Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

284 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Low3.7Red Hat

Low [CVE-2026-46582] Information disclosure via DNSSEC wildcard replay

Information disclosure via DNSSEC wildcard replay. Red Hat rates this low (CVSS 3.7). Weakness: CWE-358. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.

CVE-2026-46582
Unclassified
Jul 22, 2026
Low3.7Red Hat

Low [CVE-2026-42955] DNS cache integrity issue

DNS cache integrity issue. Red Hat rates this low (CVSS 3.7). Weakness: CWE-354. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.

CVE-2026-42955
Unclassified
Jul 22, 2026
Low3.7Red Hat

Low [CVE-2026-41637] Denial of Service via terminated DNS-over-QUIC queries

Denial of Service via terminated DNS-over-QUIC queries. Red Hat rates this low (CVSS 3.7). Weakness: CWE-911. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.

CVE-2026-41637
Unclassified
Jul 22, 2026
Low3.3Red Hat

Low [CVE-2026-44187] Ansible Lightspeed extension for Visual Studio Code: Information disclosure of Google Gemini API key

Ansible Lightspeed extension for Visual Studio Code: Information disclosure of Google Gemini API key. Red Hat rates this low (CVSS 3.3). Weakness: CWE-256.

CVE-2026-44187
Unclassified
Jul 22, 2026
Low2.9Red Hat

Low [CVE-2026-16517] Signed Integer Overflow in archive_write_zip_header

A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption. Red Hat Product Security rates this issue as Low severity. The vulnerability is in the ZIP write path only and requires both ZIP encryption to be enabled and a file size near INT64_MAX, making real-world exploitation highly unlikely. The resulting undefined behavior could theoretically cause incorrect Zip64 extension decisions or a crash, but the conditions are too contrived for practical exploitation. Weakness: CWE-190. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:43818.

CVE-2026-16517
Unclassified
Jul 21, 2026
Low3.7Red Hat

Low [CVE-2026-47010] Enhance JPEG handling (Oracle CPU 2026-07)

Enhance JPEG handling (Oracle CPU 2026-07). Red Hat rates this low (CVSS 3.7). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:50281 with package java-21-openjdk-1:21.0.12.0.8-1.1.el8, java-25-openjdk-main-25.0.4.0.7-1.1.1.hum1, java-21-openjdk-1:21.0.12.0.8-1.1.el9, java-25-openjdk-windows. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7.

CVE-2026-47010
Unclassified
Jul 21, 2026
Low3.7Red Hat

Low [CVE-2026-47059] Enhance AWT ImagingLib (Oracle CPU 2026-07)

Enhance AWT ImagingLib (Oracle CPU 2026-07). Red Hat rates this low (CVSS 3.7). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:50281 with package java-21-openjdk-1:21.0.12.0.8-1.1.el8, java-25-openjdk-main-25.0.4.0.7-1.1.1.hum1, java-21-openjdk-1:21.0.12.0.8-1.1.el9, java-25-openjdk-windows. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7.

CVE-2026-47059
Unclassified
Jul 21, 2026
Low3.4Red Hat

Low [CVE-2026-12547] information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials. This vulnerability is deemed LOW because it requires the user changing the desktop proxy settings from an authenticated proxy to the attacker's proxy. Red Hat severity: Low — CVSS 3.4 (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N). Weakness: CWE-201. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-12547
Red Hat Enterprise Linux
Jul 21, 2026
Low3.1Red Hat

Low [CVE-2026-59849] denial of service via automatic certificate authentication loop

denial of service via automatic certificate authentication loop. Red Hat rates this low (CVSS 3.1). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:42922 with package libssh-main-0.12.1-4.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Hardened Images.

CVE-2026-59849
Red Hat Enterprise Linux
Jul 21, 2026
Low3.9Red Hat

Low [CVE-2026-59846] information disclosure via ProxyCommand %r username expansion

information disclosure via ProxyCommand %r username expansion. Red Hat rates this low (CVSS 3.9). Red Hat lists fixing advisory RHSA-2026:42922 with package libssh-main-0.12.1-4.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-59846
Red Hat Enterprise Linux
Jul 21, 2026
Low3.4Red Hat

Low [CVE-2026-16410] JIT miscompilation in the JavaScript Engine: JIT component

JIT miscompilation in the JavaScript Engine: JIT component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-1037.

CVE-2026-16410
Unclassified
Jul 21, 2026
Low3.4Red Hat

Low [CVE-2026-16409] Invalid pointer in the Security: PSM component

Invalid pointer in the Security: PSM component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-476.

CVE-2026-16409
Unclassified
Jul 21, 2026
Low3.4Red Hat

Low [CVE-2026-16408] Integer overflow in the Audio/Video: Playback component

Integer overflow in the Audio/Video: Playback component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-190.

CVE-2026-16408
Unclassified
Jul 21, 2026
Low3.4Red Hat

Low [CVE-2026-16407] Mitigation bypass in the DOM: Service Workers component

Mitigation bypass in the DOM: Service Workers component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-807.

CVE-2026-16407
Unclassified
Jul 21, 2026
Low3.4Red Hat

Low [CVE-2026-16406] Mitigation bypass in the Networking component

Mitigation bypass in the Networking component. Red Hat rates this low (CVSS 3.4).

CVE-2026-16406
Unclassified
Jul 21, 2026
Low3.4Red Hat

Low [CVE-2026-16405] Information disclosure in the Networking: WebSockets component

Information disclosure in the Networking: WebSockets component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-201. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10, firefox-0:140.13.0-1.el9_8, thunderbird-0:140.13.0-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-16405
Unclassified
Jul 21, 2026
Low3.4Red Hat

Low [CVE-2026-16404] Spoofing issue in Firefox for Android

Spoofing issue in Firefox for Android. Red Hat rates this low (CVSS 3.4). Weakness: CWE-290.

CVE-2026-16404
Unclassified
Jul 21, 2026
Low3.4Red Hat

Low [CVE-2026-16403] Spoofing issue in the Address Bar component

Spoofing issue in the Address Bar component. Red Hat rates this low (CVSS 3.4).

CVE-2026-16403
Unclassified
Jul 21, 2026
Low3.7Red Hat

Low [CVE-2026-59842] information disclosure via short GSSAPI Curve25519 public key

information disclosure via short GSSAPI Curve25519 public key. Red Hat rates this low (CVSS 3.7). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:42922 with package libssh-main-0.12.1-4.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Hardened Images.

CVE-2026-59842
Red Hat Enterprise Linux
Jul 21, 2026
Low2.7Red Hat

Low [CVE-2026-61081] Performance Schema unspecified vulnerability (CPU Jul 2026)

Performance Schema unspecified vulnerability (CPU Jul 2026). Red Hat rates this low (CVSS 2.7). Weakness: CWE-497.

CVE-2026-61081
Unclassified
Jul 21, 2026

← All vendors