Red Hat Linux Security Advisories & CVEs
4429 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-96775] MLflow dspy: Arbitrary code execution via crafted MLmodel artifact
MLflow dspy: Arbitrary code execution via crafted MLmodel artifact. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-19888] Denial of Service via malformed SCRAM client-final-message
Denial of Service via malformed SCRAM client-final-message. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:70698 with package pgbouncer-main-1.26.0-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-6668] Denial of Service via integer overflow in packet buffer growth
Denial of Service via integer overflow in packet buffer growth. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:70698 with package pgbouncer-main-1.26.0-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-96275] Flatpak: flatpak: arbitrary write access as root via extra-data extraction
A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal. Red Hat estimates the CVSSv3.1 vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. Exploitation requires a user or administrator to add or trust a malicious or compromised Flatpak repository and then install or update an application from it. The malicious content is served over the network (AV:N), and the attacker needs only control over the repository content (PR:N). Meaningful user interaction is required, since a user/admin must actively configure the remote and initiate an install or update from it (UI:R). Because this is an unconstrained, attacker-controlled write as root, it is treated as equivalent to full system compromise: an attacker can overwrite files such as SSH authorized_keys, systemd units, cron entries, or setuid binaries, yielding full loss of confidentiality, integrity, and availability (C:H/I:H/A:H). Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-22.
High [CVE-2026-96577] Embedded local cache registry listens on all interfaces without authentication, with delete enabled
Embedded local cache registry listens on all interfaces without authentication, with delete enabled. Red Hat rates this important (CVSS 7.1). Weakness: CWE-306. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-94422] message filtering bypass via reply serial allows sandbox escape
message filtering bypass via reply serial allows sandbox escape. Red Hat rates this important (CVSS 8.8). Weakness: CWE-290. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: xdg-dbus-proxy.
High [CVE-2026-96512] TZ environment variable allows bypass of NOTBEFORE/NOTAFTER time-based authorization
TZ environment variable allows bypass of NOTBEFORE/NOTAFTER time-based authorization. Red Hat rates this important (CVSS 7.8). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:75571 with package sudo-0:1.9.17-10.p2.el10_2.7, sudo-0:1.9.17p2-3.el9_8.3, sudo-main-1.9.17-16.p2.2.hum1, sudo-0:1.9.5p2-2.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-86350] HTTP/2 request smuggling due to header mix-up
Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. This issue affects Apache Tomcat: from 11.0.22 through 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue. A regression in a prior security fix can cause request headers to be mixed up. This could allow a remote attacker to bypass security mechanisms or gain unauthorized access to sensitive information. This vulnerability is rated as having Important impact because unauthenticated remote clients can trigger request desynchronization and header confusion across multiplexed connections, leading to potential access control bypass or data leakage across sessions. Exploitation is limited to instances actively serving HTTP/2 connections, commonly deployed in reverse proxy architectures or direct HTTPS terminations. Instances using standard HTTP/1.1 connector definitions without explicit HTTP/2 protocol upgrade handlers are not exposed to this issue. Red Hat severity: Important — CVSS 7.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N). Weakness: CWE-444.
High [CVE-2026-79677] Denial of Service due to lost asynchronous WebSocket write timeouts
Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allows a denial of service as a result of lost time outs for asynchronous WebSocket writes. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by exploiting lost timeouts for asynchronous WebSocket writes. This can lead to the affected system becoming unresponsive or unavailable. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-772. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7. Red Hat lists Red Hat Hardened Images as not affected.
High [CVE-2026-78383] Denial of Service via AJP request
Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP request to pin an AJP processing thread leading to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue. An unauthenticated remote attacker can send a specially crafted AJP (Apache JServ Protocol) request, causing an AJP processing thread to become unresponsive. This resource exhaustion can lead to a denial of service (DoS), making the server unavailable to legitimate users. This vulnerability is rated as having Important impact because an unauthenticated remote attacker can exhaust connector thread pools without authentication, resulting in complete denial of service for the application server. In Red Hat Enterprise Linux and JBoss Web Server environments, the AJP connector is typically disabled by default or bound to loopback interfaces, limiting exposure unless explicitly configured to accept external connections.
High [CVE-2026-77791] Denial of Service via busy wait during WebSocket close
Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS attack. This issue affects Apache Tomcat: from 11.0.0-M5 through 11.0.25, from 10.1.8 through 10.1.59, from 9.0.74 through 9.0.121. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.88 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue. An uncontrolled resource consumption vulnerability occurs when sending a WebSocket close message, which can lead to a busy wait condition. A remote attacker could exploit this to cause a Denial of Service (DoS) by making the server unresponsive. Red Hat rates this vulnerability as Important because an unauthenticated remote client can cause severe CPU starvation and exhaust worker threads without requiring administrative privileges. Exploitation occurs during the termination of WebSocket sessions, forcing the application server into an infinite busy-wait loop that degrades availability for all hosted applications. Deployments are primarily exposed when running web applications that define WebSocket endpoints accessible over untrusted public networks. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1050.
High [CVE-2026-76183] Authentication Bypass in WebSocket Endpoints
Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The following versions were EOS at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue. This means that unauthorized users could gain access to protected resources or functionality, potentially leading to sensitive information disclosure or other unauthorized actions. This vulnerability is rated as having an Important severity because unauthenticated remote attackers can circumvent access control constraints protecting WebSocket endpoints, posing significant risks to application data confidentiality and integrity. The issue specifically impacts Red Hat Enterprise Linux and JBoss Web Server environments where deployed applications configure container-managed security restrictions on WebSocket communication channels. Standard HTTP endpoints and applications that do not utilize WebSocket functionality remain unaffected by this vulnerability.
High [CVE-2024-53920 +1] arbitrary code execution in Flymake mode
arbitrary code execution in Flymake mode. Red Hat rates this important (CVSS 7.8). Weakness: CWE-94. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: emacs.
High [CVE-2026-42801] ASR Crane, Falcon: NULL pointer dereference allows pointer manipulation
NULL pointer dereference vulnerability in ASR Crane,Falcon on Linux (as_rrc module) allows Pointer Manipulation. This vulnerability is associated with program file 3g.mod/lib/src/urrsir.c. An attacker could potentially exploit this to manipulate pointers, which may lead to unpredictable system behavior or a denial of service. This vulnerability is rated as Important because improper pointer handling in cellular communication stacks can allow network-adjacent or protocol-level manipulation that compromises service availability. Exploitation requires specialized hardware running proprietary ASR Microelectronics cellular baseband software, which is not shipped or supported in standard Red Hat enterprise environments. Additionally, this flaw is confined to ASR modem chipsets and does not affect the unrelated python-falcon web framework packages. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L). Weakness: CWE-476. Affected Red Hat products: Red Hat OpenStack Platform 16.2. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-91777] com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Denial of Service via quadratic forward-reference completion
com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Denial of Service via quadratic forward-reference completion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Affected products named by the advisory: OpenShift Developer Tools and Services; Red Hat build of Quarkus; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-91776] Denial of Service via unbounded cache growth in TypeDeserializerBase
Denial of Service via unbounded cache growth in TypeDeserializerBase. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat build of Quarkus.
High [CVE-2026-89425] Denial of Service via unbounded StringBuilder growth during malformed token processing
Denial of Service via unbounded StringBuilder growth during malformed token processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Affected products named by the advisory: OpenShift Developer Tools and Services; OpenShift Serverless; Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; and 13 more. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; Red Hat Certificate System 10; and 9 more.
High [CVE-2026-84475] InventorySource.source_vars lacks prevent_search, enabling zero-privilege cross-tenant extraction of inline inventory-plugin credentials via the credential_types FieldLookupBackend count-oracle
InventorySource.source_vars lacks prevent_search, enabling zero-privilege cross-tenant extraction of inline inventory-plugin credentials via the credential_types FieldLookupBackend count-oracle. Red Hat rates this important (CVSS 7.7). Weakness: CWE-204. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-84644] server-side request forgery via the Thycotic Secret Server external credential plugin test endpoint (caller-controlled server_url, backend executed in the controller web process)
server-side request forgery via the Thycotic Secret Server external credential plugin test endpoint (caller-controlled server_url, backend executed in the controller web process). Red Hat rates this important (CVSS 7.4). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-84678] GALAXY_TASK_ENV setting is not filtered for dynamic-linker / interpreter environment variables, allowing a system administrator to achieve code execution in the project-update execution environment
GALAXY_TASK_ENV setting is not filtered for dynamic-linker / interpreter environment variables, allowing a system administrator to achieve code execution in the project-update execution environment. Red Hat rates this important (CVSS 8.7). Weakness: CWE-427. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.7.