Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5244 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Low3.1Linux

Low [CVE-2026-1035] Keycloak Refresh Token Reuse Bypass via TOCTOU Race Condition

Keycloak Refresh Token Reuse Bypass via TOCTOU Race Condition. Red Hat rates this low (CVSS 3.1). Weakness: CWE-367. Affected package(s): rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-1035
Unclassified
Jan 21, 2026
High7.1Vendor: MediumLinux

High [CVE-2025-15367] POP3 command injection in user-controlled commands

POP3 command injection in user-controlled commands. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-77. Affected package(s): discovery/discovery-server-rhel9:1775668717, python3, python3.11, python3.12, rhui5/rhua-rhel9:1773670137, rhaiis/vllm-rocm-rhel9:1775680262. Resolved in Red Hat advisory RHSA-2026:5606 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 6; and 1 more.

CVE-2025-15367
Unclassified
Jan 20, 2026
High7.1Vendor: MediumLinux

High [CVE-2025-15366] IMAP command injection in user-controlled commands

IMAP command injection in user-controlled commands. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-77. Affected package(s): discovery/discovery-server-rhel9:1775668717, python3, python3.11, python3.12, rhui5/rhua-rhel9:1773670137, rhaiis/vllm-rocm-rhel9:1775680262. Resolved in Red Hat advisory RHSA-2026:5606 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 6; and 1 more.

CVE-2025-15366
Unclassified
Jan 20, 2026
High7.4Linux

High [CVE-2026-21932] Enhance Handling of URIs (Oracle CPU 2026-01)

Enhance Handling of URIs (Oracle CPU 2026-01). Red Hat rates this important (CVSS 7.4). Weakness: CWE-1287. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:0896 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of OpenJDK 17.0.18; Red Hat Build of OpenJDK 21.0.10; Red Hat Build of OpenJDK 8u482.

CVE-2026-21932
Unclassified
Jan 20, 2026
High7.5Linux

High [CVE-2026-21945] Enhance Certificate Checking (Oracle CPU 2026-01)

Enhance Certificate Checking (Oracle CPU 2026-01). Red Hat rates this important (CVSS 7.5). Weakness: CWE-295. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:0895 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of OpenJDK 17.0.18; Red Hat Build of OpenJDK 21.0.10; Red Hat Build of OpenJDK 25.0.2; Red Hat Build of OpenJDK 8u482; and 17 more.

CVE-2026-21945
Red Hat Enterprise Linux
Jan 20, 2026
High7.5Linux

High [CVE-2025-59465] Nodejs denial of service

Nodejs denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-248. Affected package(s): nodejs22, nodejs:20, nodejs:22, nodejs25-main, nodejs:24, nodejs24-main. Resolved in Red Hat advisory RHSA-2026:1842 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.

CVE-2025-59465
Red Hat Enterprise Linux
Jan 20, 2026
High7.1Linux

High [CVE-2025-55131] Nodejs uninitialized memory exposure

Nodejs uninitialized memory exposure. Red Hat rates this important (CVSS 7.1). Weakness: CWE-497. Affected package(s): nodejs22, nodejs:20, nodejs:22, nodejs25-main, nodejs:24, nodejs24-main. Resolved in Red Hat advisory RHSA-2026:1842 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.

CVE-2025-55131
Red Hat Enterprise Linux
Jan 20, 2026
High7.1Linux

High [CVE-2025-55130] Nodejs file permissions bypass

Nodejs file permissions bypass. Red Hat rates this important (CVSS 7.1). Weakness: CWE-281. Affected package(s): nodejs22, nodejs:20, nodejs:22, nodejs25-main, nodejs:24, nodejs24-main. Resolved in Red Hat advisory RHSA-2026:1842 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.

CVE-2025-55130
Red Hat Enterprise Linux
Jan 20, 2026
High8.1Linux

High [CVE-2026-23876] Arbitrary code execution via a crafted XBM image file

Arbitrary code execution via a crafted XBM image file. Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:3058 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.

CVE-2026-23876
Red Hat Enterprise Linux
Jan 20, 2026
High8.8Linux

High [CVE-2026-23950] Arbitrary file overwrite via Unicode path collision race condition

Arbitrary file overwrite via Unicode path collision race condition. Red Hat rates this important (CVSS 8.8). Weakness: CWE-367. Affected package(s): devspaces/udi-rhel9:1774451954, rhtas/rekor-search-ui-rhel9:1770107452, rhtas/rekor-search-ui-rhel9:1770739056, linux-sgx. Resolved in Red Hat advisory RHSA-2026:18868 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Dev Spaces 3.27; Red Hat Trusted Artifact Signer 1.2; and 17 more.

CVE-2026-23950
Red Hat Enterprise Linux
Jan 20, 2026
High8.6Linux

High [CVE-2026-23949] Path traversal via malicious tar archives

Path traversal via malicious tar archives. Red Hat rates this important (CVSS 8.6). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-23949
Unclassified
Jan 20, 2026
High7.8Linux

High [CVE-2025-56005] Unsafe pickle file handling in Ply

Unsafe pickle file handling in Ply. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Migration Toolkit for Containers; OpenShift Developer Tools and Services; OpenShift Pipelines; Red Hat Advanced Cluster Security 4; and 14 more.

CVE-2025-56005
Red Hat Enterprise Linux
Jan 20, 2026
Medium4.8Linux

Medium [CVE-2026-0672] Header injection in http.cookies.Morsel in Python

Header injection in http.cookies. Morsel in Python. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-93. Affected package(s): python3.12, rhui5/rhua-rhel9:1779798222, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:19064 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-0672
Unclassified
Jan 20, 2026
Medium4.8Linux

Medium [CVE-2025-15282] Header injection via newlines in data URL mediatype in Python

Header injection via newlines in data URL mediatype in Python. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-93. Affected package(s): python3.12, python3, rhui5/rhua-rhel9:1779798222, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:19064 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2025-15282
Unclassified
Jan 20, 2026
Medium4.5Linux

Medium [CVE-2026-0865] wsgiref.headers.Headers allows header newline injection in Python

wsgiref.headers. Headers allows header newline injection in Python. Red Hat rates this moderate (CVSS 4.5). Weakness: CWE-74. Affected package(s): python3.11, python3, rhui5/haproxy-rhel9:1779798164, rhui5/rhua-rhel9:1773670137, rhui5/rhua-rhel9:1779798222, python3.12. Resolved in Red Hat advisory RHSA-2026:2128 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-0865
Unclassified
Jan 20, 2026
Medium4.8Linux

Medium [CVE-2026-21925] Improve JMX connections (Oracle CPU 2026-01)

Improve JMX connections (Oracle CPU 2026-01). Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-322. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:0895 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-21925
Unclassified
Jan 20, 2026
Medium6.1Linux

Medium [CVE-2026-21933] Improve HttpServer Request handling (Oracle CPU 2026-01)

Improve HttpServer Request handling (Oracle CPU 2026-01). Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-93. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:0895 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-21933
Unclassified
Jan 20, 2026
Medium4.5Linux

Medium [CVE-2025-11468] Missing character filtering in Python

Missing character filtering in Python. Red Hat rates this moderate (CVSS 4.5). Weakness: CWE-140. Affected package(s): python3. Resolved in Red Hat advisory RHSA-2026:8824 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-11468
Unclassified
Jan 20, 2026
Medium5.3Linux

Medium [CVE-2025-55132] Nodejs filesystem permissions bypass

Nodejs filesystem permissions bypass. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-281. Affected package(s): nodejs25-main, nodejs22, nodejs:24, nodejs:22, nodejs24-main, nodejs20-main. Resolved in Red Hat advisory RHSA-2026:1842 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2025-55132
Unclassified
Jan 20, 2026
Medium5.9Linux

Medium [CVE-2026-21637] Nodejs denial of service

Nodejs denial of service. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-248. Affected package(s): nodejs22, nodejs:20, nodejs:22, nodejs25-main, nodejs:24, nodejs24-main. Resolved in Red Hat advisory RHSA-2026:1842 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-21637
Unclassified
Jan 20, 2026

← All vendors