Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11898 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.6Red Hat

Medium [CVE-2026-84380] Request Smuggling and Connection Desynchronization via Conflicting HTTP Headers

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that already contains a caller-supplied Transfer-Encoding header because its setdefault() processing checks each default header independently rather than treating the two framing headers as mutually exclusive. Fixed-size byte, JSON, form, and known-length multipart bodies can therefore be serialized over HTTP/1.1 with both headers, allowing request smuggling or connection desynchronization when downstream intermediaries disagree about which framing header takes precedence. This could allow an attacker to bypass security controls or interfere with network traffic. This vulnerability is rated Moderate. Exploitation requires a high attack complexity, as it depends on how downstream intermediaries process these conflicting headers, leading to limited impact on confidentiality, integrity, and availability. Red Hat severity: Moderate — CVSS 5.6 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L). Weakness: CWE-444. Affected Red Hat products: Lightspeed Core; Red Hat OpenShift AI (RHOAI). Red Hat lists Migration Toolkit for Applications 8; Red Hat Enterprise Linux command line assistant as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-84380
Unclassified
Sep 2, 2026
Medium5.3Red Hat

Medium [CVE-2026-84379] Multipart header injection via unvalidated input

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the files= three-element (filename, content, content_type) tuple and the files= four-element (filename, content, content_type, headers) tuple into multipart/form-data part headers without validating header names or values. CR or LF characters can terminate a part header, inject additional part headers, or end the part header block early, allowing a downstream multipart parser to treat attacker-supplied lines as genuine headers and potentially alter part semantics or bypass header-based checks. This issue is fixed in version 2.11.0. A remote attacker could exploit this vulnerability by sending specially crafted multipart/form-data requests. The `FileField.render_headers()` function fails to validate `Content-Type` values and custom headers, allowing the injection of Carriage Return (CR) or Line Feed (LF) characters. This could lead to the injection of arbitrary part headers, potentially altering the interpretation of multipart data or bypassing security checks by a downstream parser. This Moderate severity flaw in the `httpx2` Python library allows for multipart header injection.

CVE-2026-84379
Unclassified
Sep 2, 2026
Medium5.9Red Hat

Medium [CVE-2026-84378] Denial of Service via crafted Server-Sent Events stream

HTTPX2 is a next generation HTTP client for Python. From 2.5.0 until 2.10.0, the HTTPX2 Server-Sent Events parser in src/httpx2/httpx2/_sse.py repeatedly copies and rescans buffered text in _SSELineDecoder.decode() when an attacker-controlled or compromised SSE endpoint splits one unterminated line across many response chunks. The behavior affects httpx2.Client.sse() and httpx2.AsyncClient.sse(), and the total processing work grows quadratically with the line length, allowing a crafted stream to consume excessive CPU and block a synchronous worker or asynchronous event loop. This issue is fixed in version 2.10.0. This quadratic processing work consumes excessive CPU resources, leading to a Denial of Service (DoS) by blocking synchronous workers or asynchronous event loops. Moderate: A denial of service vulnerability exists in the HTTPX2 Python client library, affecting Red Hat products such as Lightspeed Core and Red Hat OpenShift AI. This flaw allows a remote attacker to consume excessive CPU resources by sending a specially crafted Server-Sent Events (SSE) stream, leading to resource exhaustion. The impact is limited to availability and requires interaction with a malicious or compromised SSE endpoint. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-606.

CVE-2026-84378
Unclassified
Sep 2, 2026
Medium6.5Red Hat

Medium [CVE-2026-84377] Authenticated Server-Side Request Forgery and credential exposure

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination the user controls and cause the proxy to send its configured provider credentials to that destination. Request validation in litellm/proxy/auth/auth_utils.py, litellm/proxy/common_request_processing.py, litellm/proxy/health_endpoints/_health_endpoints.py, litellm/proxy/image_endpoints/endpoints.py, and litellm/proxy/litellm_pre_call_utils.py used incomplete checks that did not cover every sensitive parameter or inspect equivalent values across nested request fields, path values, and bracket-notation form data. Routing and credential parameters including api_base, base_url, model_list, fallbacks, and litellm_credential_name could therefore be applied without clearing the operator's stored key, exposing upstream provider credentials and other configured secrets and permitting server-side requests to internal services reachable by the proxy. This issue is fixed in versions 1.88.6 and 1.96.2. A flaw was found in LiteLLM, a proxy server for Large Language Model (LLM) APIs. An authenticated remote attacker could exploit incomplete request validation to redirect outbound provider calls to an attacker-controlled destination.

CVE-2026-84377
Unclassified
Sep 2, 2026
Medium5.3Red Hat

Medium [CVE-2026-53600] Tar entry/content smuggling via PAX extension-header desynchronization

async-tar is a tar archive reading/writing library for async Rust. Prior to version 0.6.1, async-tar mis-applies a buffered PAX size extension to an intermediary extension header (a GNU longname L, a GNU longlink K, or a PAX x/g header) instead of to the next file entry. POSIX requires a PAX extended-header record set to describe the next file entry, never an intervening extension header. Because poll_next_raw (src/archive.rs) threads the buffered PAX records into the size computation of whatever raw header it reads next — and that header can be an intermediary L — the stream cursor is advanced by an attacker-chosen amount when the L body is consumed. The parser then desyncs relative to a POSIX-correct tar parser (e.g. GNU tar), reading subsequent bytes at the wrong block boundary. This issue has been patched in version 0.6.1. This allows an attacker to craft a malicious tar archive that manipulates the stream cursor, causing the parser to desynchronize. This desynchronization can lead to differential extraction or tar entry/content smuggling, where async-tar extracts different files or contents than a POSIX-compliant tar parser, potentially allowing an attacker to hide malicious payloads or alter expected file contents. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). Weakness: CWE-1286.

CVE-2026-53600
Unclassified
Sep 2, 2026
Medium4.3Red Hat

Medium [CVE-2026-84646] Unauthorized creation of user objects via deserialization vulnerability

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML. A flaw was found in Jenkins. While these created user objects are not actual Jenkins accounts and cannot be used for login, their unauthorized creation could lead to unexpected behavior or resource manipulation within the Jenkins environment. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N). Weakness: CWE-502. Affected Red Hat products: OpenShift Developer Tools and Services. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-84646
Unclassified
Sep 2, 2026
Medium4.3Red Hat

Medium [CVE-2026-53683] IdM/FreeIPA Web UI - Client-side open redirect in reset_password.html

reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow. Rated Moderate because exploitation requires a victim to follow a crafted link, and the direct technical impact is limited to a client-side redirect with no data disclosure or modification. The practical risk is phishing/social-engineering enablement rather than a direct technical compromise. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N). Weakness: CWE-601. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: ipa.

CVE-2026-53683
Red Hat Enterprise Linux
Sep 2, 2026
Medium6.4Red Hat

Medium [CVE-2026-82968] Cross-session email verification proof not bound to upstream identity for social providers

A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generated is not strictly bound to the specific upstream identity being verified. This allows an attacker with a different account on the same social provider to intercept the process and link their own account to the victim's local profile, gaining unauthorized access. The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that exploitation requires specific timing and user interaction during an active account-linking process. The vulnerability's root cause is the failure to bind the cross-session verification proof to the specific upstream identity for social providers. Weakness: CWE-639. Affected Red Hat products: Red Hat Build of Keycloak; Red Hat Single Sign-On 7. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-82968
Unclassified
Sep 2, 2026
Medium6.8Red Hat

Medium [CVE-2026-12704] SAML assertion replay via skipped InResponseTo validation

When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation of the InResponseTo field on all SAML responses, including SP-initiated logins. This removes anti-replay protection, allowing an attacker who obtains a valid signed SAML assertion to replay it and gain a session as the victim user. Only instances with the allow_idp_initiated SAML setting enabled are affected; this setting is off by default and Grafana OSS is not affected. An attacker who obtained a valid, signed SAML assertion for a user could replay it within its short validity window to obtain an authenticated session as that user. Red Hat severity: Moderate — CVSS 6.8 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N). Weakness: CWE-294. Red Hat lists Multicluster Global Hub; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images as not affected.

CVE-2026-12704
Unclassified
Sep 2, 2026
Critical10.0Vendor: HighRed Hat

Critical [CVE-2026-84324] Use after free in Proxy

Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-84324
Unclassified
Sep 1, 2026
High8.0Vendor: MediumRed Hat

High [CVE-2026-84335] Incorrect authorization in TabStrip

Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 8 (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-272.

CVE-2026-84335
Unclassified
Sep 1, 2026
High8.8Vendor: MediumRed Hat

High [CVE-2026-84334] Incorrect authorization in Chromoting

Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 8.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-266.

CVE-2026-84334
Unclassified
Sep 1, 2026
High8.0Red Hat

High [CVE-2026-84351] Buffer overflow in GPU

Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8 (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-787.

CVE-2026-84351
Unclassified
Sep 1, 2026
High8.8Red Hat

High [CVE-2026-84326] Uninitialized resource in V8

Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) An uninitialized resource flaw was found in the V8 component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-824.

CVE-2026-84326
Unclassified
Sep 1, 2026
High8.8Red Hat

High [CVE-2026-84347] Use after free in WebRTC

Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-84347
Unclassified
Sep 1, 2026
High8.0Red Hat

High [CVE-2026-84349] Use after free in Browser

Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8 (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-416.

CVE-2026-84349
Unclassified
Sep 1, 2026
High8.1Red Hat

High [CVE-2026-84357] Improper input validation in Omnibox

Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: High) An improper input validation flaw was found in the Omnibox component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N). Weakness: CWE-346.

CVE-2026-84357
Unclassified
Sep 1, 2026
High7.5Red Hat

High [CVE-2026-81928] Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records

Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:68787 with package perl-Net-DNS-0:1.15-2.el8_10, perl-Net-DNS-0:1.29-6.el9_8.1. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-81928
Unclassified
Sep 1, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-84375] Denial of Service vulnerability in YAML parsing

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An attacker can alias a large sequence of empty mappings into many merge targets, causing O(N * K) processing while totalMergeKeys remains unchanged and the configured resource limit is never reached. A relatively small YAML document can therefore cause prolonged CPU consumption in applications that parse untrusted YAML, and merge processing is enabled by default on these release lines. This issue is fixed in versions 3.15.2 and 4.3.2. An attacker can exploit this by providing a specially crafted YAML document that causes the parser to perform excessive processing when handling merge keys with empty sources. This can lead to prolonged CPU consumption, effectively causing a denial of service (DoS) for applications that process untrusted YAML input. The flaw allows an attacker to craft a small YAML document that, when parsed, can lead to prolonged CPU consumption due to inefficient merge key processing, potentially exhausting system resources. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-835.

CVE-2026-84375
Red Hat Enterprise Linux
Sep 1, 2026
High7.5Red Hat

High [CVE-2026-84639] Uninitialized memory in MIME parsing

Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-824. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: thunderbird.

CVE-2026-84639
Red Hat Enterprise Linux
Sep 1, 2026

← All vendors