Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3038 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.8Red Hat

High [CVE-2026-58221] authenticated LDAP access to internal LDB special DNs permits domain takeover

authenticated LDAP access to internal LDB special DNs permits domain takeover. Red Hat rates this important (CVSS 8.8). Weakness: CWE-284.

CVE-2026-58221
Unclassified
Jul 28, 2026
High7.5Red Hat

High [CVE-2026-59248] Denial of Service due to unbounded HPACK/QPACK prefixed-integer decoding

Denial of Service due to unbounded HPACK/QPACK prefixed-integer decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:47231 with package rabbitmq-server4-3-main-4.3.4-0.2.hum1, rabbitmq-server4-2-main-4.2.9-0.2.hum1.

CVE-2026-59248
Unclassified
Jul 28, 2026
High8.2Red Hat

High [CVE-2026-64649] Server-Side Request Forgery via malicious host redirection in Server Actions

Server-Side Request Forgery via malicious host redirection in Server Actions. Red Hat rates this important (CVSS 8.2). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:54435 with package next.

CVE-2026-64649
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-64648] Information disclosure via server-side fetch cache

Information disclosure via server-side fetch cache. Red Hat rates this important (CVSS 7.5). Weakness: CWE-524. Red Hat lists fixing advisory RHSA-2026:54435 with package next.

CVE-2026-64648
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-12383] ExternalEventStreamViewSet trusts Subject header without validation and leaks expected DN

ExternalEventStreamViewSet trusts Subject header without validation and leaks expected DN. Red Hat rates this important (CVSS 7.5). Weakness: CWE-345. Red Hat lists fixing advisory RHSA-2026:50340 with package automation-eda-controller-0:1.2.11-1.el9ap, ansible-automation-platform-27/eda-controller-rhel9:1785374869, automation-eda-controller-0:1.1.21-1.el9ap, automation-eda-controller-0:1.1.21-1.el8ap. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-12383
Unclassified
Jul 27, 2026
High7.1Vendor: MediumRed Hat

High [CVE-2026-66759] out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted ICNS images

A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues reading past the bounds of the buffer. This out-of-bounds read vulnerability results in information disclosure of heap contents, where memory contents are leaked as alpha channel pixel values, or a crash leading to a denial of service if unmapped memory is accessed. To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted ICNS image with GIMP, reducing the likelihood of exploitation. Due to this reason, this flaw has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-66759
Unclassified
Jul 27, 2026
High7.8Red Hat

High [CVE-2026-66758] integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted FITS images

A flaw was found in the file-fits plugin in GIMP. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service. To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted FITS image with GIMP, reducing the likelihood of exploitation. However, successful exploitation may potentially lead to arbitrary code execution or a denial of service. Default Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability. Due to this reason, this flaw has been rated with an important severity. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-66758
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-64646] Denial of Service via excessive memory consumption in Server Actions

Denial of Service via excessive memory consumption in Server Actions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:54435 with package next.

CVE-2026-64646
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-64644] Denial of Service via malicious image optimization

Denial of Service via malicious image optimization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:54435 with package next.

CVE-2026-64644
Unclassified
Jul 27, 2026
High8.2Red Hat

High [CVE-2026-64642] Authentication bypass leading to unauthorized access

Authentication bypass leading to unauthorized access. Red Hat rates this important (CVSS 8.2). Weakness: CWE-807.

CVE-2026-64642
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-64641] Denial of Service via crafted requests to App Router with Server Actions

Denial of Service via crafted requests to App Router with Server Actions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:54435 with package next.

CVE-2026-64641
Unclassified
Jul 27, 2026
High8.2Red Hat

High [CVE-2026-64645] Server-Side Request Forgery vulnerability

Server-Side Request Forgery vulnerability. Red Hat rates this important (CVSS 8.2). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:54435 with package next.

CVE-2026-64645
Unclassified
Jul 27, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-45623] Information disclosure and denial of service via crafted CSS input

Information disclosure and denial of service via crafted CSS input. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:54427 with package rhacm2/console-rhel9:1786547771.

CVE-2026-45623
Unclassified
Jul 27, 2026
High7.2Vendor: MediumRed Hat

High [CVE-2026-54272] Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification

Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification. Red Hat rates this moderate (CVSS 7.2). Weakness: CWE-918.

CVE-2026-54272
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-54890] Denial of Service via integer underflow in ETF decoding

Denial of Service via integer underflow in ETF decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. Red Hat lists fixing advisory RHSA-2026:47009 with package erlang27-main-27.3.4.15-0.1.hum1.

CVE-2026-54890
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-59251] Erlang/OTP public_key: Denial of Service via crafted TLS certificate chains

Erlang/OTP public_key: Denial of Service via crafted TLS certificate chains. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:47009 with package erlang27-main-27.3.4.15-0.1.hum1.

CVE-2026-59251
Unclassified
Jul 27, 2026
High7.4Red Hat

High [CVE-2026-55953] Erlang/OTP ssl client: Authentication bypass via unoffered anonymous cipher suite acceptance

Erlang/OTP ssl client: Authentication bypass via unoffered anonymous cipher suite acceptance. Red Hat rates this important (CVSS 7.4). Weakness: CWE-940. Red Hat lists fixing advisory RHSA-2026:47009 with package erlang27-main-27.3.4.15-0.1.hum1.

CVE-2026-55953
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-55737] Denial of Service via crafted external term format binary

Denial of Service via crafted external term format binary. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.

CVE-2026-55737
Unclassified
Jul 27, 2026
High7.5Red Hat

High [CVE-2026-42792] Erlang OTP epmd: Remote Denial of Service via connection exhaustion

Erlang OTP epmd: Remote Denial of Service via connection exhaustion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-253. Red Hat lists fixing advisory RHSA-2026:47009 with package erlang27-main-27.3.4.15-0.1.hum1.

CVE-2026-42792
Unclassified
Jul 27, 2026
High8.4Red Hat

High [CVE-2026-55971] Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow

Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow. Red Hat rates this important (CVSS 8.4). Weakness: CWE-122. Red Hat lists fixing advisory RHSA-2026:49716 with package thrift-0:0.24.0-1.el9ai, thrift-0:0.24.0-2.el9ai. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-55971
Unclassified
Jul 27, 2026

← All vendors