Red Hat Linux Security Advisories & CVEs
5515 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-95897] Deserialization vulnerability in Loader component
Deserialization vulnerability in Loader component. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-502. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-84643] missing use_role authorization on the project signature validation credential foreign key allows a project administrator to bind and use another organization's credential cross-tenant
missing use_role authorization on the project signature validation credential foreign key allows a project administrator to bind and use another organization's credential cross-tenant. Red Hat rates this moderate (CVSS 5). Weakness: CWE-639. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Medium [CVE-2026-84680] organization galaxy credential attachment checks only read permission on the credential, allowing an organization admin with read-only visibility to bind and server-side-use another tenant's Automa…
organization galaxy credential attachment checks only read permission on the credential, allowing an organization admin with read-only visibility to bind and server-side-use another tenant's Automation Hub API token. Red Hat rates this moderate (CVSS 4.1). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Medium [CVE-2026-84703] execution environment credential foreign key is not use-permission checked, allowing an organization execution-environment admin to bind and disclose another organization's container registry crede…
execution environment credential foreign key is not use-permission checked, allowing an organization execution-environment admin to bind and disclose another organization's container registry credential (cross-tenant credential disclosure). Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-639. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Medium [CVE-2026-84707] host_filter SmartFilter ORM traversal exposes JobEvent/AdHocCommandEvent event_data and stdout to users without permission on the job, enabling blind character-by-character extraction of job output…
host_filter SmartFilter ORM traversal exposes JobEvent/AdHocCommandEvent event_data and stdout to users without permission on the job, enabling blind character-by-character extraction of job output (cross-tenant information disclosure). Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-639. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Medium [CVE-2026-84709] CredentialType injector validation renders attacker-supplied Jinja2 templates synchronously in the web worker, allowing uncontrolled resource consumption (denial of service) and an unhandled-except…
CredentialType injector validation renders attacker-supplied Jinja2 templates synchronously in the web worker, allowing uncontrolled resource consumption (denial of service) and an unhandled-exception (500) via /api/controller/v2/credential_types/. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-1050. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Medium [CVE-2026-90462] Fail-open in LDAP ppolicy access check allows continued authorization
Fail-open in LDAP ppolicy access check allows continued authorization. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-280. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: sssd.
Medium [CVE-2026-89407] Denial of Service via regular expression backtracking
Denial of Service via regular expression backtracking. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-1333. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; OpenShift Serverless; Red Hat AI Inference Server; and 32 more. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 28 more.
Medium [CVE-2026-63279] Information disclosure and denial of service via out-of-bounds read in PICT image import
Information disclosure and denial of service via out-of-bounds read in PICT image import. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125.
Medium [CVE-2026-63278] Information disclosure via crafted URLs expanding environment variables
Information disclosure via crafted URLs expanding environment variables. Red Hat rates this moderate (CVSS 5). Weakness: CWE-914.
Medium [CVE-2026-63273] Denial of Service via malformed encrypted PDF import
Denial of Service via malformed encrypted PDF import. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-120.
Medium [CVE-2026-63272] Heap buffer overflow in WMF text record import
Heap buffer overflow in WMF text record import. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-787.
Medium [CVE-2026-95503] Potential KDC spoofing bypass when Kerberos password authentication is enabled
Potential KDC spoofing bypass when Kerberos password authentication is enabled. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-347. Affected products named by the advisory: Red Hat Build of Keycloak; Red Hat Single Sign-On 7.
Medium [CVE-2026-95507] out-of-bounds read in NC-SI OEM response handler discloses host memory to guest
out-of-bounds read in NC-SI OEM response handler discloses host memory to guest. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-125.
Medium [CVE-2026-74765] Net::IDN::Punycode: Net::IDN::Punycode: Information disclosure or denial of service via integer overflow
Net::IDN::Punycode: Net::IDN::Punycode: Information disclosure or denial of service via integer overflow. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125.
Medium [CVE-2026-95516] heap-buffer-overflow write in Structured-Append QR text extraction
heap-buffer-overflow write in Structured-Append QR text extraction. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.
Medium [CVE-2026-88340] Memory corruption and denial of service via specially crafted rule files
Memory corruption and denial of service via specially crafted rule files. Red Hat rates this moderate (CVSS 5). Weakness: CWE-763. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: yara.
Medium [CVE-2026-88341] Denial of Service via crafted compiled rule file
Denial of Service via crafted compiled rule file. Red Hat rates this moderate (CVSS 5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: yara.
Medium [CVE-2026-75432] Sensitive information disclosure via scanner component
Sensitive information disclosure via scanner component. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-201.
Medium [CVE-2026-79312] Missing session ID rotation after authentication leads to session fixation
Missing session ID rotation after authentication leads to session fixation. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-384.