Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

413 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Critical9.6Red Hat

Critical [CVE-2026-33945] Privilege escalation and denial of service via path traversal in systemd credential configuration

Privilege escalation and denial of service via path traversal in systemd credential configuration. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33945
Unclassified
Mar 26, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-33897] Arbitrary file read/write as root via pongo2 template chroot bypass

Arbitrary file read/write as root via pongo2 template chroot bypass. Red Hat rates this important (CVSS 9.1). Weakness: CWE-243. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33897
Unclassified
Mar 26, 2026
Critical10.0Red Hat

Critical [CVE-2025-70888] Remote privilege escalation

Remote privilege escalation. Red Hat rates this critical (CVSS 10). Weakness: CWE-266. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2025-70888
Unclassified
Mar 25, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-33211] Information disclosure via path traversal in git resolver

Information disclosure via path traversal in git resolver. Red Hat rates this important (CVSS 9.6). Weakness: CWE-22. Affected package(s): openshift-builds/openshift-builds-rhel9-operator:1776860241, serve-tkn-cli, openshift-pipelines/pipelines-resolvers-rhel9:1774556280, openshift-pipelines/pipelines-resolvers-rhel9:1774596617, openshift-builds/openshift-builds-rhel9-operator:1776859898, openshift-pipelines/pipelines-operator-bundle:1776925111. Resolved in Red Hat advisory RHSA-2026:21932 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Builds 1.6.5; Red Hat OpenShift Builds 1.7.4; Red Hat OpenShift Pipelines 1.21; Red Hat Trusted Artifact Signer 1.3; and 4 more.

CVE-2026-33211
Unclassified
Mar 23, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-4599] Private key recovery via incomplete comparison checks biasing DSA nonces

Private key recovery via incomplete comparison checks biasing DSA nonces. Red Hat rates this important (CVSS 9.1). Weakness: CWE-338. Affected package(s): migration-toolkit-virtualization/mtv-console-plugin-rhel9:1779139872, quay/quay-rhel8:1775169155, quay/quay-rhel8:1775253092, quay/quay-rhel9:1779204086, migration-toolkit-virtualization/mtv-console-plugin-rhel9:1778927462, quay/quay-rhel8:1775169219. Resolved in Red Hat advisory RHSA-2026:6926 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Quay 3.10; Red Hat Quay 3.12; Red Hat Quay 3.15; Red Hat Quay 3.16; and 1 more.

CVE-2026-4599
Unclassified
Mar 23, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-4678] Use after free in WebGPU

Use after free in WebGPU. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4678
Unclassified
Mar 23, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-4673] Heap buffer overflow in WebAudio

Heap buffer overflow in WebAudio. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4673
Unclassified
Mar 23, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-4679] Integer overflow in Fonts

Integer overflow in Fonts. Red Hat rates this important (CVSS 9.6). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4679
Unclassified
Mar 23, 2026
Critical9.8Red Hat

Critical [CVE-2026-33228] Prototype pollution vulnerability allows arbitrary code execution via crafted JSON.

Prototype pollution vulnerability allows arbitrary code execution via crafted JSON.. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-915. Affected package(s): rhdh/rhdh-hub-rhel9:1777903262, cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9; Red Hat 3scale API Management Platform 2; Red Hat Build of Keycloak; and 2 more.

CVE-2026-33228
Unclassified
Mar 20, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-33210] Denial of Service or Information Disclosure via format string injection

Denial of Service or Information Disclosure via format string injection. Red Hat rates this important (CVSS 9.1). Weakness: CWE-134. Affected package(s): ruby4.0, ruby:4.0. Resolved in Red Hat advisory RHSA-2026:20606 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images.

CVE-2026-33210
Unclassified
Mar 20, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-33186] Authorization bypass due to improper HTTP/2 path validation

Authorization bypass due to improper HTTP/2 path validation. Red Hat rates this important (CVSS 9.1). Weakness: CWE-551. Affected package(s): rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9:1780078429, odf4/odf-csi-addons-sidecar-rhel9:1781550957, rhtas/trillian-logserver-rhel9:1776243434, openshift4/ose-cluster-olm-rhel9-operator:1779787336, rhdh/rhdh-rhel9-operator:1774544220, openshift4/ose-csi-driver-nfs-rhel9:1778242571. Resolved in Red Hat advisory RHSA-2026:27893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Container Platform 4.16; Red Hat OpenShift Container Platform 4.17; Red Hat OpenShift Container Platform 4.18; Red Hat Satellite 6.16 for RHEL 8; and 129 more.

CVE-2026-33186
Unclassified
Mar 20, 2026
Critical9.1Red Hat

Critical [CVE-2026-23537] Unauthenticated Arbitrary File Write

Unauthenticated Arbitrary File Write. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-862. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-23537
Unclassified
Mar 20, 2026
Critical10.0Red Hat

Critical [CVE-2026-30836] Unauthenticated certificate issuance via SCEP Update Request

Unauthenticated certificate issuance via SCEP Update Request. Red Hat rates this critical (CVSS 10). Weakness: CWE-306. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-30836
Unclassified
Mar 19, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-4442] Heap buffer overflow in CSS

Heap buffer overflow in CSS. Red Hat rates this important (CVSS 9.6). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4442
Unclassified
Mar 18, 2026
Critical9.6Red Hat

Critical [CVE-2026-4439] Out of bounds memory access in WebGL

Out of bounds memory access in WebGL. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4439
Unclassified
Mar 18, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-4452] Integer overflow in ANGLE

Integer overflow in ANGLE. Red Hat rates this important (CVSS 9.6). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4452
Unclassified
Mar 18, 2026
Critical9.6Red Hat

Critical [CVE-2026-4440] Out of bounds read and write in WebGL

Out of bounds read and write in WebGL. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4440
Unclassified
Mar 18, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-4458] Use after free in Extensions

Use after free in Extensions. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4458
Unclassified
Mar 18, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-4449] Use after free in Blink

Use after free in Blink. Red Hat rates this important (CVSS 9.6). Weakness: CWE-1341. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4449
Unclassified
Mar 18, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-4444] Stack buffer overflow in WebRTC

Stack buffer overflow in WebRTC. Red Hat rates this important (CVSS 9.6). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4444
Unclassified
Mar 18, 2026

← All vendors