Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

10918 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.5Red Hat

Medium [CVE-2026-95512] Denial of Service via repeated subroutine allocations in CID font loader

Denial of Service via repeated subroutine allocations in CID font loader. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:74952 with package freetype-main-2.14.3-2.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat build of OpenJDK 11 ELS; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-95512
Unclassified
Oct 2, 2026
Low3.7Red Hat Updated

Low [CVE-2026-94483] Information disclosure via SSRF in Image Optimization

Information disclosure via SSRF in Image Optimization. Red Hat rates this low (CVSS 3.7). Weakness: CWE-918. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Trusted Artifact Signer; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-94483
Red Hat Enterprise Linux
Oct 2, 2026
Low3.7Red Hat Updated

Low [CVE-2026-94544] Information disclosure via shared cache fills in Draft Mode

Information disclosure via shared cache fills in Draft Mode. Red Hat rates this low (CVSS 3.7). Weakness: CWE-524. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Trusted Artifact Signer; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-94544
Red Hat Enterprise Linux
Oct 2, 2026
Critical9.0Vendor: MediumRed Hat

Critical [CVE-2026-86345] StartTLS plaintext-buffer retention allows on-path attacker to forge an LDAP client's authentication result

StartTLS plaintext-buffer retention allows on-path attacker to forge an LDAP client's authentication result. Red Hat rates this moderate (CVSS 9). Weakness: CWE-923. Affected products named by the advisory: Red Hat Directory Server 11; Red Hat Directory Server 12; Red Hat Directory Server 13; Red Hat Enterprise Linux 10; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-86345
Unclassified
Oct 1, 2026
Critical9.9Red Hat

Critical [CVE-2026-96658] Safemode Bypass leading to RCE

Safemode Bypass leading to RCE. Red Hat rates this critical (CVSS 9.9). Red Hat lists fixing advisory RHSA-2026:74503 with package python-sqlparse-0:0.6.0-1.el9pc, python-gitpython-0:3.1.62-1.el9pc, python-dynaconf-0:3.2.13-1.el9pc, python-lxml-0:5.3.1-2.el9pc. Affected products named by the advisory: Red Hat Satellite 6.16 for RHEL 8; Red Hat Satellite 6.16 for RHEL 9; Red Hat Satellite 6.17 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9; and 1 more. Affected products named by the advisory: Red Hat Satellite 6.19 for RHEL 9.

CVE-2026-96658
Unclassified
Oct 1, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-96659] Excessive Permissions for Viewer Role on Preview

Excessive Permissions for Viewer Role on Preview. Red Hat rates this important (CVSS 9.1). Weakness: CWE-267. Red Hat lists fixing advisory RHSA-2026:74503 with package python-sqlparse-0:0.6.0-1.el9pc, python-gitpython-0:3.1.62-1.el9pc, python-dynaconf-0:3.2.13-1.el9pc, python-lxml-0:5.3.1-2.el9pc. Affected products named by the advisory: Red Hat Satellite 6.16 for RHEL 8; Red Hat Satellite 6.16 for RHEL 9; Red Hat Satellite 6.17 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9; and 1 more. Affected products named by the advisory: Red Hat Satellite 6.19 for RHEL 9.

CVE-2026-96659
Unclassified
Oct 1, 2026
High7.5Red Hat

High [CVE-2026-86344] unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-PDU connection requeue

unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-PDU connection requeue. Red Hat rates this important (CVSS 7.5). Weakness: CWE-400. Affected products named by the advisory: Red Hat Directory Server 11; Red Hat Directory Server 12; Red Hat Directory Server 13; Red Hat Enterprise Linux 10; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-86344
Unclassified
Oct 1, 2026
High8.8Red Hat

High [CVE-2026-103484] Arbitrary code execution via out-of-bounds write during IVFFlat index build

Arbitrary code execution via out-of-bounds write during IVFFlat index build. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-103484
Unclassified
Oct 1, 2026
High7.4Red Hat

High [CVE-2026-15911] Information disclosure via improper TLS certificate validation in HashiCorp Vault integration

Information disclosure via improper TLS certificate validation in HashiCorp Vault integration. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected product named by the advisory: Red Hat Satellite 6.

CVE-2026-15911
Unclassified
Oct 1, 2026
High7.5Red Hat

High [CVE-2023-54404] Denial of service via unbounded array validation

Denial of service via unbounded array validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Ansible Automation Orchestrator 2026; Cost Management On Premise; Migration Toolkit for Applications 8; Red Hat Ansible Automation Platform 2; and 21 more. Affected products named by the advisory: Red Hat Build of Keycloak; Red Hat Build of Podman Desktop; Red Hat Data Grid 8; Red Hat Developer Hub; and 17 more.

CVE-2023-54404
Red Hat Enterprise Linux
Oct 1, 2026
High7.7Red Hat

High [CVE-2026-12544] SSTI and insecure deserialization in foreman-rake configuration

SSTI and insecure deserialization in foreman-rake configuration. Red Hat rates this important (CVSS 7.7). Weakness: CWE-502. Red Hat lists fixing advisory RHSA-2026:74503 with package foreman-0:3.14.0.22-1.el9sat, foreman-0:3.16.0.25-1.el9sat, foreman-0:3.12.0.23-1.el8sat, foreman-0:3.18.0.14-1.el9sat. Affected products named by the advisory: Red Hat Satellite 6.16 for RHEL 8; Red Hat Satellite 6.16 for RHEL 9; Red Hat Satellite 6.17 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9; and 1 more. Affected products named by the advisory: Red Hat Satellite 6.19 for RHEL 9.

CVE-2026-12544
Unclassified
Oct 1, 2026
High8.2Red Hat

High [CVE-2026-12541] command injection in foreman-rake database tasks

command injection in foreman-rake database tasks. Red Hat rates this important (CVSS 8.2). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:74503 with package foreman-0:3.14.0.22-1.el9sat, foreman-0:3.16.0.25-1.el9sat, foreman-0:3.12.0.23-1.el8sat, foreman-0:3.18.0.14-1.el9sat. Affected products named by the advisory: Red Hat Satellite 6.16 for RHEL 8; Red Hat Satellite 6.16 for RHEL 9; Red Hat Satellite 6.17 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9; and 1 more. Affected products named by the advisory: Red Hat Satellite 6.19 for RHEL 9.

CVE-2026-12541
Unclassified
Oct 1, 2026
High8.2Red Hat

High [CVE-2026-12540] command injection in foreman-rake errors:fetch_log via request_id parameter

command injection in foreman-rake errors:fetch_log via request_id parameter. Red Hat rates this important (CVSS 8.2). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:74503 with package foreman-0:3.14.0.22-1.el9sat, foreman-0:3.16.0.25-1.el9sat, foreman-0:3.12.0.23-1.el8sat, foreman-0:3.18.0.14-1.el9sat. Affected products named by the advisory: Red Hat Satellite 6.16 for RHEL 8; Red Hat Satellite 6.16 for RHEL 9; Red Hat Satellite 6.17 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9; and 1 more. Affected products named by the advisory: Red Hat Satellite 6.19 for RHEL 9.

CVE-2026-12540
Unclassified
Oct 1, 2026
High7.5Red Hat

High [CVE-2026-12423] unauthenticated information disclosure via provisioning token validation flaw

unauthenticated information disclosure via provisioning token validation flaw. Red Hat rates this important (CVSS 7.5). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:74503 with package foreman-0:3.14.0.22-1.el9sat, foreman-0:3.16.0.25-1.el9sat, foreman-0:3.12.0.23-1.el8sat, foreman-0:3.18.0.14-1.el9sat. Affected products named by the advisory: Red Hat Satellite 6.16 for RHEL 8; Red Hat Satellite 6.16 for RHEL 9; Red Hat Satellite 6.17 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9; and 1 more. Affected products named by the advisory: Red Hat Satellite 6.19 for RHEL 9.

CVE-2026-12423
Unclassified
Oct 1, 2026
High8.8Red Hat

High [CVE-2026-12405] command injection in job invocations via effective_user parameter

command injection in job invocations via effective_user parameter. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:74503 with package rubygem-foreman_remote_execution-0:16.2.3-2.el9sat, rubygem-foreman_remote_execution-0:15.0.2-2.el9sat, rubygem-foreman_remote_execution-0:13.2.8-2.el9sat, rubygem-foreman_remote_execution-0:16.5.3-2.el9sat. Affected products named by the advisory: Red Hat Satellite 6.16 for RHEL 8; Red Hat Satellite 6.16 for RHEL 9; Red Hat Satellite 6.17 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9; and 1 more. Affected products named by the advisory: Red Hat Satellite 6.19 for RHEL 9.

CVE-2026-12405
Unclassified
Oct 1, 2026
High7.5Red Hat

High [CVE-2026-63686] Denial of Service via charset conversion failure in mod_xml2enc

Denial of Service via charset conversion failure in mod_xml2enc. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-63686
Web Servers & Proxies
Oct 1, 2026
High8.1Red Hat

High [CVE-2026-73636] Authentication bypass via credential replay in mod_auth_digest

Authentication bypass via credential replay in mod_auth_digest. Red Hat rates this important (CVSS 8.1). Weakness: CWE-294. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-73636
Web Servers & Proxies
Oct 1, 2026
High7.5Red Hat

High [CVE-2026-63718] HTTP response smuggling via crafted Transfer-Encoding response in mod_proxy_uwsgi

HTTP response smuggling via crafted Transfer-Encoding response in mod_proxy_uwsgi. Red Hat rates this important (CVSS 7.5). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-63718
Web Servers & Proxies
Oct 1, 2026
High8.1Red Hat

High [CVE-2026-63292] Arbitrary code execution via oversized Host header in mod_vhost_alias

Arbitrary code execution via oversized Host header in mod_vhost_alias. Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.

CVE-2026-63292
Web Servers & Proxies
Oct 1, 2026
High7.5Red Hat

High [CVE-2026-59685] Denial of Service via out-of-bounds write during Windows path expansion

Denial of Service via out-of-bounds write during Windows path expansion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.

CVE-2026-59685
Unclassified
Oct 1, 2026

← All vendors