Red Hat Linux Security Advisories & CVEs
11225 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-67221] Information disclosure of AMQP 1.0 shovel URI passwords
Information disclosure of AMQP 1.0 shovel URI passwords. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-256. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-67218] Privilege escalation via super-stream HTTP creation
Privilege escalation via super-stream HTTP creation. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-862. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-66074] Denial of Service via management API regular expression filter
Denial of Service via management API regular expression filter. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-66075] Monitoring user can disrupt message flow via authorization flaw
Monitoring user can disrupt message flow via authorization flaw. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-862. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-67219] Denial of Service via unbounded consistent-hash exchange weight
Denial of Service via unbounded consistent-hash exchange weight. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-606. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-67228] Denial of Service via atom exhaustion in runtime-parameter component
Denial of Service via atom exhaustion in runtime-parameter component. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-67235] Denial of Service via AMQP 0-9-1 body size validation bypass
Denial of Service via AMQP 0-9-1 body size validation bypass. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-66068] Information disclosure of decrypted Shovel URIs in debug logs
Information disclosure of decrypted Shovel URIs in debug logs. Red Hat rates this moderate (CVSS 4.1). Weakness: CWE-215. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-67229] Denial of Service via admin-only atom exhaustion from crafted vhost metadata
Denial of Service via admin-only atom exhaustion from crafted vhost metadata. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-66080] Denial of Service via unbounded super-stream partition allocation
Denial of Service via unbounded super-stream partition allocation. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-67240] Denial of Service via crafted AMQP 1.0 SQL LIKE filter
Denial of Service via crafted AMQP 1.0 SQL LIKE filter. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-66072] Denial of Service via atom table exhaustion in stream chunk_selector
Denial of Service via atom table exhaustion in stream chunk_selector. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-66067] Authenticated user can bypass connection limits via stream protocol
Authenticated user can bypass connection limits via stream protocol. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1220. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-66069] Monitoring user can reset authentication attempt counters
Monitoring user can reset authentication attempt counters. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-862. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-67220] Denial of Service via JMS topic exchange atom exhaustion
Denial of Service via JMS topic exchange atom exhaustion. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-67224] Administrator path traversal allows arbitrary file write
Administrator path traversal allows arbitrary file write. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-67238] Denial of Service due to atom-table exhaustion via reply-to queue name decoding
Denial of Service due to atom-table exhaustion via reply-to queue name decoding. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-66076] Information disclosure via cross-vhost authorization bypass
Information disclosure via cross-vhost authorization bypass. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-639. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-84724] SystemJob extra_vars.days argument injection into uncontainerized control-plane awx-manage process
SystemJob extra_vars.days argument injection into uncontainerized control-plane awx-manage process. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-88. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, automation-controller-0:4.6.33-1.el9ap, automation-controller-0:4.6.33-1.el8ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Medium [CVE-2026-84721] Email notification backend allows SSRF via user-controlled SMTP host/port (internal port-scan oracle, SMTP password exfil)
Email notification backend allows SSRF via user-controlled SMTP host/port (internal port-scan oracle, SMTP password exfil). Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:71177 with package ansible-automation-platform-27/controller-rhel9:1789580684. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.7.