Red Hat Linux Security Advisories & CVEs
11898 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Critical [CVE-2026-78234] Service-CA signing oracle allows arbitrary-CN certificate issuance to namespace edit users
Service-CA signing oracle allows arbitrary-CN certificate issuance to namespace edit users. Red Hat rates this important (CVSS 9.9). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:66120 with package rhbac-4/hawtio-operator-bundle:2.0.1-8, rhbac-4/hawtio-rhel9-operator:2.0.1-10. Affected product named by the advisory: Red Hat build of Apache Camel - HawtIO 4.
High [CVE-2026-53938] Heap buffer overflow in AES Key Wrap decryption leads to denial of service
Heap buffer overflow in AES Key Wrap decryption leads to denial of service. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:73017 with package cjose-0:0.6.1-13.el9_2.1, cjose-0:0.6.1-16.el9_4.1. Affected product named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-87049] Over-permissive GITHUB_TOKEN and GCP WIF secrets granted to third-party reusable workflow on untrusted-triggerable events
Over-permissive GITHUB_TOKEN and GCP WIF secrets granted to third-party reusable workflow on untrusted-triggerable events. Red Hat rates this important (CVSS 8.7). Weakness: CWE-269.
High [CVE-2026-79721] Arbitrary code execution via maliciously crafted model artifact
Arbitrary code execution via maliciously crafted model artifact. Red Hat rates this important (CVSS 8). Weakness: CWE-502. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-57099] Denial of Service via uncontrolled resource allocation
Denial of Service via uncontrolled resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-69806] .NET Elevation of Privilege Vulnerability
.NET Elevation of Privilege Vulnerability. Red Hat rates this important (CVSS 7). Weakness: CWE-200. Red Hat lists fixing advisory RHSA-2026:66863 with package dotnet9.0-0:9.0.121-1.el9_8, dotnet10.0-0:10.0.112-1.el9_8, dotnet9.0-0:9.0.121-1.el8_10, dotnet10.0-0:10.0.112-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.
High [CVE-2026-12611] org.eclipse.jetty.http2/jetty-http2-common: Jetty: Denial of Service via HTTP/2 race condition
org.eclipse.jetty.http2/jetty-http2-common: Jetty: Denial of Service via HTTP/2 race condition. Red Hat rates this important (CVSS 7.5). Weakness: CWE-367. Affected products named by the advisory: OpenShift Developer Tools and Services; Red Hat Offline Knowledge Portal.
High [CVE-2026-19203] HTTP request smuggling via crafted chunked requests
HTTP request smuggling via crafted chunked requests. Red Hat rates this important (CVSS 8.2). Weakness: CWE-444. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat AMQ Broker 7; Red Hat build of Apache Camel 4 for Quarkus 3; and 11 more. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apache Camel - HawtIO 4; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; and 7 more.
High [CVE-2026-11573] Denial of Service via uncontrolled recursion in XML serialization
Denial of Service via uncontrolled recursion in XML serialization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: qt6-qtbase.
High [CVE-2026-80219] OAuthClient created with GrantMethod auto and no secret enables OAuth token theft
OAuthClient created with GrantMethod auto and no secret enables OAuth token theft. Red Hat rates this important (CVSS 8.7). Weakness: CWE-1390. Affected product named by the advisory: Red Hat build of Apache Camel - HawtIO 4.
High [CVE-2026-77968] Cluster-wide secrets read/write granted to operator ServiceAccount
Cluster-wide secrets read/write granted to operator ServiceAccount. Red Hat rates this important (CVSS 8.2). Weakness: CWE-269. Red Hat lists fixing advisory RHSA-2026:66120 with package rhbac-4/hawtio-operator-bundle:2.0.1-8, rhbac-4/hawtio-rhel9-operator:2.0.1-10. Affected product named by the advisory: Red Hat build of Apache Camel - HawtIO 4.
High [CVE-2026-74860] Libxml2: double-free/uaf in libxml2 python bindings
A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. Red Hat severity: Important — CVSS 8.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-763. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:64463. Affected products named by the advisory: Red Hat package: libxml2.
High [CVE-2026-76561] certprofile-import allows code execution via unsanitized profile content (ExternalProcessConstraint)
certprofile-import allows code execution via unsanitized profile content (ExternalProcessConstraint). Red Hat rates this important (CVSS 7.2). Weakness: CWE-78. Affected products named by the advisory: Red Hat Certificate System 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
Medium [CVE-2026-87053] Final container image runs as root (USER root never reverted)
Final container image runs as root (USER root never reverted). Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-250.
Medium [CVE-2026-87054] containers-policy.json defaults to insecureAcceptAnything for non-Red Hat registries
containers-policy.json defaults to insecureAcceptAnything for non-Red Hat registries. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-345.
Medium [CVE-2026-87050] GitHub Actions and reusable workflow not pinned to commit SHA
GitHub Actions and reusable workflow not pinned to commit SHA. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-829.
Medium [CVE-2026-87057] Runtime base images referenced by mutable floating tags
Runtime base images referenced by mutable floating tags. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-829.
Medium [CVE-2026-87062] GitHub Actions referenced by mutable tag/branch instead of commit SHA
GitHub Actions referenced by mutable tag/branch instead of commit SHA. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-829.
Medium [CVE-2026-58649] .NET Information Disclosure Vulnerability
.NET Information Disclosure Vulnerability. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-346. Red Hat lists fixing advisory RHSA-2026:68316 with package dotnet9.0-0:9.0.121-1.el9_8, dotnet10.0-0:10.0.112-1.el9_8, dotnet9.0-0:9.0.121-1.el8_10, dotnet8.0-0:8.0.131-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.
Medium [CVE-2026-74859] Gnome-tweaks: path traversal in theme installer
The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files outside ~/.themes by using../ path traversal, absolute paths, or symlink entries. This vulnerability is rated Moderate because it requires a user to actively install a specially crafted GNOME Shell theme via the `gnome-tweaks` utility. Exploitation is not possible without user interaction and the deliberate installation of a malicious theme, limiting the attack surface in typical Red Hat desktop environments. Red Hat severity: Moderate — CVSS 6.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H). Weakness: CWE-22. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gnome-tweaks.