Red Hat Linux Security Advisories & CVEs
5265 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
Medium [CVE-2025-68158] Cross-Site Request Forgery due to improper session management in state storage
Cross-Site Request Forgery due to improper session management in state storage. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-352. Affected package(s): quay/quay-rhel9:1775069491, quay/quay-rhel9:1775169226, quay/quay-rhel8:1775169219, satellite/foreman-mcp-server-rhel9:1782228427. Resolved in Red Hat advisory RHSA-2026:6568 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-68151] github.com/coredns/coredns/core/dnsserver: CoreDNS DoS via unbounded connections and oversized messages
github.com/coredns/coredns/core/dnsserver: CoreDNS DoS via unbounded connections and oversized messages. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected package(s): rhacm2/lighthouse-coredns-rhel9:1774086225, rhacm2/lighthouse-coredns-rhel9:1780204249. Resolved in Red Hat advisory RHSA-2026:8151 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-22028] Arbitrary script execution via JSON serialization protection bypass
Arbitrary script execution via JSON serialization protection bypass. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-843. Affected package(s): openshift4/ose-agent-installer-ui-rhel9:1774977480. Resolved in Red Hat advisory RHSA-2026:6564 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-14017] Security bypass due to global TLS option changes in multi-threaded LDAPS transfers
Security bypass due to global TLS option changes in multi-threaded LDAPS transfers. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-1058. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:6893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-66560] Quarkus REST Worker Thread Exhaustion Vulnerability
Quarkus REST Worker Thread Exhaustion Vulnerability. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-772. Affected package(s): quarkus-rest. Resolved in Red Hat advisory RHSA-2026:1899 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-21869] Remote code execution via invalid n_discard parameter in server endpoints
Remote code execution via invalid n_discard parameter in server endpoints. Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-21441] urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API). Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Affected package(s): rhacm2/submariner-globalnet-rhel9:1774550347, oadp/oadp-velero-rhel9:1770421082, rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1771502845, rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9:1770103255, python3.12-urllib3, rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1771502910. Resolved in Red Hat advisory RHSA-2026:2456 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 69 more.
High [CVE-2025-69264] pnpm code execution
pnpm code execution. Red Hat rates this important (CVSS 8.8). Weakness: CWE-693. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2025-69263] pnpm Lockfile Integrity Bypass
pnpm Lockfile Integrity Bypass. Red Hat rates this important (CVSS 7.5). Weakness: CWE-494. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-22184] Arbitrary code execution via buffer overflow in untgz utility
Arbitrary code execution via buffer overflow in untgz utility. Red Hat rates this important (CVSS 8.6). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2025-15079] Host verification bypass during SSH transfers
Host verification bypass during SSH transfers. Red Hat rates this low (CVSS 8.1). Weakness: CWE-358. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:6893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-13151] Denial of Service via stack-based buffer overflow in asn1_expend_octet_string
Denial of Service via stack-based buffer overflow in asn1_expend_octet_string. Red Hat rates this low (CVSS 5.9). Weakness: CWE-120. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, libtasn1, libtasn1-main, discovery/discovery-ui-rhel9:1782756541, discovery/discovery-server-rhel9:1782763840. Resolved in Red Hat advisory RHSA-2026:28235 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2025-13034] Public key pinning bypass via QUIC and GnuTLS allows server impersonation
Public key pinning bypass via QUIC and GnuTLS allows server impersonation. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-295. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:6893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-14524] Information disclosure via cross-protocol redirect with OAuth2 bearer token
Information disclosure via cross-protocol redirect with OAuth2 bearer token. Red Hat rates this low (CVSS 6.5). Weakness: CWE-201. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:6893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-14819] Improper certificate validation due to cached TLS settings reuse
Improper certificate validation due to cached TLS settings reuse. Red Hat rates this low (CVSS 6.8). Weakness: CWE-295. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:6893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-15224] libssh key passphrase bypass without agent set
libssh key passphrase bypass without agent set. Red Hat rates this low (CVSS 4.7). Weakness: CWE-305. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:6893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-0707] Keycloak Authorization Header Parsing Leading to Potential Security Control Bypass
Keycloak Authorization Header Parsing Leading to Potential Security Control Bypass. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-551. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.10, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:3947 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2025-69227] Denial of Service via specially crafted POST request
Denial of Service via specially crafted POST request. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-835. Affected package(s): ansible-automation-platform, rhaiis/vllm-cuda-rhel9:1774351144, rhoai/odh-caikit-nlp-rhel9:1780069094, rhoai/odh-vllm-gaudi-rhel9:1772093278, rhaiis/model-opt-cuda-rhel9:1774547384, rhoai/odh-vllm-cpu-rhel9:1776259063. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2025-69223] AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): automation-controller, rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:1771502844, ansible-automation-platform, rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9:1770053721, rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9:1770055428, rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1771502845. Resolved in Red Hat advisory RHSA-2026:2106 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.4 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.4 for RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 9; and 11 more.
High [CVE-2025-68428] jsPDF Local File Inclusion/Path Traversal vulnerability
jsPDF Local File Inclusion/Path Traversal vulnerability. Red Hat rates this important (CVSS 8.6). Weakness: CWE-73. Affected package(s): advanced-cluster-security/rhacs-main-rhel8:1770250889, advanced-cluster-security/rhacs-main-rhel8:1770074713, advanced-cluster-security/rhacs-main-rhel8:1769615659. Resolved in Red Hat advisory RHSA-2026:2568 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.8; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Advanced Cluster Security 4.8; Red Hat Advanced Cluster Security 4.9.