Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

275 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Low3.8Red Hat

Low [CVE-2026-71326] Authenticated identity spoofing via BasicAuth key collision

Authenticated identity spoofing via BasicAuth key collision. Red Hat rates this low (CVSS 3.8). Weakness: CWE-836.

CVE-2026-71326
Unclassified
Aug 6, 2026
Low3.7Red Hat

Low [CVE-2026-57817] Authorization Code Substitution via missing c_hash validation

Authorization Code Substitution via missing c_hash validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-303. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat JBoss Web Server 5.

CVE-2026-57817
Unclassified
Aug 6, 2026
Low2.2Red Hat

Low [CVE-2026-18839] size_t underflow in singleOptionHelp

size_t underflow in singleOptionHelp. Red Hat rates this low (CVSS 2.2). Weakness: CWE-191. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.

CVE-2026-18839
Unclassified
Aug 5, 2026
Low3.8Red Hat

Low [CVE-2026-70430] Privilege escalation via unrestricted object instantiation in project naming strategy configuration

Privilege escalation via unrestricted object instantiation in project naming strategy configuration. Red Hat rates this low (CVSS 3.8). Weakness: CWE-502. Affected product named by the advisory: OpenShift Developer Tools and Services.

CVE-2026-70430
Unclassified
Aug 5, 2026
Low2.5Red Hat Updated

Low [CVE-2026-18739] Off-by-one in poptStuffArgs

Off-by-one in poptStuffArgs. Red Hat rates this low (CVSS 2.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:56984 with package popt-main-1.19-11.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 1 more. Affected products named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-18739
Unclassified
Aug 3, 2026
Low3.3Red Hat

Low [CVE-2026-68744] NSS responder uninitialized heap disclosure in initgroups reply

NSS responder uninitialized heap disclosure in initgroups reply. Red Hat rates this low (CVSS 3.3). Weakness: CWE-908.

CVE-2026-68744
Unclassified
Aug 3, 2026
Low2.1Red Hat

Low [CVE-2026-66401] Denial of Service via out-of-bounds read in UVC H.264 parser

Denial of Service via out-of-bounds read in UVC H.264 parser. Red Hat rates this low (CVSS 2.1). Weakness: CWE-125.

CVE-2026-66401
Unclassified
Aug 1, 2026
Low3.7Red Hat

Low [CVE-2026-67316] Prototype Pollution allows unauthorized data transmission and network redirection

Prototype Pollution allows unauthorized data transmission and network redirection. Red Hat rates this low (CVSS 3.7). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:50826 with package grafana13-1-main-13.1.1-0.5.2.hum1, grafana13-1-main-13.1.1-0.5.hum1.

CVE-2026-67316
Unclassified
Aug 1, 2026
Low3.7Red Hat

Low [CVE-2026-67294] Server certificate validation bypass via improper Extended Key Usage (EKU) validation

Server certificate validation bypass via improper Extended Key Usage (EKU) validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-295.

CVE-2026-67294
Unclassified
Aug 1, 2026
Low3.1Red Hat

Low [CVE-2026-54787] Signature bypass allows acceptance of bundles signed with expired keys

Signature bypass allows acceptance of bundles signed with expired keys. Red Hat rates this low (CVSS 3.1). Weakness: CWE-347. Red Hat lists fixing advisory RHSA-2026:44162 with package spire1-14-main-1.14.7-0.3.hum1, spire1-15-main-1.15.2-0.3.hum1, trivy-main-0.72.0-0.1.3.hum1.

CVE-2026-54787
Unclassified
Jul 31, 2026
Low3.7Red Hat

Low [CVE-2026-18569] OIDC backchannel logout accepts unsigned forged logout tokens

OIDC backchannel logout accepts unsigned forged logout tokens. Red Hat rates this low (CVSS 3.7). Weakness: CWE-347.

CVE-2026-18569
Unclassified
Jul 31, 2026
Low3.4Red Hat

Low [CVE-2026-18209] OIDC redirect_uri fragment bypass in HTTP parameter pollution check

OIDC redirect_uri fragment bypass in HTTP parameter pollution check. Red Hat rates this low (CVSS 3.4). Weakness: CWE-1288.

CVE-2026-18209
Unclassified
Jul 31, 2026
Low3.7Red Hat

Low [CVE-2026-18206] Client policy source-host wildcard domain matching bypass

Client policy source-host wildcard domain matching bypass. Red Hat rates this low (CVSS 3.7). Weakness: CWE-20.

CVE-2026-18206
Unclassified
Jul 31, 2026
Low3.4Vendor: MediumRed Hat

Low [CVE-2026-18217] SAML HTTP-Redirect binding response preserves query string leading to parameter pollution

SAML HTTP-Redirect binding response preserves query string leading to parameter pollution. Red Hat rates this moderate (CVSS 3.4). Weakness: CWE-20.

CVE-2026-18217
Unclassified
Jul 31, 2026
Low3.3Red Hat

Low [CVE-2026-56847] Permission Model flaw allows trace logs to bypass filesystem write restrictions

Permission Model flaw allows trace logs to bypass filesystem write restrictions. Red Hat rates this low (CVSS 3.3). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.

CVE-2026-56847
Unclassified
Jul 30, 2026
Low2.8Red Hat

Low [CVE-2026-18018] Inappropriate implementation in Updater

Inappropriate implementation in Updater. Red Hat rates this low (CVSS 2.8).

CVE-2026-18018
Unclassified
Jul 30, 2026
Low0.0Red Hat

Low [CVE-2026-18014] Insufficient validation of untrusted input in DevTools

Insufficient validation of untrusted input in DevTools. Red Hat rates this low. Weakness: CWE-434.

CVE-2026-18014
Unclassified
Jul 30, 2026
Low0.0Red Hat

Low [CVE-2026-18010] Inappropriate implementation in Passwords

Inappropriate implementation in Passwords. Red Hat rates this low. Weakness: CWE-1021.

CVE-2026-18010
Unclassified
Jul 30, 2026
Low0.0Red Hat

Low [CVE-2026-18007] Inappropriate implementation in Input

Inappropriate implementation in Input. Red Hat rates this low. Weakness: CWE-79.

CVE-2026-18007
Unclassified
Jul 30, 2026
Low3.2Red Hat

Low [CVE-2026-18004] Insufficient policy enforcement in Speech

Insufficient policy enforcement in Speech. Red Hat rates this low (CVSS 3.2). Weakness: CWE-346.

CVE-2026-18004
Unclassified
Jul 30, 2026

← All vendors