Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5203 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Medium4.4Linux

Medium [CVE-2026-35206] Files written to unexpected directory via specially crafted Chart

Files written to unexpected directory via specially crafted Chart. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-22. Affected package(s): helm-cli, rhacm2/multicloud-integrations-rhel9:1782256081, multicluster-engine/backplane-rhel9-operator:1782476869. Resolved in Red Hat advisory RHSA-2026:26441 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-35206
Unclassified
Apr 9, 2026
Medium5.9Linux

Medium [CVE-2026-34500] Authentication bypass via client certificate misconfiguration

Authentication bypass via client certificate misconfiguration. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-303. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-34500
Unclassified
Apr 9, 2026
Medium6.5Vendor: LowLinux

Medium [CVE-2026-34487] Information disclosure via sensitive data in log files

Information disclosure via sensitive data in log files. Red Hat rates this low (CVSS 6.5). Weakness: CWE-538. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-34487
Unclassified
Apr 9, 2026
Medium5.4Vendor: LowLinux

Medium [CVE-2026-34483] Information disclosure due to improper encoding in JsonAccessLogValve

Information disclosure due to improper encoding in JsonAccessLogValve. Red Hat rates this low (CVSS 5.4). Weakness: CWE-838. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-34483
Unclassified
Apr 9, 2026
Medium5.9Linux

Medium [CVE-2026-29145] Authentication bypass due to CLIENT_CERT soft fail misconfiguration

Authentication bypass due to CLIENT_CERT soft fail misconfiguration. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-303. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-29145
Unclassified
Apr 9, 2026
Medium4.3Vendor: LowLinux

Medium [CVE-2026-25854] Open Redirect vulnerability via LoadBalancerDrainingValve

Open Redirect vulnerability via LoadBalancerDrainingValve. Red Hat rates this low (CVSS 4.3). Weakness: CWE-601. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-25854
Unclassified
Apr 9, 2026
Medium4.3Vendor: LowLinux

Medium [CVE-2026-24880] HTTP Request/Response Smuggling via invalid chunk extension

HTTP Request/Response Smuggling via invalid chunk extension. Red Hat rates this low (CVSS 4.3). Weakness: CWE-444. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-24880
Unclassified
Apr 9, 2026
Medium4.4Linux

Medium [CVE-2026-34757] Information disclosure and data corruption via use-after-free vulnerability

Information disclosure and data corruption via use-after-free vulnerability. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-825. Affected package(s): libpng-main. Resolved in Red Hat advisory RHSA-2026:13719 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34757
Unclassified
Apr 9, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-5874] Sandbox escape via use-after-free in PrivateAI

Sandbox escape via use-after-free in PrivateAI. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5874
Unclassified
Apr 8, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-27140] Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names

Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names. Red Hat rates this important (CVSS 9). Weakness: CWE-641. Affected package(s): openshift4/cloud-network-config-controller-rhel9:1780040126, openshift4/ose-agent-installer-utils-rhel9:1780044523, openshift4/ose-vsphere-csi-driver-rhel9-operator:1780040095, openshift4/ose-aws-cloud-controller-manager-rhel9:1780040386, openshift4/ose-aws-cluster-api-controllers-rhel9:1780040551, openshift4/ose-ironic-machine-os-downloader-rhel9:1780365576. Resolved in Red Hat advisory RHSA-2026:10704 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 12 more.

CVE-2026-27140
Red Hat Enterprise Linux
Apr 8, 2026
High7.9Linux

High [CVE-2026-40024] Arbitrary code execution via path traversal in tsk_recover

Arbitrary code execution via path traversal in tsk_recover. Red Hat rates this important (CVSS 7.9). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40024
Unclassified
Apr 8, 2026
High8.8Linux

High [CVE-2026-5858] Arbitrary code execution via heap buffer overflow in WebML

Arbitrary code execution via heap buffer overflow in WebML. Red Hat rates this important (CVSS 8.8). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5858
Unclassified
Apr 8, 2026
High7.3Linux

High [CVE-2026-39892] Buffer overflow via non-contiguous buffer in API

Buffer overflow via non-contiguous buffer in API. Red Hat rates this important (CVSS 7.3). Weakness: CWE-131. Affected package(s): ansible-automation-platform, quay/quay-rhel8:1779811473, quay/quay-rhel8:1779689392, ansible-automation-platform-tech-preview/metrics-service-rhel9:1779760844, automation-controller, python3.12-cryptography. Resolved in Red Hat advisory RHSA-2026:23361 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat AI Inference Server 3.3; and 20 more.

CVE-2026-39892
Red Hat Enterprise Linux
Apr 8, 2026
High8.8Linux

High [CVE-2026-39883] github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Arbitrary code execution via PATH hijacking on BSD/Solaris

github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Arbitrary code execution via PATH hijacking on BSD/Solaris. Red Hat rates this important (CVSS 8.8). Weakness: CWE-426. Affected package(s): multicluster-engine/assisted-service. Resolved in Red Hat advisory RHSA-2026:26254 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Openshift Data Foundation 4.22.

CVE-2026-39883
Unclassified
Apr 8, 2026
High7.5Linux

High [CVE-2026-23869] denial of service via specially crafted HTTP requests to Server Function endpoints

denial of service via specially crafted HTTP requests to Server Function endpoints. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-23869
Unclassified
Apr 8, 2026
High7.4Linux

High [CVE-2026-5795] early return from the JASPIAuthenticator class without clearing ThreadLocal variables

early return from the JASPIAuthenticator class without clearing ThreadLocal variables. Red Hat rates this important (CVSS 7.4). Weakness: CWE-226. Affected package(s): jetty-ee10-plus, jetty-ee10-servlets, jetty-ee10-apache-jsp, jetty-ee10-webapp, offline-knowledge-portal/rhokp-rhel9:1782239370, jetty-ee10-servlet. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14; Red Hat Offline Knowledge Portal 1.2.7; Red Hat Offline Knowledge Portal 1.2.3; Red Hat Offline Knowledge Portal 1.2.4.

CVE-2026-5795
Unclassified
Apr 8, 2026
High7.5Linux

High [CVE-2026-32280] Denial of Service vulnerability in certificate chain building

Denial of Service vulnerability in certificate chain building. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): rhc, openshift-service-mesh/pilot-rhel8:1777319850, openshift-service-mesh/istio-rhel9-operator:1778149657, grafana-pcp, openshift-service-mesh/istio-cni-rhel8:1777374598, rhtas/client-server-rhel9:1780399582. Resolved in Red Hat advisory RHSA-2026:11507 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 10; Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat OpenShift Container Platform 4.14; and 109 more.

CVE-2026-32280
Red Hat Enterprise Linux
Apr 8, 2026
High7.5Linux

High [CVE-2026-32283] Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages

Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages. Red Hat rates this important (CVSS 7.5). Weakness: CWE-764. Affected package(s): rhc, grafana-pcp, skopeo, host-metering, container-tools:rhel8, git-lfs. Resolved in Red Hat advisory RHSA-2026:11507 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 10; and 75 more.

CVE-2026-32283
Red Hat Enterprise Linux
Apr 8, 2026
High8.1Vendor: MediumLinux

High [CVE-2026-27143] possible memory corruption after bound check elimination

possible memory corruption after bound check elimination. Red Hat rates this moderate (CVSS 8.1). Weakness: CWE-733. Affected package(s): openshift4/openshift-route-controller-manager-rhel8:1781867531, openshift4/ose-gcp-cloud-controller-manager-rhel9:1781927538, openshift4/ose-nutanix-machine-controllers-rhel9:1781926777, openshift4/ose-cluster-bootstrap-rhel9:1779251452, openshift4/ose-cluster-policy-controller-rhel9:1779258265, openshift4/ose-machine-api-provider-aws-rhel9:1779249874. Resolved in Red Hat advisory RHSA-2026:10704 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-27143
Unclassified
Apr 8, 2026
High8.8Linux

High [CVE-2026-33810] Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application

Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1289. Affected package(s): rhtas/client-server-rhel9:1780399582, golang1, cryostat/cryostat-storage-rhel9:4.1.1, opentelemetry-collector, hawtio-operator-container, web-terminal/web-terminal-exec-rhel9:1780425077. Resolved in Red Hat advisory RHSA-2026:28047 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; RHEM 1.0 for RHEL 9; Red Hat Satellite 6.19 for RHEL 9; Red Hat Enterprise Linux AppStream EUS (v. 10.0); and 67 more.

CVE-2026-33810
Red Hat Enterprise Linux
Apr 8, 2026

← All vendors