Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.1Red Hat

Medium [CVE-2026-2785] Invalid pointer in the JavaScript Engine component

Invalid pointer in the JavaScript Engine component. Red Hat rates this moderate (CVSS 6.1). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-2785
Unclassified
Feb 24, 2026
Medium6.1Red Hat

Medium [CVE-2026-2786] Use-after-free in the JavaScript Engine component

Use-after-free in the JavaScript Engine component. Red Hat rates this moderate (CVSS 6.1). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-2786
Unclassified
Feb 24, 2026
Medium6.1Red Hat

Medium [CVE-2026-2784] Mitigation bypass in the DOM: Security component

Mitigation bypass in the DOM: Security component. Red Hat rates this moderate (CVSS 6.1). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-2784
Unclassified
Feb 24, 2026
Medium6.1Red Hat

Medium [CVE-2026-2783] Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component

Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. Red Hat rates this moderate (CVSS 6.1). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-2783
Unclassified
Feb 24, 2026
Medium6.1Red Hat

Medium [CVE-2026-2782] Privilege escalation in the Netmonitor component

Privilege escalation in the Netmonitor component. Red Hat rates this moderate (CVSS 6.1). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-2782
Unclassified
Feb 24, 2026
Medium6.1Red Hat

Medium [CVE-2026-2781] Integer overflow in the Libraries component in NSS

Integer overflow in the Libraries component in NSS. Red Hat rates this moderate (CVSS 6.1). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-2781
Unclassified
Feb 24, 2026
Medium6.1Red Hat

Medium [CVE-2026-2779] Incorrect boundary conditions in the Networking: JAR component

Incorrect boundary conditions in the Networking: JAR component. Red Hat rates this moderate (CVSS 6.1). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-2779
Unclassified
Feb 24, 2026
Medium6.5Red Hat

Medium [CVE-2026-3121] Privilege escalation via manage-clients permission

Privilege escalation via manage-clients permission. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-266. Affected package(s): rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3121
Unclassified
Feb 24, 2026
Medium6.5Red Hat

Medium [CVE-2026-3118] GraphQL Injection Leading to Platform-Wide Denial of Service (DoS) in RH Developer Hub Orchestrator Plugin

GraphQL Injection Leading to Platform-Wide Denial of Service (DoS) in RH Developer Hub Orchestrator Plugin. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-89. Affected package(s): rhdh/rhdh-hub-rhel9:1777903262, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3118
Unclassified
Feb 24, 2026
Medium5.0Red Hat

Medium [CVE-2025-61145] Denial of service via double free in tiffcrop.c

Denial of service via double free in tiffcrop.c. Red Hat rates this moderate (CVSS 5). Weakness: CWE-1341. Affected package(s): libtiff-main. Resolved in Red Hat advisory RHSA-2026:7504 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-61145
Unclassified
Feb 23, 2026
Medium5.0Red Hat

Medium [CVE-2025-61144] Denial of Service via buffer overflow

Denial of Service via buffer overflow. Red Hat rates this moderate (CVSS 5). Weakness: CWE-805. Affected package(s): libtiff-main. Resolved in Red Hat advisory RHSA-2026:7504 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-61144
Unclassified
Feb 23, 2026
Medium5.5Red Hat

Medium [CVE-2025-61143] Denial of Service via NULL pointer dereference in tif_open.c

Denial of Service via NULL pointer dereference in tif_open.c. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected package(s): libtiff-main. Resolved in Red Hat advisory RHSA-2026:7504 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-61143
Unclassified
Feb 23, 2026
Medium6.5Red Hat

Medium [CVE-2026-26996] Denial of Service via specially crafted glob patterns

Denial of Service via specially crafted glob patterns. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1333. Affected package(s): openshift4/ose-console-rhel9:1780365421, quay/quay-rhel9:1775069491, nodejs:20, nodejs:22, rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1776336652, devspaces/openvsx-rhel9:1779528224. Resolved in Red Hat advisory RHSA-2026:13508 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-26996
Unclassified
Feb 20, 2026
Medium5.1Vendor: LowRed Hat

Medium [CVE-2026-2243] Qemu-kvm: heap buffer out-of-bounds read in vmdk compressed grain parsing

A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS). Red Hat severity: Low — CVSS 5.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: qemu-kvm-ma.

CVE-2026-2243
Red Hat Enterprise Linux
Feb 19, 2026
Medium4.3Red Hat

Medium [CVE-2026-27100] Information disclosure via unauthorized access to build parameters

Information disclosure via unauthorized access to build parameters. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-551. Affected package(s): ocp-tools. Resolved in Red Hat advisory RHSA-2026:10209 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27100
Unclassified
Feb 18, 2026
Medium4.6Red Hat

Medium [CVE-2026-27099] Stored Cross-site Scripting (XSS) via unescaped user-provided offline cause description

Stored Cross-site Scripting (XSS) via unescaped user-provided offline cause description. Red Hat rates this moderate (CVSS 4.6). Weakness: CWE-79. Affected package(s): ocp-tools. Resolved in Red Hat advisory RHSA-2026:10209 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27099
Unclassified
Feb 18, 2026
Medium5.3Vendor: LowRed Hat

Medium [CVE-2026-24733] security constraint bypass with HTTP/0.9

security constraint bypass with HTTP/0.9. Red Hat rates this low (CVSS 5.3). Weakness: CWE-20. Affected package(s): tomcat, jws6-tomcat, tomcat10-main, tomcat11-main. Resolved in Red Hat advisory RHSA-2026:12195 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-24733
Unclassified
Feb 17, 2026
Medium5.3Red Hat

Medium [CVE-2025-66614] Client certificate verification bypass due to virtual host mapping

Client certificate verification bypass due to virtual host mapping. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1289. Affected package(s): tomcat, jws6-tomcat, tomcat10-main, tomcat11-main. Resolved in Red Hat advisory RHSA-2026:12195 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2025-66614
Unclassified
Feb 17, 2026
Medium4.0Red Hat

Medium [CVE-2026-2625] Denial of Service via crafted RPM file during signature verification

Denial of Service via crafted RPM file during signature verification. Red Hat rates this moderate (CVSS 4). Weakness: CWE-347. Affected package(s): rust-rpm-sequoia-main. Resolved in Red Hat advisory RHSA-2026:12682 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2625
Unclassified
Feb 17, 2026
Medium5.3Red Hat

Medium [CVE-2026-2575] Denial of Service due to excessive SAMLRequest decompression

Denial of Service due to excessive SAMLRequest decompression. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-409. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.10, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:3947 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2575
Unclassified
Feb 16, 2026

← All vendors