Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3038 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Red Hat

High [CVE-2026-67859] Denial of Service via Discovery/LDS handling

Denial of Service via Discovery/LDS handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-67859
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-67862] Denial of Service via buffer-overflow

Denial of Service via buffer-overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-67862
Unclassified
Aug 4, 2026
High8.1Red Hat

High [CVE-2026-8400] Arbitrary class loading and instantiation via malicious IIOP server

Arbitrary class loading and instantiation via malicious IIOP server. Red Hat rates this important (CVSS 8.1). Weakness: CWE-470. Red Hat lists fixing advisory RHSA-2026:52949 with package java-1.8.0-ibm-1:1.8.0.8.70-1.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.

CVE-2026-8400
Unclassified
Aug 4, 2026
High7.8Red Hat

High [CVE-2026-64564] don't free the ASCONF's own transport in DEL-IP processing

don't free the ASCONF's own transport in DEL-IP processing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825.

CVE-2026-64564
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-67861] Denial of Service via UA_Client_getRemoteDataTypes component

Denial of Service via UA_Client_getRemoteDataTypes component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-67861
Unclassified
Aug 4, 2026
High8.2Red Hat

High [CVE-2026-67860] Heap-based buffer overflow in HistoryRead path

Heap-based buffer overflow in HistoryRead path. Red Hat rates this important (CVSS 8.2). Weakness: CWE-120.

CVE-2026-67860
Unclassified
Aug 4, 2026
High7.5Red Hat Updated

High [CVE-2026-69244] Denial of Service via malformed HTTP responses

Denial of Service via malformed HTTP responses. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:55853 with package ansible-automation-platform/ee-minimal-rhel8:1786971288, ansible-automation-platform/ee-minimal-rhel9:1786942232, discovery/discovery-server-rhel9:1786638573. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 9 more. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; Red Hat Ansible Automation Platform Ansible Core 2; Red Hat Discovery 2; and 5 more.

CVE-2026-69244
Unclassified
Aug 3, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-69243] HTTP Request Smuggling via WebSocket Upgrade

HTTP Request Smuggling via WebSocket Upgrade. Red Hat rates this moderate (CVSS 7). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:54760 with package discovery/discovery-server-rhel9:1786638573. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 9 more. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; Red Hat Ansible Automation Platform Ansible Core 2; Red Hat Discovery 2; and 5 more.

CVE-2026-69243
Unclassified
Aug 3, 2026
High8.6Red Hat Updated

High [CVE-2026-69192] Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass

Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass. Red Hat rates this important (CVSS 8.6). Weakness: CWE-1389. Red Hat lists fixing advisory RHSA-2026:56338 with package grafana13-1-main-13.1.1-0.5.2.hum1, ansible-automation-platform/automation-portal:1787047114, grafana13-1-main-13.1.2-0.1.hum1, grafana12-4-main-12.4.7-0.1.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-69192
Unclassified
Aug 3, 2026
High7.5Red Hat

High [CVE-2026-69185] Denial of Service via memory exhaustion from crafted packets

Denial of Service via memory exhaustion from crafted packets. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.

CVE-2026-69185
Unclassified
Aug 3, 2026
High7.5Red Hat Updated

High [CVE-2026-69153] Information disclosure via crafted sourceMappingURL

Information disclosure via crafted sourceMappingURL. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:56338 with package prometheus3-13-main-3.13.2-0.2.hum1, grafana12-4-main-12.4.6-0.4.hum1, grafana13-1-main-13.1.1-0.5.2.hum1, ansible-automation-platform/automation-portal:1787047114. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-69153
Unclassified
Aug 3, 2026
High7.5Red Hat Updated

High [CVE-2026-14257 +1] DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:56338 with package grafana12-4-main-12.4.6-0.4.hum1, grafana13-1-main-13.1.1-0.5.2.hum1, ansible-automation-platform/automation-portal:1787047114, nodejs22-main-22.23.2-2.3.2.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-14257CVE-2026-69152
Unclassified
Aug 3, 2026
High8.1Red Hat

High [CVE-2026-69151] @angular/compiler: @angular/core: Angular: Cross-Site Scripting via internationalization event handlers

@angular/compiler: @angular/core: Angular: Cross-Site Scripting via internationalization event handlers. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79.

CVE-2026-69151
Unclassified
Aug 3, 2026
High8.2Red Hat

High [CVE-2026-68945] @angular/common: Angular: Cross-Request Response Reuse and State Poisoning in HttpTransferCache

@angular/common: Angular: Cross-Request Response Reuse and State Poisoning in HttpTransferCache. Red Hat rates this important (CVSS 8.2). Weakness: CWE-694.

CVE-2026-68945
Unclassified
Aug 3, 2026
High7.5Red Hat

High [CVE-2026-12852] Bouncy Castle for Java: Denial of Service via MLS wire decoder

Bouncy Castle for Java: Denial of Service via MLS wire decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284.

CVE-2026-12852
Unclassified
Aug 3, 2026
High7.4Red Hat

High [CVE-2026-58062] Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response

Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected products named by the advisory: Red Hat AMQ Clients; Red Hat Ceph Storage 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7; Red Hat package: resteasy.

CVE-2026-58062
Red Hat Enterprise Linux
Aug 3, 2026
High7.4Red Hat Updated

High [CVE-2026-59650] Bouncy Castle for Java: Cryptographic key compromise due to unvalidated Diffie-Hellman peer value

Bouncy Castle for Java: Cryptographic key compromise due to unvalidated Diffie-Hellman peer value. Red Hat rates this important (CVSS 7.4). Weakness: CWE-325.

CVE-2026-59650
Unclassified
Aug 3, 2026
High7.4Red Hat

High [CVE-2026-8763] Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI

Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected products named by the advisory: Red Hat AMQ Clients; Red Hat Ceph Storage 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7; Red Hat package: resteasy.

CVE-2026-8763
Red Hat Enterprise Linux
Aug 3, 2026
High7.5Red Hat

High [CVE-2026-68580] Remote code execution or denial of service via audio input integer overflow

Remote code execution or denial of service via audio input integer overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:54487 with package freerdp-2:2.11.7-11.el8_10, freerdp-2:2.11.7-7.el9_8.5, freerdp-2:3.10.3-12.el10_2.8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-68580
Unclassified
Aug 2, 2026
High8.4Red Hat

High [CVE-2026-67323] Arbitrary code execution via command injection due to unguarded Git options

Arbitrary code execution via command injection due to unguarded Git options. Red Hat rates this important (CVSS 8.4). Weakness: CWE-88. Red Hat lists fixing advisory RHSA-2026:44416 with package swift-lang-main-6.3.3-0.1.1.hum1, llvm21-main-21.1.8-8.hum1, llvm-main-22.1.8-4.1.hum1.

CVE-2026-67323
Unclassified
Aug 1, 2026

← All vendors