Red Hat Linux Security Advisories & CVEs
275 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Low [CVE-2026-71326] Authenticated identity spoofing via BasicAuth key collision
Authenticated identity spoofing via BasicAuth key collision. Red Hat rates this low (CVSS 3.8). Weakness: CWE-836.
Low [CVE-2026-57817] Authorization Code Substitution via missing c_hash validation
Authorization Code Substitution via missing c_hash validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-303. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat JBoss Web Server 5.
Low [CVE-2026-18839] size_t underflow in singleOptionHelp
size_t underflow in singleOptionHelp. Red Hat rates this low (CVSS 2.2). Weakness: CWE-191. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.
Low [CVE-2026-70430] Privilege escalation via unrestricted object instantiation in project naming strategy configuration
Privilege escalation via unrestricted object instantiation in project naming strategy configuration. Red Hat rates this low (CVSS 3.8). Weakness: CWE-502. Affected product named by the advisory: OpenShift Developer Tools and Services.
Low [CVE-2026-18739] Off-by-one in poptStuffArgs
Off-by-one in poptStuffArgs. Red Hat rates this low (CVSS 2.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:56984 with package popt-main-1.19-11.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 1 more. Affected products named by the advisory: Red Hat Enterprise Linux 9.
Low [CVE-2026-68744] NSS responder uninitialized heap disclosure in initgroups reply
NSS responder uninitialized heap disclosure in initgroups reply. Red Hat rates this low (CVSS 3.3). Weakness: CWE-908.
Low [CVE-2026-66401] Denial of Service via out-of-bounds read in UVC H.264 parser
Denial of Service via out-of-bounds read in UVC H.264 parser. Red Hat rates this low (CVSS 2.1). Weakness: CWE-125.
Low [CVE-2026-67316] Prototype Pollution allows unauthorized data transmission and network redirection
Prototype Pollution allows unauthorized data transmission and network redirection. Red Hat rates this low (CVSS 3.7). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:50826 with package grafana13-1-main-13.1.1-0.5.2.hum1, grafana13-1-main-13.1.1-0.5.hum1.
Low [CVE-2026-67294] Server certificate validation bypass via improper Extended Key Usage (EKU) validation
Server certificate validation bypass via improper Extended Key Usage (EKU) validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-295.
Low [CVE-2026-54787] Signature bypass allows acceptance of bundles signed with expired keys
Signature bypass allows acceptance of bundles signed with expired keys. Red Hat rates this low (CVSS 3.1). Weakness: CWE-347. Red Hat lists fixing advisory RHSA-2026:44162 with package spire1-14-main-1.14.7-0.3.hum1, spire1-15-main-1.15.2-0.3.hum1, trivy-main-0.72.0-0.1.3.hum1.
Low [CVE-2026-18569] OIDC backchannel logout accepts unsigned forged logout tokens
OIDC backchannel logout accepts unsigned forged logout tokens. Red Hat rates this low (CVSS 3.7). Weakness: CWE-347.
Low [CVE-2026-18209] OIDC redirect_uri fragment bypass in HTTP parameter pollution check
OIDC redirect_uri fragment bypass in HTTP parameter pollution check. Red Hat rates this low (CVSS 3.4). Weakness: CWE-1288.
Low [CVE-2026-18206] Client policy source-host wildcard domain matching bypass
Client policy source-host wildcard domain matching bypass. Red Hat rates this low (CVSS 3.7). Weakness: CWE-20.
Low [CVE-2026-18217] SAML HTTP-Redirect binding response preserves query string leading to parameter pollution
SAML HTTP-Redirect binding response preserves query string leading to parameter pollution. Red Hat rates this moderate (CVSS 3.4). Weakness: CWE-20.
Low [CVE-2026-56847] Permission Model flaw allows trace logs to bypass filesystem write restrictions
Permission Model flaw allows trace logs to bypass filesystem write restrictions. Red Hat rates this low (CVSS 3.3). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.
Low [CVE-2026-18018] Inappropriate implementation in Updater
Inappropriate implementation in Updater. Red Hat rates this low (CVSS 2.8).
Low [CVE-2026-18014] Insufficient validation of untrusted input in DevTools
Insufficient validation of untrusted input in DevTools. Red Hat rates this low. Weakness: CWE-434.
Low [CVE-2026-18010] Inappropriate implementation in Passwords
Inappropriate implementation in Passwords. Red Hat rates this low. Weakness: CWE-1021.
Low [CVE-2026-18007] Inappropriate implementation in Input
Inappropriate implementation in Input. Red Hat rates this low. Weakness: CWE-79.
Low [CVE-2026-18004] Insufficient policy enforcement in Speech
Insufficient policy enforcement in Speech. Red Hat rates this low (CVSS 3.2). Weakness: CWE-346.