Red Hat Linux Security Advisories & CVEs
4661 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-16645] Unauthorized access due to missing authorization
Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This missing authorization vulnerability allows an attacker to perform forceful browsing, potentially leading to unauthorized access to sensitive information or resources. By exploiting this flaw, an attacker can bypass intended access controls. This Important vulnerability in Drupal PhotoSwipe does not affect Red Hat products as the vulnerable code is not present in the versions shipped with Red Hat offerings. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-425. Red Hat lists Red Hat Developer Hub; Self-service automation portal 2 as not affected.
High [CVE-2026-68763] Denial of Service via HTTP/2 allocation leak
Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue. A remote attacker could exploit this to cause a Denial of Service (DoS), making the server unresponsive or unavailable to users. This Important flaw in Apache Tomcat, as shipped with Red Hat JBoss Web Server, allows a remote, unauthenticated attacker to cause a denial of service. The vulnerability stems from an allocation leak in the HTTP/2 backlog tracking, which can be triggered by resetting an HTTP/2 stream, leading to resource exhaustion and service unavailability. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected products named by the advisory: Red Hat JBoss Web Server 6.2.5; Red Hat JBoss Web Server 6.2 on RHEL 10; Red Hat JBoss Web Server 6.2 on RHEL 8; Red Hat JBoss Web Server 6.2 on RHEL 9; and 11 more.
High [CVE-2026-68569] Improper Authentication due to principal lookup failure
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue. This can lead to unauthorized access to the system. This Important vulnerability in Apache Tomcat allows unauthorized access when configured with CLIENT-CERT or SPNEGO authentication alongside a DataSourceRealm. This flaw could permit a user to be authenticated even if their account does not exist, bypassing intended security controls in Red Hat deployments where these specific configurations are in use. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N). Weakness: CWE-305. Affected products named by the advisory: Red Hat JBoss Web Server 6.2.5; Red Hat JBoss Web Server 6.2 on RHEL 10; Red Hat JBoss Web Server 6.2 on RHEL 8; Red Hat JBoss Web Server 6.2 on RHEL 9; and 11 more.
High [CVE-2026-80186] Stack Overflow in name2utf8 causes DoS and potential code execution
A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution. Red Hat severity: Important — CVSS 7.6 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: bluez.
High [CVE-2026-65927] Access control bypass due to off-by-one error in RewriteValve [N] flag processing
Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121 which fix the issue. This vulnerability may allow an attacker to bypass intended access controls. This vulnerability can lead to an access control bypass, allowing unauthorized access to resources in applications that utilize the RewriteValve with the [N] flag. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N). Weakness: CWE-193. Affected Red Hat products: Red Hat JBoss Web Server 6.2.5; Red Hat JBoss Web Server 6.2 on RHEL 10; Red Hat JBoss Web Server 6.2 on RHEL 8; Red Hat JBoss Web Server 6.2 on RHEL 9; Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 7.
High [CVE-2026-65182] Security constraint bypass due to improper access control
Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue. This Important vulnerability in Apache Tomcat allows for security constraint bypasses, potentially granting unauthorized access to protected web application resources. The flaw occurs when security constraints for longer URL paths are defined before more restrictive constraints for shorter, specific sub-paths within the application's `web.xml` configuration. This misconfiguration can undermine intended access controls in Red Hat deployments of Apache Tomcat. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N). Weakness: CWE-551. Affected products named by the advisory: Red Hat JBoss Web Server 6.2.5; Red Hat JBoss Web Server 6.2 on RHEL 10; Red Hat JBoss Web Server 6.2 on RHEL 8; Red Hat JBoss Web Server 6.2 on RHEL 9; and 11 more.
High [CVE-2026-79203] Improper input validation in DevTools
Improper input validation in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N). Weakness: CWE-1289.
High [CVE-2026-79013] Improper input validation in Sync
Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium) An improper input validation flaw was found in the Sync component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-201.
High [CVE-2026-79066] Improper input validation in Navigation
Improper input validation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 7.9 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N). Weakness: CWE-1286.
High [CVE-2026-78899] Use after free in V8
Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) An use after free flaw was found in the V8 component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825.
High [CVE-2026-68515] Heap out-of-bounds write in exrmultiview via crafted EXR files
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, exrmultiview can write past a heap allocation when it combines two attacker-supplied, individually valid scanline EXR files whose union dataWindow is not aligned to one view's channel subsampling. The utility allocates sampled channel storage using a truncated union_width / xSampling, then reads the sampled input through a Slice based on the misaligned union window, producing a heap out-of-bounds write. The trigger is normal public-tool processing, such as exrmultiview left A.exr right B.exr out.exr with crafted but valid inputs, so this is not solely an API or caller-precondition issue. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14. A flaw was found in OpenEXR. A remote attacker could exploit this vulnerability by providing specially crafted EXR image files to the exrmultiview utility. When processing these files, the utility can write beyond its allocated memory on the heap, leading to a heap out-of-bounds write. This could allow an attacker to achieve arbitrary code execution or cause a denial of service (DoS) on the affected system. Exploitation requires a local attacker to persuade a user to process specially crafted EXR image files.
High [CVE-2026-79992] local shell command injection through the user field in emacs tramp
A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution. This issue requires user interaction with a malicious file, limiting its remote exploitability. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-78. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: emacs.
High [CVE-2026-19913] Information disclosure via improper validation of ServiceUrl parameter
Information disclosure via improper validation of ServiceUrl parameter. Red Hat rates this important (CVSS 7.5). Weakness: CWE-918.
High [CVE-2026-55553] Credential leakage via cross-origin redirects
urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prior to 4.9.1 and 2.44.1, urllib follows redirects through followRedirect but reuses caller-supplied options across origins. In src/HttpClient.ts, #requestInternal recursively calls this.#requestInternal(nextUrl.href, options, requestContext), causing options.headers and auth or digestAuth values to be reused when the redirect target has a different scheme, host, or port. Authorization, Cookie, Proxy-Authorization, x-api-key, x-auth-token, and x-access-token can therefore be sent to an attacker-controlled redirected origin, exposing credentials intended for the original origin and potentially allowing reuse against the original partner API or related services. No user interaction is required. This issue is fixed in versions 2.44.1 and 4.9.1. A flaw was found in urllib. This HTTP client for Node.js can be exploited by a remote attacker due to improper handling of cross-origin redirects. When following redirects, urllib reuses sensitive request headers, such as Authorization and Cookie, across different origins. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-201.
High [CVE-2026-63075] QUIC ACK-only packet retention can cause memory exhaustion
Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection. Impact summary: A remote peer that can complete a QUIC handshake can cause connection-scoped memory growth which may lead to Denial of Service through memory exhaustion, especially with sustained traffic or many concurrent QUIC connections. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: When the OpenSSL QUIC stack sends an ACK-only packet, there is no requirement by the QUIC protocol that the peer will acknowledge that ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL implementation stores the metadata about the ACK frames regardless. In and of itself that's ok, but if a malicious peer establishes a connection, and then drives the connection such that ACK-only packets are forced from the OpenSSL implementation peer (i.e., by sending numerous PING frames), and then withholding any subsequent acks for ack-eliciting data, like legitimate data, said malicious peer can force inappropriate memory growth on the OpenSSL peer, potentially leading to a Denial of Service.
High [CVE-2026-79776] Authentication bypass leads to backend credential disclosure
rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler. Attackers can access the /debug/pprof/cmdline endpoint unauthenticated to retrieve the full process argv including backend credentials. A flaw was found in rclone. A remote attacker can bypass the authentication mechanism by accessing the `/debug/pprof/cmdline` endpoint. Successful exploitation allows an unauthenticated attacker to retrieve sensitive backend credentials, leading to information disclosure. This flaw is rated as Important because unauthenticated attackers can remotely access sensitive backend credentials from rclone instances running with the remote control daemon enabled. This bypasses the intended authentication, allowing for critical information disclosure. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-305. Red Hat lists Cryostat 4; Red Hat Advanced Cluster Management for Kubernetes 2 as not affected.
High [CVE-2026-79770] Denial of Service via crafted CSS selectors
Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into methods like Node#css, Node#at_css, and Searchable#search to cause exponential regex backtracking and denial of service. A flaw was found in Nokogiri. This injection can lead to regular expression denial of service (ReDoS) due to exponential regex backtracking, causing the application to become unresponsive. When processing untrusted user input passed to methods like Node#css, Node#at_css, or Searchable#search, an attacker can inject adversarial CSS selectors containing malicious string literals or identifiers. This triggers exponential regex backtracking within the parser, causing severe CPU exhaustion and leading to a Denial of Service (DoS) for the application thread. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1333. Red Hat lists Red Hat 3scale API Management Platform 2; Red Hat Satellite 6 as not affected.
High [CVE-2026-79674] Information disclosure via path traversal in corpus-reader constructors
NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCorpusReader constructors to access filesystem content and SQLite databases outside the pathsec sandbox boundary. A flaw was found in NLTK. A path traversal vulnerability exists in NLTK's corpus reader constructors LinThesaurusCorpusReader and PanLexLiteCorpusReader. An attacker capable of supplying arbitrary corpus root inputs can read files outside the intended data directory. Data exposure is restricted to files readable by the executing process user, and OS discretionary access controls or container isolation boundaries prevent privilege escalation beyond the application context. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-22. Affected Red Hat products: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.5; Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat OpenShift AI (RHOAI). Red Hat lists OpenShift Lightspeed as not affected. Will not fix / out of support: Exploit Intelligence; Red Hat Ansible Automation Platform 2. Red Hat fixing advisory: RHSA-2026:73987, RHSA-2026:69539.
High [CVE-2026-79675] NLTK before 3.10.3 JVM Argument Injection via Per-Call Options
NLTK before 3.10.3 JVM Argument Injection via Per-Call Options. Red Hat rates this important (CVSS 8.1). Weakness: CWE-88. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2025-71407] Nokogiri before 1.18.3 Stack Buffer Overflow and Use-After-Free
Nokogiri before 1.18.3 Stack Buffer Overflow and Use-After-Free. Red Hat rates this important (CVSS 8.1). Weakness: CWE-121.