Red Hat Linux Security Advisories & CVEs
5532 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-92597] Email domain validation bypass via RFC 5322 comment mis-parsing
Email domain validation bypass via RFC 5322 comment mis-parsing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1286. Affected product named by the advisory: Self-service automation portal 2.
Medium [CVE-2026-92595] Information disclosure and SSRF via sandbox bypass in resolveContent
Information disclosure and SSRF via sandbox bypass in resolveContent. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-918. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Self-service automation portal 2; Red Hat package: grafana.
Medium [CVE-2026-64684] Sensitive HTTP headers leaked during cross-origin redirects
Sensitive HTTP headers leaked during cross-origin redirects. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-212. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: goose.
Medium [CVE-2026-81871] go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:74865 with package distribution-main-3.1.1-0.2.hum1, helm4-main-4.3.0-0.2.hum1, caddy-main-2.11.4-0.4.hum1, helm3-main-3.22.0-0.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Assisted Installer for Red Hat OpenShift Container Platform 2; Logging Subsystem for Red Hat OpenShift; Multiarch Tuning Operator; and 22 more. Affected products named by the advisory: Multicluster Engine for Kubernetes; Multicluster Global Hub; OpenShift Developer Tools and Services; OpenShift Lightspeed; and 18 more.
Medium [CVE-2026-81872] Denial of Service via attacker-driven log emission
Denial of Service via attacker-driven log emission. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:68778 with package grafana13-2-main-13.2.1-0.5.hum1, opentelemetry-collector-contrib-main-0.161.0-0.1.hum1, opentofu1-12-main-1.12.6-0.3.hum1, distribution-main-3.1.1-0.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Assisted Installer for Red Hat OpenShift Container Platform 2; Logging Subsystem for Red Hat OpenShift; Multiarch Tuning Operator; and 22 more. Affected products named by the advisory: Multicluster Engine for Kubernetes; Multicluster Global Hub; OpenShift Developer Tools and Services; OpenShift Lightspeed; and 18 more.
Medium [CVE-2026-62949] Denial of Service via zero-sized SSH packets
Denial of Service via zero-sized SSH packets. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9.
Medium [CVE-2026-91103] Multiple vulnerabilities leading to remote code execution, privilege escalation, and denial of service
Multiple vulnerabilities leading to remote code execution, privilege escalation, and denial of service. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.
Medium [CVE-2026-91101] Remote Code Execution and Privilege Escalation Vulnerabilities
Remote Code Execution and Privilege Escalation Vulnerabilities. Red Hat rates this moderate (CVSS 4.6). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.
Medium [CVE-2026-91100] Multiple vulnerabilities allow remote code execution, privilege escalation, and denial of service.
Multiple vulnerabilities allow remote code execution, privilege escalation, and denial of service. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.
Medium [CVE-2026-91099] Multiple vulnerabilities enabling local code execution and privilege escalation
Multiple vulnerabilities enabling local code execution and privilege escalation. Red Hat rates this moderate (CVSS 5.1). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.
Medium [CVE-2026-68536] Server-Side Request Forgery and Local File Inclusion Vulnerability
Server-Side Request Forgery and Local File Inclusion Vulnerability. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-918. Affected product named by the advisory: Red Hat OpenStack Platform 13 (Queens).
Medium [CVE-2026-81176] Denial of Service via malformed input parsing
Denial of Service via malformed input parsing. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1285. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat OpenShift AI (RHOAI); Red Hat Trusted Artifact Signer.
Medium [CVE-2026-69147] GPU memory exhaustion via PyNvVideoCodec decode bypass
GPU memory exhaustion via PyNvVideoCodec decode bypass. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-57173] Denial of Service via unauthenticated audio decompression
Denial of Service via unauthenticated audio decompression. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-59944] Security bypass allows execution of unauthorized binaries via symlinked paths
Security bypass allows execution of unauthorized binaries via symlinked paths. Red Hat rates this moderate (CVSS 5). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:63151 with package composer-main-2.10.3-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-19607] Broker-originated username collision causes account lockout
Broker-originated username collision causes account lockout. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-287. Red Hat lists fixing advisory RHSA-2026:68277 with package rhbk/keycloak-rhel9:26.6-20, keycloak-services, rhbk-openshift-rhel9/rhbk-openshift-rhel9, rhbk/keycloak-rhel9-operator:26.6-20. Affected products named by the advisory: Red Hat build of Keycloak 26.4.16; Red Hat build of Keycloak 26.6.7.
Medium [CVE-2026-92615] Package-global go-git HTTPS transport mutated per-repo -- cross-tenant TLS-config bleed
Package-global go-git HTTPS transport mutated per-repo -- cross-tenant TLS-config bleed. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-413. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Edge Manager 1.
Medium [CVE-2026-92627] Memory corruption via crafted HDF5 file
Memory corruption via crafted HDF5 file. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:61630 with package hdf5-main-2.2.0-0.1.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenStack Platform 13 (Queens).
Medium [CVE-2026-77407] RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Fields
RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Fields. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-256. Red Hat lists fixing advisory RHSA-2026:68290 with package opentelemetry-collector-contrib-main-0.161.0-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Custom Metric Autoscaler operator for Red Hat Openshift; Multicluster Global Hub; and 4 more. Affected products named by the advisory: OpenShift Serverless; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat OpenStack Platform 18.0; Red Hat Quay 3.
Medium [CVE-2026-77119] DNSSEC bypass via NSEC3 insecure-referral proof
DNSSEC bypass via NSEC3 insecure-referral proof. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-290. Red Hat lists fixing advisory RHSA-2026:68279 with package bind-main-9.20.29-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: bind9.16; Red Hat package: bind9.18.