Red Hat Linux Security Advisories & CVEs
11225 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-93228] Reject Write/Reply chunks with segcount 0
Reject Write/Reply chunks with segcount 0. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-839. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-93225] fix typec switch leak on probe error path
fix typec switch leak on probe error path. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.
Critical [CVE-2026-84719] WorkflowJobTemplate /copy/ deep-copy sanitizer omits instance_groups authorization (InstanceGroup use_role bypass to control-plane)
WorkflowJobTemplate /copy/ deep-copy sanitizer omits instance_groups authorization (InstanceGroup use_role bypass to control-plane). Red Hat rates this critical (CVSS 9.9). Weakness: CWE-862. Red Hat lists fixing advisory RHSA-2026:71177 with package automation-controller-0:4.5.36-1.el8ap, automation-controller-0:4.5.36-1.el9ap, ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.4 for RHEL 8; Red Hat Ansible Automation Platform 2.4 for RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; and 2 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Critical [CVE-2026-75884] Privilege escalation to OpenShift namespace via pod_spec_override injection in container groups
Privilege escalation to OpenShift namespace via pod_spec_override injection in container groups. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-184. Red Hat lists fixing advisory RHSA-2026:71177 with package automation-controller-0:4.5.36-1.el8ap, automation-controller-0:4.5.36-1.el9ap, ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.4 for RHEL 8; Red Hat Ansible Automation Platform 2.4 for RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; and 2 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Critical [CVE-2026-84502] Project scm_url argument injection into `git ls-remote --upload-pack` yields RCE on the controller-task control-plane pod
Project scm_url argument injection into `git ls-remote --upload-pack` yields RCE on the controller-task control-plane pod. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-88. Red Hat lists fixing advisory RHSA-2026:71177 with package automation-controller-0:4.5.36-1.el8ap, automation-controller-0:4.5.36-1.el9ap, ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.4 for RHEL 8; Red Hat Ansible Automation Platform 2.4 for RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; and 2 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Critical [CVE-2026-84474] view_jobtemplate to execute privilege escalation via host_config_key exposure and X-Forwarded-For spoofing of provisioning-callback host match
view_jobtemplate to execute privilege escalation via host_config_key exposure and X-Forwarded-For spoofing of provisioning-callback host match. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-807. Red Hat lists fixing advisory RHSA-2026:71177 with package automation-controller-0:4.5.36-1.el8ap, automation-controller-0:4.5.36-1.el9ap, ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.4 for RHEL 8; Red Hat Ansible Automation Platform 2.4 for RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; and 2 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Critical [CVE-2026-84638] instance group attachment to schedules and workflow job template nodes checks only read permission, allowing use of restricted (controlplane / other-tenant) instance groups and privilege escalation…
instance group attachment to schedules and workflow job template nodes checks only read permission, allowing use of restricted (controlplane / other-tenant) instance groups and privilege escalation to control-plane code execution. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:71177 with package automation-controller-0:4.5.36-1.el8ap, automation-controller-0:4.5.36-1.el9ap, ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.4 for RHEL 8; Red Hat Ansible Automation Platform 2.4 for RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; and 2 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Critical [CVE-2026-84684] constructed inventory input inventory attachment checks only read permission on the source inventory, allowing a read-only user to clone another tenant's hosts and secrets and run ad hoc commands a…
constructed inventory input inventory attachment checks only read permission on the source inventory, allowing a read-only user to clone another tenant's hosts and secrets and run ad hoc commands against them. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:71177 with package automation-controller-0:4.5.36-1.el8ap, automation-controller-0:4.5.36-1.el9ap, ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.4 for RHEL 8; Red Hat Ansible Automation Platform 2.4 for RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; and 2 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Critical [CVE-2026-84711] Project scm_branch/scm_refspec argument injection into git during project sync allows arbitrary file read on the sync host (control-plane ServiceAccount token, SECRET_KEY, and DB credentials on con…
Project scm_branch/scm_refspec argument injection into git during project sync allows arbitrary file read on the sync host (control-plane ServiceAccount token, SECRET_KEY, and DB credentials on control-plane deployments) leading to full AAP and Kubernetes-namespace compromise. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-88. Red Hat lists fixing advisory RHSA-2026:71177 with package automation-controller-0:4.5.36-1.el8ap, automation-controller-0:4.5.36-1.el9ap, ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.4 for RHEL 8; Red Hat Ansible Automation Platform 2.4 for RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; and 2 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-75887] Unauthenticated path traversal in i18n locale handler
Unauthenticated path traversal in i18n locale handler. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:70647 with package openshift4/ose-console-rhel9:1789939565, openshift4/ose-console-rhel9:1789904865, openshift4/ose-console-rhel9:1790130905, openshift4/ose-console:1790102793. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.12; Red Hat OpenShift Container Platform 4.17; Red Hat OpenShift Container Platform 4.18; Red Hat OpenShift Container Platform 4.19; and 3 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.20; Red Hat OpenShift Container Platform 4.21; Red Hat OpenShift Container Platform 4.22.
High [CVE-2026-75886] Unauthenticated reverse proxy to in-cluster catalogd service with session token forwarding
Unauthenticated reverse proxy to in-cluster catalogd service with session token forwarding. Red Hat rates this important (CVSS 7.2). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:70617 with package openshift4/ose-console-rhel9:1789939565, openshift4/ose-console-rhel9:1789904865, openshift4/ose-console-rhel9:1790130905, openshift4/ose-console-rhel9:1790095950. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.17; Red Hat OpenShift Container Platform 4.18; Red Hat OpenShift Container Platform 4.19; Red Hat OpenShift Container Platform 4.20; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.21; Red Hat OpenShift Container Platform 4.22.
High [CVE-2026-67231] Trust-store whitelist by Issuer+Serial only
Trust-store whitelist by Issuer+Serial only. Red Hat rates this important (CVSS 8.1). Weakness: CWE-295.
High [CVE-2026-67232] RabbitMQ Web-MQTT plugin: Denial of Service via decompression bomb
RabbitMQ Web-MQTT plugin: Denial of Service via decompression bomb. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-67405] Cross-Site WebSocket Hijacking via missing Origin header validation
Cross-Site WebSocket Hijacking via missing Origin header validation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-1385. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-66077] Account takeover via stored Cross-Site Scripting in TLS peer-certificate DN
Account takeover via stored Cross-Site Scripting in TLS peer-certificate DN. Red Hat rates this important (CVSS 8.7). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-66079] Denial of Service via AMQP 1.0 array32 parsing
Denial of Service via AMQP 1.0 array32 parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-66070] Cross-Origin Resource Sharing (CORS) misconfiguration allows unauthorized actions
Cross-Origin Resource Sharing (CORS) misconfiguration allows unauthorized actions. Red Hat rates this important (CVSS 8.1). Weakness: CWE-942. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-96889] Use-after-free when XML includes have duplicated entities
Use-after-free when XML includes have duplicated entities. Red Hat rates this important (CVSS 7.8). Weakness: CWE-416. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: glycin-loaders; Red Hat package: librsvg2.
High [CVE-2026-85475] rsyslog configuration injection via LOG_AGGREGATOR_* settings leads to remote code execution in the control-plane rsyslog component
rsyslog configuration injection via LOG_AGGREGATOR_* settings leads to remote code execution in the control-plane rsyslog component. Red Hat rates this important (CVSS 7.2). Weakness: CWE-96. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-84714] incomplete sanitize_jinja regex allows Jinja template injection into ad-hoc module_args, Machine-credential fields, and Host names, reaching ansible-core templating in the execution environment
incomplete sanitize_jinja() regex allows Jinja template injection into ad-hoc module_args, Machine-credential fields, and Host names, reaching ansible-core templating in the execution environment. Red Hat rates this important (CVSS 7.1). Weakness: CWE-184. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.