Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

411 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Critical10.0Red Hat

Critical [CVE-2026-17656] Use after free in Ozone

Use after free in Ozone. Red Hat rates this critical (CVSS 10). Weakness: CWE-825.

CVE-2026-17656
Unclassified
Jul 30, 2026
Critical9.6Red Hat

Critical [CVE-2026-17655] Insufficient validation of untrusted input in ANGLE

Insufficient validation of untrusted input in ANGLE. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-1286.

CVE-2026-17655
Unclassified
Jul 30, 2026
Critical9.0Red Hat

Critical [CVE-2026-17653] Use after free in Skia

Use after free in Skia. Red Hat rates this critical (CVSS 9). Weakness: CWE-825.

CVE-2026-17653
Unclassified
Jul 30, 2026
Critical9.6Red Hat

Critical [CVE-2026-17651] Insufficient validation of untrusted input in Dawn

Insufficient validation of untrusted input in Dawn. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-79.

CVE-2026-17651
Unclassified
Jul 30, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-17650] Use after free in Compositing

Use after free in Compositing. Red Hat rates this important (CVSS 9.9). Weakness: CWE-825.

CVE-2026-17650
Unclassified
Jul 30, 2026
Critical9.0Red Hat

Critical [CVE-2026-17652] Use after free in Views

Use after free in Views. Red Hat rates this critical (CVSS 9). Weakness: CWE-825.

CVE-2026-17652
Unclassified
Jul 30, 2026
Critical9.8Red Hat

Critical [CVE-2026-51992] Arbitrary code execution via SQL Injection in create dictionaries function

Arbitrary code execution via SQL Injection in create dictionaries function. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-89.

CVE-2026-51992
Unclassified
Jul 29, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-44210] Privilege escalation and information disclosure via command-line argument injection

Privilege escalation and information disclosure via command-line argument injection. Red Hat rates this important (CVSS 9.9). Weakness: CWE-88.

CVE-2026-44210
Unclassified
Jul 23, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-65601] Privilege Escalation via Kubernetes Gateway API Namespace Confusion

Privilege Escalation via Kubernetes Gateway API Namespace Confusion. Red Hat rates this important (CVSS 9.6). Weakness: CWE-348.

CVE-2026-65601
Unclassified
Jul 22, 2026
Critical10.0Red Hat

Critical [CVE-2026-65600] Authentication bypass via path traversal in ReplacePathRegex middleware

Authentication bypass via path traversal in ReplacePathRegex middleware. Red Hat rates this critical (CVSS 10). Weakness: CWE-22.

CVE-2026-65600
Unclassified
Jul 22, 2026
Critical9.8Red Hat

Critical [CVE-2026-64193] Net::DNS: Net::DNS: Arbitrary code execution via EDNS EXTENDED ERROR handling

Net::DNS: Net::DNS: Arbitrary code execution via EDNS EXTENDED ERROR handling. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-78.

CVE-2026-64193
Unclassified
Jul 20, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-12701] relative_path_validator bypass via directory traversal in FilesystemExport

relative_path_validator bypass via directory traversal in FilesystemExport. Red Hat rates this important (CVSS 9). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:42079 with package python3.12-pulpcore-0:3.49.63-2.el9ap, ansible-automation-platform-26/hub-rhel9:1783979593, python-pulpcore-0:3.49.39-2.el9pc, python3.12-pulpcore-0:3.85.15-5.el9pc. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-12701
Unclassified
Jul 20, 2026
Critical9.4Red Hat

Critical [CVE-2026-16242] Konnectivity proxy-server accepts agent connections without validating client certificates

Konnectivity proxy-server accepts agent connections without validating client certificates. Red Hat rates this critical (CVSS 9.4). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:48284 with package multicluster-engine/hypershift-rhel9-operator:1784856942, multicluster-engine/hypershift-rhel9-operator:1784905769, openshift4/ose-hypershift-rhel9:1785192936, multicluster-engine/hypershift-rhel9-operator:1784905804.

CVE-2026-16242
Unclassified
Jul 20, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-15773] Use after free in Core

Use after free in Core. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825.

CVE-2026-15773
Unclassified
Jul 14, 2026
Critical9.3Vendor: HighRed Hat

Critical [CVE-2026-15775] Insufficient policy enforcement in V8

Insufficient policy enforcement in V8. Red Hat rates this important (CVSS 9.3). Weakness: CWE-346.

CVE-2026-15775
Unclassified
Jul 14, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-15774] Use after free in Skia

Use after free in Skia. Red Hat rates this important (CVSS 9). Weakness: CWE-825.

CVE-2026-15774
Unclassified
Jul 14, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-54058] Memory disclosure or denial of service via crafted McIdas AREA image

Memory disclosure or denial of service via crafted McIdas AREA image. Red Hat rates this important (CVSS 9.1). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:48021 with package quay/quay-rhel8:1785261506, python-pillow-0:5.1.1-23.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.

CVE-2026-54058
Unclassified
Jul 14, 2026
Critical10.0Red Hat

Critical [CVE-2026-57211] Information disclosure via path validation bypass in management plugin

RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extension plugins are enabled, causing outbound DNS and SMB requests to attacker-controlled UNC paths. This issue is fixed in versions 4.1.11 and 4.2.6. A flaw was found in RabbitMQ. This can lead to outbound DNS and Server Message Block (SMB) requests to attacker-controlled network paths, potentially disclosing sensitive information. Red Hat severity: Critical — CVSS 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-76. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0 as not affected. Red Hat fixing advisory: RHSA-2026:35939, RHSA-2026:35940.

CVE-2026-57211
Unclassified
Jul 10, 2026
Critical9.3Vendor: HighRed Hat

Critical [CVE-2026-15143] SSRF and local file read via user-supplied XML Schema (xml-with-schema:)

SSRF and local file read via user-supplied XML Schema (xml-with-schema:). Red Hat rates this important (CVSS 9.3). Weakness: CWE-918.

CVE-2026-15143
Unclassified
Jul 10, 2026
Critical9.3Vendor: MediumRed Hat

Critical [CVE-2026-15131] Insufficient data validation in Navigation

Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) An insufficient data validation flaw was found in the Navigation component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N). Weakness: CWE-653.

CVE-2026-15131
Unclassified
Jul 8, 2026

← All vendors