Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3038 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.0Vendor: MediumRed Hat

High [CVE-2026-67326] Remote Code Execution via Newline Injection in config_writer

Remote Code Execution via Newline Injection in config_writer(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-93. Red Hat lists fixing advisory RHSA-2026:44416 with package swift-lang-main-6.3.3-0.1.1.hum1, llvm21-main-21.1.8-8.hum1, llvm-main-22.1.8-4.1.hum1.

CVE-2026-67326
Unclassified
Aug 1, 2026
High7.5Red Hat

High [CVE-2026-67312] Denial of Service via uncontrolled recursion in form data processing

Denial of Service via uncontrolled recursion in form data processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-674. Red Hat lists fixing advisory RHSA-2026:47619 with package jaeger-main-2.20.0-0.8.hum1, grafana13-1-main-13.1.1-0.3.hum1, grafana12-4-main-12.4.6-0.2.hum1.

CVE-2026-67312
Unclassified
Aug 1, 2026
High7.5Red Hat

High [CVE-2026-67321] Denial of Service via object serialization bypass

Denial of Service via object serialization bypass. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:47619 with package jaeger-main-2.20.0-0.8.hum1, grafana13-1-main-13.1.1-0.3.hum1, grafana12-4-main-12.4.6-0.2.hum1.

CVE-2026-67321
Unclassified
Aug 1, 2026
High8.8Red Hat

High [CVE-2026-67324] Arbitrary Code Execution via Joined Short Options Bypass

Arbitrary Code Execution via Joined Short Options Bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78.

CVE-2026-67324
Unclassified
Aug 1, 2026
High7.1Red Hat

High [CVE-2026-67298] Denial of Service via integer underflow in RAIL channel handling

Denial of Service via integer underflow in RAIL channel handling. Red Hat rates this important (CVSS 7.1). Weakness: CWE-191.

CVE-2026-67298
Unclassified
Aug 1, 2026
High7.4Red Hat

High [CVE-2026-67320] Information disclosure via Prototype Pollution in Node HTTP adapter

Information disclosure via Prototype Pollution in Node HTTP adapter. Red Hat rates this important (CVSS 7.4). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:47619 with package jaeger-main-2.20.0-0.8.hum1, grafana13-1-main-13.1.1-0.3.hum1, grafana12-4-main-12.4.6-0.2.hum1.

CVE-2026-67320
Unclassified
Aug 1, 2026
High7.5Red Hat

High [CVE-2026-67322] Environment variable exfiltration via attacker-controlled clone URL

Environment variable exfiltration via attacker-controlled clone URL. Red Hat rates this important (CVSS 7.5). Weakness: CWE-214. Red Hat lists fixing advisory RHSA-2026:44416 with package swift-lang-main-6.3.3-0.1.1.hum1, llvm21-main-21.1.8-8.hum1, llvm-main-22.1.8-4.1.hum1.

CVE-2026-67322
Unclassified
Aug 1, 2026
High8.8Red Hat

High [CVE-2026-67325] Command Injection via Git option prefix abbreviation

Command Injection via Git option prefix abbreviation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:44416 with package swift-lang-main-6.3.3-0.1.1.hum1, llvm21-main-21.1.8-8.hum1, llvm-main-22.1.8-4.1.hum1.

CVE-2026-67325
Unclassified
Aug 1, 2026
High7.5Red Hat

High [CVE-2026-67313] Denial of Service via uncontrolled recursion in formDataToJSON

Denial of Service via uncontrolled recursion in formDataToJSON. Red Hat rates this important (CVSS 7.5). Weakness: CWE-674. Red Hat lists fixing advisory RHSA-2026:50826 with package jaeger-main-2.20.0-0.8.hum1, grafana13-1-main-13.1.1-0.5.2.hum1, grafana13-1-main-13.1.1-0.5.hum1.

CVE-2026-67313
Unclassified
Aug 1, 2026
High7.4Red Hat

High [CVE-2026-67314] Outbound Request Tampering via Prototype Pollution in Basic Auth

Outbound Request Tampering via Prototype Pollution in Basic Auth. Red Hat rates this important (CVSS 7.4). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:50826 with package jaeger-main-2.20.0-0.8.hum1, grafana13-1-main-13.1.1-0.5.2.hum1, grafana13-1-main-13.1.1-0.5.hum1.

CVE-2026-67314
Unclassified
Aug 1, 2026
High7.5Red Hat

High [CVE-2026-67305] Remote Code Execution via Heap Buffer Overflow in Clipboard Processing

Remote Code Execution via Heap Buffer Overflow in Clipboard Processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-122.

CVE-2026-67305
Unclassified
Aug 1, 2026
High7.5Red Hat

High [CVE-2026-18536] Predictable random numbers due to unencrypted remote entropy sources

Predictable random numbers due to unencrypted remote entropy sources. Red Hat rates this important (CVSS 7.5). Weakness: CWE-319.

CVE-2026-18536
Unclassified
Aug 1, 2026
High7.1Red Hat

High [CVE-2026-65981] Authorization bypass allows session takeover via MOBILITY-TICKET session resume

Authorization bypass allows session takeover via MOBILITY-TICKET session resume. Red Hat rates this important (CVSS 7.1). Weakness: CWE-303.

CVE-2026-65981
Unclassified
Jul 31, 2026
High7.4Red Hat

High [CVE-2026-68770] Remote Code Execution via Security Control Bypass

Remote Code Execution via Security Control Bypass. Red Hat rates this important (CVSS 7.4). Weakness: CWE-454. Affected products named by the advisory: Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-68770
Unclassified
Jul 31, 2026
High7.5Red Hat

High [CVE-2026-62959] Pre-authentication heap memory disclosure

Pre-authentication heap memory disclosure. Red Hat rates this important (CVSS 7.5). Weakness: CWE-908.

CVE-2026-62959
Unclassified
Jul 31, 2026
High8.8Red Hat

High [CVE-2026-17346] pgAdmin 4: pgAdmin 4: SQL injection via unescaped object names

pgAdmin 4: pgAdmin 4: SQL injection via unescaped object names. Red Hat rates this important (CVSS 8.8). Weakness: CWE-89.

CVE-2026-17346
Unclassified
Jul 31, 2026
High8.2Red Hat

High [CVE-2026-18141] Authentication bypass in Event-Driven Ansible via forged HTTP header

Authentication bypass in Event-Driven Ansible via forged HTTP header. Red Hat rates this important (CVSS 8.2). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:50340 with package automation-eda-controller-0:1.2.11-1.el9ap, ansible-automation-platform-27/gateway-rhel9:1785435970, ansible-automation-platform-26/gateway-rhel9:1785780020. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-18141
Unclassified
Jul 31, 2026
High7.5Red Hat

High [CVE-2026-18446] Host confusion vulnerability via backslash in URI authority

Host confusion vulnerability via backslash in URI authority. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1289. Red Hat lists fixing advisory RHSA-2026:49387 with package grafana13-1-main-13.1.1-0.4.hum1, grafana12-4-main-12.4.6-0.3.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-18446
Unclassified
Jul 31, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-18358] gnome-remote-desktop system-mode RDP server missing connection throttling allows unauthenticated denial of service

gnome-remote-desktop system-mode RDP server missing connection throttling allows unauthenticated denial of service. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:54512 with package gnome-remote-desktop-0:49.3-4.el10_2. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-18358
Unclassified
Jul 31, 2026
High7.5Vendor: MediumRed Hat Updated

High [CVE-2026-11770] pre-auth LDAP filter injection in CleanAllRUV status check

pre-auth LDAP filter injection in CleanAllRUV status check. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-90. Red Hat lists fixing advisory RHSA-2026:55425 with package 389-ds-base-0:3.0.6-20.el10_0, redhat-ds:11-8080020260806114250.f969626e, 389-ds-base-0:3.2.0-9.el10_2, 389-ds:1.4-8080020260806114228.6dbb3803. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-11770
Unclassified
Jul 31, 2026

← All vendors