Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5205 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.5Linux

High [CVE-2026-34601] XML structure injection via CDATA terminator

XML structure injection via CDATA terminator. Red Hat rates this important (CVSS 7.5). Weakness: CWE-91. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34601
Unclassified
Apr 2, 2026
High7.5Linux

High [CVE-2026-34827] Denial of Service via crafted multipart/form-data requests

Denial of Service via crafted multipart/form-data requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Logging Subsystem for Red Hat OpenShift; Red Hat 3scale API Management Platform 2.

CVE-2026-34827
Unclassified
Apr 2, 2026
High7.5Linux

High [CVE-2026-34829] Denial of Service via unbounded multipart file upload

Denial of Service via unbounded multipart file upload. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Logging Subsystem for Red Hat OpenShift; Red Hat 3scale API Management Platform 2.

CVE-2026-34829
Unclassified
Apr 2, 2026
High7.5Linux

High [CVE-2026-34785] Information disclosure via incorrect static file serving prefix check

Information disclosure via incorrect static file serving prefix check. Red Hat rates this important (CVSS 7.5). Weakness: CWE-552. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34785
Unclassified
Apr 2, 2026
High7.5Linux

High [CVE-2026-35385] Privilege escalation via scp legacy protocol when not preserving file mode

Privilege escalation via scp legacy protocol when not preserving file mode. Red Hat rates this important (CVSS 7.5). Weakness: CWE-281. Affected package(s): rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, openssh, rhcos, rhui5/rhua-rhel9:1779798222, rhaiis/model-opt-cuda-rhel9:1780681984. Resolved in Red Hat advisory RHSA-2026:26542 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 22 more.

CVE-2026-35385
Red Hat Enterprise Linux
Apr 2, 2026
High8.5Linux

High [CVE-2026-32871] Authenticated Server-Side Request Forgery via path traversal in OpenAPI path parameters

Authenticated Server-Side Request Forgery via path traversal in OpenAPI path parameters. Red Hat rates this important (CVSS 8.5). Weakness: CWE-918. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Satellite 6.18.

CVE-2026-32871
Unclassified
Apr 2, 2026
High7.5Linux

High [CVE-2026-31937] Denial of Service via DCERPC buffering inefficiency

Denial of Service via DCERPC buffering inefficiency. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-31937
Unclassified
Apr 2, 2026
High7.5Linux

High [CVE-2026-31935] Denial of Service via HTTP2 continuation frame flooding

Denial of Service via HTTP2 continuation frame flooding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-31935
Unclassified
Apr 2, 2026
High7.5Linux

High [CVE-2026-31934] Denial of Service via quadratic complexity in URL search of MIME-encoded SMTP messages

Denial of Service via quadratic complexity in URL search of MIME-encoded SMTP messages. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-31934
Unclassified
Apr 2, 2026
High7.5Linux

High [CVE-2026-31933] Denial of Service due to specially crafted network traffic

Denial of Service due to specially crafted network traffic. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-31933
Unclassified
Apr 2, 2026
High7.5Linux

High [CVE-2026-31932] Denial of Service due to inefficiency in KRB5 buffering

Denial of Service due to inefficiency in KRB5 buffering. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-31932
Unclassified
Apr 2, 2026
High7.5Linux

High [CVE-2026-31931] Denial of Service via 'tls.alpn' rule keyword

Denial of Service via 'tls.alpn' rule keyword. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-31931
Unclassified
Apr 2, 2026
High7.3Linux

High [CVE-2026-3872] Information disclosure due to redirect_uri validation bypass

Information disclosure due to redirect_uri validation bypass. Red Hat rates this important (CVSS 7.3). Weakness: CWE-601. Affected package(s): rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-operator-bundle:26.2.15, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.2; Red Hat build of Keycloak 26.4.

CVE-2026-3872
Unclassified
Apr 2, 2026
High7.4Linux

High [CVE-2026-4282] Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw

Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw. Red Hat rates this important (CVSS 7.4). Weakness: CWE-653. Affected package(s): rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-operator-bundle:26.2.15, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.2; Red Hat build of Keycloak 26.4.

CVE-2026-4282
Unclassified
Apr 2, 2026
High7.5Linux

High [CVE-2026-4634] Denial of Service via excessive processing of OpenID Connect scope parameters

Denial of Service via excessive processing of OpenID Connect scope parameters. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Affected package(s): rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-operator-bundle:26.2.15, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.2; Red Hat build of Keycloak 26.4.

CVE-2026-4634
Unclassified
Apr 2, 2026
High8.1Linux

High [CVE-2026-4636] UMA policy bypass allows authenticated users to gain unauthorized access to victim-owned resources.

UMA policy bypass allows authenticated users to gain unauthorized access to victim-owned resources.. Red Hat rates this important (CVSS 8.1). Weakness: CWE-551. Affected package(s): rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-operator-bundle:26.2.15, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.2; Red Hat build of Keycloak 26.4.

CVE-2026-4636
Unclassified
Apr 2, 2026
Medium5.3Linux

Medium [CVE-2026-34743] Denial of Service via buffer overflow in index decoding

Denial of Service via buffer overflow in index decoding. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-131. Affected package(s): xz-main. Resolved in Red Hat advisory RHSA-2026:7647 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34743
Unclassified
Apr 2, 2026
Medium4.8Linux

Medium [CVE-2026-35414] Security bypass via mishandling of authorized_keys principals option

Security bypass via mishandling of authorized_keys principals option. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-168. Affected package(s): openssh, rhaiis/model-opt-cuda-rhel9:1780681984, rhui5/rhua-rhel9:1779798222, discovery/discovery-server-rhel9:1778101579, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-35414
Unclassified
Apr 2, 2026
Medium5.3Linux

Medium [CVE-2026-4325] Replay of action tokens via improper handling of single-use entries

Replay of action tokens via improper handling of single-use entries. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-653. Affected package(s): rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-operator-bundle:26.2.15, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4325
Unclassified
Apr 2, 2026
Low2.2Linux

Low [CVE-2026-35388] Low integrity impact from unconfirmed proxy-mode multiplexing sessions

Low integrity impact from unconfirmed proxy-mode multiplexing sessions. Red Hat rates this low (CVSS 2.2). Weakness: CWE-306. Affected package(s): openssh, rhaiis/model-opt-cuda-rhel9:1780681984, discovery/discovery-ui-rhel9:1778156756, rhui5/rhua-rhel9:1779798222, discovery/discovery-server-rhel9:1778101579, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-35388
Unclassified
Apr 2, 2026

← All vendors