Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

465 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Low3.4Red Hat

Low [CVE-2026-92060] Use-after-free in the Internationalization component

Use-after-free in the Internationalization component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-825.

CVE-2026-92060
Unclassified
Sep 15, 2026
Low3.7Red Hat

Low [CVE-2026-91926] memory leak in ntlm_decode_target_info via duplicated AV_PAIR entries in NTLM CHALLENGE

memory leak in ntlm_decode_target_info via duplicated AV_PAIR entries in NTLM CHALLENGE. Red Hat rates this low (CVSS 3.7). Weakness: CWE-401. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: gssntlmssp.

CVE-2026-91926
Red Hat Enterprise Linux
Sep 15, 2026
Low3.3Red Hat

Low [CVE-2026-90713] vLLM and tiktoken: Local Denial of Service vulnerability

vLLM and tiktoken: Local Denial of Service vulnerability. Red Hat rates this low (CVSS 3.3). Weakness: CWE-770. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 4 more. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-90713
Unclassified
Sep 14, 2026
Low2.9Red Hat

Low [CVE-2026-89162] Information disclosure via pcre2_serialize_encode

Information disclosure via pcre2_serialize_encode. Red Hat rates this low (CVSS 2.9). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:67534 with package pcre2-main-10.48-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 2 more. Affected products named by the advisory: Red Hat package: mariadb10.11; Red Hat package: mariadb11.8.

CVE-2026-89162
Red Hat Enterprise Linux
Sep 11, 2026
Low3.7Red Hat

Low [CVE-2026-89160] Denial of Service via out-of-bounds read during invalid UTF matching

Denial of Service via out-of-bounds read during invalid UTF matching. Red Hat rates this low (CVSS 3.7). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:67534 with package pcre2-main-10.48-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.

CVE-2026-89160
Unclassified
Sep 11, 2026
Low2.9Red Hat

Low [CVE-2026-89156] Out-of-bounds read via invalid UTF data during JIT fallback

Out-of-bounds read via invalid UTF data during JIT fallback. Red Hat rates this low (CVSS 2.9). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:67534 with package pcre2-main-10.48-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 7 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: bootc; Red Hat package: mariadb10.11; and 3 more.

CVE-2026-89156
Red Hat Enterprise Linux
Sep 11, 2026
Low3.7Red Hat

Low [CVE-2026-88013] Information disclosure via HTTP backend forwarding headers on redirect

Information disclosure via HTTP backend forwarding headers on redirect. Red Hat rates this low (CVSS 3.7). Weakness: CWE-212. Affected products named by the advisory: Cryostat 4; Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-88013
Unclassified
Sep 10, 2026
Low3.0Red Hat

Low [CVE-2026-27447 +1] Remaining case-insensitive username matching in scheduler side paths (CVE-2026-27447 follow-up)

Remaining case-insensitive username matching in scheduler side paths (CVE-2026-27447 follow-up). Red Hat rates this low (CVSS 3). Weakness: CWE-178. Red Hat lists fixing advisory RHSA-2026:67568 with package cups-main-2.4.19-4.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.

CVE-2026-27447CVE-2026-87876
Unclassified
Sep 9, 2026
Low3.3Red Hat

Low [CVE-2026-86564] Missing length validation before reading command_data in virtio-net control queue handler

Missing length validation before reading command_data in virtio-net control queue handler. Red Hat rates this low (CVSS 3.3). Weakness: CWE-125. Affected products named by the advisory: Fast Datapath for RHEL 10; Fast Datapath for RHEL 8; Fast Datapath for RHEL 9; Red Hat Enterprise Linux 10; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: dpdk.

CVE-2026-86564
Red Hat Enterprise Linux
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87055] Base image referenced by mutable tag rather than sha256 digest

Base image referenced by mutable tag rather than sha256 digest. Red Hat rates this low (CVSS 2.6). Weakness: CWE-829.

CVE-2026-87055
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87056] No automated dependency-update configuration for submodules or Containerfile

No automated dependency-update configuration for submodules or Containerfile. Red Hat rates this low (CVSS 2.6). Weakness: CWE-1104.

CVE-2026-87056
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87051] resolveAndValidatePath performs lexical containment only — symlinks can escape the build context

resolveAndValidatePath performs lexical containment only — symlinks can escape the build context. Red Hat rates this low (CVSS 2.6). Weakness: CWE-59.

CVE-2026-87051
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87052] No automated dependency-update or vulnerability-scanning configuration

No automated dependency-update or vulnerability-scanning configuration. Red Hat rates this low (CVSS 2.6). Weakness: CWE-1104.

CVE-2026-87052
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87058] Hermetic build disabled by default; bundle build performs live network fetches

Hermetic build disabled by default; bundle build performs live network fetches. Red Hat rates this low (CVSS 2.6). Weakness: CWE-829.

CVE-2026-87058
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87059] Unpinned pip dependency installation in bundle builder stage

Unpinned pip dependency installation in bundle builder stage. Red Hat rates this low (CVSS 2.6). Weakness: CWE-494.

CVE-2026-87059
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87060] Renovate automerge enabled with base-image update exclusions

Renovate automerge enabled with base-image update exclusions. Red Hat rates this low (CVSS 2.6). Weakness: CWE-1357.

CVE-2026-87060
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87061] bundle-hack/update_bundle.sh lacks fail-fast shell options

bundle-hack/update_bundle.sh lacks fail-fast shell options. Red Hat rates this low (CVSS 2.6). Weakness: CWE-252.

CVE-2026-87061
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87063] tkn CLI installed from network without checksum or signature verification

tkn CLI installed from network without checksum or signature verification. Red Hat rates this low (CVSS 2.6). Weakness: CWE-494.

CVE-2026-87063
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87064] GitHub workflows lack explicit least-privilege permissions blocks

GitHub workflows lack explicit least-privilege permissions blocks. Red Hat rates this low (CVSS 2.6). Weakness: CWE-269.

CVE-2026-87064
Unclassified
Sep 8, 2026
Low2.6Red Hat

Low [CVE-2026-87065] Tekton task steps run as root without defense-in-depth securityContext hardening

Tekton task steps run as root without defense-in-depth securityContext hardening. Red Hat rates this low (CVSS 2.6). Weakness: CWE-250.

CVE-2026-87065
Unclassified
Sep 8, 2026

← All vendors