Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.1Red Hat

High [CVE-2026-8286] Insecure connection establishment due to TLS configuration mismatch

Insecure connection establishment due to TLS configuration mismatch. Red Hat rates this important (CVSS 8.1). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:29017 with package rust-main-1.96.1-1.hum1, curl-main-8.21.0-0.1.hum1.

CVE-2026-8286
Unclassified
Jul 3, 2026
High7.5Red Hat

High [CVE-2026-12064] SSH host verification bypass when using schemeless URLs with SFTP/SCP

SSH host verification bypass when using schemeless URLs with SFTP/SCP. Red Hat rates this important (CVSS 7.5). Weakness: CWE-358. Red Hat lists fixing advisory RHSA-2026:29017 with package rust-main-1.96.1-1.hum1, curl-main-8.21.0-0.1.hum1.

CVE-2026-12064
Unclassified
Jul 3, 2026
High7.5Red Hat

High [CVE-2026-11586] Denial of Service via WebSocket PING flood

Denial of Service via WebSocket PING flood. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:29017 with package rust-main-1.96.1-1.hum1, curl-main-8.21.0-0.1.hum1.

CVE-2026-11586
Unclassified
Jul 3, 2026
High7.5Red Hat

High [CVE-2026-11352] Remote denial of service via QUIC UDP receive function vulnerability

Remote denial of service via QUIC UDP receive function vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:29017 with package rust-main-1.96.1-1.hum1, curl-main-8.21.0-0.1.hum1.

CVE-2026-11352
Unclassified
Jul 3, 2026
High7.5Red Hat

High [CVE-2026-58467] Arbitrary file read and code execution via path traversal

Arbitrary file read and code execution via path traversal. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22.

CVE-2026-58467
Unclassified
Jul 2, 2026
High7.5Red Hat

High [CVE-2026-55952] Denial of Service in TLS 1.3 session ticket handling

Denial of Service in TLS 1.3 session ticket handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-130.

CVE-2026-55952
Unclassified
Jul 2, 2026
High7.5Red Hat

High [CVE-2026-11946] Denial of Service via unvalidated endpoint URL length

Denial of Service via unvalidated endpoint URL length. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284.

CVE-2026-11946
Unclassified
Jul 2, 2026
High7.5Red Hat

High [CVE-2026-9563] Denial of Service via uncontrolled resource consumption in JSON parsing

Denial of Service via uncontrolled resource consumption in JSON parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-9563
Unclassified
Jul 2, 2026
High8.1Red Hat

High [CVE-2026-8147] Unauthorized access to trace data due to missing authorization validation

Unauthorized access to trace data due to missing authorization validation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-425.

CVE-2026-8147
Unclassified
Jul 2, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-53357] fix UAF in l2cap_sock_cleanup_listen vs l2cap_conn_del

fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-366.

CVE-2026-53357
Unclassified
Jul 2, 2026
High7.5Red Hat

High [CVE-2026-55153] Remote code execution via JNDI injection

Remote code execution via JNDI injection. Red Hat rates this important (CVSS 7.5). Weakness: CWE-502.

CVE-2026-55153
Unclassified
Jul 1, 2026
High7.3Red Hat

High [CVE-2026-14363] SQL Injection vulnerability

SQL Injection vulnerability. Red Hat rates this important (CVSS 7.3). Weakness: CWE-89.

CVE-2026-14363
Unclassified
Jul 1, 2026
High8.2Red Hat

High [CVE-2026-53492] Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration.

Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration. Red Hat rates this important (CVSS 8.2). Weakness: CWE-807. Red Hat lists fixing advisory RHSA-2026:42852 with package multicluster-globalhub/multicluster-globalhub-agent-rhel9:1784061472, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784060681, rhacm2/submariner-rhel9-operator:1782933193, multicluster-globalhub/multicluster-globalhub-agent-rhel9:1784127491.

CVE-2026-53492
Unclassified
Jul 1, 2026
High7.8Red Hat

High [CVE-2026-46680] Privilege escalation via incorrect user ID handling

Privilege escalation via incorrect user ID handling. Red Hat rates this important (CVSS 7.8). Weakness: CWE-681. Red Hat lists fixing advisory RHSA-2026:35111 with package trivy-main-0.72.0-0.1.hum1.

CVE-2026-46680
Unclassified
Jul 1, 2026
High7.5Red Hat

High [CVE-2026-54428] org.apache.httpcomponents.core5/httpcore5: org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks

org.apache.httpcomponents.core5/httpcore5: org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-54428
Unclassified
Jul 1, 2026
High7.5Red Hat

High [CVE-2026-54399] org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers

org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-54399
Unclassified
Jul 1, 2026
High7.5Red Hat

High [CVE-2026-20243] Denial of Service via crafted ALZ file

Denial of Service via crafted ALZ file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-20243
Unclassified
Jul 1, 2026
High7.5Red Hat

High [CVE-2026-20244] Denial of Service via crafted DMG file

Denial of Service via crafted DMG file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190.

CVE-2026-20244
Unclassified
Jul 1, 2026
High7.5Red Hat

High [CVE-2026-20215] Denial of Service via crafted 7z file

Denial of Service via crafted 7z file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-20215
Unclassified
Jul 1, 2026
High7.5Red Hat

High [CVE-2026-20217] Denial of Service via crafted PESpin file

Denial of Service via crafted PESpin file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-20217
Unclassified
Jul 1, 2026

← All vendors