Red Hat Linux Security Advisories & CVEs
11898 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-85666] Information disclosure via Server-Side Request Forgery in MCP tool server_url
Information disclosure via Server-Side Request Forgery in MCP tool server_url. Red Hat rates this important (CVSS 7.5). Weakness: CWE-918. Affected products named by the advisory: Lightspeed Core; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-85664] Denial of service via unbounded HNSW index parameters.
A flaw was found in Chroma. Unauthenticated attackers can exploit this vulnerability by providing excessively large parameters during collection creation. This can lead to the exhaustion of server memory, resulting in a denial of service during index compaction. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1284. Red Hat lists Multicluster Global Hub; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Hardened Images; Red Hat OpenShift GitOps; Red Hat OpenStack Platform 18.0 as not affected.
High [CVE-2026-85625] sift 17.1.3 Prototype Pollution Remote Code Execution via $where
sift 17.1.3 Prototype Pollution Remote Code Execution via $where. Red Hat rates this important (CVSS 8.1). Weakness: CWE-94. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.
High [CVE-2026-85623] Arbitrary Command Execution via Recipe Extensions
Arbitrary Command Execution via Recipe Extensions. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78.
High [CVE-2026-85597] Authentication bypass via TLS option conflict
Authentication bypass via TLS option conflict. Red Hat rates this important (CVSS 7.5). Weakness: CWE-303. Affected product named by the advisory: Red Hat OpenShift Dev Spaces.
High [CVE-2026-85596] Authentication bypass due to TLS configuration conflict
Authentication bypass due to TLS configuration conflict. Red Hat rates this important (CVSS 7.5). Weakness: CWE-305.
High [CVE-2026-85594] Information disclosure via crossProviderNamespaces bypass in Kubernetes Ingress provider
Information disclosure via crossProviderNamespaces bypass in Kubernetes Ingress provider. Red Hat rates this important (CVSS 7.7). Weakness: CWE-1220.
High [CVE-2026-84428] Header validation bypass via incomplete schema case normalization
fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it lowercases the properties keys and the root-level required array, and does not lowercase the trigger and dependent names inside the JSON Schema Draft 7 dependencies keyword. Because Node stores request header names in lowercase, a canonical-case dependency such as requiring an authentication header whenever a privileged-mode header is present never matches, and the presence assertion is silently skipped. An unauthenticated remote client can therefore send the header that activates a privileged branch while omitting the header the dependency was meant to require, bypassing the conditional check. Users should upgrade to fastify 5.12.2 or later. A flaw was found in fastify. Due to incomplete case normalization of HTTP header names within a route's header schema, specifically within the JSON Schema Draft 7 dependencies keyword, an unauthenticated remote attacker can bypass intended conditional checks. This allows the attacker to send headers that activate privileged functionality without providing the required authentication headers, leading to an authorization bypass.
High [CVE-2026-84469] Request validation bypass allows unauthorized operations
fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as a valid schema that rejects every instance. When an application assigns false to a route's body, querystring, params, or headers schema to deny all input, fastify treats it as a missing schema, compiles no validator, and runs the route handler on any request. An unauthenticated remote client can therefore reach a handler that a valid deny-all schema was intended to make unreachable, a complete validation bypass that can lead to unauthorized state changes or execution of disabled operations. Users should upgrade to fastify 5.12.2 or later. A flaw was found in fastify. An unauthenticated remote attacker can bypass request validation by exploiting how fastify processes boolean false schemas. This bypass occurs when a `false` boolean is used as a schema to deny input, leading to the execution of otherwise unreachable route handlers. This could result in unauthorized operations or state changes within affected Red Hat OpenShift AI, Red Hat Enterprise Linux AI, and Red Hat OpenShift Dev Spaces deployments. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-1287. Will not fix / out of support: Red Hat Enterprise Linux AI (RHEL AI) 3.
High [CVE-2026-76169] Authentication bypass via malformed URLs
fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-found router for encapsulated handlers dispatches malformed paths through a single shared handler pointer before URL decoding, ignoring the prefix and skipping the selected handler's normal lifecycle. An unauthenticated attacker can therefore reach an authentication-protected private fallback through an unrelated public prefix and read its full response, bypassing the authentication hook and breaking prefix encapsulation. Users should upgrade to fastify 5.12.2 or later. A flaw was found in fastify. Malformed URLs can be routed to a custom not-found handler of a different plugin, bypassing the intended security checks. This is an Important flaw in fastify that allows an unauthenticated attacker to bypass authentication hooks. By sending a specially crafted malformed URL, an attacker can access private fallback handlers and read their responses, thereby circumventing intended access controls in Red Hat OpenShift AI and Red Hat OpenShift Dev Spaces deployments. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-289.
High [CVE-2026-84504] Unauthorized state changes and data disclosure via request body replacement
fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If a request that passes its route schema contains a property named value at the root, fastify replaces the entire request body with that property's value before the handler runs, so the handler receives a different object than the one that satisfied the schema. An authenticated low-privilege caller can use this to make nested data replace the validated body and trigger an operation the route schema did not authorize, leading to unauthorized state changes and data disclosure. Users should upgrade to fastify 5.12.2 or later. A flaw was found in fastify. An authenticated low-privilege caller can exploit a vulnerability where the framework incorrectly processes the result of an Ajv asynchronous (async) validator. This can lead to unauthorized state changes and the disclosure of sensitive data, as the application handler receives an unvalidated object. This Important flaw in fastify allows an authenticated low-privilege user to bypass schema validation. By injecting a 'value' property into the request body, an attacker can trigger unauthorized state changes and data disclosure, impacting the integrity and confidentiality of data in affected Red Hat OpenShift AI and Red Hat OpenShift Dev Spaces deployments.
High [CVE-2026-81665] heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly
A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control. This vulnerability is rated as Important. The published Red Hat CVSS score is 7.5 (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), matching the unmitigated upstream baseline. RHEL High Availability Add-On clusters are configured via the pcs (Pacemaker/Corosync configuration system) tool, whose 'pcs cluster setup' command has defaulted to generating a corosync.conf with crypto_hash=sha256 and crypto_cipher=aes256 for multiple RHEL 8.x and 9.x releases, which meaningfully reduces real-world risk by requiring an attacker to already possess the cluster's shared authentication key before the vulnerable code is ever reached. This has been confirmed directly with upstream corosync maintainer Jan Friesse (2026-08-31).
High [CVE-2026-71198] SSRF via location API missing host validation
In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks the URL scheme and does not apply the import_filtering_opts host restrictions. An authenticated user can add a location pointing to internal endpoints such as the cloud metadata service (169.254.169.254), and retrieve the response by downloading the image data. This affects both the new POST /v2/images/{id}/locations API and the old PATCH API when show_multiple_locations is enabled. Deployments with the HTTP store backend enabled are affected. A server-side request forgery (SSRF) vulnerability was found in OpenStack Glance. Glance validates only the URL scheme and does not check the host or IP address, allowing the server to make requests to arbitrary internal endpoints. An attacker can read the response by downloading the image, resulting in a full-read SSRF that may expose sensitive data such as cloud metadata credentials. This vulnerability is rated as Important because an authenticated project member can use the Glance location API as a full-read SSRF proxy to internal HTTP services, including cloud metadata credentials. It is separate from the web-download SSRF fixed in CVE-2026-34881.
High [CVE-2026-71196] SSRF via web-download import due to empty default host filters
A server-side request forgery (SSRF) vulnerability was found in OpenStack Glance. The web-download image import method allows authenticated users to provide a URI from which the Glance service fetches data. Due to insufficient default host filtering, an attacker with standard tenant credentials can make Glance issue HTTP requests to arbitrary internal network hosts, including the cloud metadata service. The fetched response is stored as image data and can be downloaded by the attacker, enabling exfiltration of sensitive internal data such as cloud instance credentials. This vulnerability is rated as Important because an authenticated tenant with the standard member role can use Glance as a full-read SSRF proxy to internal HTTP services, including cloud metadata credentials. No administrative role is required. Red Hat OpenStack Services on OpenShift (RHOSO) and Red Hat OpenStack Platform (RHOSP) deployments that ship OpenStack Glance with web-download enabled are affected. Deployments that have removed web-download from enabled_import_methods, or that have explicitly configured disallowed_hosts to block internal IP ranges, are not affected by the default-config path. Red Hat severity: Important — CVSS 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N). Weakness: CWE-918. Red Hat lists Red Hat OpenStack Platform 13 (Queens) as not affected.
High [CVE-2026-85525] Data interception via improper OCSP response validation
Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and definitive verification failures were treated as transient. A man-in-the-middle attacker holding a revoked certificate and its private key for a Snowflake or stage hostname could cause the driver to establish a TLS session to the attacker-controlled endpoint anyway, allowing the attacker to read and modify data transmitted within that connection. Successful exploitation requires that on-path position and the corresponding private key, and impact is limited to data carried within the intercepted connection. The fix is available in the patched versions listed above. Users must manually upgrade. This flaw involves improper Online Certificate Status Protocol (OCSP) response validation, which allows a revoked Transport Layer Security (TLS) certificate to be accepted as valid. This vulnerability is rated as Important because improper OCSP response validation in Snowflake drivers, utilized by Red Hat OpenShift AI, could enable a man-in-the-middle attacker to intercept and modify data. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-85197] Heap use-after-free in libsoup HTTP/2 client on_data_read via GOAWAY during body upload
A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution. This flaw only affects libsoup3. Red Hat severity: Important — CVSS 7.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H). Weakness: CWE-416. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat fixing advisory: RHSA-2026:68235. Affected products named by the advisory: Red Hat package: libsoup3.
High [CVE-2026-85509] Arbitrary code execution via stack-based buffer overflow
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested. A flaw was found in FreeIPMI. This vulnerability involves a stack-based buffer overflow that occurs when a Baseboard Management Controller (BMC) sends an oversized response during data reading. An attacker could exploit this by tricking an administrator into running FreeIPMI commands against a malicious BMC. Successful exploitation could lead to arbitrary code execution, allowing the attacker to run their own code on the affected system. FreeIPMI contains a stack-based buffer overflow triggered by oversized responses from a Baseboard Management Controller (BMC), potentially allowing arbitrary code execution. The severity is constrained to Moderate because the vulnerability cannot be exploited without direct administrative interaction. An attacker must possess a compromised BMC and rely on an administrator to explicitly execute FreeIPMI commands against it to trigger the vulnerable code path. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-121. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6.
High [CVE-2026-85508] stack-based buffer overflow in ipmi-oem Dell system info handler
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info). The vulnerable function _output_dell_system_info_cmc_ipv6_info uses a 256-byte stack buffer but allows up to 65536 bytes of data to be copied from a BMC response without proper bounds checking. This flaw has limited practical impact for several reasons: (1) ipmi-oem is a client-side command-line tool run manually by administrators, not a listening service or daemon — exploitation requires a user to actively run the specific Dell OEM subcommand against a compromised or malicious BMC; (2) IPMI communication typically occurs over a dedicated out-of-band management network, not the general Internet; (3) Red Hat Enterprise Linux builds FreeIPMI with full hardening enabled (_hardened_build 1), including stack protector (-fstack-protector-strong), which detects stack buffer corruption and terminates the process before the return address can be hijacked — effectively limiting the impact to a client-side crash rather than code execution; (4) additional mitigations including PIE, full RELRO, and NX further hinder exploitation even if the stack canary were bypassed. Fix is available in FreeIPMI version 1.6.19. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
High [CVE-2026-85507] Arbitrary code execution via stack-based buffer overflow
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info). A flaw was found in FreeIPMI. This can lead to arbitrary code execution, allowing the attacker to run malicious code on the affected system. This vulnerability is classified as Moderate because the high potential impact (arbitrary code execution) is offset by limited exploitability: an attacker must already possess local access to the system and intentionally execute this specific subcommand to trigger the flaw. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-121. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: freeipmi.
High [CVE-2026-85506] Arbitrary code execution via stack-based buffer overflow in ipmi-oem
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info). A flaw was found in FreeIPMI. A stack-based buffer overflow in the `ipmi-oem` utility can lead to arbitrary code execution. This vulnerability can be exploited by a local user who executes a specially crafted `ipmi-oem` command, potentially when processing untrusted data from a remote source. To exploit this moderate-severity flaw, a local user must be tricked into running a specially crafted command that processes untrusted data. The requirement for local access and active user interaction significantly increases the overall complexity of the attack. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-121. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: freeipmi.