Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3199 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

MediumRed Hat

Medium [CVE-2026-18785] Use-after-free vulnerability via local manipulation

Use-after-free vulnerability via local manipulation. Red Hat rates this moderate. Weakness: CWE-825.

CVE-2026-18785
Unclassified
Aug 4, 2026
Medium5.4Red Hat

Medium [CVE-2026-15920] Cross-site scripting via unvalidated URLField values in the admin

Cross-site scripting via unvalidated URLField values in the admin. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79.

CVE-2026-15920
Unclassified
Aug 4, 2026
Medium5.3Red Hat

Medium [CVE-2026-15830] Denial of Service via parsing deeply nested geometry collections

Denial of Service via parsing deeply nested geometry collections. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-606.

CVE-2026-15830
Unclassified
Aug 4, 2026
Medium5.3Red Hat

Medium [CVE-2026-15337] Denial-of-service vulnerability due to excessive memory consumption

Denial-of-service vulnerability due to excessive memory consumption. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1050.

CVE-2026-15337
Unclassified
Aug 4, 2026
Medium5.3Red Hat

Medium [CVE-2026-18401] Denial of Service due to number length bypass in asynchronous JSON parser

Denial of Service due to number length bypass in asynchronous JSON parser. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770.

CVE-2026-18401
Unclassified
Aug 4, 2026
Medium6.5Red Hat

Medium [CVE-2026-70368] Stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message

Stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-70368
Unclassified
Aug 4, 2026
Medium5.4Red Hat

Medium [CVE-2026-70367] SSRF bypass in stunnel SOCKS proxy via IPv4-mapped IPv6 loopback and unspecified addresses allows access to loopback-only services

SSRF bypass in stunnel SOCKS proxy via IPv4-mapped IPv6 loopback and unspecified addresses allows access to loopback-only services. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-918. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-70367
Unclassified
Aug 4, 2026
Medium4.4Red Hat

Medium [CVE-2026-17614] Path Traversal on WildFly Domain Controller

Path Traversal on WildFly Domain Controller. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-22.

CVE-2026-17614
Unclassified
Aug 4, 2026
Medium4.8Red Hat

Medium [CVE-2026-58044] Request smuggling via HTTP client header truncation

Request smuggling via HTTP client header truncation. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:52990 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1, nodejs26-main-26.7.0-1.5.1.hum1.

CVE-2026-58044
Unclassified
Aug 4, 2026
Medium5.9Red Hat

Medium [CVE-2026-58042] Denial of Service via DNS responses with excessive A records

Denial of Service via DNS responses with excessive A records. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:52990 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1, nodejs26-main-26.7.0-1.5.1.hum1.

CVE-2026-58042
Unclassified
Aug 4, 2026
Medium6.2Red Hat

Medium [CVE-2026-58045] Denial of Service vulnerability

Denial of Service vulnerability. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-617. Red Hat lists fixing advisory RHSA-2026:52990 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1, nodejs26-main-26.7.0-1.5.1.hum1.

CVE-2026-58045
Unclassified
Aug 4, 2026
Medium5.3Red Hat

Medium [CVE-2026-58041] Node.js node:sqlite: Unintended data modification due to stale statement iterator

Node.js node:sqlite: Unintended data modification due to stale statement iterator. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-367. Red Hat lists fixing advisory RHSA-2026:52990 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1, nodejs26-main-26.7.0-1.5.1.hum1.

CVE-2026-58041
Unclassified
Aug 4, 2026
Medium5.5Red Hat

Medium [CVE-2026-51400] Arbitrary code execution via vms_fixfilename function

Arbitrary code execution via vms_fixfilename() function. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-94.

CVE-2026-51400
Unclassified
Aug 4, 2026
Medium5.3Red Hat

Medium [CVE-2026-69198] Server-Side Request Forgery (SSRF) and trust-boundary bypass

Server-Side Request Forgery (SSRF) and trust-boundary bypass. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1389. Red Hat lists fixing advisory RHSA-2026:50826 with package grafana13-1-main-13.1.1-0.5.2.hum1, grafana12-4-main-12.4.6-0.3.hum1.

CVE-2026-69198
Unclassified
Aug 3, 2026
Medium4.4Red Hat

Medium [CVE-2026-18477] TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape

TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-367. Red Hat lists fixing advisory RHSA-2026:49361 with package tar-main-1.35-9.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.

CVE-2026-18477
Red Hat Enterprise Linux
Aug 3, 2026
Medium5.4Red Hat

Medium [CVE-2026-18651] SASL PLAIN bind installs connection credentials before account-lock check, allowing continued access as a locked account

SASL PLAIN bind installs connection credentials before account-lock check, allowing continued access as a locked account. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-287.

CVE-2026-18651
Unclassified
Aug 3, 2026
Medium4.4Red Hat

Medium [CVE-2026-18508] --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite

- -one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:50807 with package tar-main-1.35-9.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.

CVE-2026-18508
Red Hat Enterprise Linux
Aug 3, 2026
Medium5.5Red Hat

Medium [CVE-2026-68742] NSS responder out-of-bounds read via unchecked addrlen in GETHOSTBYADDR

NSS responder out-of-bounds read via unchecked addrlen in GETHOSTBYADDR. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.

CVE-2026-68742
Unclassified
Aug 3, 2026
Medium5.5Red Hat

Medium [CVE-2026-68743] PAM responder out-of-bounds read via unchecked auth_token_length in protocol v1

PAM responder out-of-bounds read via unchecked auth_token_length in protocol v1. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.

CVE-2026-68743
Unclassified
Aug 3, 2026
Medium5.3Red Hat

Medium [CVE-2026-12259] Installation of attacker-controlled packages due to improper checksum validation

Installation of attacker-controlled packages due to improper checksum validation. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-354. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-12259
Unclassified
Aug 3, 2026

← All vendors