Red Hat Linux Security Advisories & CVEs
3038 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-67859] Denial of Service via Discovery/LDS handling
Denial of Service via Discovery/LDS handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-67862] Denial of Service via buffer-overflow
Denial of Service via buffer-overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-8400] Arbitrary class loading and instantiation via malicious IIOP server
Arbitrary class loading and instantiation via malicious IIOP server. Red Hat rates this important (CVSS 8.1). Weakness: CWE-470. Red Hat lists fixing advisory RHSA-2026:52949 with package java-1.8.0-ibm-1:1.8.0.8.70-1.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.
High [CVE-2026-64564] don't free the ASCONF's own transport in DEL-IP processing
don't free the ASCONF's own transport in DEL-IP processing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825.
High [CVE-2026-67861] Denial of Service via UA_Client_getRemoteDataTypes component
Denial of Service via UA_Client_getRemoteDataTypes component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-67860] Heap-based buffer overflow in HistoryRead path
Heap-based buffer overflow in HistoryRead path. Red Hat rates this important (CVSS 8.2). Weakness: CWE-120.
High [CVE-2026-69244] Denial of Service via malformed HTTP responses
Denial of Service via malformed HTTP responses. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:55853 with package ansible-automation-platform/ee-minimal-rhel8:1786971288, ansible-automation-platform/ee-minimal-rhel9:1786942232, discovery/discovery-server-rhel9:1786638573. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 9 more. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; Red Hat Ansible Automation Platform Ansible Core 2; Red Hat Discovery 2; and 5 more.
High [CVE-2026-69243] HTTP Request Smuggling via WebSocket Upgrade
HTTP Request Smuggling via WebSocket Upgrade. Red Hat rates this moderate (CVSS 7). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:54760 with package discovery/discovery-server-rhel9:1786638573. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 9 more. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; Red Hat Ansible Automation Platform Ansible Core 2; Red Hat Discovery 2; and 5 more.
High [CVE-2026-69192] Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass
Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass. Red Hat rates this important (CVSS 8.6). Weakness: CWE-1389. Red Hat lists fixing advisory RHSA-2026:56338 with package grafana13-1-main-13.1.1-0.5.2.hum1, ansible-automation-platform/automation-portal:1787047114, grafana13-1-main-13.1.2-0.1.hum1, grafana12-4-main-12.4.7-0.1.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-69185] Denial of Service via memory exhaustion from crafted packets
Denial of Service via memory exhaustion from crafted packets. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.
High [CVE-2026-69153] Information disclosure via crafted sourceMappingURL
Information disclosure via crafted sourceMappingURL. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:56338 with package prometheus3-13-main-3.13.2-0.2.hum1, grafana12-4-main-12.4.6-0.4.hum1, grafana13-1-main-13.1.1-0.5.2.hum1, ansible-automation-platform/automation-portal:1787047114. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-14257 +1] DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:56338 with package grafana12-4-main-12.4.6-0.4.hum1, grafana13-1-main-13.1.1-0.5.2.hum1, ansible-automation-platform/automation-portal:1787047114, nodejs22-main-22.23.2-2.3.2.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-69151] @angular/compiler: @angular/core: Angular: Cross-Site Scripting via internationalization event handlers
@angular/compiler: @angular/core: Angular: Cross-Site Scripting via internationalization event handlers. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79.
High [CVE-2026-68945] @angular/common: Angular: Cross-Request Response Reuse and State Poisoning in HttpTransferCache
@angular/common: Angular: Cross-Request Response Reuse and State Poisoning in HttpTransferCache. Red Hat rates this important (CVSS 8.2). Weakness: CWE-694.
High [CVE-2026-12852] Bouncy Castle for Java: Denial of Service via MLS wire decoder
Bouncy Castle for Java: Denial of Service via MLS wire decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284.
High [CVE-2026-58062] Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response
Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected products named by the advisory: Red Hat AMQ Clients; Red Hat Ceph Storage 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7; Red Hat package: resteasy.
High [CVE-2026-59650] Bouncy Castle for Java: Cryptographic key compromise due to unvalidated Diffie-Hellman peer value
Bouncy Castle for Java: Cryptographic key compromise due to unvalidated Diffie-Hellman peer value. Red Hat rates this important (CVSS 7.4). Weakness: CWE-325.
High [CVE-2026-8763] Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI
Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected products named by the advisory: Red Hat AMQ Clients; Red Hat Ceph Storage 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7; Red Hat package: resteasy.
High [CVE-2026-68580] Remote code execution or denial of service via audio input integer overflow
Remote code execution or denial of service via audio input integer overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:54487 with package freerdp-2:2.11.7-11.el8_10, freerdp-2:2.11.7-7.el9_8.5, freerdp-2:3.10.3-12.el10_2.8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-67323] Arbitrary code execution via command injection due to unguarded Git options
Arbitrary code execution via command injection due to unguarded Git options. Red Hat rates this important (CVSS 8.4). Weakness: CWE-88. Red Hat lists fixing advisory RHSA-2026:44416 with package swift-lang-main-6.3.3-0.1.1.hum1, llvm21-main-21.1.8-8.hum1, llvm-main-22.1.8-4.1.hum1.