Red Hat Linux Security Advisories & CVEs
3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-8286] Insecure connection establishment due to TLS configuration mismatch
Insecure connection establishment due to TLS configuration mismatch. Red Hat rates this important (CVSS 8.1). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:29017 with package rust-main-1.96.1-1.hum1, curl-main-8.21.0-0.1.hum1.
High [CVE-2026-12064] SSH host verification bypass when using schemeless URLs with SFTP/SCP
SSH host verification bypass when using schemeless URLs with SFTP/SCP. Red Hat rates this important (CVSS 7.5). Weakness: CWE-358. Red Hat lists fixing advisory RHSA-2026:29017 with package rust-main-1.96.1-1.hum1, curl-main-8.21.0-0.1.hum1.
High [CVE-2026-11586] Denial of Service via WebSocket PING flood
Denial of Service via WebSocket PING flood. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:29017 with package rust-main-1.96.1-1.hum1, curl-main-8.21.0-0.1.hum1.
High [CVE-2026-11352] Remote denial of service via QUIC UDP receive function vulnerability
Remote denial of service via QUIC UDP receive function vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:29017 with package rust-main-1.96.1-1.hum1, curl-main-8.21.0-0.1.hum1.
High [CVE-2026-58467] Arbitrary file read and code execution via path traversal
Arbitrary file read and code execution via path traversal. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22.
High [CVE-2026-55952] Denial of Service in TLS 1.3 session ticket handling
Denial of Service in TLS 1.3 session ticket handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-130.
High [CVE-2026-11946] Denial of Service via unvalidated endpoint URL length
Denial of Service via unvalidated endpoint URL length. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284.
High [CVE-2026-9563] Denial of Service via uncontrolled resource consumption in JSON parsing
Denial of Service via uncontrolled resource consumption in JSON parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-8147] Unauthorized access to trace data due to missing authorization validation
Unauthorized access to trace data due to missing authorization validation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-425.
High [CVE-2026-53357] fix UAF in l2cap_sock_cleanup_listen vs l2cap_conn_del
fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-366.
High [CVE-2026-55153] Remote code execution via JNDI injection
Remote code execution via JNDI injection. Red Hat rates this important (CVSS 7.5). Weakness: CWE-502.
High [CVE-2026-14363] SQL Injection vulnerability
SQL Injection vulnerability. Red Hat rates this important (CVSS 7.3). Weakness: CWE-89.
High [CVE-2026-53492] Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration.
Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration. Red Hat rates this important (CVSS 8.2). Weakness: CWE-807. Red Hat lists fixing advisory RHSA-2026:42852 with package multicluster-globalhub/multicluster-globalhub-agent-rhel9:1784061472, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784060681, rhacm2/submariner-rhel9-operator:1782933193, multicluster-globalhub/multicluster-globalhub-agent-rhel9:1784127491.
High [CVE-2026-46680] Privilege escalation via incorrect user ID handling
Privilege escalation via incorrect user ID handling. Red Hat rates this important (CVSS 7.8). Weakness: CWE-681. Red Hat lists fixing advisory RHSA-2026:35111 with package trivy-main-0.72.0-0.1.hum1.
High [CVE-2026-54428] org.apache.httpcomponents.core5/httpcore5: org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks
org.apache.httpcomponents.core5/httpcore5: org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-54399] org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers
org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-20243] Denial of Service via crafted ALZ file
Denial of Service via crafted ALZ file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-20244] Denial of Service via crafted DMG file
Denial of Service via crafted DMG file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190.
High [CVE-2026-20215] Denial of Service via crafted 7z file
Denial of Service via crafted 7z file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-20217] Denial of Service via crafted PESpin file
Denial of Service via crafted PESpin file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.