Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4632 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Red Hat

High [CVE-2025-61164] Information Leak via WebSocket Endpoint

Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint. A remote attacker could exploit this to gain unauthorized access to sensitive data. An unauthenticated remote attacker can establish a connection or interact with the endpoint to intercept sensitive data exchanged through active channels. Under default Red Hat container deployment standards, risk is limited to data handled by the service instance itself, though sensitive API responses or telemetry may still be exposed without requiring elevated privileges. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-319. Affected Red Hat products: Red Hat OpenShift AI (RHOAI). Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2025-61164
Unclassified
Aug 26, 2026
High7.5Red Hat

High [CVE-2025-61162] Arbitrary user information overwrite via incorrect access control

Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted request to the /api/internal/v1/users/{{USER_ID}} endpoint This action enables the attacker to arbitrarily overwrite user information. The primary impact is unauthorized modification of user data. An unauthenticated remote attacker can exploit this flaw by issuing a specially crafted request to overwrite arbitrary user profile information. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-639. Affected Red Hat products: Red Hat OpenShift AI (RHOAI). Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2025-61162
Unclassified
Aug 26, 2026
High7.5Red Hat

High [CVE-2026-26445] Denial of Service via partial STOMP frames

stomper 5e2741e is vulnerable to Denial of Service. A malicious client can send partial STOMP frames and keep the TCP connections open, which, combined with the broker s use of edge-triggered epoll (EPOLLET) and MSG_PEEK in recv(), causes sockets to enter a permanent half-read state. When enough such connections accumulate, the broker stops receiving any further epoll events for those sockets and eventually hangs in epoll_wait, effectively refusing to process new messages. A flaw was found in stomper. A remote attacker can exploit this by sending partial STOMP (Streaming Text Oriented Messaging Protocol) frames. Consequently, the broker stops processing new messages, leading to a Denial of Service (DoS) for legitimate users. A remote unauthenticated attacker can cause a Denial of Service by sending partial STOMP frames over open TCP connections. Red Hat default security controls (e.g., non-root execution, process isolation) do not prevent this service-level socket starvation, though network boundaries can limit exposure. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-772.

CVE-2026-26445
Unclassified
Aug 26, 2026
High7.5Red Hat

High [CVE-2026-26447] Denial of Service via Use-After-Free vulnerability

Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same destination over one connection and then closes that connection, the broker performs incorrect cleanup of its internal subscription structures. This results in a heap use-after-free during StompClient destruction, causing the broker process to crash. An unauthenticated client can exploit this to reliably trigger a denial of service. A flaw was found in Stomper. This leads to incorrect cleanup of internal subscription structures, resulting in a heap use-after-free during StompClient destruction. Successful exploitation causes the broker process to crash, leading to a denial of service. A remote, unauthenticated attacker can exploit this by repeatedly issuing SUBSCRIBE commands for the same destination over a single connection and subsequently closing the connection. RHEL default security controls like address space layout randomization (ASLR) and process isolation limit this impact to a Denial of Service against the broker process, without granting arbitrary code execution. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-825.

CVE-2026-26447
Unclassified
Aug 26, 2026
High7.5Red Hat

High [CVE-2026-26449] Denial of Service via missing destination header in SEND frame

In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null pointer dereference (or access to invalid memory) while processing the frame, causing the process to crash. A flaw was found in Stomper. A remote attacker can send a specially crafted message, specifically a SEND frame missing the destination header field, to the server. This vulnerability leads to a Denial of Service (DoS), making the server unavailable to legitimate users. Red Hat default security controls, such as process isolation and non-root execution environments, mitigate the issue by preventing privilege escalation or arbitrary code execution beyond a Denial of Service against the message broker. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-476.

CVE-2026-26449
Unclassified
Aug 26, 2026
High7.5Red Hat

High [CVE-2026-26448] Denial of Service via Use-After-Free

Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, and subsequently another client (or a later connection) sends SEND frames to a destination previously subscribed on that connection, the broker may dereference a pointer to a StompStreamSocket object that has already been freed. This results in a heap use-after-free and process crash. Because the protocol does not authenticate or restrict such sequences by default. A flaw was found in Stomper. A remote attacker can trigger a use-after-free vulnerability by sending multiple CONNECT frames on the same TCP connection, followed by SEND frames to a previously subscribed destination. This sequence causes the broker to dereference a freed StompStreamSocket object, triggering a heap corruption and crashing the broker process. Red Hat default security controls (such as process isolation and non-root execution boundaries) constrain the issue to a Denial of Service against the messaging daemon, preventing arbitrary code execution. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-825.

CVE-2026-26448
Unclassified
Aug 26, 2026
High7.5Red Hat

High [CVE-2026-26446] Denial of Service due to improper handling of closed TCP connections

Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, the server process receives SIGPIPE and immediately terminates, resulting in a denial of service. Any unauthenticated client can trigger the crash by closing the socket at specific points. A flaw was found in Stomper. This action causes the server process to receive a SIGPIPE signal, leading to its immediate termination and a denial of service for legitimate users. Because the process fails to ignore or handle SIGPIPE during active write operations, the daemon terminates abruptly. Red Hat default security controls (such as process isolation and systemd service auto-restart directives) restrict the failure strictly to an availability impact on the message broker service, without allowing privilege escalation or memory corruption. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-248.

CVE-2026-26446
Unclassified
Aug 26, 2026
High7.7Red Hat

High [CVE-2026-57171] Arbitrary file write via path traversal in author generate commands

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author commands write generated Markdown to an attacker-influenced output path without path-traversal validation, allowing arbitrary file write outside the Trestle workspace. These commands join the user-supplied output argument onto the Trestle root and write to the result, but guard it only with an is_directory_name_allowed() task-name-collision check rather than the PathSecurityValidator.validate_local_path() guard used by the jinja command, so an absolute path or one containing traversal sequences escapes the workspace and writes files under an attacker-chosen location as the invoking process owner. The security boundary is crossed when a trusted CI job, shared service, or wrapper derives the output argument from repository-controlled, tenant-controlled, or otherwise untrusted data while expecting output to stay inside the workspace. When --force-overwrite is used, the selected output directory is first recursively deleted, extending the primitive to destruction of an attacker-chosen directory tree and enabling indirect code execution by overwriting files a pipeline later runs. This issue is fixed in versions 3.12.4 and 4.1.0.

CVE-2026-57171
Unclassified
Aug 25, 2026
High7.8Red Hat

High [CVE-2026-57170] Arbitrary code execution via Server-Side Template Injection

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse the content of an included Markdown file as Jinja2 template code in a non-sandboxed environment, allowing server-side template injection that can lead to arbitrary code execution. The MDSectionInclude and MDCleanInclude tags in Trestle/core/jinja/tags.py pass included file content to Parser(self.environment,...).parse(), splicing it into the host template's compilation, and the environment is a plain jinja2.Environment rather than a SandboxedEnvironment, so any expressions in the file are evaluated with full access to the usual SSTI gadget chain. Because Trestle's Markdown writers emit OSCAL prose and component-description fields verbatim, applying delimiter neutralization only to parameter tables, attacker-controlled OSCAL data such as a control statement, part prose, or component description containing Jinja2 syntax flows into an included Markdown file and is executed when the include tag re-parses it. This issue is fixed in version 4.1.0. This vulnerability, known as Server-Side Template Injection (SSTI), allows an attacker to embed malicious Jinja2 syntax within OSCAL data.

CVE-2026-57170
Unclassified
Aug 25, 2026
High8.1Red Hat

High [CVE-2026-52776] Server-Side Request Forgery (SSRF) bypass via IPv4-mapped IPv6 and 0.0.0.0

Server-Side Request Forgery (SSRF) bypass via IPv4-mapped IPv6 and 0.0.0.0. Red Hat rates this important (CVSS 8.1). Weakness: CWE-1289. Affected product named by the advisory: File Integrity Operator.

CVE-2026-52776
Unclassified
Aug 25, 2026
High7.8Red Hat

High [CVE-2026-54757] Remote Code Execution via Server-Side Template Injection

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server-side template injection that can lead to remote code execution. This occurs because the MDCleanInclude and MDSectionInclude Jinja2 tags re-parse untrusted Markdown content as template source code using a non-sandboxed jinja2.Environment. An attacker who controls content that Trestle renders, such as a crafted workspace Markdown file, a third-party SSP document, or a YAML lookup-table value, can inject a Jinja2 expression that traverses Python object internals to execute arbitrary operating system commands in the context of the Trestle process. This issue is fixed in versions 3.12.4 and 4.1.0. This allows for remote code execution, enabling the attacker to run arbitrary operating system commands within the Trestle process. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-917. Affected Red Hat products: File Integrity Operator. Red Hat lists Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-54757
Unclassified
Aug 25, 2026
High7.5Red Hat

High [CVE-2026-16645] Unauthorized access due to missing authorization

Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This missing authorization vulnerability allows an attacker to perform forceful browsing, potentially leading to unauthorized access to sensitive information or resources. By exploiting this flaw, an attacker can bypass intended access controls. This Important vulnerability in Drupal PhotoSwipe does not affect Red Hat products as the vulnerable code is not present in the versions shipped with Red Hat offerings. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-425. Red Hat lists Red Hat Developer Hub; Self-service automation portal 2 as not affected.

CVE-2026-16645
Unclassified
Aug 25, 2026
High7.5Red Hat

High [CVE-2026-68763] Denial of Service via HTTP/2 allocation leak

Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue. A remote attacker could exploit this to cause a Denial of Service (DoS), making the server unresponsive or unavailable to users. This Important flaw in Apache Tomcat, as shipped with Red Hat JBoss Web Server, allows a remote, unauthenticated attacker to cause a denial of service. The vulnerability stems from an allocation leak in the HTTP/2 backlog tracking, which can be triggered by resetting an HTTP/2 stream, leading to resource exhaustion and service unavailability. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected products named by the advisory: Red Hat JBoss Web Server 6.2.5; Red Hat JBoss Web Server 6.2 on RHEL 10; Red Hat JBoss Web Server 6.2 on RHEL 8; Red Hat JBoss Web Server 6.2 on RHEL 9; and 11 more.

CVE-2026-68763
Red Hat Enterprise Linux
Aug 25, 2026
High8.2Red Hat

High [CVE-2026-68569] Improper Authentication due to principal lookup failure

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue. This can lead to unauthorized access to the system. This Important vulnerability in Apache Tomcat allows unauthorized access when configured with CLIENT-CERT or SPNEGO authentication alongside a DataSourceRealm. This flaw could permit a user to be authenticated even if their account does not exist, bypassing intended security controls in Red Hat deployments where these specific configurations are in use. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N). Weakness: CWE-305. Affected products named by the advisory: Red Hat JBoss Web Server 6.2.5; Red Hat JBoss Web Server 6.2 on RHEL 10; Red Hat JBoss Web Server 6.2 on RHEL 8; Red Hat JBoss Web Server 6.2 on RHEL 9; and 11 more.

CVE-2026-68569
Red Hat Enterprise Linux
Aug 25, 2026
High7.6Red Hat

High [CVE-2026-80186] Stack Overflow in name2utf8 causes DoS and potential code execution

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution. Red Hat severity: Important — CVSS 7.6 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: bluez.

CVE-2026-80186
Red Hat Enterprise Linux
Aug 25, 2026
High8.2Red Hat

High [CVE-2026-65927] Access control bypass due to off-by-one error in RewriteValve [N] flag processing

Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121 which fix the issue. This vulnerability may allow an attacker to bypass intended access controls. This vulnerability can lead to an access control bypass, allowing unauthorized access to resources in applications that utilize the RewriteValve with the [N] flag. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N). Weakness: CWE-193. Affected Red Hat products: Red Hat JBoss Web Server 6.2.5; Red Hat JBoss Web Server 6.2 on RHEL 10; Red Hat JBoss Web Server 6.2 on RHEL 8; Red Hat JBoss Web Server 6.2 on RHEL 9; Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 7.

CVE-2026-65927
Red Hat Enterprise Linux
Aug 25, 2026
High8.2Red Hat

High [CVE-2026-65182] Security constraint bypass due to improper access control

Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue. This Important vulnerability in Apache Tomcat allows for security constraint bypasses, potentially granting unauthorized access to protected web application resources. The flaw occurs when security constraints for longer URL paths are defined before more restrictive constraints for shorter, specific sub-paths within the application's `web.xml` configuration. This misconfiguration can undermine intended access controls in Red Hat deployments of Apache Tomcat. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N). Weakness: CWE-551. Affected products named by the advisory: Red Hat JBoss Web Server 6.2.5; Red Hat JBoss Web Server 6.2 on RHEL 10; Red Hat JBoss Web Server 6.2 on RHEL 8; Red Hat JBoss Web Server 6.2 on RHEL 9; and 11 more.

CVE-2026-65182
Red Hat Enterprise Linux
Aug 25, 2026
High8.7Red Hat

High [CVE-2026-79203] Improper input validation in DevTools

Improper input validation in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N). Weakness: CWE-1289.

CVE-2026-79203
Unclassified
Aug 25, 2026
High7.5Red Hat

High [CVE-2026-79013] Improper input validation in Sync

Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium) An improper input validation flaw was found in the Sync component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-201.

CVE-2026-79013
Unclassified
Aug 25, 2026
High7.9Red Hat

High [CVE-2026-79066] Improper input validation in Navigation

Improper input validation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 7.9 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N). Weakness: CWE-1286.

CVE-2026-79066
Unclassified
Aug 25, 2026

← All vendors