Red Hat Linux Security Advisories & CVEs
465 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Low [CVE-2026-86425] Denial of Service due to heap-use-after-free vulnerability
Denial of Service due to heap-use-after-free vulnerability. Red Hat rates this low (CVSS 3.3). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: imagemagick.
Low [CVE-2026-86424] Local attacker can modify files via TOCTOU symlink race
Local attacker can modify files via TOCTOU symlink race. Red Hat rates this low (CVSS 2.5). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: imagemagick.
Low [CVE-2026-86423] Denial of service via heap-use-after-free in PerlMagick's GetList method
Denial of service via heap-use-after-free in PerlMagick's GetList method. Red Hat rates this low (CVSS 3.3). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: imagemagick.
Low [CVE-2026-86422] Information disclosure and modification via TOCTOU symlink race on Windows
Information disclosure and modification via TOCTOU symlink race on Windows. Red Hat rates this low (CVSS 3.3). Weakness: CWE-367.
Low [CVE-2026-86421] Denial of Service via memory leak in MSL decoder
Denial of Service via memory leak in MSL decoder. Red Hat rates this low (CVSS 3.7). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: imagemagick.
Low [CVE-2026-86420] Denial of Service due to memory budget exhaustion
Denial of Service due to memory budget exhaustion. Red Hat rates this low (CVSS 3.7). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: imagemagick.
Low [CVE-2026-82209] Information disclosure via improper Public Suffix List boundary check
Information disclosure via improper Public Suffix List boundary check. Red Hat rates this low (CVSS 3.1). Weakness: CWE-501. Red Hat lists fixing advisory RHSA-2026:63161 with package curl-main-8.22.0-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat package: curl.
Low [CVE-2026-80255] Information disclosure due to secure cookie attribute bypass
A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host. A flaw was found in curl. This misinterpretation can cause a secure cookie to be transmitted over an unencrypted HTTP connection, potentially exposing its contents to an attacker. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-201. Affected Red Hat products: Red Hat Hardened Images; Red Hat Satellite 6. Red Hat lists Confidential Compute Attestation; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat JBoss Core Services; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat Satellite 6 as not affected. Red Hat fixing advisory: RHSA-2026:63161.
Low [CVE-2026-80231] Incorrect HTTPS connection reuse with Native CA Store
A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created. This could potentially lead to a client trusting a malicious server if the initial connection used a less strict CA store than intended for subsequent connections. This Low impact flaw in libcurl arises from incorrect reuse of HTTPS connections when the `CURLSSLOPT_NATIVE_CA` option is employed with differing Native CA Store settings. This flaw does not affect any Red Hat products. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-295. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Confidential Compute Attestation; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat Satellite 6 as not affected. Red Hat fixing advisory: RHSA-2026:63161.
Low [CVE-2026-80230] Public key pinning bypass allows unauthenticated connections
When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected. A flaw was found in libcurl, a client-side URL transfer library. This bypass enables unauthenticated connections that should have been rejected, potentially compromising the integrity of the connection. This Low impact flaw in curl arises when public key pinning is enabled alongside explicitly disabled SSL/TLS peer verification. In such an atypical and insecure configuration, libcurl fails to enforce the public key pinning, allowing unauthenticated connections to proceed without proper certificate validation. Red Hat products typically employ secure default configurations that enable full peer verification, thus reducing exposure to this issue. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-303. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 4 more.
Low [CVE-2026-18924] Use-after-free in HTTP/2 Server Push with shared connections
Use-after-free in HTTP/2 Server Push with shared connections. Red Hat rates this low (CVSS 3.7). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:63161 with package curl-main-8.22.0-0.1.hum1, rust-main-1.98.0-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Confidential Compute Attestation; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; and 11 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; and 7 more.
Low [CVE-2026-13608] Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack
A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation. A flaw was found in libcurl's SASL (Simple Authentication and Security Layer) negotiation for LDAP (Lightweight Directory Access Protocol) authentication when using the OpenLDAP backend. This Low impact flaw in libcurl's SASL negotiation for LDAP authentication could allow an attacker to bypass peer validation through a Man-in-the-Middle (MITM) attack. Exploitation requires an active network attacker to inject a premature response during the authentication handshake. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-923. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Satellite 6. Red Hat fixing advisory: RHSA-2026:63161, RHSA-2026:63514. Affected products named by the advisory: Red Hat package: curl.
Low [CVE-2026-86141] Denial of Service due to NULL pointer dereference in xmlRegNewParserCtxt
Denial of Service due to NULL pointer dereference in xmlRegNewParserCtxt. Red Hat rates this low (CVSS 2.9). Weakness: CWE-252. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-main-2.15.4-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Low [CVE-2026-86137] Denial of Service via out-of-bounds read in xmlFAParsePosCharGroup
Denial of Service via out-of-bounds read in xmlFAParsePosCharGroup. Red Hat rates this low (CVSS 2.9). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-main-2.15.4-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Low [CVE-2026-18540] HTTP response splitting via retry interceptor
HTTP response splitting via retry interceptor. Red Hat rates this low (CVSS 3.7). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:66008 with package nodejs26-main-26.8.2-0.1.hum1, grafana12-4-main-12.4.10-0.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.
Low [CVE-2026-85008] Integrity failure due to caching of unsafe HTTP method responses
Integrity failure due to caching of unsafe HTTP method responses. Red Hat rates this low (CVSS 3.7). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.
Low [CVE-2026-4897 +1] Regression in CVE-2026-4897 fix (polkit read_cookie) - stack buffer underflow
Regression in CVE-2026-4897 fix (polkit read_cookie()) - stack buffer underflow. Red Hat rates this low (CVSS 3.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:66287 with package polkit-main-127-5.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 7 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: polkit-pkla-compat; and 3 more.
Low [CVE-2026-77465] Denial of Service via uncontrolled recursion in TOML parsing
Denial of Service via uncontrolled recursion in TOML parsing. Red Hat rates this low (CVSS 3.5). Weakness: CWE-606. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: cockpit-image-builder.
Low [CVE-2026-63376] Arbitrary Code Execution via Prototype Pollution in TOML Parsing
Arbitrary Code Execution via Prototype Pollution in TOML Parsing. Red Hat rates this low (CVSS 3.7). Weakness: CWE-915. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: cockpit-image-builder.
Low [CVE-2026-84329] Confused deputy in CredentialProvider
Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Weakness: CWE-201.