Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11898 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.3Red Hat

Medium [CVE-2026-86512] java-json-tools json-patch: Improper Access Control in Copy/Move Operations

java-json-tools json-patch: Improper Access Control in Copy/Move Operations. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-281. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; Red Hat build of Quarkus; and 1 more. Affected products named by the advisory: Red Hat Fuse 7.

CVE-2026-86512
Unclassified
Sep 8, 2026
Low3.3Red Hat

Low [CVE-2026-86564] Missing length validation before reading command_data in virtio-net control queue handler

Missing length validation before reading command_data in virtio-net control queue handler. Red Hat rates this low (CVSS 3.3). Weakness: CWE-125. Affected products named by the advisory: Fast Datapath for RHEL 10; Fast Datapath for RHEL 8; Fast Datapath for RHEL 9; Red Hat Enterprise Linux 10; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: dpdk.

CVE-2026-86564
Red Hat Enterprise Linux
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87055] Base image referenced by mutable tag rather than sha256 digest

Base image referenced by mutable tag rather than sha256 digest. Red Hat rates this low (CVSS 2.6). Weakness: CWE-829.

CVE-2026-87055
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87056] No automated dependency-update configuration for submodules or Containerfile

No automated dependency-update configuration for submodules or Containerfile. Red Hat rates this low (CVSS 2.6). Weakness: CWE-1104.

CVE-2026-87056
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87051] resolveAndValidatePath performs lexical containment only — symlinks can escape the build context

resolveAndValidatePath performs lexical containment only — symlinks can escape the build context. Red Hat rates this low (CVSS 2.6). Weakness: CWE-59.

CVE-2026-87051
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87052] No automated dependency-update or vulnerability-scanning configuration

No automated dependency-update or vulnerability-scanning configuration. Red Hat rates this low (CVSS 2.6). Weakness: CWE-1104.

CVE-2026-87052
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87058] Hermetic build disabled by default; bundle build performs live network fetches

Hermetic build disabled by default; bundle build performs live network fetches. Red Hat rates this low (CVSS 2.6). Weakness: CWE-829.

CVE-2026-87058
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87059] Unpinned pip dependency installation in bundle builder stage

Unpinned pip dependency installation in bundle builder stage. Red Hat rates this low (CVSS 2.6). Weakness: CWE-494.

CVE-2026-87059
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87060] Renovate automerge enabled with base-image update exclusions

Renovate automerge enabled with base-image update exclusions. Red Hat rates this low (CVSS 2.6). Weakness: CWE-1357.

CVE-2026-87060
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87061] bundle-hack/update_bundle.sh lacks fail-fast shell options

bundle-hack/update_bundle.sh lacks fail-fast shell options. Red Hat rates this low (CVSS 2.6). Weakness: CWE-252.

CVE-2026-87061
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87063] tkn CLI installed from network without checksum or signature verification

tkn CLI installed from network without checksum or signature verification. Red Hat rates this low (CVSS 2.6). Weakness: CWE-494.

CVE-2026-87063
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87064] GitHub workflows lack explicit least-privilege permissions blocks

GitHub workflows lack explicit least-privilege permissions blocks. Red Hat rates this low (CVSS 2.6). Weakness: CWE-269.

CVE-2026-87064
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87065] Tekton task steps run as root without defense-in-depth securityContext hardening

Tekton task steps run as root without defense-in-depth securityContext hardening. Red Hat rates this low (CVSS 2.6). Weakness: CWE-250.

CVE-2026-87065
Unclassified
Sep 8, 2026
Critical9.8Red Hat

Critical [CVE-2026-18922] SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property

SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-287. Red Hat lists fixing advisory RHSA-2026:64783 with package 389-ds-base-0:2.4.5-29.el9_4, 389-ds-base-0:2.6.1-24.el9_6, 389-ds-base-0:3.0.6-21.el10_0, redhat-ds:12-9020020260903155914.1674d574. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Affected products named by the advisory: Red Hat Directory Server 11.5 E4S for RHEL 8; Red Hat Directory Server 11.7 E4S for RHEL 8; Red Hat Directory Server 11.9 for RHEL 8; Red Hat Directory Server 12.2 E4S for RHEL 9; and 13 more.

CVE-2026-18922
Unclassified
Sep 7, 2026
Critical9.8Red Hat

Critical [CVE-2026-76578] unauthenticated LDAP client can obtain administrator credentials via the self-managed-token ACI

unauthenticated LDAP client can obtain administrator credentials via the self-managed-token ACI. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:72279 with package ipa-0:4.13.4-1.el9_8, ipa-0:4.13.4-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-76578
Unclassified
Sep 7, 2026
High7.5Red Hat

High [CVE-2026-6377] Information disclosure via path traversal vulnerability

Information disclosure via path traversal vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22.

CVE-2026-6377
Unclassified
Sep 7, 2026
High8.4Red Hat

High [CVE-2026-19843] Command injection via unescaped LDAP DN in Cockpit 389 Console LDAP editor

Command injection via unescaped LDAP DN in Cockpit 389 Console LDAP editor. Red Hat rates this important (CVSS 8.4). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:64780 with package 389-ds-base-0:3.0.6-4.el10dsrv, redhat-ds:12-9040020260903102623.1674d574, redhat-ds:12-9020020260903155914.1674d574, 389-ds-base-0:3.2.0-7.el10dsrv. Affected products named by the advisory: Red Hat Directory Server 11.7 E4S for RHEL 8; Red Hat Directory Server 11.9 for RHEL 8; Red Hat Directory Server 12.2 E4S for RHEL 9; Red Hat Directory Server 12.4 E4S for RHEL 9; and 9 more. Affected products named by the advisory: Red Hat Directory Server 11.5 E4S for RHEL 8; Red Hat Directory Server 12.6 EUS for RHEL 9; Red Hat Directory Server 12.8 for RHEL 9; Red Hat Directory Server 13.0 EUS for RHEL 10; and 4 more.

CVE-2026-19843
Unclassified
Sep 7, 2026
High7.5Red Hat

High [CVE-2026-18453] pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search

pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:64783 with package 389-ds-base-0:2.4.5-29.el9_4, 389-ds-base-0:2.6.1-24.el9_6, 389-ds-base-0:3.0.6-21.el10_0, redhat-ds:12-9020020260903155914.1674d574. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7. Affected products named by the advisory: Red Hat Directory Server 11.5 E4S for RHEL 8; Red Hat Directory Server 11.7 E4S for RHEL 8; Red Hat Directory Server 11.9 for RHEL 8; Red Hat Directory Server 12.2 E4S for RHEL 9; and 13 more.

CVE-2026-18453
Unclassified
Sep 7, 2026
High7.5Red Hat

High [CVE-2026-11774 +1] heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet

heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. Red Hat lists fixing advisory RHSA-2026:64783 with package 389-ds-base-0:2.4.5-29.el9_4, 389-ds-base-0:2.6.1-24.el9_6, 389-ds-base-0:3.0.6-21.el10_0, redhat-ds:12-9020020260903155914.1674d574. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7. Affected products named by the advisory: Red Hat Directory Server 11.5 E4S for RHEL 8; Red Hat Directory Server 11.7 E4S for RHEL 8; Red Hat Directory Server 11.9 for RHEL 8; Red Hat Directory Server 12.2 E4S for RHEL 9; and 13 more.

CVE-2026-11774CVE-2026-18355
Unclassified
Sep 7, 2026
High7.5Red Hat

High [CVE-2026-76560] anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN

anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN. Red Hat rates this important (CVSS 7.5). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:64783 with package 389-ds-base-0:2.4.5-29.el9_4, 389-ds-base-0:2.6.1-24.el9_6, 389-ds-base-0:3.0.6-21.el10_0, redhat-ds:12-9020020260903155914.1674d574. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7. Affected products named by the advisory: Red Hat Directory Server 11.5 E4S for RHEL 8; Red Hat Directory Server 11.7 E4S for RHEL 8; Red Hat Directory Server 11.9 for RHEL 8; Red Hat Directory Server 12.2 E4S for RHEL 9; and 13 more.

CVE-2026-76560
Unclassified
Sep 7, 2026

← All vendors