Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.8Red Hat

High [CVE-2026-15719] Site isolation issue in the DOM: Navigation component

Site isolation issue in the DOM: Navigation component. Red Hat rates this important (CVSS 8.8). Weakness: CWE-501. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10, firefox-0:140.13.0-1.el9_8, thunderbird-0:140.13.0-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-15719
Unclassified
Jul 14, 2026
High8.8Vendor: MediumRed Hat

High [CVE-2026-15718] Invalid pointer in the JavaScript: WebAssembly component

Invalid pointer in the JavaScript: WebAssembly component. Red Hat rates this moderate (CVSS 8.8). Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10, firefox-0:140.13.0-1.el9_8, thunderbird-0:140.13.0-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-15718
Unclassified
Jul 14, 2026
High8.9Red Hat

High [CVE-2026-15416] Argo CD unauthenticated remote code execution in repo-server via GenerateManifest gRPC endpoint

Argo CD unauthenticated remote code execution in repo-server via GenerateManifest gRPC endpoint. Red Hat rates this important (CVSS 8.9). Weakness: CWE-306.

CVE-2026-15416
Unclassified
Jul 14, 2026
High7.5Red Hat

High [CVE-2026-15075] Information disclosure via improper handling of HTTP 30x redirects

Information disclosure via improper handling of HTTP 30x redirects. Red Hat rates this important (CVSS 7.5). Weakness: CWE-346. Red Hat lists fixing advisory RHSA-2026:47172 with package smallrye-mutiny-vertx-core, vertx-core.

CVE-2026-15075
Unclassified
Jul 14, 2026
High7.5Red Hat

High [CVE-2026-15076] Information disclosure via improper cookie domain validation

Information disclosure via improper cookie domain validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-346. Red Hat lists fixing advisory RHSA-2026:47172 with package vertx-web-client.

CVE-2026-15076
Unclassified
Jul 14, 2026
High8.8Red Hat

High [CVE-2026-59674] Privilege escalation via symbolic link following

Privilege escalation via symbolic link following. Red Hat rates this important (CVSS 8.8). Weakness: CWE-59.

CVE-2026-59674
Unclassified
Jul 14, 2026
High7.8Red Hat

High [CVE-2026-64600] XFS data corruption using reflink

XFS data corruption using reflink. Red Hat rates this important (CVSS 7.8). Weakness: CWE-362. Red Hat lists fixing advisory RHSA-2026:47981 with package kernel-0:6.12.0-55.89.1.el10_0, kernel-0:4.18.0-553.144.1.el8_10, kpatch-patch, kernel-0:5.14.0-284.182.1.el9_2. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-64600
Unclassified
Jul 14, 2026
High7.5Red Hat

High [CVE-2026-15685] Denial of Service via improper array index validation in downloadBlob function

Denial of Service via improper array index validation in download Blob function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.

CVE-2026-15685
Unclassified
Jul 13, 2026
High7.5Red Hat

High [CVE-2026-15584] privileged host-chroot debug pods created in shared default namespace enable privilege escalation to node root

A privilege escalation vulnerability was found in the incluster-checks tool for OpenShift. The tool creates privileged debug pods with host filesystem access in the shared default namespace, where any user with the standard edit role can exec into them and obtain root access on cluster nodes. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-250. Affected Red Hat products: Pen Drive Powered by Red Hat Lightspeed. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-15584
Unclassified
Jul 13, 2026
High8.2Red Hat

High [CVE-2026-51537] Out-of-bounds read via malformed ForwardOpen requests

Out-of-bounds read via malformed ForwardOpen requests. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125.

CVE-2026-51537
Unclassified
Jul 13, 2026
High8.1Red Hat

High [CVE-2026-55810] Object Injection Vulnerability

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This could enable an attacker to manipulate application data or potentially execute unauthorized code. This risk is heightened by the network-based attack vector and lack of user interaction required for exploitation, impacting the confidentiality and integrity of Red Hat products such as Ansible Services and Red Hat OpenShift AI. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-915. Red Hat lists Red Hat OpenShift AI (RHOAI) as not affected.

CVE-2026-55810
Unclassified
Jul 10, 2026
High8.1Red Hat

High [CVE-2026-57215] Persistent foreign bindings allow unauthorized message routing

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations because volatile direct-reply-to queues can be accepted at bind and route time but are missing from Khepri-backed deletion checks, leaving persistent route entries after unbind. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6. This occurs because temporary queues are not properly removed, leaving behind active routing entries. This can lead to unauthorized message routing and potential exposure of sensitive information. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-459. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0 as not affected. Red Hat fixing advisory: RHSA-2026:35939, RHSA-2026:35940.

CVE-2026-57215
Unclassified
Jul 10, 2026
High7.5Red Hat

High [CVE-2026-57219] OAuth 2 client secret disclosure via obsolete API endpoint

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and that OAuth configuration are enabled. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-477. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0 as not affected. Red Hat fixing advisory: RHSA-2026:35939, RHSA-2026:35940.

CVE-2026-57219
Unclassified
Jul 10, 2026
High7.5Red Hat

High [CVE-2026-57220] Denial of Service via oversized stream frames

RabbitMQ is a messaging and streaming broker. This issue is fixed in version 4.2.6. A flaw was found in RabbitMQ. The stream listener in RabbitMQ does not properly enforce frame-size limits during authentication and before negotiation. This allows an unauthenticated remote client to send oversized stream frames, which can consume excessive broker memory. This can lead to a denial of service (DoS) condition, making the service unavailable to legitimate users. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0 as not affected. Red Hat fixing advisory: RHSA-2026:35939, RHSA-2026:35940.

CVE-2026-57220
Unclassified
Jul 10, 2026
High7.7Vendor: MediumRed Hat

High [CVE-2026-57212] Denial of Service via oversized JSON bodies in HTTP API

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request paths because read_complete_body checks the accumulated size before the final chunk but not the final combined size. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5. The API's body size check is incomplete, allowing the final combined size to exceed limits. This could lead to a Denial of Service (DoS) due to excessive resource consumption. Red Hat severity: Moderate — CVSS 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0 as not affected. Red Hat fixing advisory: RHSA-2026:35939, RHSA-2026:35940.

CVE-2026-57212
Unclassified
Jul 10, 2026
High8.8Red Hat

High [CVE-2026-57156] Arbitrary code execution or denial of service via integer overflow in RDP message processing

Arbitrary code execution or denial of service via integer overflow in RDP message processing. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-57156
Unclassified
Jul 10, 2026
High7.5Red Hat

High [CVE-2026-55827] Remote code execution via heap out-of-bounds write in RemoteFX decoding

Remote code execution via heap out-of-bounds write in RemoteFX decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.

CVE-2026-55827
Unclassified
Jul 10, 2026
High7.4Red Hat

High [CVE-2026-53450] Localhost services exposed via IPv4-mapped IPv6 address bypass

Localhost services exposed via IPv4-mapped IPv6 address bypass. Red Hat rates this important (CVSS 7.4). Weakness: CWE-289.

CVE-2026-53450
Unclassified
Jul 10, 2026
High7.2Red Hat

High [CVE-2026-53448] Arbitrary code execution via SQL injection in HTTPS admin panel

Arbitrary code execution via SQL injection in HTTPS admin panel. Red Hat rates this important (CVSS 7.2). Weakness: CWE-89.

CVE-2026-53448
Unclassified
Jul 10, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-15574] Authorization header and full chat payloads logged at hard-coded DEBUG default

Authorization header and full chat payloads logged at hard-coded DEBUG default. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-538.

CVE-2026-15574
Unclassified
Jul 10, 2026

← All vendors