Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11898 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.1Red Hat

High [CVE-2026-79678] idp-add eval reachable before authorization check allows environment disclosure and denial of service

idp-add eval() reachable before authorization check allows environment disclosure and denial of service. Red Hat rates this important (CVSS 8.1). Weakness: CWE-95. Red Hat lists fixing advisory RHSA-2026:72279 with package ipa-0:4.13.4-1.el9_8, ipa-0:4.13.4-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10. Affected products named by the advisory: Red Hat Enterprise Linux 8.

CVE-2026-79678
Unclassified
Sep 7, 2026
High8.8Red Hat

High [CVE-2026-86404] Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging-activemq-subsystem: artemis messaging handlers in red hat eap permit deserialization by default

EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method. However, by default both allow-list and block-list are empty. When the allow-list is empty (size == 0), isTrustedType() returns true for ALL classes. This means all classes are deserializable by default. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-502. Affected Red Hat products: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8. Red Hat lists Red Hat AMQ Broker 7; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4 as not affected. Red Hat fixing advisory: RHSA-2026:53644.

CVE-2026-86404
Unclassified
Sep 7, 2026
High7.5Red Hat

High [CVE-2026-19204] org.eclipse.jetty.websocket/websocket-core-common: Jetty: Denial of Service via crafted WebSocket frame with unknown opcode

org.eclipse.jetty.websocket/websocket-core-common: Jetty: Denial of Service via crafted WebSocket frame with unknown opcode. Red Hat rates this important (CVSS 7.5). Weakness: CWE-789. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Satellite 6; Red Hat package: jmc.

CVE-2026-19204
Red Hat Enterprise Linux
Sep 7, 2026
High7.5Red Hat

High [CVE-2026-84732] Remote Denial of Service via crafted ACK packets

Remote Denial of Service via crafted ACK packets. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190.

CVE-2026-84732
Unclassified
Sep 7, 2026
High8.8Red Hat

High [CVE-2026-84256] Arbitrary command execution via crafted certificate subject

Arbitrary command execution via crafted certificate subject. Red Hat rates this important (CVSS 8.8). Weakness: CWE-88.

CVE-2026-84256
Unclassified
Sep 7, 2026
High7.8Red Hat

High [CVE-2026-84226] Arbitrary Code Execution via Binary Planting on Windows

Arbitrary Code Execution via Binary Planting on Windows. Red Hat rates this important (CVSS 7.8). Weakness: CWE-426.

CVE-2026-84226
Unclassified
Sep 7, 2026
High7.5Red Hat

High [CVE-2026-78221] Memory corruption and information disclosure vulnerability

Memory corruption and information disclosure vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-78221
Unclassified
Sep 7, 2026
Medium5.3Red Hat

Medium [CVE-2026-86469] TOCTOU Symlink Race in `G_FILE_CREATE_REPLACE_DESTINATION` Fallback Path

TOCTOU Symlink Race in `G_FILE_CREATE_REPLACE_DESTINATION` Fallback Path. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: glib2; and 1 more.

CVE-2026-86469
Red Hat Enterprise Linux
Sep 7, 2026
Medium5.3Red Hat

Medium [CVE-2026-86321] java-json-tools jackson-coreutils: Server-Side Request Forgery via JsonLoader.fromURL

java-json-tools jackson-coreutils: Server-Side Request Forgery via JsonLoader.fromURL. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-918. Affected products named by the advisory: Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 1 more. Affected products named by the advisory: Red Hat Single Sign-On 7.

CVE-2026-86321
Unclassified
Sep 7, 2026
Medium5.3Red Hat

Medium [CVE-2026-86319] java-json-tools json-patch: Resource Consumption Vulnerability

A vulnerability has been found in java-json-tools json-patch up to 1.13. Affected by this vulnerability is the function JsonPatch.apply of the file src/main/java/com/github/fge/jsonpatch/JsonPatch.java of the component Patch Operation Handler. The manipulation leads to resource consumption. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. By manipulating input, an attacker can cause excessive resource consumption, leading to a Denial of Service (DoS) condition. An attacker can craft a malicious JSON Patch document containing deeply nested structures, excessively large arrays, or recursive references that cause the parser to enter an infinite loop or allocate memory exponentially, leading to CPU or memory exhaustion and denial of service. This vulnerability can be exploited remotely and does not require authentication. As of September 2026, the project maintainers have not responded to vulnerability reports and no patch is currently available. This issue affects Red Hat products that bundle vulnerable versions of json-patch. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-606.

CVE-2026-86319
Unclassified
Sep 7, 2026
Medium5.3Red Hat

Medium [CVE-2026-86318] java-json-tools json-patch: Remote stack-based buffer overflow via JSON manipulation

java-json-tools json-patch: Remote stack-based buffer overflow via JSON manipulation. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-120. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; Red Hat build of Quarkus; and 1 more. Affected products named by the advisory: Red Hat Fuse 7.

CVE-2026-86318
Unclassified
Sep 7, 2026
Medium5.3Red Hat

Medium [CVE-2026-86308] light0011 cms: Information disclosure via Debug Mode configuration

light0011 cms: Information disclosure via Debug Mode configuration. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-215.

CVE-2026-86308
Unclassified
Sep 7, 2026
Medium6.5Red Hat

Medium [CVE-2026-16456 +2] NIM credential Secret readable by any authenticated user

NIM credential Secret readable by any authenticated user. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-862. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-16456CVE-2026-5483CVE-2026-86332
Unclassified
Sep 7, 2026
Medium6.8Red Hat

Medium [CVE-2026-78254] Arbitrary file write via path traversal in ftp and scp tasks

Arbitrary file write via path traversal in ftp and scp tasks. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-22. Affected products named by the advisory: Migration Toolkit for Applications 8; OpenShift Developer Tools and Services; Red Hat build of Apicurio Registry 3; Red Hat Enterprise Linux 10; and 23 more. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 19 more.

CVE-2026-78254
Red Hat Enterprise Linux
Sep 7, 2026
Medium5.5Red Hat

Medium [CVE-2026-82312] Denial of service via NULL DACL on named IPC objects

Denial of service via NULL DACL on named IPC objects. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-279.

CVE-2026-82312
Unclassified
Sep 7, 2026
Medium5.5Red Hat

Medium [CVE-2026-81830] Security Bypass via incorrect file path validation

Security Bypass via incorrect file path validation. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-22.

CVE-2026-81830
Unclassified
Sep 7, 2026
Medium4.2Vendor: LowRed Hat

Medium [CVE-2026-81738] Out-of-bounds write via crafted DOMAIN-SEARCH entries

Out-of-bounds write via crafted DOMAIN-SEARCH entries. Red Hat rates this low (CVSS 4.2). Weakness: CWE-787.

CVE-2026-81738
Unclassified
Sep 7, 2026
Medium5.5Red Hat

Medium [CVE-2026-78043] Privilege Escalation via Arbitrary Configuration File Loading

Privilege Escalation via Arbitrary Configuration File Loading. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-22.

CVE-2026-78043
Unclassified
Sep 7, 2026
Medium6.2Red Hat

Medium [CVE-2026-86315] Out-of-bounds write leads to Denial of Service

Out-of-bounds write leads to Denial of Service. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-787. Affected products named by the advisory: OpenShift Lightspeed; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 8 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Update Service; and 4 more.

CVE-2026-86315
Red Hat Enterprise Linux
Sep 7, 2026
Low3.3Red Hat

Low [CVE-2026-86425] Denial of Service due to heap-use-after-free vulnerability

Denial of Service due to heap-use-after-free vulnerability. Red Hat rates this low (CVSS 3.3). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: imagemagick.

CVE-2026-86425
Red Hat Enterprise Linux
Sep 7, 2026

← All vendors