Red Hat Linux Security Advisories & CVEs
5203 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
Medium [CVE-2026-35206] Files written to unexpected directory via specially crafted Chart
Files written to unexpected directory via specially crafted Chart. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-22. Affected package(s): helm-cli, rhacm2/multicloud-integrations-rhel9:1782256081, multicluster-engine/backplane-rhel9-operator:1782476869. Resolved in Red Hat advisory RHSA-2026:26441 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-34500] Authentication bypass via client certificate misconfiguration
Authentication bypass via client certificate misconfiguration. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-303. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-34487] Information disclosure via sensitive data in log files
Information disclosure via sensitive data in log files. Red Hat rates this low (CVSS 6.5). Weakness: CWE-538. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-34483] Information disclosure due to improper encoding in JsonAccessLogValve
Information disclosure due to improper encoding in JsonAccessLogValve. Red Hat rates this low (CVSS 5.4). Weakness: CWE-838. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-29145] Authentication bypass due to CLIENT_CERT soft fail misconfiguration
Authentication bypass due to CLIENT_CERT soft fail misconfiguration. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-303. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-25854] Open Redirect vulnerability via LoadBalancerDrainingValve
Open Redirect vulnerability via LoadBalancerDrainingValve. Red Hat rates this low (CVSS 4.3). Weakness: CWE-601. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-24880] HTTP Request/Response Smuggling via invalid chunk extension
HTTP Request/Response Smuggling via invalid chunk extension. Red Hat rates this low (CVSS 4.3). Weakness: CWE-444. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-34757] Information disclosure and data corruption via use-after-free vulnerability
Information disclosure and data corruption via use-after-free vulnerability. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-825. Affected package(s): libpng-main. Resolved in Red Hat advisory RHSA-2026:13719 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-5874] Sandbox escape via use-after-free in PrivateAI
Sandbox escape via use-after-free in PrivateAI. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-27140] Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names
Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names. Red Hat rates this important (CVSS 9). Weakness: CWE-641. Affected package(s): openshift4/cloud-network-config-controller-rhel9:1780040126, openshift4/ose-agent-installer-utils-rhel9:1780044523, openshift4/ose-vsphere-csi-driver-rhel9-operator:1780040095, openshift4/ose-aws-cloud-controller-manager-rhel9:1780040386, openshift4/ose-aws-cluster-api-controllers-rhel9:1780040551, openshift4/ose-ironic-machine-os-downloader-rhel9:1780365576. Resolved in Red Hat advisory RHSA-2026:10704 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 12 more.
High [CVE-2026-40024] Arbitrary code execution via path traversal in tsk_recover
Arbitrary code execution via path traversal in tsk_recover. Red Hat rates this important (CVSS 7.9). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-5858] Arbitrary code execution via heap buffer overflow in WebML
Arbitrary code execution via heap buffer overflow in WebML. Red Hat rates this important (CVSS 8.8). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-39892] Buffer overflow via non-contiguous buffer in API
Buffer overflow via non-contiguous buffer in API. Red Hat rates this important (CVSS 7.3). Weakness: CWE-131. Affected package(s): ansible-automation-platform, quay/quay-rhel8:1779811473, quay/quay-rhel8:1779689392, ansible-automation-platform-tech-preview/metrics-service-rhel9:1779760844, automation-controller, python3.12-cryptography. Resolved in Red Hat advisory RHSA-2026:23361 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat AI Inference Server 3.3; and 20 more.
High [CVE-2026-39883] github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Arbitrary code execution via PATH hijacking on BSD/Solaris
github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Arbitrary code execution via PATH hijacking on BSD/Solaris. Red Hat rates this important (CVSS 8.8). Weakness: CWE-426. Affected package(s): multicluster-engine/assisted-service. Resolved in Red Hat advisory RHSA-2026:26254 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Openshift Data Foundation 4.22.
High [CVE-2026-23869] denial of service via specially crafted HTTP requests to Server Function endpoints
denial of service via specially crafted HTTP requests to Server Function endpoints. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-5795] early return from the JASPIAuthenticator class without clearing ThreadLocal variables
early return from the JASPIAuthenticator class without clearing ThreadLocal variables. Red Hat rates this important (CVSS 7.4). Weakness: CWE-226. Affected package(s): jetty-ee10-plus, jetty-ee10-servlets, jetty-ee10-apache-jsp, jetty-ee10-webapp, offline-knowledge-portal/rhokp-rhel9:1782239370, jetty-ee10-servlet. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14; Red Hat Offline Knowledge Portal 1.2.7; Red Hat Offline Knowledge Portal 1.2.3; Red Hat Offline Knowledge Portal 1.2.4.
High [CVE-2026-32280] Denial of Service vulnerability in certificate chain building
Denial of Service vulnerability in certificate chain building. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): rhc, openshift-service-mesh/pilot-rhel8:1777319850, openshift-service-mesh/istio-rhel9-operator:1778149657, grafana-pcp, openshift-service-mesh/istio-cni-rhel8:1777374598, rhtas/client-server-rhel9:1780399582. Resolved in Red Hat advisory RHSA-2026:11507 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 10; Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat OpenShift Container Platform 4.14; and 109 more.
High [CVE-2026-32283] Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages. Red Hat rates this important (CVSS 7.5). Weakness: CWE-764. Affected package(s): rhc, grafana-pcp, skopeo, host-metering, container-tools:rhel8, git-lfs. Resolved in Red Hat advisory RHSA-2026:11507 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 10; and 75 more.
High [CVE-2026-27143] possible memory corruption after bound check elimination
possible memory corruption after bound check elimination. Red Hat rates this moderate (CVSS 8.1). Weakness: CWE-733. Affected package(s): openshift4/openshift-route-controller-manager-rhel8:1781867531, openshift4/ose-gcp-cloud-controller-manager-rhel9:1781927538, openshift4/ose-nutanix-machine-controllers-rhel9:1781926777, openshift4/ose-cluster-bootstrap-rhel9:1779251452, openshift4/ose-cluster-policy-controller-rhel9:1779258265, openshift4/ose-machine-api-provider-aws-rhel9:1779249874. Resolved in Red Hat advisory RHSA-2026:10704 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
High [CVE-2026-33810] Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application
Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1289. Affected package(s): rhtas/client-server-rhel9:1780399582, golang1, cryostat/cryostat-storage-rhel9:4.1.1, opentelemetry-collector, hawtio-operator-container, web-terminal/web-terminal-exec-rhel9:1780425077. Resolved in Red Hat advisory RHSA-2026:28047 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; RHEM 1.0 for RHEL 9; Red Hat Satellite 6.19 for RHEL 9; Red Hat Enterprise Linux AppStream EUS (v. 10.0); and 67 more.