Red Hat Linux Security Advisories & CVEs
10918 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-56153] Denial of Service via heap-based buffer overflow in mod_charset_lite
Denial of Service via heap-based buffer overflow in mod_charset_lite. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.
High [CVE-2026-46729] Denial of Service via NULL pointer dereference
Denial of Service via NULL pointer dereference. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.
High [CVE-2026-103262] Denial of Service via decompression bomb in CurlAsyncHTTPClient
Denial of Service via decompression bomb in CurlAsyncHTTPClient. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Affected products named by the advisory: Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 10 more. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; and 6 more.
Medium [CVE-2026-104183] Object prototype manipulation via crafted JSON input
Object prototype manipulation via crafted JSON input. Red Hat rates this moderate (CVSS 5.1). Weakness: CWE-915. Affected product named by the advisory: Red Hat Build of Podman Desktop.
Medium [CVE-2026-104182] Denial of Service via inefficient comment scanning
Denial of Service via inefficient comment scanning. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-1322. Affected product named by the advisory: Red Hat Build of Podman Desktop.
Medium [CVE-2026-104056] Information disclosure via unvalidated discovery metadata
Information disclosure via unvalidated discovery metadata. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-346. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 5 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux command line assistant; Red Hat OpenShift Virtualization 4; Red Hat Quay 3; and 1 more.
Medium [CVE-2026-103923] Cross-site scripting via prototype pollution inheritance
Cross-site scripting via prototype pollution inheritance. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-79. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces.
Medium [CVE-2026-103884] CVE-2026-103884
CVE-2026-103884. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22. Affected products named by the advisory: Red Hat Build of Keycloak; Red Hat Single Sign-On 7.
Medium [CVE-2026-56098] improper authorization logic allows resource enumeration
improper authorization logic allows resource enumeration. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-203. Red Hat lists fixing advisory RHSA-2026:74503 with package rubygem-katello-0:4.18.0.24-1.el9sat, rubygem-katello-0:4.20.0.11-1.el9sat, rubygem-katello-0:4.14.0.23-1.el8sat, rubygem-katello-0:4.14.0.23-1.el9sat. Affected products named by the advisory: Red Hat Satellite 6.16 for RHEL 8; Red Hat Satellite 6.16 for RHEL 9; Red Hat Satellite 6.17 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9; and 1 more. Affected products named by the advisory: Red Hat Satellite 6.19 for RHEL 9.
Medium [CVE-2026-56097] SQL injection in Registry Proxy via labels
SQL injection in Registry Proxy via labels. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-89. Red Hat lists fixing advisory RHSA-2026:74503 with package rubygem-katello-0:4.18.0.24-1.el9sat, rubygem-katello-0:4.20.0.11-1.el9sat, rubygem-katello-0:4.14.0.23-1.el8sat, rubygem-katello-0:4.14.0.23-1.el9sat. Affected products named by the advisory: Red Hat Satellite 6.16 for RHEL 8; Red Hat Satellite 6.16 for RHEL 9; Red Hat Satellite 6.17 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9; and 1 more. Affected products named by the advisory: Red Hat Satellite 6.19 for RHEL 9.
Medium [CVE-2026-12542] command injection in foreman-tail
command injection in foreman-tail. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:74503 with package foreman-0:3.14.0.22-1.el9sat, foreman-0:3.16.0.25-1.el9sat, foreman-0:3.12.0.23-1.el8sat, foreman-0:3.18.0.14-1.el9sat. Affected products named by the advisory: Red Hat Satellite 6.16 for RHEL 8; Red Hat Satellite 6.16 for RHEL 9; Red Hat Satellite 6.17 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9; and 1 more. Affected products named by the advisory: Red Hat Satellite 6.19 for RHEL 9.
Medium [CVE-2026-12545] command injection via insecure editor invocation
command injection via insecure editor invocation. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:74503 with package rubygem-hammer_cli-0:3.14.0-2.el9sat, rubygem-hammer_cli-0:3.16.0-2.el9sat, rubygem-hammer_cli-0:3.12.0-2.el9sat, rubygem-hammer_cli-0:3.18.0-2.el9sat. Affected products named by the advisory: Red Hat Satellite 6.16 for RHEL 8; Red Hat Satellite 6.16 for RHEL 9; Red Hat Satellite 6.17 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9; and 1 more. Affected products named by the advisory: Red Hat Satellite 6.19 for RHEL 9.
Medium [CVE-2026-77387] Denial of Service via inefficient regular expression coordinate parsing
Denial of Service via inefficient regular expression coordinate parsing. Red Hat rates this moderate (CVSS 4). Weakness: CWE-1333. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3.
Medium [CVE-2026-93546] Denial of Service via integer overflow in mod_dav_fs
Denial of Service via integer overflow in mod_dav_fs. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: httpd.
Medium [CVE-2026-79768] Information disclosure in mod_userdir via single-dot path equivalence
Information disclosure in mod_userdir via single-dot path equivalence. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-41. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.
Medium [CVE-2026-73637] Authentication state corruption via concurrent Digest authentication requests
Authentication state corruption via concurrent Digest authentication requests. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.
Medium [CVE-2026-63045] unauthorized connection to arbitrary hosts via crafted FTP PASV response
unauthorized connection to arbitrary hosts via crafted FTP PASV response. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.
Medium [CVE-2026-58415] Information disclosure via direct request to the WebDAV state directory
Information disclosure via direct request to the WebDAV state directory. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-552. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.
Medium [CVE-2026-42528] Denial of Service via mod_dav shared lock memory calculation error
Denial of Service via mod_dav shared lock memory calculation error. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-131. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.
Medium [CVE-2026-103505] github.com/kubernetes-sigs/aws-efs-csi-driver: AWS EFS CSI Driver: Arbitrary mount option injection via mounttargetipmap attribute
github.com/kubernetes-sigs/aws-efs-csi-driver: AWS EFS CSI Driver: Arbitrary mount option injection via mounttargetipmap attribute. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-88. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.