Red Hat Linux Security Advisories & CVEs
4620 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-81521] Write redirection via unvalidated database name in Client.BulkWrite
Write redirection via unvalidated database name in Client. BulkWrite. Red Hat rates this important (CVSS 7.5). Weakness: CWE-791. Red Hat lists fixing advisory RHSA-2026:68334 with package flightctl-0:1.1.4-1.el10em, flightctl-0:1.1.4-1.el9em. Affected products named by the advisory: OpenShift Pipelines; Red Hat Edge Manager 1; Red Hat OpenShift Dev Spaces; Red Hat OpenShift GitOps; and 1 more. Affected products named by the advisory: Red Hat Trusted Artifact Signer.
High [CVE-2026-59324] org.springframework.integration/spring-integration-core: Spring Integration: Information disclosure via cross-message header leakage
org.springframework.integration/spring-integration-core: Spring Integration: Information disclosure via cross-message header leakage. Red Hat rates this important (CVSS 8.2). Weakness: CWE-821. Affected product named by the advisory: Red Hat Fuse 7.
High [CVE-2026-5680] Undertow-core: undertow: denial of service via websocket permessage-deflate processing
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Data Grid 8; Red Hat Enterprise Linux 9; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Process Automation 7; Red Hat Single Sign-On 7. Will not fix / out of support: Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Process Automation 7; Red Hat Single Sign-On 7. Red Hat fixing advisory: RHSA-2026:70230, RHSA-2026:70228, RHSA-2026:70229. Affected products named by the advisory: Red Hat package: resteasy.
High [CVE-2026-78002] Denial of service via heap buffer overflow in RainerScript replace function
A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful exploitation can lead to a denial of service (DoS) for the affected system. Red Hat Enterprise Linux systems configured to receive remote syslog messages are susceptible to this issue, potentially impacting logging availability. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-131. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Update Infrastructure 5; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8. Red Hat lists Red Hat Enterprise Linux 6 as not affected. Red Hat fixing advisory: RHSA-2026:69541, RHSA-2026:69540, RHSA-2026:71603. Affected products named by the advisory: Red Hat package: rsyslog.
High [CVE-2026-81727] Filesystem containment bypass allows local file overwrite
NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree. A flaw was found in NLTK. This vulnerability, a filesystem containment bypass, allows a local attacker with write access to a shared downloader directory to create special links (hardlinks) that point to files outside the intended installation area. When a package is extracted, these hardlinks can cause files outside the NLTK installation to be overwritten, leading to unauthorized modification or corruption of data. The NLTK library is vulnerable to a local file overwrite due to a filesystem containment bypass. This could result in data integrity and availability impacts. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H). Weakness: CWE-59. Affected Red Hat products: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.5; Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-81726] Unauthorized file access via path traversal in model-artifact APIs
NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs when pathsec is enabled. A flaw was found in NLTK. This vulnerability, known as path traversal, allows an attacker to bypass security restrictions in the model-artifact APIs. By exploiting this, an attacker can perform unauthorized read or write operations on files outside the intended secure directories. This could lead to sensitive information disclosure or system compromise. This vulnerability is rated as Important. NLTK's model-artifact APIs are susceptible to path traversal, allowing an attacker to read or write files outside intended sandbox directories. Exploitation requires no user interaction or privileges, but the attack complexity is high. Red Hat severity: Important — CVSS 8.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N). Weakness: CWE-22. Affected Red Hat products: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat OpenShift AI (RHOAI). Will not fix / out of support: Exploit Intelligence; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2.
High [CVE-2026-81724] Denial of Service via Uncontrolled Recursion
NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct. FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input. Attackers can craft trivial payloads with nested brackets that exceed Python's recursion limit and raise an unhandled RecursionError, crashing applications that parse user-supplied feature structures or feature grammars. A flaw was found in NLTK. By providing deeply nested feature-structure input, applications processing untrusted data can experience crashes due to uncontrolled recursion, impacting service availability. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-606. Affected Red Hat products: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.5; Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat OpenShift AI (RHOAI). Red Hat lists OpenShift Lightspeed as not affected. Will not fix / out of support: Exploit Intelligence; Red Hat Ansible Automation Platform 2. Red Hat fixing advisory: RHSA-2026:73987, RHSA-2026:69539.
High [CVE-2026-81722] nltk PorterStemmer: Denial of Service due to inefficient token processing
nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y' characters on every call, and _measure() invokes it for each stem position, causing O(n^2) behavior. A single ~20-50 KB untrusted token consisting of a long run of the letter 'y' followed by a matching suffix (e.g., 'ness') can pin a CPU core for seconds to minutes, causing availability impact. A flaw was found in the nltk PorterStemmer component. A remote attacker could exploit this vulnerability by providing a specially crafted, untrusted token. The inefficient algorithmic complexity in the stemming process, specifically within the _is_consonant() and _measure() helper functions, causes excessive CPU usage when processing certain inputs. This can lead to a denial of service (DoS) condition, where the system becomes unresponsive for an extended period. Processing a specially crafted, untrusted token can lead to excessive CPU consumption due to inefficient algorithmic complexity, potentially causing a denial of service for applications that rely on the affected stemming functionality. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-606.
High [CVE-2026-80212] resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses
An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::Resource.get_class, Resolv::DNS::Resource::Generic.create, and Resolv::DNS::SvcParam::Generic.create generate a new class for each unknown DNS resource record (type, class) pair, or each unknown SvcParamKey, encountered while decoding a response. Each generated class was permanently registered both as a constant on Resource (or SvcParam::Generic) and as an entry in a class-lookup hash (ClassHash), and thus the class remained reachable through that constant after the response was discarded. Type and class are each 16-bit values, and thus an attacker controlling DNS responses (a spoofed response, or a malicious or hijacked upstream DNS server) has roughly 2^32 distinct (type, class) pairs to choose from. A single response of a few hundred kilobytes carrying tens of thousands of distinct unknown types permanently grows process memory by tens of megabytes; repeated responses accumulate without bound and are never reclaimed by garbage collection, because the constant keeps each class alive. Any code path that calls Resolv::DNS::Message.decode on attacker-influenced DNS responses is affected. resolv is a default gem, and thus this is reachable from a plain Ruby installation without any additional dependency.
High [CVE-2026-47891] Denial of Service due to maxInMemorySize bypass
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier A remote attacker could exploit this vulnerability by sending specially crafted XML, causing the application to bypass the maxInMemorySize limit. This can lead to excessive memory consumption, potentially resulting in a denial of service (DoS) condition for the application. CVE-2026-47891 affects Spring Framework's WebFlux module only when an application uses the reactive WebFlux stack together with the Aalto XML processor (com.fasterxml:aalto-xml) to parse XML request bodies. Red Hat products ship spring-web/spring-webflux transitively as part of servlet-based (Spring MVC) or non-web integrations; none run the reactive WebFlux XML-decode path, and the Aalto XML processor is not shipped in any Red Hat product (verified across the portfolio). The vulnerable code path is therefore never in execution, and these products are not affected. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770.
High [CVE-2026-47864] org.springframework.integration/spring-integration-http: Spring Integration: Arbitrary code execution via unsafe Java deserialization
org.springframework.integration/spring-integration-http: Spring Integration: Arbitrary code execution via unsafe Java deserialization. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502. Affected product named by the advisory: Red Hat Fuse 7.
High [CVE-2026-38349] Denial of Service via crafted image file due to integer overflow
An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file. A flaw was found in FFmpeg. This can lead to the application becoming unresponsive or crashing, preventing legitimate users from accessing the service. The ffmpeg package is not shipped in base Red Hat Enterprise Linux. It is available through EPEL, Red Hat Enterprise Linux AI, and as a bundled dependency in Red Hat OpenShift AI container images. The vulnerable code resides in libswscale, which is compiled and shipped in all FFmpeg builds across these products. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI). Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-65642] Information disclosure and data modification via Insecure Direct Object Reference
Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases. A flaw was found in Plesk. An attacker can exploit this to read and modify other customers' databases, leading to unauthorized information disclosure and data tampering. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-639. Affected Red Hat products: Red Hat OpenShift Dev Spaces. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-65646] Remote Privilege Escalation and File Disclosure Vulnerability
Remote Privilege Escalation and File Disclosure Vulnerability. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Affected product named by the advisory: Red Hat OpenShift Dev Spaces.
High [CVE-2026-79921] Denial of Service via oversized AMQP payloads
amqp091-go is a Go AMQP 0.9.1 client. This can lead to unexpected memory consumption or application-layer denial of service (DoS), bypassing the protocol's built-in framing constraints. Version 1.13.0 contains a fix. No known workarounds are available. The impact is considered Important due to the potential for resource exhaustion and disruption of service. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Custom Metric Autoscaler 2.19; Multicluster Global Hub 1.7.3; Multicluster Global Hub 1.8.2; Red Hat Hardened Images; OpenShift Serverless; Red Hat OpenStack Platform 18.0; Red Hat Quay 3. Red Hat lists Cryostat 4; Red Hat Advanced Cluster Management for Kubernetes 2 as not affected. Red Hat fixing advisory: RHSA-2026:62866, RHSA-2026:67842, RHSA-2026:68515, RHSA-2026:73038, RHSA-2026:60854.
High [CVE-2026-54523] NamespacedGeneratingPolicy generator.apply namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system
NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system. Red Hat rates this important (CVSS 8.7). Weakness: CWE-862.
High [CVE-2026-73513] HTTP/2 trailers without END_STREAM in oghttp2 cause heap use-after-free
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's optional oghttp2 upstream HTTP/2 codec accepts a response trailer HEADERS frame without END_STREAM. Envoy completes and deferred-deletes the ActiveRequest while oghttp2 keeps the stream open, leaving ClientStreamImpl with a dangling response_decoder_ reference. A later frame on the stream can dispatch through the freed object and crash the process. The relevant scope boundary is that the default nghttp2 codec rejects the malformed trailers, and the trigger is upstream-only with oghttp2 enabled. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. A flaw was found in Envoy. A malicious upstream server can cause a Denial of Service (DoS) by sending HTTP/2 response trailers that lack the end-of-stream flag to a proxy configured with the optional oghttp2 codec. This malformed response corrupts the stream state and causes a use-after-free memory error when subsequent frames are received. As a result, the Envoy proxy terminates abnormally, disrupting service availability. This vulnerability is rated as an Important severity issue for Red Hat products because an untrusted upstream service can remotely trigger memory corruption, crashing the Envoy proxy process and causing a denial of service.
High [CVE-2026-73552] RBAC safe_regex fails to match non-UTF-8 HTTP header values
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy HTTP RBAC accepts RFC-valid opaque header bytes but evaluates safe_regex values with RE2's UTF-8 subject semantics. A downstream client can preserve a prohibited marker and add an unrelated obs-text octet, causing RE2::FullMatch to return false and a negative RBAC policy to treat the invalid subject as an ordinary no-match. A byte-oriented route matcher can still observe the marker, allowing the request to reach a route intended to be denied. The relevant scope boundary is that plain positive ALLOW regexes normally fail closed, and exact, prefix, suffix, and contains matchers are not shown to have this subject-domain failure. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. A flaw was found in Envoy. When evaluating regular expressions in role-based access control (RBAC) policies, Envoy improperly treats non-UTF-8 characters in HTTP header values as non-matching input. A remote attacker can exploit this flaw by sending requests with specially crafted HTTP headers to bypass negative matching rules, potentially gaining unauthorized access to protected resources.
High [CVE-2026-73512] HTTP/3 use-after-free when processing late datagrams
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current RequestDecoder when Capsule Protocol is enabled. Stream recreation, including an internal redirect, replaces the ActiveStream and updates EnvoyQuicServerStream but does not update the handler's cached pointer. A subsequent HTTP/3 datagram can call decodeData through the freed decoder, causing invalid virtual dispatch and a process crash. The relevant scope boundary is that hTTP/3 datagrams and Capsule Protocol must be enabled, and the request must enter a stream-recreation path such as an internal redirect. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. A flaw was found in Envoy. A remote attacker can cause a Denial of Service (DoS) by triggering a use-after-free memory vulnerability in the QUIC HTTP datagram handler. When HTTP/3 datagrams and the Capsule Protocol are enabled, stream recreation events such as internal redirects can leave the handler referencing a stream decoder that has already been freed. Subsequent datagrams attempting to access this invalid memory cause the application to crash. This vulnerability is rated as Important because an unauthenticated remote attacker can trigger a denial of service by crashing the Envoy proxy process over the network.
High [CVE-2026-73547] ext_authz crash on CONNECT requests without:path pseudo-header
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ext_authz filter assumes that a request contains a:path pseudoheader when applying query_parameters_to_set or query_parameters_to_remove from an authorization response. A path-less CONNECT request makes request_headers_->Path() return null, and Filter::onComplete dereferences that pointer while parsing the query string. An unauthenticated downstream client can crash the Envoy process when the filter and authorization response use query-parameter mutation. The relevant scope boundary is that the deployment must accept path-less CONNECT and configure ext_authz query-parameter mutation. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. A flaw was found in Envoy. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by crashing the Envoy process. When the external authorization filter is configured to modify query parameters, it fails to verify whether a request path header exists before processing it. An attacker can exploit this issue by sending a specially crafted HTTP CONNECT request missing the path header, leading to an abnormal process termination.