675] Cross-origin information disclosure via improper CORS enforcement in custom protocol handlers
Cross-origin information disclosure via improper CORS enforcement in custom protocol handlers. Red Hat rates this important (CVSS 7.4). Weakness: CWE-346. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Enterprise Linux 10; Red Hat package: podman-desktop; Red Hat package: rh-podman-desktop.
High [CVE-2026-102674] Sandbox bypass via popup window creation
Sandbox bypass via popup window creation. Red Hat rates this important (CVSS 8.2). Weakness: CWE-281. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Enterprise Linux 10; Red Hat package: podman-desktop; Red Hat package: rh-podman-desktop.
High [CVE-2026-102673] Sandbox bypass via popups opened from sandboxed iframes
Sandbox bypass via popups opened from sandboxed iframes. Red Hat rates this important (CVSS 8.2). Weakness: CWE-281. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Enterprise Linux 10; Red Hat package: podman-desktop; Red Hat package: rh-podman-desktop.
High [CVE-2026-102557] Libsoup: libsoup: heap buffer overflow during websocket message reassembly
A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total message size against the limits of the underlying buffer type. A remote peer could send fragments that caused size truncation while the implementation still used the full length, leading to heap corruption or a crash. This issue is rated Important. A remote, unauthenticated WebSocket peer can trigger heap corruption or denial of service during message reassembly. Any Red Hat product or application exposing or consuming libsoup WebSockets with untrusted peers is affected until updated. Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3.
High [CVE-2026-102556] Libsoup: libsoup: heap buffer overflow from websocket pong signal type confusion
A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting a handler that follows the documented GBytes API can trigger heap corruption or a crash upon receiving a crafted Pong. This issue is rated Important. A remote peer can send a WebSocket Pong that reaches receive_pong(). Exploitation requires an application to connect a::pong handler that expects GBytes; many keep-alive users do. Successful triggering can crash the process or corrupt heap state. libsoup WebSocket support is used by client and server applications on Red Hat platforms. Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-843. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3.
High [CVE-2026-94603] The `podman run` command can be instructed to disable almost all sandboxing - including user-requested sandboxing - by image annotation
The `podman run` command can be instructed to disable almost all sandboxing - including user-requested sandboxing - by image annotation. Red Hat rates this important (CVSS 8.6). Weakness: CWE-15. Red Hat lists fixing advisory RHSA-2026:74861 with package podman-main-6.1.3-1.hum1, podman-main-6.1.2-1.1.hum1. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 6 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat OpenShift Virtualization 4; and 2 more.
High [CVE-2026-97689] Denial of Service via unbounded memory allocation in chunk parser
Denial of Service via unbounded memory allocation in chunk parser. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:69612 with package python-urllib3-main-2.8.0-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.