Red Hat Linux Security Advisories & CVEs
5615 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-91953] Heap buffer overflow via oversized LB_LOAD_BALANCE_INFO routing token can lead to heap corruption.
Heap buffer overflow via oversized LB_LOAD_BALANCE_INFO routing token can lead to heap corruption. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.
Medium [CVE-2026-91951] Denial of Service via out-of-bounds write in urbdrc client channel
Denial of Service via out-of-bounds write in urbdrc client channel. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.
Medium [CVE-2026-91946] Information Disclosure via RDPGFX ResetGraphics PDU
Information Disclosure via RDPGFX ResetGraphics PDU. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-824. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.
Medium [CVE-2026-91945] Denial of Service due to out-of-bounds read in smartcard response processing
Denial of Service due to out-of-bounds read in smartcard response processing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.
Medium [CVE-2024-58384] CRLF injection in CurlAsyncHTTPClient allows arbitrary header injection or new HTTP requests.
CRLF injection in CurlAsyncHTTPClient allows arbitrary header injection or new HTTP requests. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-93. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 11 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 7 more.
Medium [CVE-2026-55701] github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver: OpenTelemetry Collector Contrib githubreceiver: Unauthorized data injection via authentication bypass
github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver: OpenTelemetry Collector Contrib githubreceiver: Unauthorized data injection via authentication bypass. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:63152 with package opentelemetry-collector-contrib-main-0.160.0-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-54168] github.com/openshift-pipelines/pipelines-as-code: Pipelines-as-Code: Information disclosure via unscoped GitHub App installation token
github.com/openshift-pipelines/pipelines-as-code: Pipelines-as-Code: Information disclosure via unscoped GitHub App installation token. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-862.
Medium [CVE-2026-90439] NGINX ngx_http_v3_module: Denial of Service via TLS handshake heap buffer overflow
NGINX ngx_http_v3_module: Denial of Service via TLS handshake heap buffer overflow. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:67977 with package nginx-main-1.30.5-4.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-92059] Incorrect boundary conditions in the DOM: Editor component
Incorrect boundary conditions in the DOM: Editor component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-787.
Medium [CVE-2026-92058] Use-after-free in the Graphics component
Use-after-free in the Graphics component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825.
Medium [CVE-2026-92057] Mitigation bypass in the Enterprise Policies component
Mitigation bypass in the Enterprise Policies component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-1220.
Medium [CVE-2026-92056] Use-after-free in the Graphics: Text component
Use-after-free in the Graphics: Text component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825.
Medium [CVE-2026-92055] Privilege escalation in the DevTools component
Privilege escalation in the DevTools component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-368.
Medium [CVE-2026-92054] Privilege escalation in the Memory component
Privilege escalation in the Memory component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825.
Medium [CVE-2026-92053] Privilege escalation in the Graphics: CanvasWebGL component
Privilege escalation in the Graphics: CanvasWebGL component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-266.
Medium [CVE-2026-92052] Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component
Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-824.
Medium [CVE-2026-92050] Sandbox escape due to race condition in the XPConnect component
Sandbox escape due to race condition in the XPConnect component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-368.
Medium [CVE-2026-92049] Use-after-free in the Widget: Win32 component
Use-after-free in the Widget: Win32 component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825.
Medium [CVE-2026-92048] Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-501.
Medium [CVE-2026-92047] Privilege escalation in the Crash Reporting component
Privilege escalation in the Crash Reporting component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-266.