Red Hat Linux Security Advisories & CVEs
11225 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-84706] Credential Type env-injector deny-list omits process-hijacking variables (BASH_ENV/LD_PRELOAD) allowing code execution in the execution environment
Credential Type env-injector deny-list omits process-hijacking variables (BASH_ENV/LD_PRELOAD) allowing code execution in the execution environment. Red Hat rates this important (CVSS 7.6). Weakness: CWE-184. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-84691] format string injection in the API 4XX error log setting discloses Django SECRET_KEY and database credentials to an administrator
format string injection in the API 4XX error log setting discloses Django SECRET_KEY and database credentials to an administrator. Red Hat rates this important (CVSS 8.7). Weakness: CWE-134. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-84683] stored cross-site scripting in the job stdout HTML view via ANSI OSC 8 hyperlink sequences (javascript: anchor) enabling session takeover
stored cross-site scripting in the job stdout HTML view via ANSI OSC 8 hyperlink sequences (javascript: anchor) enabling session takeover. Red Hat rates this important (CVSS 8.7). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-84499] write-only survey password recovered in plaintext via Schedule/WorkflowJobTemplateNode survey min/max validation error message
write-only survey password recovered in plaintext via Schedule/WorkflowJobTemplateNode survey min/max validation error message. Red Hat rates this moderate (CVSS 7.7). Weakness: CWE-209. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-84679] the AWX_TASK_ENV setting applies arbitrary environment variables to the control-plane web and task processes, enabling TLS interception of external credentials and code execution
the AWX_TASK_ENV setting applies arbitrary environment variables to the control-plane web and task processes, enabling TLS interception of external credentials and code execution. Red Hat rates this important (CVSS 8.7). Weakness: CWE-15. Red Hat lists fixing advisory RHSA-2026:71113 with package automation-controller-0:4.7.17-1.el9ap, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap, ansible-automation-platform-26/controller-rhel9:1789673739. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9.
High [CVE-2026-84486] unauthenticated debug scheduler-trigger endpoints (AllowAny, routed without DEBUG guard) allow advisory-lock starvation of job dispatch (DoS)
unauthenticated debug scheduler-trigger endpoints (AllowAny, routed without DEBUG guard) allow advisory-lock starvation of job dispatch (DoS). Red Hat rates this important (CVSS 8.2). Weakness: CWE-489. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, ansible-automation-platform-26/controller-rhel9:1789673739. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-76648] CopyAPIView.post missing read authorization check enables Job Template secret recovery
CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC. The get() handler (lines 988–991) explicitly guards with request.user.can_access(obj._class_, 'read', obj) — but post() (lines 1001–1010) does not. POST only checks: can_access(model, 'add', create_kwargs_check) can_access(model, 'copy_related', obj) For JobTemplate, can_add (awx/awx/main/access.py:1465–1520) gates on inventory.use_role + project.use_role + execution_environment.read_role — resource-level roles that do not imply read on the source JT — and can_copy_related (1522–1534) checks only credentials.use_role. None of these imply the caller can read the source JT. Red Hat severity: Important — CVSS 8.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N). Weakness: CWE-862. Affected Red Hat products: Red Hat Ansible Automation Platform 2.7; Red Hat Ansible Automation Platform 2. Red Hat fixing advisory: RHSA-2026:71177.
High [CVE-2026-77423] Denial of Service via user-controlled regular expressions
Denial of Service via user-controlled regular expressions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 13 (Queens).
High [CVE-2026-77422] Denial of Service via regular expression processing in built-in grep command
Denial of Service via regular expression processing in built-in grep command. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 13 (Queens).
High [CVE-2026-96541] Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake deadline
A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an attacker can prevent new RDP clients from connecting until a holding socket is closed. By holding open unauthenticated RDP sockets indefinitely, an attacker can exhaust the default global connection limit. Exploitation requires connecting from at least two distinct source IP addresses to fully utilize the default per-source and global connection limits. Existing authenticated RDP sessions remain unaffected. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-400. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gnome-remote-desktop.
High [CVE-2026-63132] OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack. Red Hat rates this important (CVSS 7.4). Weakness: CWE-208. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift GitOps.
High [CVE-2026-88832] romfs volume ID parsing performs unbounded memcpy into fixed-size label buffer, causing heap overflow
romfs volume ID parsing performs unbounded memcpy into fixed-size label buffer, causing heap overflow. Red Hat rates this important (CVSS 7.3). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:72111 with package busybox-main-1.37.0-9.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-88830] TLS Montgomery reduction allocates bytes instead of digits, causing a pre-auth heap buffer overflow
TLS Montgomery reduction allocates bytes instead of digits, causing a pre-auth heap buffer overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-131. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-96808] Local privilege escalation via symlink traversal in revokefs writer
Local privilege escalation via symlink traversal in revokefs writer. Red Hat rates this important (CVSS 7.8). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: flatpak.
High [CVE-2026-96804] Arbitrary Code Execution via Insecure Deserialization
Arbitrary Code Execution via Insecure Deserialization. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-96775] MLflow dspy: Arbitrary code execution via crafted MLmodel artifact
MLflow dspy: Arbitrary code execution via crafted MLmodel artifact. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-19888] Denial of Service via malformed SCRAM client-final-message
Denial of Service via malformed SCRAM client-final-message. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:70698 with package pgbouncer-main-1.26.0-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-6668] Denial of Service via integer overflow in packet buffer growth
Denial of Service via integer overflow in packet buffer growth. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:70698 with package pgbouncer-main-1.26.0-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-96275] Flatpak: flatpak: arbitrary write access as root via extra-data extraction
A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal. Red Hat estimates the CVSSv3.1 vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. Exploitation requires a user or administrator to add or trust a malicious or compromised Flatpak repository and then install or update an application from it. The malicious content is served over the network (AV:N), and the attacker needs only control over the repository content (PR:N). Meaningful user interaction is required, since a user/admin must actively configure the remote and initiate an install or update from it (UI:R). Because this is an unconstrained, attacker-controlled write as root, it is treated as equivalent to full system compromise: an attacker can overwrite files such as SSH authorized_keys, systemd units, cron entries, or setuid binaries, yielding full loss of confidentiality, integrity, and availability (C:H/I:H/A:H). Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-22.
High [CVE-2026-96577] Embedded local cache registry listens on all interfaces without authentication, with delete enabled
Embedded local cache registry listens on all interfaces without authentication, with delete enabled. Red Hat rates this important (CVSS 7.1). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:74383 with package openshift4/oc-mirror-plugin-rhel9:1790775357, openshift4/oc-mirror-plugin-rhel9:1790782357, openshift4/oc-mirror-plugin-rhel9:1790777129. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.20; Red Hat OpenShift Container Platform 4.21; Red Hat OpenShift Container Platform 4.22. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.19.