Red Hat Linux Security Advisories & CVEs
5195 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-40022] Information disclosure and authentication bypass in embedded HTTP/management servers
Information disclosure and authentication bypass in embedded HTTP/management servers. Red Hat rates this important (CVSS 8.2). Weakness: CWE-551. Affected package(s): camel-http-starter, camel-http-common, camel-http-base, camel-http. Resolved in Red Hat advisory RHSA-2026:17668 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14.
High [CVE-2026-40858] Apache Camel camel-infinispan: Arbitrary code execution via deserialization of untrusted data
Apache Camel camel-infinispan: Arbitrary code execution via deserialization of untrusted data. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Affected package(s): camel-infinispan, camel-infinispan-common, camel-infinispan-embedded. Resolved in Red Hat advisory RHSA-2026:22453 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14; Red Hat build of Apache Camel 4 for Quarkus 3.
High [CVE-2026-40860] Remote Code Execution via deserialization of JMS ObjectMessage
Remote Code Execution via deserialization of JMS ObjectMessage. Red Hat rates this important (CVSS 7.5). Weakness: CWE-502. Affected package(s): camel-jms, camel-amqp. Resolved in Red Hat advisory RHSA-2026:22453 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3.
High [CVE-2026-40048] Arbitrary code execution via insecure deserialization of crafted key files
Arbitrary code execution via insecure deserialization of crafted key files. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-40473] Apache Camel camel-mina: Arbitrary code execution via insecure deserialization
Apache Camel camel-mina: Arbitrary code execution via insecure deserialization. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-3006] Local privilege escalation via race condition and kernel heap overflow
Local privilege escalation via race condition and kernel heap overflow. Red Hat rates this important (CVSS 7). Weakness: CWE-368. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-42371] Denial of Service via numeric truncation with oversized URIs
Denial of Service via numeric truncation with oversized URIs. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-190. Affected package(s): uriparser-main. Resolved in Red Hat advisory RHSA-2026:12430 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-10843] CCO Mint-mode CredentialsRequest manifests grant account-wide IAM access beyond cluster scope on AWS
CCO Mint-mode CredentialsRequest manifests grant account-wide IAM access beyond cluster scope on AWS. Red Hat rates this important (CVSS 7.2). Weakness: CWE-250. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-6951] Remote Code Execution due to incomplete fix bypass
Remote Code Execution due to incomplete fix bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-88. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 8.
High [CVE-2026-31684] validate nested VLAN headers
validate nested VLAN headers. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-1285. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:21745 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
High [CVE-2026-10840] tekton-scheduler-rolebinding grants system:authenticated write access to Kueue and cert-manager resources
tekton-scheduler-rolebinding grants system:authenticated write access to Kueue and cert-manager resources. Red Hat rates this important (CVSS 7.1). Weakness: CWE-732. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat OpenShift Builds 1.7.4; OpenShift Pipelines; Red Hat OpenShift Builds 1.8.1; Red Hat OpenShift Builds 1.7.1; and 2 more.
High [CVE-2026-31685] reject invalid MAC header for all packets
reject invalid MAC header for all packets. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-1287. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:26462 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.
Medium [CVE-2026-31677] af_alg - limit RX SG extraction by receive buffer budget
af_alg - limit RX SG extraction by receive buffer budget. Red Hat rates this low (CVSS 5.5). Weakness: CWE-770. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:19074 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
High [CVE-2026-41415] Denial of service via malformed Content-ID URI in SIP multipart message
Denial of service via malformed Content-ID URI in SIP multipart message. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-42039] Denial of Service via unbounded recursion in toFormData with deeply nested request data
Denial of Service via unbounded recursion in toFormData with deeply nested request data. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): openshift-service-mesh/kiali-rhel9:1778164042, rhoai/odh-mod-arch-model-registry-rhel9:1780467147, openshift4/ose-agent-installer-ui-rhel9:1778539338, satellite/iop-advisor-frontend-rhel9:1781181673, openshift-service-mesh/kiali-rhel8:1778191378, rhacm2/console-rhel9:1780600823. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 33 more.
High [CVE-2026-42041] Authentication bypass due to prototype pollution of HTTP error handling
Authentication bypass due to prototype pollution of HTTP error handling. Red Hat rates this important (CVSS 8.2). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-rhel9:1778164042, rhoai/odh-mod-arch-model-registry-rhel9:1780467147, openshift4/ose-agent-installer-ui-rhel9:1778539338, satellite/iop-advisor-frontend-rhel9:1781181673, openshift-service-mesh/kiali-rhel8:1778191378, rhacm2/console-rhel9:1780600823. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 33 more.
High [CVE-2026-42043] NO_PROXY bypass via crafted URL
NO_PROXY bypass via crafted URL. Red Hat rates this important (CVSS 7.2). Weakness: CWE-918. Affected package(s): openshift-service-mesh/kiali-rhel9:1778164042, rhoai/odh-mod-arch-model-registry-rhel9:1780467147, openshift4/ose-agent-installer-ui-rhel9:1778539338, satellite/iop-advisor-frontend-rhel9:1781181673, openshift-service-mesh/kiali-rhel8:1778191378, rhacm2/console-rhel9:1780600823. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 32 more.
High [CVE-2026-42044] Invisible JSON Response Tampering via Prototype Pollution Gadget
Invisible JSON Response Tampering via Prototype Pollution Gadget. Red Hat rates this important (CVSS 7.4). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-rhel9:1778164042, network-observability/network-observability-console-plugin-rhel9:1780556069, satellite/iop-advisor-frontend-rhel9:1781181673, rhacm2/console-rhel9:1780600823, devspaces/code-rhel9:1779814592, multicluster-engine/console-mce-rhel9:1778383863. Resolved in Red Hat advisory RHSA-2026:26068 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 36 more.
High [CVE-2026-42035] Arbitrary HTTP header injection via prototype pollution
Arbitrary HTTP header injection via prototype pollution. Red Hat rates this moderate (CVSS 7.4). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-rhel9:1778164042, cluster-observability-operator/monitoring-console-plugin-pf5-rhel9:1781116667, satellite/iop-advisor-frontend-rhel9:1781181673, rhacm2/console-rhel9:1780600823, cluster-observability-operator/distributed-tracing-console-plugin-pf6-rhel9:1781116387, quay/quay-rhel9:1779922205. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-42033] HTTP Transport Hijacking via Prototype Pollution
HTTP Transport Hijacking via Prototype Pollution. Red Hat rates this important (CVSS 7.4). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-rhel9:1778164042, rhoai/odh-mod-arch-model-registry-rhel9:1780467147, openshift4/ose-agent-installer-ui-rhel9:1778539338, satellite/iop-advisor-frontend-rhel9:1781181673, openshift-service-mesh/kiali-rhel8:1778191378, rhacm2/console-rhel9:1780600823. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 35 more.