Red Hat Linux Security Advisories & CVEs
3010 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-29036] Data corruption and unauthorized modification via JSON Pointer escape decoding
Data corruption and unauthorized modification via JSON Pointer escape decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-386.
High [CVE-2026-19560] Arbitrary code execution via use-after-free in Blink
Arbitrary code execution via use-after-free in Blink. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-19559] Arbitrary code execution via use after free in HTML
Arbitrary code execution via use after free in HTML. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416.
High [CVE-2026-19557] Sandbox escape via use-after-free in TabStrip
Sandbox escape via use-after-free in TabStrip. Red Hat rates this important (CVSS 8.2). Weakness: CWE-825.
High [CVE-2026-19558] Arbitrary code execution via malicious extension installation
Arbitrary code execution via malicious extension installation. Red Hat rates this important (CVSS 7.3). Weakness: CWE-416.
High [CVE-2026-19556] Arbitrary code execution via use-after-free in V8
Arbitrary code execution via use-after-free in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416.
High [CVE-2026-19550] trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes
trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes. Red Hat rates this important (CVSS 8.2). Weakness: CWE-863. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-71290] Server impersonation via improper TLS hostname verification
Server impersonation via improper TLS hostname verification. Red Hat rates this important (CVSS 8.1). Weakness: CWE-295.
High [CVE-2026-29035] Arbitrary code execution via crafted WebSocket frames
Arbitrary code execution via crafted WebSocket frames. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.
High [CVE-2026-73241] Authentication bypass via incorrect RDSTLS PDU handling
Authentication bypass via incorrect RDSTLS PDU handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-287. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.
High [CVE-2026-73231] @faker-js/faker: Faker: Arbitrary Code Execution via attacker-controlled fake templates
@faker-js/faker: Faker: Arbitrary Code Execution via attacker-controlled fake templates. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected products named by the advisory: Cryostat 4; Red Hat AMQ Broker 7; Red Hat Build of Keycloak; Red Hat Enterprise Linux 10; and 4 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat package: grafana.
High [CVE-2026-71467] Authentication bypass on /federated via Upgrade: websocket header spoofing
Authentication bypass on /federated via Upgrade: websocket header spoofing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-287. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-48804] Denial of Service via binary attachment accumulation
Denial of Service via binary attachment accumulation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-73214] Denial of Service via unverified DTLS session state
Denial of Service via unverified DTLS session state. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-73089] Denial of Service via unbounded memory growth from distinct query results
Denial of Service via unbounded memory growth from distinct query results. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:56338 with package ansible-automation-platform/automation-portal:1787047114, grafana13-1-main-13.1.3-0.1.1.hum1, discovery/discovery-ui-rhel9:1786634825, grafana12-4-main-12.4.8-0.1.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Gatekeeper 3; Migration Toolkit for Containers; and 43 more. Affected products named by the advisory: Node HealthCheck Operator; OpenShift Lightspeed; OpenShift Pipelines; OpenShift Service Mesh 3; and 39 more.
High [CVE-2026-73088] Prototype pollution leading to denial of service
Prototype pollution leading to denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:56338 with package ansible-automation-platform/automation-portal:1787047114, grafana13-1-main-13.1.3-0.1.1.hum1, discovery/discovery-ui-rhel9:1786634825, grafana12-4-main-12.4.8-0.1.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Gatekeeper 3; Migration Toolkit for Containers; and 43 more. Affected products named by the advisory: Node HealthCheck Operator; OpenShift Lightspeed; OpenShift Pipelines; OpenShift Service Mesh 3; and 39 more.
High [CVE-2026-73086] Predictable ID generation due to integer overflow
Predictable ID generation due to integer overflow. Red Hat rates this important (CVSS 7.4). Weakness: CWE-1241. Red Hat lists fixing advisory RHSA-2026:56338 with package jaeger-main-2.20.0-0.8.hum1, prometheus3-13-main-3.13.2-0.2.hum1, ansible-automation-platform/automation-portal:1787047114, rhacm2/console-rhel9:1786908361. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Gatekeeper 3; Migration Toolkit for Containers; and 39 more. Affected products named by the advisory: Multicluster Engine for Kubernetes; Network Observability Operator; Node HealthCheck Operator; OpenShift Lightspeed; and 35 more.
High [CVE-2025-35973] Privilege escalation in Ring 0 via improper value handling
Privilege escalation in Ring 0 via improper value handling. Red Hat rates this important (CVSS 7.2). Weakness: CWE-266. Affected products named by the advisory: Confidential Compute Attestation; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat OpenShift Container Platform 4; and 1 more.
High [CVE-2026-73078] Arbitrary Code Execution via Crafted Netrw Menu Entries
Arbitrary Code Execution via Crafted Netrw Menu Entries. Red Hat rates this important (CVSS 8.8). Weakness: CWE-77.
High [CVE-2026-73077] Arbitrary Code Execution via Insecure Shell Command Handling
Arbitrary Code Execution via Insecure Shell Command Handling. Red Hat rates this important (CVSS 7.3). Weakness: CWE-78.