Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3037 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Red Hat

High [CVE-2026-67422] Denial of Service via Regular Expression Vulnerability

Denial of Service via Regular Expression Vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Hardened Images; Self-service automation portal 2.

CVE-2026-67422
Unclassified
Aug 6, 2026
High8.7Red Hat Updated

High [CVE-2026-66808] unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection)

unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection). Red Hat rates this important (CVSS 8.7). Weakness: CWE-88. Red Hat lists fixing advisory RHSA-2026:54432 with package multicluster-engine/hypershift-addon-rhel9-operator:1786912006, multicluster-engine/hypershift-addon-rhel9-operator:1786548381. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-66808
Unclassified
Aug 6, 2026
High7.5Red Hat

High [CVE-2026-71436] Denial of Service via invalid X-Axis parameters

Denial of Service via invalid X-Axis parameters. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces.

CVE-2026-71436
Unclassified
Aug 6, 2026
High8.1Red Hat

High [CVE-2026-43632] Potential code execution via a race condition in tokenization endpoints

Potential code execution via a race condition in tokenization endpoints. Red Hat rates this important (CVSS 8.1). Weakness: CWE-364.

CVE-2026-43632
Unclassified
Aug 6, 2026
High8.1Red Hat

High [CVE-2026-43631] Remote code execution via use-after-free vulnerability in llama-server

Remote code execution via use-after-free vulnerability in llama-server. Red Hat rates this important (CVSS 8.1). Weakness: CWE-825.

CVE-2026-43631
Unclassified
Aug 6, 2026
High8.1Red Hat

High [CVE-2026-43629] Arbitrary code execution via crafted KV cache state files

Arbitrary code execution via crafted KV cache state files. Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.

CVE-2026-43629
Unclassified
Aug 6, 2026
High7.8Red Hat

High [CVE-2026-43627] Arbitrary Code Execution via Integer Overflow in Memory Allocation

Arbitrary Code Execution via Integer Overflow in Memory Allocation. Red Hat rates this important (CVSS 7.8). Weakness: CWE-805. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.

CVE-2026-43627
Unclassified
Aug 6, 2026
High7.8Red Hat

High [CVE-2026-7867] Local Privilege Escalation via as-user option spoofing

Local Privilege Escalation via as-user option spoofing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:53435 with package udisks2-0:2.11.0-2.el10_2.1. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-7867
Unclassified
Aug 6, 2026
High7.5Red Hat

High [CVE-2026-18427] @fastify/static: @fastify/static: Information disclosure via route guard bypass

@fastify/static: @fastify/static: Information disclosure via route guard bypass. Red Hat rates this important (CVSS 7.5). Weakness: CWE-41. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-18427
Unclassified
Aug 6, 2026
High8.1Red Hat

High [CVE-2026-34191] SQL Injection via apr_dbd_oracle

SQL Injection via apr_dbd_oracle. Red Hat rates this important (CVSS 8.1). Weakness: CWE-89.

CVE-2026-34191
Unclassified
Aug 6, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-34501] Heap buffer overflow in redis client

Heap buffer overflow in redis client. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: apr-util.

CVE-2026-34501
Red Hat Enterprise Linux
Aug 6, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-34502] Heap buffer overflow in APR memcached client

Heap buffer overflow in APR memcached client. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: apr-util.

CVE-2026-34502
Red Hat Enterprise Linux
Aug 6, 2026
High8.1Red Hat

High [CVE-2026-46581] com.sun.faces:jsf-impl: org.glassfish:jakarta.faces: mojarra: Unauthenticated RCE in EAP JSF applications via EL injection in ui:include

com.sun.faces:jsf-impl: org.glassfish:jakarta.faces: mojarra: Unauthenticated RCE in EAP JSF applications via EL injection in ui:include. Red Hat rates this important (CVSS 8.1). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8.

CVE-2026-46581
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-68480] Safe RET Interrupt Vulnerability

Safe RET Interrupt Vulnerability. Red Hat rates this important (CVSS 8.8). Weakness: CWE-201. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-68480
Unclassified
Aug 6, 2026
High8.1Red Hat

High [CVE-2026-66909] Remote Code Execution via unsafe deserialization of JMS ObjectMessage

Remote Code Execution via unsafe deserialization of JMS ObjectMessage. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 1 more. Affected products named by the advisory: Red Hat Single Sign-On 7.

CVE-2026-66909
Unclassified
Aug 6, 2026
High7.5Vendor: MediumRed Hat Updated

High [CVE-2026-18649] unbounded memory growth in rtph264depay and rtph265depay RTP depayloaders

unbounded memory growth in rtph264depay and rtph265depay RTP depayloaders. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:53451 with package gstreamer1-plugins-good-0:1.26.7-2.el10_2.3, gstreamer1-plugins-good-0:1.22.12-7.el9_8.2, gstreamer1-plugins-good-0:1.16.1-7.el8_10.3. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-18649
Unclassified
Aug 6, 2026
High7.0Red Hat

High [CVE-2026-64597] fix double-free in SMB2_close replay

fix double-free in SMB2_close() replay. Red Hat rates this important (CVSS 7). Weakness: CWE-415. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel-rt.

CVE-2026-64597
Linux Kernel
Aug 6, 2026
High8.0Red Hat

High [CVE-2026-71312] Server-Side Command Execution via Malicious SFTP Filenames

Server-Side Command Execution via Malicious SFTP Filenames. Red Hat rates this important (CVSS 8). Weakness: CWE-78.

CVE-2026-71312
Unclassified
Aug 5, 2026
High7.6Red Hat

High [CVE-2026-34966] Information disclosure via Server-Side Request Forgery (SSRF) bypass

Information disclosure via Server-Side Request Forgery (SSRF) bypass. Red Hat rates this important (CVSS 7.6). Weakness: CWE-918.

CVE-2026-34966
Unclassified
Aug 5, 2026
High8.1Red Hat

High [CVE-2026-71309] Backend Root Escape via Incomplete Path Validation

Backend Root Escape via Incomplete Path Validation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-22.

CVE-2026-71309
Unclassified
Aug 5, 2026

← All vendors