Red Hat Linux Security Advisories & CVEs
3066 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2025-65518] Denial of Service via crafted request to get_password.php
Denial of Service via crafted request to get_password.php. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-21869] Remote code execution via invalid n_discard parameter in server endpoints
Remote code execution via invalid n_discard parameter in server endpoints. Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-21441] urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API). Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Affected package(s): rhacm2/submariner-globalnet-rhel9:1774550347, oadp/oadp-velero-rhel9:1770421082, rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1771502845, rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9:1770103255, python3.12-urllib3, rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1771502910. Resolved in Red Hat advisory RHSA-2026:2456 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 71 more.
High [CVE-2025-69264] pnpm code execution
pnpm code execution. Red Hat rates this important (CVSS 8.8). Weakness: CWE-693. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2025-69263] pnpm Lockfile Integrity Bypass
pnpm Lockfile Integrity Bypass. Red Hat rates this important (CVSS 7.5). Weakness: CWE-494. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-22184] Arbitrary code execution via buffer overflow in untgz utility
Arbitrary code execution via buffer overflow in untgz utility. Red Hat rates this important (CVSS 8.6). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2025-15079] Host verification bypass during SSH transfers
Host verification bypass during SSH transfers. Red Hat rates this low (CVSS 8.1). Weakness: CWE-358. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:6893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2025-69227] Denial of Service via specially crafted POST request
Denial of Service via specially crafted POST request. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-835. Affected package(s): ansible-automation-platform, rhaiis/vllm-cuda-rhel9:1774351144, rhoai/odh-caikit-nlp-rhel9:1780069094, rhoai/odh-vllm-gaudi-rhel9:1772093278, rhaiis/model-opt-cuda-rhel9:1774547384, rhoai/odh-vllm-cpu-rhel9:1776259063. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2025-69223] AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): automation-controller, rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:1771502844, ansible-automation-platform, rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9:1770053721, rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9:1770055428, rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1771502845. Resolved in Red Hat advisory RHSA-2026:2106 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.4 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.4 for RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 9; and 11 more.
High [CVE-2025-68428] jsPDF Local File Inclusion/Path Traversal vulnerability
jsPDF Local File Inclusion/Path Traversal vulnerability. Red Hat rates this important (CVSS 8.6). Weakness: CWE-73. Affected package(s): advanced-cluster-security/rhacs-main-rhel8:1770250889, advanced-cluster-security/rhacs-main-rhel8:1770074713, advanced-cluster-security/rhacs-main-rhel8:1769615659. Resolved in Red Hat advisory RHSA-2026:2568 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.8; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Advanced Cluster Security 4.8; Red Hat Advanced Cluster Security 4.9.
High [CVE-2025-66648] Cross-Site Scripting via untrusted user input
Cross-Site Scripting via untrusted user input. Red Hat rates this important (CVSS 7.2). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2025-65110] Arbitrary code execution through malicious visualization definitions
Arbitrary code execution through malicious visualization definitions. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2025-67269] Denial of Service due to malformed NAVCOM packet parsing
Denial of Service due to malformed NAVCOM packet parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. Affected package(s): gpsd-minimal, gpsd. Resolved in Red Hat advisory RHSA-2026:0770 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
High [CVE-2025-67268] Arbitrary code execution via heap-based out-of-bounds write in NMEA2000 packet handling
Arbitrary code execution via heap-based out-of-bounds write in NMEA2000 packet handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1285. Affected package(s): gpsd-minimal, gpsd. Resolved in Red Hat advisory RHSA-2026:1621 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.
High [CVE-2026-21428] Server-Side Request Forgery via header injection
Server-Side Request Forgery via header injection. Red Hat rates this important (CVSS 8.7). Weakness: CWE-93. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2025-11157] Remote Code Execution via insecure YAML deserialization
Remote Code Execution via insecure YAML deserialization. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502. Affected package(s): rhoai/odh-feature-server-rhel9:1776338381. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI (RHOAI).
High [CVE-2025-11393] Insights-runtimes-tech-preview/runtimes-inventory-rhel8-operator: improper proxy configuration allows unauthorized administrative commands
A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to handle. This allows a standard user within the cluster to send unauthorized commands to the management platform, effectively acting with the full permissions of the cluster administrator. This could lead to unauthorized changes to the cluster's configuration or status on the Red Hat platform. Affected products named by the advisory: Red Hat Lightspeed (formerly Insights) for Runtimes 1.0; Red Hat Runtimes Inventory Operator.
High [CVE-2024-3884] outofmemory when parsing form data encoding with application/x-www-form-urlencoded
A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform; Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; and 7 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9; Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9; and 3 more.
High [CVE-2025-9784] undertow madeyoureset http/2 ddos vulnerability
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS). Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform; Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; and 12 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9; Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9; and 8 more.
High [CVE-2025-7365] phishing attack via email verification step in first login flow
A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequently be prompted to "review profile" information. This vulnerability allows the attacker to modify their email address to match that of a victim's account, triggering a verification email sent to the victim's email address. The attacker's email address is not present in the verification email content, making it a potential phishing opportunity. If the victim clicks the verification link, the attacker can gain access to the victim's account. Affected products named by the advisory: Red Hat build of Keycloak 26.0; Red Hat build of Keycloak 26.2.