Red Hat Linux Security Advisories & CVEs
5198 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-3336] Certificate validation bypass via improper handling of PKCS7 objects
Certificate validation bypass via improper handling of PKCS7 objects. Red Hat rates this important (CVSS 7.5). Weakness: CWE-295. Affected package(s): rhtas/tuffer-rhel9:1773307309, rhtas/tuftool-rhel9:1773307309. Resolved in Red Hat advisory RHSA-2026:5459 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Trusted Artifact Signer 1.3; Confidential Compute Attestation; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 2 more.
Medium [CVE-2026-23865] Information disclosure or denial of service via specially crafted font files
Information disclosure or denial of service via specially crafted font files. Red Hat rates this moderate (CVSS 5.3). Affected package(s): java, freetype-main. Resolved in Red Hat advisory RHSA-2026:11822 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-3441] Information disclosure via specially crafted XCOFF object file
Information disclosure via specially crafted XCOFF object file. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:33527 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 6.
Medium [CVE-2026-3442] Information disclosure or denial of service via out-of-bounds read in bfd linker
Information disclosure or denial of service via out-of-bounds read in bfd linker. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:33527 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 6.
Medium [CVE-2026-3429] Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API
Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-284. Affected package(s): rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-28416] Server-Side Request Forgery allows access to internal services via malicious Space loading
Server-Side Request Forgery allows access to internal services via malicious Space loading. Red Hat rates this important (CVSS 8.2). Weakness: CWE-918. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-28406] Arbitrary code execution via path traversal in build context archive unpacking
Arbitrary code execution via path traversal in build context archive unpacking. Red Hat rates this important (CVSS 8.5). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-2293] Authentication bypass via Fastify path-normalization
Authentication bypass via Fastify path-normalization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-551. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-3304] Denial of Service via malformed requests
Denial of Service via malformed requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-459. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:6174 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9.
High [CVE-2026-2359] Denial of Service via dropped file upload connections
Denial of Service via dropped file upload connections. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:6174 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9.
High [CVE-2026-28364] Remote code execution via buffer over-read in Marshal deserialization
Remote code execution via buffer over-read in Marshal deserialization. Red Hat rates this important (CVSS 7.9). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-28421] Denial of service and information disclosure via crafted swap file
Denial of service and information disclosure via crafted swap file. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-120. Affected package(s): rhcos, rhaiis/vllm-rocm-rhel9:1778244531, rhui5/cds-kubernetes-tp-rhel9:1777459441, rhui5/haproxy-rhel9:1776868744, rhui5/installer-rhel9:1776868772, vim. Resolved in Red Hat advisory RHSA-2026:6915 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7.
Medium [CVE-2026-28417] Arbitrary code execution via OS command injection in the netrw plugin
Arbitrary code execution via OS command injection in the netrw plugin. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-78. Affected package(s): rhcos, rhaiis/vllm-rocm-rhel9:1778244531, rhui5/cds-kubernetes-tp-rhel9:1777459441, rhui5/haproxy-rhel9:1776868744, rhui5/installer-rhel9:1776868772, vim. Resolved in Red Hat advisory RHSA-2026:6915 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7.
High [CVE-2026-27970] @angular/core: Angular: Cross-site scripting via compromised translation files
@angular/core: Angular: Cross-site scripting via compromised translation files. Red Hat rates this important (CVSS 7.1). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7.
High [CVE-2026-27959] Host header injection vulnerability due to malformed HTTP Host header parsing
Host header injection vulnerability due to malformed HTTP Host header parsing. Red Hat rates this important (CVSS 8.2). Weakness: CWE-20. Affected package(s): rhoai/odh-mod-arch-model-registry-rhel9:1776742141, rhoai/odh-dashboard-rhel9:1776742021, openshift4/ose-monitoring-plugin-rhel9:1775577192. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift Container Platform 4.19; Red Hat Developer Hub.
High [CVE-2026-27942] Stack overflow leads to Denial of Service
Stack overflow leads to Denial of Service. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-776. Affected package(s): odf4/mcg-core-rhel9:1776403991, odf4/mcg-rhel9-operator:1776404009, odf4/odf-cloudnative-pg-rhel9-operator:1776406131, odf4/odf-external-snapshotter-rhel9-operator:1776406284, odf4/odf-external-snapshotter-sidecar-rhel9:1776406291, advanced-cluster-security/rhacs-main-rhel8:1775594284. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-27896] improper handling of case sensitivity
improper handling of case sensitivity. Red Hat rates this important (CVSS 7.2). Weakness: CWE-178. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: OpenShift Lightspeed; OpenShift Serverless; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-27830] Arbitrary Code Execution via deserialization of crafted objects
Arbitrary Code Execution via deserialization of crafted objects. Red Hat rates this important (CVSS 8). Weakness: CWE-502. Affected package(s): com.mchange/c3p0, org.hibernate.orm/hibernate-c3p0, eap8-hibernate, c3p0/c3p0, candlepin. Resolved in Red Hat advisory RHSA-2026:28385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9; Red Hat build of Debezium 2; and 3 more.
Medium [CVE-2026-27141] Denial of Service due to malformed HTTP/2 frames
Denial of Service due to malformed HTTP/2 frames. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-476. Affected package(s): openshift-pipelines/pipelines-operator-bundle:1781686494, openshift-pipelines/pipelines-rhel9-operator:1780645012, golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-27904] Denial of Service via catastrophic backtracking in glob expressions
Denial of Service via catastrophic backtracking in glob expressions. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1333. Affected package(s): quay/quay-rhel9:1775069491, nodejs:20, nodejs:22, rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1776336652, devspaces/openvsx-rhel9:1779528224, satellite/iop-advisor-frontend-rhel9:1781181673. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.