Red Hat Linux Security Advisories & CVEs
4597 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-49837] Malformed BGP OPEN message can disrupt BGP sessions
Malformed BGP OPEN message can disrupt BGP sessions. Red Hat rates this important (CVSS 7.4). Weakness: CWE-125. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-45769] Denial of Service via unbounded IKEv2 parser state
Denial of Service via unbounded IKEv2 parser state. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-45768] Denial of Service via unbounded LDAP responses
Denial of Service via unbounded LDAP responses. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-45766] Denial of Service via unbounded NFS parser state structures
Denial of Service via unbounded NFS parser state structures. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-45765] Denial of Service via unbounded DNP3 reassembly
Denial of Service via unbounded DNP3 reassembly. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284.
High [CVE-2026-45764] Suricata http2: protocol-change type confusion can lead to denial of service
Suricata http2: protocol-change type confusion can lead to denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-843.
High [CVE-2026-89011] Information disclosure via prototype pollution in getRemoteInfo function.
Information disclosure via prototype pollution in getRemoteInfo function. Red Hat rates this important (CVSS 7.1). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:72722 with package ansible-automation-platform/automation-portal:1790254963, ansible-automation-platform/automation-portal:1790256405. Affected products named by the advisory: Red Hat Developer Hub; Self-service automation portal 2.
High [CVE-2026-88033] Data disclosure and denial of service via query-operator injection in GridFS file IDs
Data disclosure and denial of service via query-operator injection in GridFS file IDs. Red Hat rates this important (CVSS 8.3). Weakness: CWE-94. Affected products named by the advisory: Exploit Intelligence; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; and 1 more. Affected products named by the advisory: Red Hat Fuse 7.
High [CVE-2026-88031] Data deletion via query-operator injection in GridFS file IDs
Data deletion via query-operator injection in GridFS file IDs. Red Hat rates this important (CVSS 8.1). Weakness: CWE-1287. Red Hat lists fixing advisory RHSA-2026:72849 with package multicluster-engine/maestro-rhel9:1790134239, multicluster-engine/hive-rhel9:1790286311. Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; Compliance Operator; Confidential Compute Attestation; Cryostat 4; and 38 more. Affected products named by the advisory: ExternalDNS Operator; File Integrity Operator; Lightspeed Core; Logging Subsystem for Red Hat OpenShift; and 34 more.
High [CVE-2026-88030] Data disclosure and denial of service via query-operator injection
Data disclosure and denial of service via query-operator injection. Red Hat rates this important (CVSS 8.3). Weakness: CWE-917. Red Hat lists fixing advisory RHSA-2026:73519 with package ruby:2.5-8100020260923114349.489197e6. Affected product named by the advisory: Red Hat Enterprise Linux 8.
High [CVE-2026-88029] Data disclosure and denial of service via query-operator injection
Data disclosure and denial of service via query-operator injection. Red Hat rates this important (CVSS 8.3). Weakness: CWE-943. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; and 1 more. Affected products named by the advisory: Red Hat Satellite 6.
High [CVE-2026-88024] MongoDB Rust Driver (GridFS): Data disclosure and deletion via query-operator injection in file IDs.
MongoDB Rust Driver (GridFS): Data disclosure and deletion via query-operator injection in file IDs. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected product named by the advisory: Logging Subsystem for Red Hat OpenShift.
High [CVE-2026-89046] Information disclosure or denial of service via out-of-bounds read
Information disclosure or denial of service via out-of-bounds read. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 11 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 7 more.
High [CVE-2026-88053] Heap out-of-bounds write leads to heap corruption via crafted data file
Heap out-of-bounds write leads to heap corruption via crafted data file. Red Hat rates this important (CVSS 8.4). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.
High [CVE-2026-88052] Heap out-of-bounds write can lead to arbitrary code execution
Heap out-of-bounds write can lead to arbitrary code execution. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.
High [CVE-2026-88051] Heap out-of-bounds write via crafted.traineddata model
Heap out-of-bounds write via crafted.traineddata model. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.
High [CVE-2026-88049] Heap out-of-bounds write allows arbitrary code execution or denial of service
Heap out-of-bounds write allows arbitrary code execution or denial of service. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.
High [CVE-2026-88048] Heap out-of-bounds write/read leading to information disclosure via crafted data
Heap out-of-bounds write/read leading to information disclosure via crafted data. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.
High [CVE-2026-88047] Stack buffer overflow via crafted.traineddata file
Stack buffer overflow via crafted.traineddata file. Red Hat rates this important (CVSS 8.4). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.
High [CVE-2026-88045] Memory exhaustion leading to Denial of Service
Memory exhaustion leading to Denial of Service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.