Red Hat Linux Security Advisories & CVEs
3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2025-11468] Missing character filtering in Python
Missing character filtering in Python. Red Hat rates this moderate (CVSS 4.5). Weakness: CWE-140. Affected package(s): python3. Resolved in Red Hat advisory RHSA-2026:8824 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-55132] Nodejs filesystem permissions bypass
Nodejs filesystem permissions bypass. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-281. Affected package(s): nodejs25-main, nodejs22, nodejs:24, nodejs:22, nodejs24-main, nodejs20-main. Resolved in Red Hat advisory RHSA-2026:1842 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-21637] Nodejs denial of service
Nodejs denial of service. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-248. Affected package(s): nodejs22, nodejs:20, nodejs:22, nodejs25-main, nodejs:24, nodejs24-main. Resolved in Red Hat advisory RHSA-2026:1842 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-21636] Nodejs network segmentation bypass
Nodejs network segmentation bypass. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-281. Affected package(s): nodejs20-main, nodejs25-main, nodejs22-main, nodejs24-main. Resolved in Red Hat advisory RHSA-2026:6402 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-59466] Nodejs denial of service
Nodejs denial of service. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-770. Affected package(s): nodejs22, nodejs:20, nodejs:22, nodejs25-main, nodejs:24, nodejs24-main. Resolved in Red Hat advisory RHSA-2026:1842 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2025-59464] Nodejs memory leak
Nodejs memory leak. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected package(s): nodejs20-main, nodejs25-main, nodejs22-main, nodejs24-main. Resolved in Red Hat advisory RHSA-2026:7657 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-15281] wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory
wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory. Red Hat rates this low (CVSS 5.9). Weakness: CWE-908. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1773685509, rhui5/rhua-rhel9:1773670137, glibc, discovery/discovery-server-rhel9:1773273243, discovery/discovery-ui-rhel9:1773273070, glibc-main. Resolved in Red Hat advisory RHSA-2026:18139 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
Medium [CVE-2024-31884] Improper use of Pybind
Improper use of Pybind. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-295. Affected package(s): ceph, rhceph/rhceph. Resolved in Red Hat advisory RHSA-2026:2711 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-21941] Optimizer unspecified vulnerability (CPU Jan 2026)
Optimizer unspecified vulnerability (CPU Jan 2026). Red Hat rates this moderate (CVSS 4.9). Affected package(s): mysql8.4, mysql:8.0, mysql, mysql:8.4. Resolved in Red Hat advisory RHSA-2026:5580 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2026-21936] InnoDB unspecified vulnerability (CPU Jan 2026)
InnoDB unspecified vulnerability (CPU Jan 2026). Red Hat rates this moderate (CVSS 4.9). Affected package(s): mysql8.4, mysql:8.0, mysql, mysql:8.4. Resolved in Red Hat advisory RHSA-2026:5580 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2026-21968] Optimizer unspecified vulnerability (CPU Jan 2026)
Optimizer unspecified vulnerability (CPU Jan 2026). Red Hat rates this moderate (CVSS 6.5). Affected package(s): mariadb:10.11, mysql8.4, mariadb10.11, mysql:8.0, mysql, mysql:8.4. Resolved in Red Hat advisory RHSA-2026:0334 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2026-21937] DDL unspecified vulnerability (CPU Jan 2026)
DDL unspecified vulnerability (CPU Jan 2026). Red Hat rates this moderate (CVSS 4.9). Affected package(s): mysql8.4, mysql:8.0, mysql, mysql:8.4. Resolved in Red Hat advisory RHSA-2026:5580 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2026-21964] Thread Pooling unspecified vulnerability (CPU Jan 2026)
Thread Pooling unspecified vulnerability (CPU Jan 2026). Red Hat rates this moderate (CVSS 4.9). Affected package(s): mysql8.4, mysql:8.0, mysql, mysql:8.4. Resolved in Red Hat advisory RHSA-2026:5580 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2026-23732] Denial of Service via FastGlyph parsing buffer overflow
Denial of Service via FastGlyph parsing buffer overflow. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-122. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:6958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2026-1145] quickjs-ng quickjs: Heap-based buffer overflow leading to information disclosure or denial of service
quickjs-ng quickjs: Heap-based buffer overflow leading to information disclosure or denial of service. Red Hat rates this important (CVSS 6.3). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-1144] Use-after-free vulnerability in Atomics Ops Handler
Use-after-free vulnerability in Atomics Ops Handler. Red Hat rates this important (CVSS 6.3). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-1180] Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_uri
Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_uri. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-918. Affected package(s): rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-22045] Denial of Service via ACME TLS-ALPN fast path resource exhaustion
Denial of Service via ACME TLS-ALPN fast path resource exhaustion. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-770. Affected package(s): devspaces/traefik-rhel9:1774227265. Resolved in Red Hat advisory RHSA-2026:6192 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-0915] Information disclosure via zero-valued network query
Information disclosure via zero-valued network query. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-908. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1773685509, rhui5/rhua-rhel9:1773670137, glibc, discovery/discovery-server-rhel9:1773273243, discovery/discovery-ui-rhel9:1773273070, glibc-main. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
Medium [CVE-2026-1002] static handler component cache can be manipulated to deny the access to static files
static handler component cache can be manipulated to deny the access to static files. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-444. Affected package(s): rhoai/odh-trustyai-service-rhel9:1776748859, eap7-wildfly, vertx-core, cryostat/jfr-datasource-rhel9:4.2.0, vertx-core-logging, devspaces/server-rhel9:1774228740. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7.