Red Hat Linux Security Advisories & CVEs
11225 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-94422] message filtering bypass via reply serial allows sandbox escape
message filtering bypass via reply serial allows sandbox escape. Red Hat rates this important (CVSS 8.8). Weakness: CWE-290. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: xdg-dbus-proxy.
High [CVE-2026-96512] TZ environment variable allows bypass of NOTBEFORE/NOTAFTER time-based authorization
TZ environment variable allows bypass of NOTBEFORE/NOTAFTER time-based authorization. Red Hat rates this important (CVSS 7.8). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:75571 with package sudo-0:1.9.17-10.p2.el10_2.7, sudo-0:1.9.17p2-3.el9_8.3, sudo-main-1.9.17-16.p2.2.hum1, sudo-0:1.9.5p2-2.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-86350] HTTP/2 request smuggling due to header mix-up
HTTP/2 request smuggling due to header mix-up. Red Hat rates this important (CVSS 7.2). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:68257 with package tomcat11-main-11.0.26-0.1.hum1, tomcat10-main-10.1.60-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 4 more. Affected products named by the advisory: Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7; Red Hat package: tomcat9.
High [CVE-2026-79677] Denial of Service due to lost asynchronous WebSocket write timeouts
Denial of Service due to lost asynchronous WebSocket write timeouts. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-772. Red Hat lists fixing advisory RHSA-2026:68257 with package tomcat11-main-11.0.26-0.1.hum1, tomcat10-main-10.1.60-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 8 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 6; and 4 more.
High [CVE-2026-78383] Denial of Service via AJP request
Denial of Service via AJP request. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:68257 with package tomcat11-main-11.0.26-0.1.hum1, tomcat10-main-10.1.60-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 8 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 6; and 4 more.
High [CVE-2026-77791] Denial of Service via busy wait during WebSocket close
Denial of Service via busy wait during WebSocket close. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Red Hat lists fixing advisory RHSA-2026:68257 with package tomcat11-main-11.0.26-0.1.hum1, tomcat10-main-10.1.60-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 4 more. Affected products named by the advisory: Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7; Red Hat package: tomcat9.
High [CVE-2026-76183] Authentication Bypass in WebSocket Endpoints
Authentication Bypass in WebSocket Endpoints. Red Hat rates this important (CVSS 7.4). Weakness: CWE-289. Red Hat lists fixing advisory RHSA-2026:68257 with package tomcat11-main-11.0.26-0.1.hum1, tomcat10-main-10.1.60-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 6 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7; and 2 more.
High [CVE-2024-53920 +1] arbitrary code execution in Flymake mode
arbitrary code execution in Flymake mode. Red Hat rates this important (CVSS 7.8). Weakness: CWE-94. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: emacs.
High [CVE-2026-42801] ASR Crane, Falcon: NULL pointer dereference allows pointer manipulation
ASR Crane, Falcon: NULL pointer dereference allows pointer manipulation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-476. Affected product named by the advisory: Red Hat OpenStack Platform 16.2.
High [CVE-2026-91777] com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Denial of Service via quadratic forward-reference completion
com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Denial of Service via quadratic forward-reference completion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Affected products named by the advisory: OpenShift Developer Tools and Services; Red Hat build of Quarkus; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-91776] Denial of Service via unbounded cache growth in TypeDeserializerBase
Denial of Service via unbounded cache growth in TypeDeserializerBase. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat build of Quarkus.
High [CVE-2026-89425] Denial of Service via unbounded StringBuilder growth during malformed token processing
Denial of Service via unbounded StringBuilder growth during malformed token processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Affected products named by the advisory: OpenShift Developer Tools and Services; OpenShift Serverless; Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; and 13 more. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; Red Hat Certificate System 10; and 9 more.
High [CVE-2026-84475] InventorySource.source_vars lacks prevent_search, enabling zero-privilege cross-tenant extraction of inline inventory-plugin credentials via the credential_types FieldLookupBackend count-oracle
InventorySource.source_vars lacks prevent_search, enabling zero-privilege cross-tenant extraction of inline inventory-plugin credentials via the credential_types FieldLookupBackend count-oracle. Red Hat rates this important (CVSS 7.7). Weakness: CWE-204. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-84644] server-side request forgery via the Thycotic Secret Server external credential plugin test endpoint (caller-controlled server_url, backend executed in the controller web process)
server-side request forgery via the Thycotic Secret Server external credential plugin test endpoint (caller-controlled server_url, backend executed in the controller web process). Red Hat rates this important (CVSS 7.4). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-84678] GALAXY_TASK_ENV setting is not filtered for dynamic-linker / interpreter environment variables, allowing a system administrator to achieve code execution in the project-update execution environment
GALAXY_TASK_ENV setting is not filtered for dynamic-linker / interpreter environment variables, allowing a system administrator to achieve code execution in the project-update execution environment. Red Hat rates this important (CVSS 8.7). Weakness: CWE-427. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-84686] notification template password fields can be decrypted by a notification-template administrator by replaying encrypted values across subfields, exposing plaintext Slack, PagerDuty, Twilio, AWS SNS …
notification template password fields can be decrypted by a notification-template administrator by replaying encrypted values across subfields, exposing plaintext Slack, PagerDuty, Twilio, AWS SNS and Grafana credentials. Red Hat rates this important (CVSS 7.6). Weakness: CWE-522. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-84689] bulk job launch allows setting a workflow node's job reference to an arbitrary unified job, enabling a low-privileged user to cancel and read metadata of jobs in other organizations
bulk job launch allows setting a workflow node's job reference to an arbitrary unified job, enabling a low-privileged user to cancel and read metadata of jobs in other organizations. Red Hat rates this important (CVSS 8.5). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-84692] workflow job template node execute permission check bypassed by creating a node with a null unified_job_template and then patching it, allowing a single workflow-admin to execute any other tenant's…
workflow job template node execute permission check bypassed by creating a node with a null unified_job_template and then patching it, allowing a single workflow-admin to execute any other tenant's job template with the victim's credentials (cross-tenant privilege escalation). Red Hat rates this important (CVSS 8.5). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-84708] container group pod_spec_override mints the automation-controller ServiceAccount token and mounts control-plane namespace secrets into job pods, bypassing automountServiceAccountToken:false (contro…
container group pod_spec_override mints the automation-controller ServiceAccount token and mounts control-plane namespace secrets into job pods, bypassing automountServiceAccountToken:false (control-plane secret and identity compromise). Red Hat rates this important (CVSS 8.7). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Medium [CVE-2026-59980] Denial of Service via malformed HTTP/2 header encoding
Denial of Service via malformed HTTP/2 header encoding. Red Hat rates this low (CVSS 5.3). Weakness: CWE-770. Affected products named by the advisory: Migration Toolkit for Containers; Red Hat Ansible Automation Platform 2; Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 17.1; and 1 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0.