Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11870 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Red Hat

High [CVE-2026-11573] Denial of Service via uncontrolled recursion in XML serialization

Denial of Service via uncontrolled recursion in XML serialization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: qt6-qtbase.

CVE-2026-11573
Red Hat Enterprise Linux
Sep 8, 2026
High8.7Red Hat

High [CVE-2026-80219] OAuthClient created with GrantMethod auto and no secret enables OAuth token theft

OAuthClient created with GrantMethod auto and no secret enables OAuth token theft. Red Hat rates this important (CVSS 8.7). Weakness: CWE-1390. Affected product named by the advisory: Red Hat build of Apache Camel - HawtIO 4.

CVE-2026-80219
Unclassified
Sep 8, 2026
High8.2Red Hat

High [CVE-2026-77968] Cluster-wide secrets read/write granted to operator ServiceAccount

Cluster-wide secrets read/write granted to operator ServiceAccount. Red Hat rates this important (CVSS 8.2). Weakness: CWE-269. Red Hat lists fixing advisory RHSA-2026:66120 with package rhbac-4/hawtio-operator-bundle:2.0.1-8, rhbac-4/hawtio-rhel9-operator:2.0.1-10. Affected product named by the advisory: Red Hat build of Apache Camel - HawtIO 4.

CVE-2026-77968
Unclassified
Sep 8, 2026
High8.5Red Hat

High [CVE-2026-74860] Libxml2: double-free/uaf in libxml2 python bindings

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. Red Hat severity: Important — CVSS 8.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-763. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:64463. Affected products named by the advisory: Red Hat package: libxml2.

CVE-2026-74860
Red Hat Enterprise Linux
Sep 8, 2026
High7.2Red Hat

High [CVE-2026-76561] certprofile-import allows code execution via unsanitized profile content (ExternalProcessConstraint)

certprofile-import allows code execution via unsanitized profile content (ExternalProcessConstraint). Red Hat rates this important (CVSS 7.2). Weakness: CWE-78. Affected products named by the advisory: Red Hat Certificate System 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-76561
Unclassified
Sep 8, 2026
Medium4.2Red Hat

Medium [CVE-2026-87053] Final container image runs as root (USER root never reverted)

Final container image runs as root (USER root never reverted). Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-250.

CVE-2026-87053
Unclassified
Sep 8, 2026
Medium4.2Red Hat

Medium [CVE-2026-87054] containers-policy.json defaults to insecureAcceptAnything for non-Red Hat registries

containers-policy.json defaults to insecureAcceptAnything for non-Red Hat registries. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-345.

CVE-2026-87054
Unclassified
Sep 8, 2026
Medium4.2Red Hat

Medium [CVE-2026-87050] GitHub Actions and reusable workflow not pinned to commit SHA

GitHub Actions and reusable workflow not pinned to commit SHA. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-829.

CVE-2026-87050
Unclassified
Sep 8, 2026
Medium4.2Red Hat

Medium [CVE-2026-87057] Runtime base images referenced by mutable floating tags

Runtime base images referenced by mutable floating tags. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-829.

CVE-2026-87057
Unclassified
Sep 8, 2026
Medium4.2Red Hat

Medium [CVE-2026-87062] GitHub Actions referenced by mutable tag/branch instead of commit SHA

GitHub Actions referenced by mutable tag/branch instead of commit SHA. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-829.

CVE-2026-87062
Unclassified
Sep 8, 2026
Medium6.5Red Hat

Medium [CVE-2026-58649] .NET Information Disclosure Vulnerability

.NET Information Disclosure Vulnerability. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-346. Red Hat lists fixing advisory RHSA-2026:68316 with package dotnet9.0-0:9.0.121-1.el9_8, dotnet10.0-0:10.0.112-1.el9_8, dotnet9.0-0:9.0.121-1.el8_10, dotnet8.0-0:8.0.131-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-58649
Unclassified
Sep 8, 2026
Medium6.8Red Hat

Medium [CVE-2026-74859] Gnome-tweaks: path traversal in theme installer

The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files outside ~/.themes by using../ path traversal, absolute paths, or symlink entries. This vulnerability is rated Moderate because it requires a user to actively install a specially crafted GNOME Shell theme via the `gnome-tweaks` utility. Exploitation is not possible without user interaction and the deliberate installation of a malicious theme, limiting the attack surface in typical Red Hat desktop environments. Red Hat severity: Moderate — CVSS 6.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H). Weakness: CWE-22. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gnome-tweaks.

CVE-2026-74859
Red Hat Enterprise Linux
Sep 8, 2026
Medium6.3Red Hat

Medium [CVE-2026-86512] java-json-tools json-patch: Improper Access Control in Copy/Move Operations

java-json-tools json-patch: Improper Access Control in Copy/Move Operations. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-281. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; Red Hat build of Quarkus; and 1 more. Affected products named by the advisory: Red Hat Fuse 7.

CVE-2026-86512
Unclassified
Sep 8, 2026
Low3.3Red Hat

Low [CVE-2026-86564] Missing length validation before reading command_data in virtio-net control queue handler

Missing length validation before reading command_data in virtio-net control queue handler. Red Hat rates this low (CVSS 3.3). Weakness: CWE-125. Affected products named by the advisory: Fast Datapath for RHEL 10; Fast Datapath for RHEL 8; Fast Datapath for RHEL 9; Red Hat Enterprise Linux 10; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: dpdk.

CVE-2026-86564
Red Hat Enterprise Linux
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87055] Base image referenced by mutable tag rather than sha256 digest

Base image referenced by mutable tag rather than sha256 digest. Red Hat rates this low (CVSS 2.6). Weakness: CWE-829.

CVE-2026-87055
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87056] No automated dependency-update configuration for submodules or Containerfile

No automated dependency-update configuration for submodules or Containerfile. Red Hat rates this low (CVSS 2.6). Weakness: CWE-1104.

CVE-2026-87056
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87051] resolveAndValidatePath performs lexical containment only — symlinks can escape the build context

resolveAndValidatePath performs lexical containment only — symlinks can escape the build context. Red Hat rates this low (CVSS 2.6). Weakness: CWE-59.

CVE-2026-87051
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87052] No automated dependency-update or vulnerability-scanning configuration

No automated dependency-update or vulnerability-scanning configuration. Red Hat rates this low (CVSS 2.6). Weakness: CWE-1104.

CVE-2026-87052
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87058] Hermetic build disabled by default; bundle build performs live network fetches

Hermetic build disabled by default; bundle build performs live network fetches. Red Hat rates this low (CVSS 2.6). Weakness: CWE-829.

CVE-2026-87058
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87059] Unpinned pip dependency installation in bundle builder stage

Unpinned pip dependency installation in bundle builder stage. Red Hat rates this low (CVSS 2.6). Weakness: CWE-494.

CVE-2026-87059
Unclassified
Sep 8, 2026

← All vendors