Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4620 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.5Red Hat

High [CVE-2026-75762] Manager trusts self-asserted evt.Source for leaf-hub identity in all status handlers

Manager trusts self-asserted evt. Source() for leaf-hub identity in all status handlers. Red Hat rates this important (CVSS 8.5). Weakness: CWE-290. Red Hat lists fixing advisory RHSA-2026:68515 with package multicluster-globalhub/multicluster-globalhub-manager-rhel9:1788355599, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1788359461, multicluster-globalhub/multicluster-globalhub-agent-rhel9:1788377473, multicluster-globalhub/multicluster-globalhub-agent-rhel9:1788355439. Affected product named by the advisory: Multicluster Global Hub.

CVE-2026-75762
Unclassified
Aug 31, 2026
High8.8Red Hat

High [CVE-2026-12894] io.quarkus:quarkus-qute: quarkus-qute:Server-Side Template Injection (SSTI) vulnerability in ReflectionValueResolver of the Quarkus Qute template engine

A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue exists in the component responsible for looking up data values (ReflectionValueResolver), which fails to properly block access to sensitive Java internal functions when processing certain data types like Enums. An attacker who can provide or influence the template text can exploit this bypass to take control of the server by executing unauthorized commands. An attacker with the ability to supply or modify template content can bypass security filters designed to restrict access to sensitive Java methods. This bypass allows for arbitrary remote code execution within the context of the Java process, leading to a complete compromise of the affected application. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-1336. Affected Red Hat products: Red Hat build of Apache Camel 4 for Quarkus 3. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-12894
Unclassified
Aug 31, 2026
High8.7Red Hat

High [CVE-2026-19625] Cross-tenant authentication bypass via shared token-introspection cache

When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2. A shared token-introspection cache can be exploited by a remote attacker to bypass authentication across different tenants. This allows unauthorized access to resources or data, leading to a cross-tenant authentication bypass. Important: This flaw in Quarkus OIDC allows for cross-tenant authentication bypass due to a shared token-introspection cache. In multi-tenant deployments of Red Hat products utilizing Quarkus OIDC, an attacker could potentially gain unauthorized access to other tenants' resources by exploiting this shared cache mechanism. Red Hat severity: Important — CVSS 8.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N). Weakness: CWE-524. Affected Red Hat products: Exploit Intelligence; Red Hat build of Apicurio Registry 3. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-19625
Unclassified
Aug 31, 2026
HighRed Hat

High [CVE-2026-19651] Authorization bypass via URL query string manipulation

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input. A flaw was found in quarkus-spring-web. The system incorrectly reads the URL query string as a request header, which can lead to an authorization bypass, allowing unauthorized access to resources. This could enable unauthorized access to resources or functionality within applications utilizing the affected component, elevating the risk to Important due to the potential for privilege escalation or data exposure. Red Hat severity: Important. Weakness: CWE-551.

CVE-2026-19651
Unclassified
Aug 31, 2026
High7.5Red Hat

High [CVE-2026-81624] WebSocketContainer defaults for buffers and timeouts are infinite

Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being unlimited. This allows a remote attacker to send large amounts of data or maintain connections indefinitely, potentially crashing the server by exhausting its memory or other resources. The Red Hat Product Security team has assessed the severity of this vulnerability as Important, given that the default configuration allows for unlimited resource consumption. Successful exploitation allows an attacker to cause a denial of service via resource exhaustion. The vulnerability's root cause is the lack of configuration options for WebSocket buffer sizes and timeouts in the container boot process. Weakness: CWE-770. Affected Red Hat products: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat Single Sign-On 7. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat JBoss Enterprise Application Platform Expansion Pack as not affected. Will not fix / out of support: Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7.

CVE-2026-81624
Unclassified
Aug 31, 2026
High7.1Red Hat

High [CVE-2026-82659] Arbitrary file read and Server-Side Request Forgery via raw option bypass

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or URLs that bypass the intended sandbox, with fetched content delivered in the outgoing message to attacker-controlled recipients. A flaw was found in nodemailer. This allows them to read arbitrary files from the system or perform Server-Side Request Forgery (SSRF), potentially leading to information disclosure or unauthorized access to internal network resources. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N). Weakness: CWE-918. Affected Red Hat products: Red Hat Developer Hub; Self-service automation portal 2. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Hardened Images as not affected. Will not fix / out of support: Red Hat Developer Hub. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-82659
Unclassified
Aug 31, 2026
High7.5Red Hat

High [CVE-2026-82623] Denial of service via use-after-free vulnerability

A vulnerability was detected in open62541 up to 1.5.5. Affected by this vulnerability is the function UA_DataValue_backend_copyRange of the file plugins/historydata/ua_history_data_backend_memory.c of the component History Backend. The manipulation results in use after free. The attack can be launched remotely. The exploit is now public and may be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability. This flaw could lead to a denial of service, making the affected system unavailable. The open62541 library is not shipped in any Red Hat product. It is available in the Fedora community distribution, which already ships version 1.5.6, beyond the affected range (up to 1.5.5). Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-825.

CVE-2026-82623
Unclassified
Aug 31, 2026
High7.5Red Hat

High [CVE-2026-82417] Denial of Service via improper validation in stringify function

### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)` after checking only that the property is truthy, so a value such as `{ constructor: { isBuffer: "x" } }` makes the call throw `TypeError: obj.constructor.isBuffer is not a function`. ### Details `lib/stringify.js:127` calls `utils.isBuffer` on every non-primitive value it serializes. `utils.isBuffer` (`lib/utils.js:332`) reads `obj.constructor.isBuffer` and invokes it without verifying that it is a function. `constructor` and `isBuffer` are ordinary property names, so any object carrying them as own properties reaches the unchecked call. Such an object can be built from untrusted input. `qs.parse("x[constructor][isBuffer]=y", { plainObjects: true })` or `{ allowPrototypes: true }` keeps the `constructor` key as an own property (the default parse options drop it), and `JSON.parse("{\"a\":{\"constructor\":{\"isBuffer\":\"x\"}}}")` produces the same shape with no qs option involved. The unguarded duck-type was introduced in 3768a75 and first shipped in v2.2.5 (September 2014). v2.2.4 and earlier used `Buffer.isBuffer` and are not affected.

CVE-2026-82417
Red Hat Enterprise Linux
Aug 29, 2026
High7.8Red Hat

High [CVE-2026-82474] Policy bypass allows unauthorized program execution via execveat

Policy bypass allows unauthorized program execution via execveat. Red Hat rates this important (CVSS 7.8). Weakness: CWE-1220. Red Hat lists fixing advisory RHSA-2026:68692 with package sudo-0:1.9.17-10.p2.el10_2.6, sudo-main-1.9.17-16.p2.1.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-82474
Unclassified
Aug 29, 2026
High8.6Red Hat

High [CVE-2026-80725] properly validate BIG TCP aggregation criteria

In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregation criteria When GRO attempts to aggregate packets beyond GRO_LEGACY_MAX_SIZE (64KB), BIG TCP should only be permitted for plain IPv4 TCP and plain IPv6 TCP (with sufficient MAC header room to insert the temporary HBH jumbo header). However, commit b1a78b9b9886 ("net: add support for ipv4 big tcp") loosened the check in skb_gro_receive(), leading to several issues: 1. skb_gro_receive() checked skb_headroom(p) instead of the actual space before the MAC header (p->mac_header). Because skb_headroom(p) includes mac_len, crafted frames (e.g. injected via AF_PACKET) can pass the check with p->mac_header head, causing an out-of-bounds write and wrapping skb->mac_header. 2. It allowed non-IP protocols such as software VLAN (ETH_P_8021Q / ETH_P_8021AD) to aggregate beyond 64KB because p->protocol!= ETH_P_IPV6 was true. 3. It checked p->encapsulation instead of NAPI_GRO_CB(skb)->encap_mark, allowing encapsulated flows (e.g. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-80725
Linux Kernel
Aug 29, 2026
High8.2Red Hat

High [CVE-2026-82265] org.springframework.boot/spring-boot-actuator: Zipkin: Information disclosure via unauthenticated Spring Boot Actuator endpoints

Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read environment variables, bean configurations, and storage credentials via actuator endpoints, or modify log levels to suppress logging. A flaw was found in Zipkin. Additionally, attackers can modify log levels, potentially suppressing important logging information. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N). Weakness: CWE-306. Red Hat lists Red Hat Fuse 7; Red Hat OpenShift Dev Spaces as not affected.

CVE-2026-82265
Unclassified
Aug 28, 2026
High7.4Red Hat

High [CVE-2026-73208] Authentication bypass via incorrect OAuth2 token validation

An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the audience claim is used in its place and checked against the configured required scopes. A token that grants no relevant permissions can be accepted because its intended recipient value happens to match a configured scope name, granting access that should have been denied. It also hides an identity provider misconfiguration where scopes are not being issued at all. Ensure the identity provider issues a scope claim for all tokens used with Dovecot, and that configured scope names do not match audience values. Update to non-vulnerable version. No publicly available exploits are known. A flaw was found in Dovecot. This vulnerability allows an attacker to bypass authentication by exploiting how OAuth2 tokens are validated. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-303. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:76763. Affected products named by the advisory: Red Hat package: dovecot.

CVE-2026-73208
Red Hat Enterprise Linux
Aug 28, 2026
High7.5Red Hat

High [CVE-2026-42391] Denial of Service via IMAP ID command with excessive parameters

An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage to grow disproportionately. The login process can be terminated by the out-of-memory handling, which also terminates all other connections handled by the same process. This can cause degradation or denial of service for IMAP logins. Limit the number of connections handled by a single imap-login process. This has a performance impact though. Update to non-vulnerable version. No publicly available exploits are known. A flaw was found in Dovecot. This action causes the server to consume excessive memory and CPU resources, leading to the termination of login processes and other active connections. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:76763. Affected products named by the advisory: Red Hat package: dovecot.

CVE-2026-42391
Red Hat Enterprise Linux
Aug 28, 2026
High7.5Red Hat

High [CVE-2026-40019] Denial of Service via truncated quoted argument in ManageSieve

An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop consuming CPU. This can cause degradation or denial of service for Sieve script management, and repeated connections can consume all available CPU on the server. Monitor system for abnormal CPU usage and kill the offending process. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known. This action causes the process to enter an infinite loop, consuming excessive CPU resources. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:76763. Affected products named by the advisory: Red Hat package: dovecot.

CVE-2026-40019
Red Hat Enterprise Linux
Aug 28, 2026
High7.4Red Hat

High [CVE-2026-40018] MySQL multi-byte escaping wrong

None None None No publicly available exploits are known. A flaw was found in Dovecot. A remote attacker with high attack complexity could exploit this vulnerability to gain access to sensitive information and modify data without requiring any user interaction or privileges. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-89. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:76763. Affected products named by the advisory: Red Hat package: dovecot.

CVE-2026-40018
Red Hat Enterprise Linux
Aug 28, 2026
High7.5Red Hat

High [CVE-2026-33605] Denial of Service in ManageSieve login process

An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community releases), only the attacker's own connection is terminated. If running in high-performance mode (default for Pro releases), all connections handled by the same managesieve-login process are terminated. Repeating the attack can cause denial of service for Sieve script management. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known. A flaw was found in Dovecot. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1286. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:76763. Affected products named by the advisory: Red Hat package: dovecot.

CVE-2026-33605
Red Hat Enterprise Linux
Aug 28, 2026
High7.1Red Hat

High [CVE-2026-33263] Denial of Service and potential message duplication via connection limit exhaustion

When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused by file descriptor handling issues. If running in high-security mode (default for community releases), only the new submission connection gets terminated. The crashes can cause failure for user to send a message, or it can cause duplicate messages to be sent. If TLS is not used (in the backend server processing the submission), duplicate deliveries cannot happen, because the crash can only happen at AUTH stage. Limit the number of connections handled by single submission-login process. This has a performance impact though. Update to non-vulnerable version. No publicly available exploits are known. A flaw was found in the Dovecot mail server's `submission-login` component. This vulnerability occurs when the server reaches its maximum allowed user IP connections, leading to a crash due to file descriptor handling issues. This can result in a denial of service, preventing users from sending emails, and potentially causing duplicate message delivery under certain conditions. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H). Weakness: CWE-910. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9.

CVE-2026-33263
Red Hat Enterprise Linux
Aug 28, 2026
High7.5Red Hat

High [CVE-2026-27852] Denial of service via crafted email headers

An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME parameters, which causes excessive memory usage when the message is later parsed. The message is still delivered, but reading it over IMAP can exhaust the memory limit of the process and terminate it, causing denial of service for the affected user. Update to non-vulnerable version. No publicly available exploits are known. A flaw was found in dovecot. When a user attempts to read this message over IMAP, the parsing process consumes an inordinate amount of memory, leading to the termination of the process. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:76763. Affected products named by the advisory: Red Hat package: dovecot.

CVE-2026-27852
Red Hat Enterprise Linux
Aug 28, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-80603] fix parse_dcc off-by-one OOB read

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read parse_dcc() treats data_end as an inclusive end pointer, but its only caller passes data_limit = ib_ptr + datalen, which points one past the last valid byte. The newline search loop iterates while tmp <= data_end, so when no newline is present, *tmp is read at tmp == data_end, one byte beyond the region filled by skb_header_pointer(). irc_buffer is kmalloc'd as MAX_SEARCH_SIZE + 1 bytes and datalen is capped at MAX_SEARCH_SIZE, so the stray read does not fault. The byte is uninitialized or stale; if it contains an ASCII digit, simple_strtoul will consume it and produce a wrong DCC IP or port in the conntrack expectation. The extra allocation byte is also a fragile guard: if the cap or allocation size changes, this becomes a real out-of-bounds read. Change the loop and its post-loop check to use strict less-than, consistent with the caller's exclusive-end convention. Update the function comment accordingly. A flaw was found in the Linux kernel's netfilter component, specifically within the nf_conntrack_irc module. An off-by-one error in the parse_dcc() function can cause the system to read one byte beyond an allocated buffer.

CVE-2026-80603
Linux Kernel
Aug 28, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-80718] fix bitmap overflow and accounting in pcpu_create_chunk

In the Linux kernel, the following vulnerability has been resolved: mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() In pcpu_create_chunk(), nr_pages is the total contiguous backing allocation, i.e., nr_units * pcpu_unit_pages, but pcpu_chunk_populated() uses it to set chunk->populated, whose size is pcpu_unit_pages, bitmap. Since bit N in chunk->populated means page offset N inside every unit is backed. When nr_units > 1, the function writes beyond chunk->populated. It also fixes the global pcpu_nr_empty_pop_pages accounting, since pcpu_balance_free() only iterates up to chunk->nr_pages. Later, commit b539b87fed37f ("percpu: implmeent pcpu_nr_empty_pop_pages and chunk->nr_populated") added pcpu_nr_empty_pop_pages and caused the accounting issue. Specifically, within the `mm/percpu-km` module, the `pcpu_create_chunk()` function incorrectly calculates the size of a bitmap used for tracking memory pages. This miscalculation can lead to a bitmap overflow, where data is written beyond the intended memory boundary. Such an issue can result in memory corruption, potentially allowing a local attacker to escalate privileges or cause a system crash (Denial of Service). Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-805.

CVE-2026-80718
Unclassified
Aug 28, 2026

← All vendors