Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11898 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.4Red Hat

Medium [CVE-2026-85090] Heap Out-of-Bounds Read in AVC444 Chroma Combine

FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane. A flaw was found in FreeRDP. A remote attacker, acting as a malicious Remote Desktop Protocol (RDP) server, can exploit this by sending a specially crafted `RFX_AVC444_BITMAP_STREAM` with specific frame geometry. This can lead to an out-of-bounds memory read, potentially disclosing sensitive heap data to the client or causing a client crash, resulting in a denial of service. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-85090
Red Hat Enterprise Linux
Sep 3, 2026
Low3.5Red Hat

Low [CVE-2026-77465] Denial of Service via uncontrolled recursion in TOML parsing

toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() uses a Peggy 5.1.0 generated recursive-descent parser in lib/parser.js whose peg$parsevalue, peg$parsearray, and peg$parseinline_table_entry functions recurse through nested arrays and inline tables without a depth limit. The corresponding grammar source is src/toml.pegjs, where the generated parser must be bounded. This issue is fixed in version 4.2.0. A remote, unauthenticated attacker can exploit an uncontrolled recursion vulnerability in the TOML parser by crafting a malicious TOML document with deeply nested arrays or inline tables. This can lead to the exhaustion of the Node.js call stack, causing a RangeError and terminating the application process, resulting in a Denial of Service (DoS). The toml npm package is bundled in cockpit-image-builder, but the vulnerable TOML parser is only invoked client-side when an authenticated user manually uploads a blueprint file. The parsing error is caught, limiting impact to a browser-side error notification. Red Hat rates this as Low impact. Red Hat severity: Low — CVSS 3.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L). Weakness: CWE-606. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: cockpit-image-builder.

CVE-2026-77465
Red Hat Enterprise Linux
Sep 3, 2026
Low3.7Red Hat

Low [CVE-2026-63376] Arbitrary Code Execution via Prototype Pollution in TOML Parsing

toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Object.prototype. The currentPath tracking value uses both arrays and strings, so valueAssignments records a comma-joined path such as a,b.y while deepRef checks the dot-joined path a.b.y, allowing the duplicate-key guard to miss and attacker-controlled keys to be written to Object.prototype. A table-array prefix-clearing path in addTableArray can also erase guard state before the same __proto__ traversal. Injected properties become visible throughout the Node.js process and can cause denial of service, logic or authorization bypass, or code execution when an application contains a suitable gadget. This issue is fixed in version 4.1.2. A flaw was found in toml-node, a software library used for parsing TOML (Tom's Obvious, Minimal Language) files in Node.js and web applications. A remote attacker could exploit a vulnerability known as prototype pollution by providing specially crafted TOML input. This could allow the attacker to inject properties into fundamental JavaScript objects, potentially leading to arbitrary code execution, denial of service, or bypassing security controls within the affected application.

CVE-2026-63376
Red Hat Enterprise Linux
Sep 3, 2026
CriticalRed Hat

Critical [CVE-2026-76595] Unsafe YAML deserialization of associate-editable Task playbook (yaml.Loader)

A flaw was found in advisor-backend. Multiple code paths within the application deserialize YAML (YAML Ain't Markup Language) with an unsafe full Loader, which can instantiate arbitrary Python objects via YAML tags. This compromise could allow access to shared database credentials and impact all tenants. Red Hat severity: Critical. Weakness: CWE-502.

CVE-2026-76595
Unclassified
Sep 2, 2026
High7.5Red Hat

High [CVE-2026-84394] Host confusion via unbalanced URI brackets can bypass security policies

fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but does not end with a closing bracket is neither validated as an IP literal nor canonicalized as a domain name, so parse() returns it as the host with error undefined, while Node's URL and the HTTP clients built on it resolve the same string to a different host. An application that reads the parsed host to make a host decision, such as an SSRF denylist, a redirect allowlist, or proxy routing, and then passes the original URL to an HTTP client evaluates its policy against a string that is not the host the request reaches. This affects fast-uri versions 2.4.5, 3.1.6, and 4.1.3, and is fixed in 2.4.6, 3.1.7, and 4.1.4, where parse() reports a malformed host for any host that contains a bracket but is not a valid IPv6 literal. The library incorrectly processes Uniform Resource Identifier (URI) hosts containing unbalanced brackets, leading to a discrepancy in how the host is parsed by fast-uri compared to other HTTP clients. This host confusion can allow an attacker to bypass security policies, such as Server-Side Request Forgery (SSRF) denylists or redirect allowlists, by causing an application to evaluate its policy against an incorrect host string.

CVE-2026-84394
Unclassified
Sep 2, 2026
High7.5Red Hat

High [CVE-2026-84292] Authority Injection via Unvalidated Port Serialization

fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node's URL read the result back as the attacker's host with no error, so re-validating the built URI does not catch it. This affects applications that build URIs from parts and assign untrusted data to the port component through the serialize, normalize, or equal functions in their object forms. It is fixed in 2.4.6, 3.1.7, and 4.1.4, where recomposeAuthority rejects any port that is not a digit sequence per RFC 3986. A remote attacker can exploit this by crafting a malicious port value that injects authority delimiters. This manipulation can demote the intended host to user information and redirect the authority to an attacker-controlled host, leading to information disclosure as applications interpret the attacker's host as legitimate. This is an Important flaw. This could allow an attacker to redirect network traffic to an arbitrary host, compromising communication integrity. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-140.

CVE-2026-84292
Red Hat Enterprise Linux
Sep 2, 2026
High7.5Red Hat

High [CVE-2026-84382] Denial of Service via streaming response decompression memory amplification

HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bounded pieces to the application. A 64 KiB compressed chunk can expand to approximately 64 MiB in one intermediate allocation, so an attacker-controlled or compromised server can cause severe memory pressure or out-of-memory process termination even when the application streams the response. This issue is fixed in version 2.12.0. This can lead to a small compressed chunk expanding significantly in memory, for example, a 64 KiB chunk expanding to approximately 64 MiB. A remote attacker, by controlling or compromising a server, could exploit this vulnerability to cause severe memory pressure or out-of-memory process termination, leading to a Denial of Service (DoS) for applications using httpx2. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-409. Affected Red Hat products: Lightspeed Core; Red Hat OpenShift AI (RHOAI). Red Hat lists Red Hat OpenShift AI (RHOAI) as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-84382
Unclassified
Sep 2, 2026
High8.1Red Hat

High [CVE-2026-84381] WebSocket traffic sent in plaintext via SOCKS5 proxy due to TLS failure

HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 proxy because the TLS upgrade condition only recognizes https. HTTPX2 exposes the flaw through Client.websocket() and AsyncClient.websocket() from 2.6.0 through 2.9.1, so the opening handshake, query parameters, Authorization headers, cookies, and subsequent frames can cross the proxy path in plaintext without certificate verification. An attacker controlling or observing that path can read or modify traffic and impersonate the WebSocket server. This issue is fixed in httpcore2 2.10.0 and HTTPX2 2.10.0. A flaw was found in httpcore2, a component used by HTTPX2. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-319. Affected Red Hat products: Lightspeed Core; Red Hat OpenShift AI (RHOAI). Red Hat lists Red Hat OpenShift AI (RHOAI) as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-84381
Unclassified
Sep 2, 2026
High8.1Red Hat

High [CVE-2026-84649] Cross-site request forgery token disclosure allows session hijacking

In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site request forgery (CSRF) token (crumb) as a string literal, allowing attackers with control over a page hosted on the same site as Jenkins to obtain a valid crumb for the targeted user's session and perform actions on their behalf. A flaw was found in Stapler, a web framework used by Jenkins. Consequently, the attacker can perform unauthorized actions on behalf of the user, leading to session hijacking. This Important vulnerability in Stapler, as used in Jenkins, allows an attacker to perform session hijacking. This risk is elevated when the Resource Root URL is configured on the same domain as the Jenkins URL. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N). Weakness: CWE-201. Affected Red Hat products: OpenShift Developer Tools and Services. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-84649
Unclassified
Sep 2, 2026
High8.5Red Hat

High [CVE-2026-84647] Unintended configuration object instantiation via form data binding

In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field type, allowing attackers with Overall/Read permission to instantiate types related to configuration for which that field type was not intended. This could lead to unauthorized manipulation of system configurations. Red Hat rates this Important, CVSS 8.5, against CISA's 8.8. Both agree on attack vector, complexity, and the Overall/Read requirement; they differ on impact. Stapler's form binding normally restricts which object types a submitted form can instantiate to match the target field. This flaw removes that restriction, so an attacker can force creation of unintended configuration objects. That is unauthorized modification of config state, an integrity problem. It is not a confidentiality or availability problem: instantiating an object doesn't return its contents to the attacker, and nothing in the advisory shows a crash or resource exhaustion path. Red Hat scores confidentiality Low and availability None accordingly. CISA's C:H/A:H assumes a worst case gadget chain outcome; Red Hat scores to what the advisory actually demonstrates.

CVE-2026-84647
Unclassified
Sep 2, 2026
High7.8Vendor: MediumRed Hat

High [CVE-2026-84838] Command injection in rpmuncompress via unescaped filenames passed to popen

A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow invokes rpmuncompress on the malicious file, leading to high impact on the confidentiality, integrity, and availability of data accessible to the invoking user. This issue is considered Moderate severity because, although successful exploitation allows arbitrary command execution with the privileges of the user running rpmuncompress (or a build workflow that invokes it via %{__rpmuncompress}), exploitation requires a specially crafted local archive filename to be processed by that tool. The vulnerable code is not exposed as a network service and cannot be triggered remotely without a user or automated workflow invoking rpmuncompress on the attacker-controlled filename. Red Hat severity: Moderate — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-78. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Hardened Images. Affected products named by the advisory: Red Hat package: rpm.

CVE-2026-84838
Red Hat Enterprise Linux
Sep 2, 2026
High7.8Vendor: MediumRed Hat

High [CVE-2026-84837] Command Injection in `rpmbuild -t*` (`getTarSpec`) via Unescaped Tarball Path

A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment. The vulnerable code is not exposed as a network service and cannot be triggered remotely without a local build or CI workflow processing an attacker-controlled tarball name. Red Hat severity: Moderate — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-78. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: rpm.

CVE-2026-84837
Red Hat Enterprise Linux
Sep 2, 2026
High7.0Red Hat

High [CVE-2026-78409] X-mount.subdir detached-tree resolution can escape via intermediate symlinks

The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint. Affected versions: util-linux v2.42 through v2.42.2. Earlier releases, including v2.40 and v2.41, are not affected. Restricted-user SUID mount(8) reproduction also requires Linux >= 6.15. Fixed in v2.41.6 and v2.42.3. Red Hat severity: Important — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-59. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4 as not affected. Red Hat fixing advisory: RHSA-2026:63162.

CVE-2026-78409
Unclassified
Sep 2, 2026
High7.8Red Hat

High [CVE-2026-78410] restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection

A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode. X-mount.owner/group/mode was introduced in v2.39; earlier releases are not affected. Fixed in v2.41.6 and v2.42.3. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-367. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10. Red Hat lists Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4 as not affected. Red Hat fixing advisory: RHSA-2026:63162. Affected products named by the advisory: Red Hat package: util-linux.

CVE-2026-78410
Red Hat Enterprise Linux
Sep 2, 2026
High7.9Red Hat

High [CVE-2026-78408] nsenter --join-cgroup leaks root cgroup migration authority

The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes. Affected versions: util-linux v2.40 through v2.42.2. Fixed in v2.41.6 and v2.42.3. Red Hat severity: Important — CVSS 7.9 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H). Weakness: CWE-775. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10. Red Hat lists Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4 as not affected. Red Hat fixing advisory: RHSA-2026:63162. Affected products named by the advisory: Red Hat package: util-linux.

CVE-2026-78408
Red Hat Enterprise Linux
Sep 2, 2026
High8.1Red Hat

High [CVE-2026-76594] Unauthenticated /private/import_content/ endpoint allows global rule-catalogue overwrite

A flaw was found in advisor-backend. A network-adjacent unauthenticated attacker could exploit a vulnerability in the `/private/import_content/` endpoint, which lacks proper authentication and permission checks. This allows the attacker to overwrite the global Advisor rule, resolution, and playbook catalogue. When combined with another vulnerability involving unsafe YAML deserialization, this could lead to arbitrary code execution on affected systems. This flaw, when chained with a separate unsafe YAML deserialization vulnerability, could lead to remote code execution on customer hosts by injecting malicious Ansible playbooks. The affected endpoint is exposed on the same listener as the public API, increasing the risk in standard deployments. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H). Weakness: CWE-306.

CVE-2026-76594
Unclassified
Sep 2, 2026
High7.8Red Hat

High [CVE-2026-76642] failed external mount helper still runs privileged X-mount post-hooks

util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation. When an external mount. helper runs but exits with a nonzero status, libmount still treats the helper invocation as successful and runs privileged post-mount hooks. A local unprivileged user with an /etc/fstab entry that uses the user option together with X-mount.idmap or X-mount.owner/group/mode can cause those hooks to clone or re-own the underlying filesystem after the helper fails, leading to local privilege escalation. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-390. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10. Red Hat lists Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4 as not affected. Red Hat fixing advisory: RHSA-2026:63162. Affected products named by the advisory: Red Hat package: util-linux.

CVE-2026-76642
Red Hat Enterprise Linux
Sep 2, 2026
High7.1Red Hat

High [CVE-2026-14199] Session takeover via Auth Proxy cache key collision

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing). On instances using Auth Proxy header authentication ([auth.proxy]) with identity caching enabled (sync_ttl > 0), two distinct user identities could produce the same cache key. An authenticated low-privileged user able to influence their own forwarded identity attributes could be served a higher-privileged user's cached session and act as that user for the duration of the cache TTL. Default configurations are not affected. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L). Weakness: CWE-639. Affected Red Hat products: Red Hat Hardened Images; Multicluster Global Hub; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9.

CVE-2026-14199
Unclassified
Sep 2, 2026
Medium5.3Red Hat

Medium [CVE-2026-78662] Denial of Service via channel request flooding

Denial of Service via channel request flooding. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-833. Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; Builds for Red Hat OpenShift; cert-manager Operator for Red Hat OpenShift; Confidential Compute Attestation; and 34 more. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Multicluster Engine for Kubernetes; OpenShift API for Data Protection; and 30 more.

CVE-2026-78662
Red Hat Enterprise Linux
Sep 2, 2026
Medium5.3Red Hat

Medium [CVE-2026-56855] Denial of Service via crafted messages

Denial of Service via crafted messages. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-833. Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; Builds for Red Hat OpenShift; cert-manager Operator for Red Hat OpenShift; Confidential Compute Attestation; and 34 more. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Multicluster Engine for Kubernetes; OpenShift API for Data Protection; and 30 more.

CVE-2026-56855
Red Hat Enterprise Linux
Sep 2, 2026

← All vendors