Red Hat Linux Security Advisories & CVEs
3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-59892] @opentelemetry/propagator-jaeger: OpenTelemetry JavaScript: Denial of Service via malformed HTTP header decoding
@opentelemetry/propagator-jaeger: OpenTelemetry JavaScript: Denial of Service via malformed HTTP header decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-248.
High [CVE-2026-39822] Go os.Root: Symlink following vulnerability allows directory traversal
Go os.Root: Symlink following vulnerability allows directory traversal. Red Hat rates this important (CVSS 7.8). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:44624 with package podman-6:5.8.2-5.el9_8, rhosdt/tempo-query-rhel9:1784775793, golang-0:1.26.5-1.el10_2, buildah-2:1.43.1-4.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-59725] Denial of Service via invalid binary POST requests
Denial of Service via invalid binary POST requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Red Hat lists fixing advisory RHSA-2026:37577 with package dotnet8-0-main-8.0.128-1.1.hum1.
High [CVE-2026-59724] Denial of Service via crafted WebTransport session ID
Denial of Service via crafted WebTransport session ID. Red Hat rates this important (CVSS 7.5). Weakness: CWE-843. Red Hat lists fixing advisory RHSA-2026:26994 with package dotnet8-0-main-8.0.128-1.hum1.
High [CVE-2026-59877] Denial of Service via crafted.proto schema
Denial of Service via crafted.proto schema. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835.
High [CVE-2026-59874] Denial of Service via malformed tar archive header
Denial of Service via malformed tar archive header. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Red Hat lists fixing advisory RHSA-2026:42815 with package nodejs:22-8100020260724100938.6d880403, ansible-automation-platform/automation-portal:1784622951, nodejs:24-8100020260724132848.6d880403.
High [CVE-2026-59873] Denial of Service via crafted gzip bomb
Denial of Service via crafted gzip bomb. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:44263 with package nodejs:22-8100020260724100938.6d880403, openshift4/ose-agent-installer-ui-rhel9:1784724699, ansible-automation-platform/automation-portal:1784622951, openshift4/ose-agent-installer-ui-rhel9:1784713741.
High [CVE-2026-59868] Denial of Service via quadratic CPU time parsing with merge keys
Denial of Service via quadratic CPU time parsing with merge keys. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:35272 with package nodejs20-main-20.20.2-1.hum1, dotnet8-0-main-8.0.128-1.hum1, rust-main-1.96.1-1.hum1, nodejs25-main-25.9.0-1.1.hum1.
High [CVE-2026-59869] Denial of Service via crafted YAML documents
Denial of Service via crafted YAML documents. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Red Hat lists fixing advisory RHSA-2026:47451 with package rust-main-1.97.0-1.1.hum1, openshift4/ose-agent-installer-ui-rhel9:1784724699, container-native-virtualization/kubevirt-console-plugin:1784710594, nodejs22-main-22.23.1-2.1.hum1.
High [CVE-2026-59870] Denial of Service via crafted YAML ordered-map document
Denial of Service via crafted YAML ordered-map document. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:35272 with package nodejs20-main-20.20.2-1.hum1, dotnet8-0-main-8.0.128-1.hum1, rust-main-1.96.1-1.hum1, nodejs25-main-25.9.0-1.1.hum1.
High [CVE-2026-44918] Prevent rehoming resources to nodes with different owner
Prevent rehoming resources to nodes with different owner. Red Hat rates this important (CVSS 8.7). Weakness: CWE-1220.
High [CVE-2026-55874] Information disclosure via S3 API gateway path traversal
Information disclosure via S3 API gateway path traversal. Red Hat rates this important (CVSS 7.7). Weakness: CWE-22.
High [CVE-2026-60002] Use-after-free vulnerability during host key re-exchange on the client side
Use-after-free vulnerability during host key re-exchange on the client side. Red Hat rates this important (CVSS 7.7). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:37382 with package openssh-main-10.4p1-1.hum1.
High [CVE-2026-55999] glamor Font Atlas Heap Buffer Overflow
glamor Font Atlas Heap Buffer Overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-805. Red Hat lists fixing advisory RHSA-2026:38486 with package xorg-x11-server-0:1.20.11-34.el9_8.3, xorg-x11-server-Xwayland-0:21.1.3-20.el8_10.3, xorg-x11-server-Xwayland-0:24.1.9-4.el9_8.3, xorg-x11-server-0:1.20.11-28.el8_10.3. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-56001] BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow
BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow. Red Hat rates this important (CVSS 7.3). Red Hat lists fixing advisory RHSA-2026:47079 with package libXfont2-0:2.0.3-2.el8_10.1, libXfont2-0:2.0.6-5.el10_2.1. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-56002] PCF Font Parsing Heap Buffer Overflow
PCF Font Parsing Heap Buffer Overflow. Red Hat rates this important (CVSS 7.3). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:47079 with package libXfont2-0:2.0.3-2.el8_10.1, libXfont2-0:2.0.6-5.el10_2.1. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-59691] rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer
rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer. Red Hat rates this important (CVSS 7.1). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:47180 with package gstreamer1-plugins-bad-free-0:1.26.7-2.el10_2.6. Affected product named by the advisory: Red Hat Enterprise Linux 1.
High [CVE-2026-59692] DTLS certificate Subject DN stack buffer overflow in openssl_verify_callback
DTLS certificate Subject DN stack buffer overflow in openssl_verify_callback. Red Hat rates this important (CVSS 7.5). Weakness: CWE-121. Red Hat lists fixing advisory RHSA-2026:47180 with package gstreamer1-plugins-bad-free-0:1.26.7-2.el10_2.6. Affected product named by the advisory: Red Hat Enterprise Linux 1.
High [CVE-2026-56003] computeProps Property Buffer Heap Buffer Overflow
A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:47103.
High [CVE-2026-14739] Heap overflow when preparsing SQL statements with excessive placeholders
Heap overflow when preparsing SQL statements with excessive placeholders. Red Hat rates this important (CVSS 8.1). Weakness: CWE-131.