Red Hat Linux Security Advisories & CVEs
5196 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-32304] Arbitrary code execution via unsanitized parameters in create_function
Arbitrary code execution via unsanitized parameters in create_function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-88. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Logging Subsystem for Red Hat OpenShift.
High [CVE-2026-2229] Denial of Service via invalid WebSocket permessage-deflate extension parameter
Denial of Service via invalid WebSocket permessage-deflate extension parameter. Red Hat rates this important (CVSS 7.5). Weakness: CWE-248. Affected package(s): cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, rhoai/odh-dashboard-rhel8:1774282136, nodejs:22, cryostat/cryostat-openshift-console-plugin-rhel9:4.2.0, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; and 7 more.
High [CVE-2026-1528] Denial of Service via crafted WebSocket frame with large length
Denial of Service via crafted WebSocket frame with large length. Red Hat rates this important (CVSS 7.5). Weakness: CWE-248. Affected package(s): cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, rhoai/odh-dashboard-rhel8:1774282136, nodejs:22, cryostat/cryostat-openshift-console-plugin-rhel9:4.2.0, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; and 7 more.
High [CVE-2026-1526] Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression
Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, rhoai/odh-dashboard-rhel8:1774282136, nodejs:22, cryostat/cryostat-openshift-console-plugin-rhel9:4.2.0, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; and 7 more.
High [CVE-2026-1525] HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers
HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-444. Affected package(s): nodejs:22, cryostat/cryostat-openshift-console-plugin-rhel9:4.2.0, rhdh/rhdh-hub-rhel9:1776784286, devspaces/code-rhel9:1779814592, nodejs:24, cryostat/cryostat-rhel9:4.2.0. Resolved in Red Hat advisory RHSA-2026:7350 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
High [CVE-2026-32274] Arbitrary file writes from unsanitized user input in cache file name
Arbitrary file writes from unsanitized user input in cache file name. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Affected package(s): ansible-automation-platform, rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1776319179, rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9:1776319275, rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1776318795, rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9:1776319193, rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1776319185. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5; Red Hat Ansible Automation Platform 2.6; Red Hat OpenShift AI 2.25; OpenShift Lightspeed; and 3 more.
High [CVE-2026-3497] Information disclosure or denial of service due to uninitialized variables
Information disclosure or denial of service due to uninitialized variables. Red Hat rates this important (CVSS 8.2). Weakness: CWE-824. Affected package(s): openssh, rhcos, rhpam, rhaiis/vllm-rocm-rhel9:1778244531, rhaiis/vllm-cuda-rhel9:1778274666, rhui5/installer-rhel9:1776868772. Resolved in Red Hat advisory RHSA-2026:20040 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Container Platform 4.12; Middleware Containers for OpenShift; Red Hat OpenShift Container Platform 4.13; Red Hat OpenShift Container Platform 4.14; and 52 more.
High [CVE-2026-32141] Unbounded recursion DoS in parse() revive phase
Unbounded recursion DoS in parse() revive phase. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): rhdh/rhdh-hub-rhel9:1777903262, devspaces/dashboard-rhel9:1779341289, cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, rhoai/odh-dashboard-rhel8:1774282136, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9; Red Hat Edge Manager 1.0; Red Hat OpenShift AI 2.16; and 9 more.
High [CVE-2026-28356] denial of service via maliciously crafted HTTP or multipart segment headers
denial of service via maliciously crafted HTTP or multipart segment headers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected package(s): rhaiis/vllm-cuda-rhel9:1774351144, rhaiis/model-opt-cuda-rhel9:1774547384, rhoai/odh-caikit-tgis-serving-rhel9:1776247907, rhaiis/vllm-rocm-rhel9:1775252598, rhoai/odh-feature-server-rhel9:1776338381. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat AI Inference Server 3.2; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; OpenShift Lightspeed; and 3 more.
High [CVE-2026-3909] Out of bounds write in Skia
Out of bounds write in Skia. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-3910] Inappropriate implementation in V8
Inappropriate implementation in V8. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-1527] HTTP header injection and request smuggling vulnerability
HTTP header injection and request smuggling vulnerability. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-93. Affected package(s): nodejs24, nodejs:24. Resolved in Red Hat advisory RHSA-2026:7350 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-2581] Denial of Service due to uncontrolled resource consumption
Denial of Service due to uncontrolled resource consumption. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-770. Affected package(s): nodejs24, nodejs:24. Resolved in Red Hat advisory RHSA-2026:7350 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-32235] @backstage/plugin-auth-backend: @backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass
@backstage/plugin-auth-backend: @backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-601. Affected package(s): rhdh/rhdh-hub-rhel9:1780930740. Resolved in Red Hat advisory RHSA-2026:24841 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2025-13462] `tarfile` module misinterprets crafted tar archives leading to data integrity issues
`tarfile` module misinterprets crafted tar archives leading to data integrity issues. Red Hat rates this low (CVSS 2.5). Weakness: CWE-237. Affected package(s): python3. Resolved in Red Hat advisory RHSA-2026:10118 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2025-70873] Information Disclosure via Crafted ZIP File
Information Disclosure via Crafted ZIP File. Red Hat rates this low (CVSS 3.3). Weakness: CWE-908. Affected package(s): sqlite-main. Resolved in Red Hat advisory RHSA-2026:7656 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-31892] Security bypass allows privilege escalation via podSpecPatch field
Security bypass allows privilege escalation via podSpecPatch field. Red Hat rates this important (CVSS 9.9). Weakness: CWE-807. Affected package(s): rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9:1776740351, rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9:1776740640, rhoai/odh-ml-pipelines-api-server-v2-rhel9:1776740726, rhoai/odh-data-science-pipelines-argo-argoexec-rhel9:1776740558, rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9:1776740366, rhoai/odh-ml-pipelines-driver-rhel9:1776740379. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat OpenShift AI 2.25.
High [CVE-2026-31870] Denial of Service via malformed Content-Length header
Denial of Service via malformed Content-Length header. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1287. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-28229] Argo Workflows has unauthorized access to Argo Workflows Template
Argo Workflows has unauthorized access to Argo Workflows Template. Red Hat rates this important (CVSS 7.5). Weakness: CWE-306. Affected package(s): rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9:1776740351, rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9:1776740640, rhoai/odh-ml-pipelines-api-server-v2-rhel9:1776740726, rhoai/odh-data-science-pipelines-argo-argoexec-rhel9:1776740558, rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9:1776740366, rhoai/odh-ml-pipelines-driver-rhel9:1776740379. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat OpenShift AI 2.25.
High [CVE-2026-4111] Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive
Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected package(s): rhcos, rhaiis/vllm-rocm-rhel9:1778244531, discovery/discovery-server-rhel9:1775668717, libarchive, rhui5/haproxy-rhel9:1776868744, rhui5/installer-rhel9:1776868772. Resolved in Red Hat advisory RHSA-2026:7329 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Extended Update Support; and 14 more.