Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

413 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-5873] Out of bounds read and write in V8

Out of bounds read and write in V8. Red Hat rates this important (CVSS 9.6). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5873
Unclassified
Apr 7, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-5859] Integer overflow in WebML

Integer overflow in WebML. Red Hat rates this important (CVSS 9.6). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5859
Unclassified
Apr 7, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-35030] Authentication bypass and privilege escalation via OIDC userinfo cache key collision

Authentication bypass and privilege escalation via OIDC userinfo cache key collision. Red Hat rates this important (CVSS 9.1). Weakness: CWE-222. Affected package(s): ansible-automation-platform, rhoai/odh-llama-stack-core-rhel9:1781826406, rhoai/odh-llama-stack-core-rhel9:1782310008. Resolved in Red Hat advisory RHSA-2026:28960 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3.

CVE-2026-35030
Unclassified
Apr 6, 2026
Critical9.8Red Hat

Critical [CVE-2026-34875] Mbed TLS and TF-PSA-Crypto: Arbitrary code execution due to buffer overflow in FFDH key export

Mbed TLS and TF-PSA-Crypto: Arbitrary code execution due to buffer overflow in FFDH key export. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34875
Unclassified
Apr 1, 2026
Critical10.0Red Hat

Critical [CVE-2026-34873] Client impersonation during TLS 1.3 session resumption

Client impersonation during TLS 1.3 session resumption. Red Hat rates this critical (CVSS 10). Weakness: CWE-290. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34873
Unclassified
Apr 1, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-5272] Heap buffer overflow in GPU

Heap buffer overflow in GPU. Red Hat rates this important (CVSS 9.6). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5272
Unclassified
Mar 31, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-5284] Use after free in Dawn

Use after free in Dawn. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5284
Unclassified
Mar 31, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-5278] Use after free in Web MIDI

Use after free in Web MIDI. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5278
Unclassified
Mar 31, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-5285] Use after free in WebGL

Use after free in WebGL. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5285
Unclassified
Mar 31, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-5274] Integer overflow in Codecs

Integer overflow in Codecs. Red Hat rates this important (CVSS 9.6). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5274
Unclassified
Mar 31, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-5275] Heap buffer overflow in ANGLE

Heap buffer overflow in ANGLE. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5275
Unclassified
Mar 31, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-5273] Use after free in CSS

Use after free in CSS. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5273
Unclassified
Mar 31, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-5277] Integer overflow in ANGLE

Integer overflow in ANGLE. Red Hat rates this important (CVSS 9). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5277
Unclassified
Mar 31, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-5279] Object corruption in V8

Object corruption in V8. Red Hat rates this important (CVSS 9.6). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5279
Unclassified
Mar 31, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2025-15379] Arbitrary command execution via command injection in model serving container initialization.

Arbitrary command execution via command injection in model serving container initialization.. Red Hat rates this important (CVSS 9). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2025-15379
Unclassified
Mar 30, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2025-15036] Path traversal vulnerability allows arbitrary file overwrite and privilege escalation

Path traversal vulnerability allows arbitrary file overwrite and privilege escalation. Red Hat rates this important (CVSS 9.6). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2025-15036
Unclassified
Mar 30, 2026
Critical9.8Vendor: HighRed Hat

Critical [CVE-2026-33937] Remote Code Execution via crafted Abstract Syntax Tree object in compile()

Remote Code Execution via crafted Abstract Syntax Tree object in compile(). Red Hat rates this important (CVSS 9.8). Weakness: CWE-94. Affected package(s): cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, devspaces/code-rhel9:1776744110. Resolved in Red Hat advisory RHSA-2026:34342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.27; Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; and 1 more.

CVE-2026-33937
Unclassified
Mar 27, 2026
Critical9.1Red Hat

Critical [CVE-2026-27876] Remote arbitrary code execution via chained SQL Expressions and Enterprise plugin attack

Remote arbitrary code execution via chained SQL Expressions and Enterprise plugin attack. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-89. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27876
Unclassified
Mar 27, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-33758] reflected XSS in OpenBao OIDC authentication error message

reflected XSS in OpenBao OIDC authentication error message. Red Hat rates this important (CVSS 9.6). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33758
Unclassified
Mar 27, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-33757] lack of user confirmation for OpenBao OIDC direct callback mode

lack of user confirmation for OpenBao OIDC direct callback mode. Red Hat rates this important (CVSS 9.6). Weakness: CWE-384. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33757
Unclassified
Mar 27, 2026

← All vendors