Red Hat Linux Security Advisories & CVEs
5588 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Critical [CVE-2026-66801] shared Kafka gh-spec topic Write ACL plus spoofable CloudEvent source enables fleet-wide cluster-admin from any compromised managed hub
shared Kafka gh-spec topic Write ACL plus spoofable CloudEvent source enables fleet-wide cluster-admin from any compromised managed hub. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-290. Red Hat lists fixing advisory RHSA-2026:52946 with package multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786067967.
High [CVE-2026-66806] TLS verification disabled when sending hub pull-secret to console.redhat.com
A flaw was found in console. When the `HTTPS_PROXY` environment variable is not configured, the console component fails to verify Transport Layer Security (TLS) certificates for outbound connections. A network-positioned attacker (Man-in-the-Middle) can exploit this vulnerability to intercept the cluster pull-secret while it is being sent to console.redhat.com. This pull-secret is a critical credential that provides access to Red Hat container registries and cloud services, potentially leading to unauthorized access and sensitive information disclosure. This allows a network-positioned attacker to intercept the cluster pull-secret, a high-value credential, due to the lack of server certificate validation. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-295. Affected Red Hat products: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-63622] swtpm privilege escalation via symlink following
A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user. This allows for privilege escalation from the `swtpm` sandbox to root-level file ownership control. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-59. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26. Red Hat lists Red Hat Enterprise Linux 6 as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libvirt.
High [CVE-2026-18982] RHOAI fork aggregates training job create onto native edit/admin ClusterRoles
A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can impersonate service accounts, access the host filesystem, and potentially execute arbitrary code remotely. This issue arises from the aggregation of training job permissions onto native Kubernetes edit and admin ClusterRoles, coupled with unrestricted PodTemplateSpec passthrough. This is a Critical vulnerability. This allows any namespace editor to escalate privileges by creating training jobs that can impersonate ServiceAccounts, mount hostPath volumes, set privileged security contexts, and achieve remote code execution, expanding the attack surface beyond users explicitly granted training workload access. Red Hat severity: Critical — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-250. Affected Red Hat products: Red Hat OpenShift AI 3.3. Red Hat fixing advisory: RHSA-2026:53263.
High [CVE-2026-18951] [Trainer v2 Security] TRN-02: RHOAI overlay aggregates trainjobs CRUD into standard edit ClusterRole
A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit ClusterRole` permissions in a namespace to create, modify, and delete `TrainJobs`. When combined with a separate vulnerability (TRN-01) that permits arbitrary pod configurations, a remote attacker with namespace editor privileges could exploit this to escalate privileges, potentially leading to arbitrary code execution. This issue is specific to the RHOAI fork and not present in upstream Kubeflow trainer. Red Hat severity: Critical — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Affected Red Hat products: Red Hat OpenShift AI 3.3. Red Hat fixing advisory: RHSA-2026:53263.
High [CVE-2026-18950] Confused-deputy privilege escalation via unchecked roleRef in RoleBinding creation
A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role, including highly privileged ones like `cluster-admin`. This can lead to privilege escalation, where an attacker gains unauthorized elevated access within their namespace and potentially persistent control over the system. By crafting a RoleBinding with an arbitrary roleRef, an attacker can grant themselves any ClusterRole, including 'cluster-admin', within their namespace. Red Hat severity: Critical — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Affected Red Hat products: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI (RHOAI). Red Hat fixing advisory: RHSA-2026:53263.
High [CVE-2026-18949] ClusterRole grants cluster-wide CRUD on secrets and RBAC management resources
A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to cluster-administrator level, gain access to sensitive data like credentials and keys across the entire cluster, and disrupt multi-tenant isolation. A compromised dashboard Service Account could read and delete sensitive secrets across the cluster and create `ClusterRoleBindings`, leading to full cluster-admin privilege escalation and breaking multi-tenant isolation. This risk is present in Red Hat OpenShift AI deployments with the dashboard component enabled. Red Hat severity: Critical — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-250. Affected Red Hat products: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI (RHOAI). Red Hat fixing advisory: RHSA-2026:53263.
High [CVE-2026-18947] Authorization bypass in /materialize endpoints enables DoS via unauthorized full re-materialization
Authorization bypass in /materialize endpoints enables DoS via unauthorized full re-materialization. Red Hat rates this important (CVSS 8.5). Red Hat lists fixing advisory RHSA-2026:53263 with package rhoai/odh-feature-server-rhel9:1786110033.
High [CVE-2026-18941] Default authentication mode is no_auth — shared multi-tenant instances deployed without authentication
Default authentication mode is no_auth — shared multi-tenant instances deployed without authentication. Red Hat rates this important (CVSS 7.7). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:53263 with package rhoai/odh-feature-server-rhel9:1786110033.
High [CVE-2026-15581] TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide
TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide. Red Hat rates this important (CVSS 8). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:53263 with package rhoai/odh-trustyai-service-operator-rhel9:1785187521. Affected product named by the advisory: Red Hat OpenShift AI 3.3.
High [CVE-2026-15467] LMEvalJob sidecar containers bypass protected environment variable filtering, allowing TRUST_REMOTE_CODE policy override
LMEvalJob sidecar containers bypass protected environment variable filtering, allowing TRUST_REMOTE_CODE policy override. Red Hat rates this important (CVSS 8.1). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:53263 with package rhoai/odh-trustyai-service-operator-rhel9:1785187521.
High [CVE-2026-13717] MaaS/llm-d inference Gateway: default allowedRoutes.namespaces.from: All allows namespace users to hijack shared model-serving traffic (tokens, prompts, outputs)
MaaS/llm-d inference Gateway: default allowedRoutes.namespaces.from: All allows namespace users to hijack shared model-serving traffic (tokens, prompts, outputs). Red Hat rates this important (CVSS 8.8). Weakness: CWE-284.
High [CVE-2026-66805] stored DOM XSS via unescaped pod logs in document.write
stored DOM XSS via unescaped pod logs in document.write. Red Hat rates this important (CVSS 8). Weakness: CWE-79.
High [CVE-2026-18621] V1 Argo template path accepts arbitrary Workflow spec, bypassing all v2 security hardening
V1 Argo template path accepts arbitrary Workflow spec, bypassing all v2 security hardening. Red Hat rates this important (CVSS 7.6). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:53263 with package rhoai/odh-ml-pipelines-api-server-v2-rhel9:1785187920.
High [CVE-2026-18620] User-controlled ServiceAccount for workflow pods without authorization check — confused deputy
User-controlled ServiceAccount for workflow pods without authorization check — confused deputy. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-639. Red Hat lists fixing advisory RHSA-2026:53263 with package rhoai/odh-ml-pipelines-api-server-v2-rhel9:1785187920.
High [CVE-2026-18618] Bundled gRPC 1.46.3 (2022) with published HTTP/2 DoS CVEs — directly reachable on listener
Bundled gRPC 1.46.3 (2022) with published HTTP/2 DoS CVEs — directly reachable on listener. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:53263 with package rhoai/odh-mlmd-grpc-server-rhel9:1785262015.
High [CVE-2026-59091] multiple vulnerabilities in file format plugins via crafted image file
A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a specially crafted image file. This could lead to unexpected application behavior or other potential security impacts without requiring further user interaction. It is triggered when a user opens a specially crafted image file, a common user action for image manipulation software. The local nature of the exploit is offset by the significant impact of potential system compromise or sensitive data exposure. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-18617] MySQL DSN parameter injection via CustomExtraParams enables LOCAL INFILE file exfiltration from operator pod
MySQL DSN parameter injection via CustomExtraParams enables LOCAL INFILE file exfiltration from operator pod. Red Hat rates this important (CVSS 8.8). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:53263 with package rhoai/odh-data-science-pipelines-operator-controller-rhel9:1785187936.
High [CVE-2026-18611] Cryptographically weak secret generation (math/rand) for DB and S3 credentials
Cryptographically weak secret generation (math/rand) for DB and S3 credentials. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-338. Red Hat lists fixing advisory RHSA-2026:53263 with package rhoai/odh-data-science-pipelines-operator-controller-rhel9:1785187936.
High [CVE-2026-18608] Operator ClusterRole grants pods/exec:*, kubeflow.org */*, and ClusterRole/Binding CRUD cluster-wide
Operator ClusterRole grants pods/exec:*, kubeflow.org */*, and ClusterRole/Binding CRUD cluster-wide. Red Hat rates this important (CVSS 8.7). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:53263 with package rhoai/odh-data-science-pipelines-operator-controller-rhel9:1785187936.