Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

411 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-15121] Use after free in WebRTC

Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) An use after free flaw was found in the WebRTC component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-15121
Unclassified
Jul 8, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-15120] Use after free in Core

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-15120
Unclassified
Jul 8, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-15113] Use after free in Autofill

Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) An use after free flaw was found in the Autofill component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-15113
Unclassified
Jul 8, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-15132] Uninitialized Use in V8

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) An uninitialized use flaw was found in the V8 component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-824.

CVE-2026-15132
Unclassified
Jul 8, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-15112] Use after free in Ozone

Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) An use after free flaw was found in the Ozone component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).

CVE-2026-15112
Unclassified
Jul 8, 2026
Critical9.8Vendor: HighRed Hat

Critical [CVE-2026-44024] Remote Code Execution via arbitrary file write due to insufficient tag validation

Remote Code Execution via arbitrary file write due to insufficient tag validation. Red Hat rates this important (CVSS 9.8). Weakness: CWE-22.

CVE-2026-44024
Unclassified
Jul 8, 2026
Critical10.0Vendor: HighRed Hat

Critical [CVE-2026-54763] Identity spoofing via improper header handling in authentication middlewares

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing Traefik's own value, but do not account for underscore-variant header names, which many backends normalize identically to dashed forms. An attacker able to reach a protected route can inject an underscore-variant header that survives Traefik's stripping and reaches the backend alongside, or on the unauthenticated ForwardAuth authResponseHeaders path instead of, the value Traefik intended to set, spoofing identity or authorization context. This issue is fixed in versions v2.11.51, v3.6.22, and v3.7.6. This allows a remote attacker to inject a specially crafted header that bypasses Traefik's security mechanisms. As a result, the attacker can spoof identity or authorization context to the backend, potentially gaining unauthorized access to protected resources. This can lead to identity spoofing or unauthorized access to backend services, as Traefik fails to properly strip these headers before forwarding them. The vulnerability is significant because many backend systems normalize these header forms, making exploitation feasible in typical deployments. Red Hat severity: Important — CVSS 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N). Weakness: CWE-178.

CVE-2026-54763
Unclassified
Jul 6, 2026
Critical9.9Red Hat

Critical [CVE-2026-48614] Privilege escalation via improper authorization in XML API

Privilege escalation via improper authorization in XML API. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-15.

CVE-2026-48614
Unclassified
Jul 6, 2026
Critical9.8Vendor: HighRed Hat

Critical [CVE-2026-14544 +1] Incomplete Fix for CVE-2026-8631

Incomplete Fix for CVE-2026-8631. Red Hat rates this important (CVSS 9.8). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:40894 with package hplip-0:3.23.12-10.el10_2.5, hplip-0:3.21.2-6.el9_8.5, hplip-0:3.18.4-14.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-14544CVE-2026-8631
Unclassified
Jul 3, 2026
Critical9.1Red Hat

Critical [CVE-2026-58517] Authentication bypass due to improper input neutralization

Authentication bypass due to improper input neutralization. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-140.

CVE-2026-58517
Unclassified
Jul 1, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-13283] Use after free in AdFilter

Use after free in AdFilter. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825.

CVE-2026-13283
Unclassified
Jun 25, 2026
Critical9.6Red Hat

Critical [CVE-2026-13032] Use after free in WebGL

Use after free in WebGL. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-825.

CVE-2026-13032
Unclassified
Jun 24, 2026
Critical9.8Vendor: HighRed Hat

Critical [CVE-2026-49980] Remote Code Execution via unauthenticated requests when `rcd --rc-serve` is enabled

Remote Code Execution via unauthenticated requests when `rcd --rc-serve` is enabled. Red Hat rates this important (CVSS 9.8). Weakness: CWE-78.

CVE-2026-49980
Unclassified
Jun 24, 2026
Critical9.4Vendor: HighRed Hat

Critical [CVE-2026-44020] Information disclosure via XML External Entity (XXE) vulnerability

Information disclosure via XML External Entity (XXE) vulnerability. Red Hat rates this important (CVSS 9.4). Weakness: CWE-611.

CVE-2026-44020
Unclassified
Jun 24, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-53622] mTLS enforcement bypass due to HTTP/3 TLS configuration flaw

mTLS enforcement bypass due to HTTP/3 TLS configuration flaw. Red Hat rates this important (CVSS 9.1). Weakness: CWE-289.

CVE-2026-53622
Unclassified
Jun 23, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-48491] Unauthorized access due to mutual TLS bypass

Unauthorized access due to mutual TLS bypass. Red Hat rates this important (CVSS 9.1). Weakness: CWE-807.

CVE-2026-48491
Unclassified
Jun 23, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-48020] Authentication bypass in StripPrefix middleware allows unauthorized access to protected paths

Authentication bypass in StripPrefix middleware allows unauthorized access to protected paths. Red Hat rates this important (CVSS 9.1). Weakness: CWE-22.

CVE-2026-48020
Unclassified
Jun 23, 2026
Critical9.6Red Hat

Critical [CVE-2026-11807] websocket missing authorization allows credential theft via activation_id spoofing

websocket missing authorization allows credential theft via activation_id spoofing. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-862. Red Hat lists fixing advisory RHSA-2026:28376 with package automation-eda-controller-0:1.2.9-2.el9ap, ansible-automation-platform-26/eda-controller-rhel9:1781732675, automation-eda-controller-0:1.1.19-1.el8ap, ansible-automation-platform-25/eda-controller-rhel8:1781741251. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-11807
Unclassified
Jun 23, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-48746] Critical authentication bypass allows unauthorized API access

Critical authentication bypass allows unauthorized API access. Red Hat rates this important (CVSS 9.1). Weakness: CWE-501. Red Hat lists fixing advisory RHSA-2026:36006 with package rhaiis/vllm-rocm-rhel9:1782353093, rhaiis/vllm-cuda-rhel9:1782352847, rhaiis/vllm-cuda-rhel9:1782951012, rhaiis/vllm-rocm-rhel9:1782951244.

CVE-2026-48746
Unclassified
Jun 22, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-44727] Remote Code Execution via stored Cross-Site Scripting in nbconvert handlers

Remote Code Execution via stored Cross-Site Scripting in nbconvert handlers. Red Hat rates this important (CVSS 9). Weakness: CWE-79.

CVE-2026-44727
Unclassified
Jun 22, 2026

← All vendors