Red Hat Linux Security Advisories & CVEs
10918 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-75804] Denial of Service via unenforced QUIC connection flow control
Denial of Service via unenforced QUIC connection flow control. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:74162 with package openssl-main-3.5.9-0.1.hum1, openssl3-main-3.5.9-0.1.hum1. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 15 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat JBoss Core Services; and 11 more.
High [CVE-2026-97687] Traffic interception via HTTPS proxy TLS configuration override
Traffic interception via HTTPS proxy TLS configuration override. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:69612 with package python-urllib3-main-2.8.0-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-100308] Arbitrary command execution via untrusted model deserialization
Arbitrary command execution via untrusted model deserialization. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-68911] Denial of Service via decompression bomb in peer messages
Denial of Service via decompression bomb in peer messages. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409.
High [CVE-2026-63209] Denial of Service via integer overflow in dictionary processing
Denial of Service via integer overflow in dictionary processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-823. Red Hat lists fixing advisory RHSA-2026:72492 with package nats-server2-12-main-2.12.15-0.1.hum1, podman-main-6.1.2-1.hum1, helm4-main-4.3.0-0.2.hum1, k6v1-main-1.8.1-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-102496] Denial of Service (DoS) via deeply nested schema structures
Denial of Service (DoS) via deeply nested schema structures. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; and 4 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat OpenShift AI (RHOAI); Red Hat Single Sign-On 7.
High [CVE-2026-102495] Denial of Service via unbounded recursion during schema parsing
Denial of Service via unbounded recursion during schema parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; and 4 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat OpenShift AI (RHOAI); Red Hat Single Sign-On 7.
High [CVE-2026-95520] integer overflow in iterReadArchiveNext leads to heap-based buffer overflow when parsing untrusted RPM packages
integer overflow in iterReadArchiveNext() leads to heap-based buffer overflow when parsing untrusted RPM packages. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 1 more. Affected products named by the advisory: Red Hat package: rpm.
High [CVE-2026-19547] Local privilege escalation via predictable resource search path
Local privilege escalation via predictable resource search path. Red Hat rates this important (CVSS 7.3). Weakness: CWE-427.
High [CVE-2026-95389] Heap-based Buffer Overflow in Wireshark
Heap-based Buffer Overflow in Wireshark. Red Hat rates this important (CVSS 7.8). Weakness: CWE-122. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
High [CVE-2026-95387] Denial of Service via heap-based buffer overflow in SPDY dissector
Denial of Service via heap-based buffer overflow in SPDY dissector. Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: wireshark.
High [CVE-2026-91012] org.apache.karaf.config/org.apache.karaf.config.core: Apache Karaf: Privilege escalation via path traversal in configuration service
org.apache.karaf.config/org.apache.karaf.config.core: Apache Karaf: Privilege escalation via path traversal in configuration service. Red Hat rates this important (CVSS 8.8). Weakness: CWE-22.
High [CVE-2026-97024] Arbitrary write in root context via path traversal in deploy directory files/etc
Arbitrary write in root context via path traversal in deploy directory files/etc. Red Hat rates this important (CVSS 7.1). Weakness: CWE-61. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: flatpak.
High [CVE-2026-84782] Information disclosure via DTLS handshake retransmission
Information disclosure via DTLS handshake retransmission. Red Hat rates this important (CVSS 7.4). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:74162 with package ruby3-4-main-3.4.10-31.7.hum1, rust-bootupd-main-0.3.2-1.hum1, openssl-main-3.5.9-0.1.hum1, openssl3-main-3.5.9-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Ansible Automation Orchestrator 2026; Confidential Cluster Operator; Confidential Compute Attestation; and 53 more. Affected products named by the advisory: Lightspeed Core; Logging Subsystem for Red Hat OpenShift; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 49 more.
Medium [CVE-2026-81842] Authorization bypass via missing destination folder permission check
Authorization bypass via missing destination folder permission check. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-639. Red Hat lists fixing advisory RHSA-2026:74164 with package grafana13-2-main-13.2.1-0.8.hum1, grafana13-1-main-13.1.6-0.5.hum1, grafana12-4-main-12.4.12-0.2.hum1. Affected products named by the advisory: Multicluster Global Hub; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; and 6 more. Affected products named by the advisory: Red Hat Ceph Storage 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more.
Medium [CVE-2026-102904] Information disclosure via extension uninstallation argument injection
Information disclosure via extension uninstallation argument injection. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-88. Affected products named by the advisory: Migration Toolkit for Applications 8; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-81841] Information disclosure via unrevoked access tokens in paused shared dashboards
Information disclosure via unrevoked access tokens in paused shared dashboards. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-613. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-102314] UI misrepresentation in TabStrip
UI misrepresentation in TabStrip. Red Hat rates this low (CVSS 4.3). Weakness: CWE-1021.
Medium [CVE-2026-102305] UI misrepresentation in SignIn
UI misrepresentation in SignIn. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-1021.
Medium [CVE-2026-102320] Missing authorization in CORS
Missing authorization in CORS. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-346.