Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11217 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium4.3Red Hat

Medium [CVE-2026-71461] Verbose internal exception disclosure via HostList bare-Exception handler

HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated user triggers Django FieldError (leaking complete Host model relation graph including internal reverse accessors) or PostgreSQL DataError (leaking raw database error strings). Two primitives: credential__search=x dumps ORM schema, name__regex=[bad reflects PostgreSQL errors. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-209. Affected Red Hat products: Red Hat Ansible Automation Platform 2.7; Red Hat Ansible Automation Platform 2. Red Hat fixing advisory: RHSA-2026:71177.

CVE-2026-71461
Unclassified
Sep 23, 2026
Medium4.3Red Hat

Medium [CVE-2026-71460] Any authenticated user reads Red Hat subscription/license details via /config/

/api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_id, sku, support_level, instance counts) returned to any authenticated user. The superuser/auditor gate only covers project_base_dir/project_local_paths/custom_virtualenvs, not license_info. Enables social engineering against Red Hat support and estate sizing reconnaissance. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-862. Affected Red Hat products: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.6; Red Hat Ansible Automation Platform 2.7. Red Hat fixing advisory: RHSA-2026:71114, RHSA-2026:71113, RHSA-2026:71179, RHSA-2026:71177.

CVE-2026-71460
Unclassified
Sep 23, 2026
Medium5.5Red Hat

Medium [CVE-2026-77420] Denial of Service vulnerability in history configuration processing

Denial of Service vulnerability in history configuration processing. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 13 (Queens).

CVE-2026-77420
Unclassified
Sep 23, 2026
Medium5.0Red Hat

Medium [CVE-2026-71459] JobJobEventsChildrenSummary RBAC bypass exposes cross-tenant job event tree structure

JobJobEventsChildrenSummary view has no model/parent_model. ModelAccessPermission.check_get_permissions() falls through (returns True) for any authenticated user. The view uses raw get_object_or_404(Job, pk) without DRF object-level permission check. Zero-privilege user reads event tree structure, event_processing_finished status, and enumerates Job IDs platform-wide via 200/404 oracle. Sibling endpoint /jobs/{id}/job_events/ correctly returns 403. Red Hat severity: Moderate — CVSS 5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N). Weakness: CWE-862. Affected Red Hat products: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.6; Red Hat Ansible Automation Platform 2.7. Red Hat fixing advisory: RHSA-2026:71114, RHSA-2026:71113, RHSA-2026:71179, RHSA-2026:71177.

CVE-2026-71459
Unclassified
Sep 23, 2026
Medium5.0Red Hat

Medium [CVE-2026-71458] Named-URL 404 body oracle enables cross-tenant resource name enumeration

URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before RBAC. The 403→404 shim only rewrites 403 responses, leaving the pk=0 miss path with a different 404 detail string. Differential "Not found." vs "No matches..." reveals whether a named resource (org, credential, inventory, host) exists anywhere on the platform. Enables cross-tenant internal hostname enumeration. Red Hat severity: Moderate — CVSS 5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N). Weakness: CWE-204. Affected Red Hat products: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.6; Red Hat Ansible Automation Platform 2.7. Red Hat fixing advisory: RHSA-2026:71114, RHSA-2026:71113, RHSA-2026:71179, RHSA-2026:71177.

CVE-2026-71458
Unclassified
Sep 23, 2026
Medium5.7Red Hat

Medium [CVE-2026-77421] Denial of Service in Nano Editor Regex Search

Denial of Service in Nano Editor Regex Search. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-1333. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 13 (Queens).

CVE-2026-77421
Unclassified
Sep 23, 2026
Medium5.3Red Hat

Medium [CVE-2026-88840] TLS ssl_server reads one byte out of bounds when parsing truncated ClientHello

TLS ssl_server reads one byte out of bounds when parsing truncated ClientHello. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125.

CVE-2026-88840
Unclassified
Sep 23, 2026
Medium6.7Red Hat

Medium [CVE-2026-88839] passwd/group parser writes heap pointers out of bounds due to stale tokenize endpoint

passwd/group parser writes heap pointers out of bounds due to stale tokenize() endpoint. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:72111 with package busybox-main-1.37.0-9.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-88839
Unclassified
Sep 23, 2026
Medium6.5Red Hat

Medium [CVE-2026-88837] httpd misidentifies yescrypt password hashes as plaintext, inverting authentication

httpd misidentifies yescrypt password hashes as plaintext, inverting authentication. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-305. Red Hat lists fixing advisory RHSA-2026:72111 with package busybox-main-1.37.0-9.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-88837
Unclassified
Sep 23, 2026
Medium6.1Red Hat

Medium [CVE-2026-88835] dpkg read_package_field steps past NUL terminator, causing out-of-bounds read on malformed.deb packages

dpkg read_package_field() steps past NUL terminator, causing out-of-bounds read on malformed.deb packages. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:72111 with package busybox-main-1.37.0-9.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-88835
Unclassified
Sep 23, 2026
Medium5.3Red Hat

Medium [CVE-2026-88831] httpd silently fails open when IP deny rules contain invalid CIDR prefix lengths

httpd silently fails open when IP deny rules contain invalid CIDR prefix lengths. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-636. Red Hat lists fixing advisory RHSA-2026:72111 with package busybox-main-1.37.0-9.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-88831
Unclassified
Sep 23, 2026
Medium4.5Red Hat

Medium [CVE-2026-96807] Low integrity or availability impact via symlink manipulation

Low integrity or availability impact via symlink manipulation. Red Hat rates this moderate (CVSS 4.5). Weakness: CWE-22. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: flatpak.

CVE-2026-96807
Red Hat Enterprise Linux
Sep 23, 2026
Medium5.9Red Hat

Medium [CVE-2026-6669] Denial of Service via unbounded SCRAM iteration count

Denial of Service via unbounded SCRAM iteration count. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:70698 with package pgbouncer-main-1.26.0-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-6669
Unclassified
Sep 23, 2026
Medium5.5Red Hat

Medium [CVE-2026-96675] Denial of Service via malicious ALSA configuration file

Denial of Service via malicious ALSA configuration file. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: alsa-lib.

CVE-2026-96675
Red Hat Enterprise Linux
Sep 23, 2026
Medium4.4Red Hat

Medium [CVE-2026-96674] Integer Overflow via Crafted Topology Files

Integer Overflow via Crafted Topology Files. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: alsa-lib.

CVE-2026-96674
Red Hat Enterprise Linux
Sep 23, 2026
Medium6.5Red Hat

Medium [CVE-2026-96276] Flatpak: flatpak: arbitrary write in host context via flatpak build-init

If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows `..` traversal. Red Hat estimates the CVSSv3.1 vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N. The SDK content is retrieved from a remote registry, so no local access to the victim's system is required by the attacker (AV:N), and the attacker needs no privileges of their own (PR:N). Once the developer builds against the malicious SDK, exploitation is deterministic: the extension point's directory field is resolved via g_file_resolve_relative_path, which does not reject.. components, allowing a crafted value such as directory=../../ to redirect the copy operation outside the build tree (AC:L). Meaningful user interaction is required, as the developer must actively choose to build against the untrusted SDK (UI:R). flatpak build-init runs entirely with the invoking developer's own privileges, so the impact is bounded by that user's existing filesystem access and no privilege boundary is crossed (S:U). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.

CVE-2026-96276
Red Hat Enterprise Linux
Sep 23, 2026
Medium6.5Red Hat

Medium [CVE-2026-96611] Data corruption and information disclosure via signed integer overflow in HEIF processing

Data corruption and information disclosure via signed integer overflow in HEIF processing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-96611
Unclassified
Sep 23, 2026
Medium4.8Red Hat Updated

Medium [CVE-2026-86247] Client certificate verification requirements can be down-graded via race condition

Client certificate verification requirements can be down-graded via race condition. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-366. Affected products named by the advisory: Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7.

CVE-2026-86247
Unclassified
Sep 23, 2026
Medium4.7Red Hat

Medium [CVE-2026-78253] Denial of Service via uncontrolled recursion in XML processing

Denial of Service via uncontrolled recursion in XML processing. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-776. Red Hat lists fixing advisory RHSA-2026:59393 with package qt6-qtbase-main-6.11.2-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat package: qt6.

CVE-2026-78253
Red Hat Enterprise Linux
Sep 23, 2026
Medium6.5Vendor: LowRed Hat Updated

Medium [CVE-2026-87022] WebSocket message smuggling via improper length handling

WebSocket message smuggling via improper length handling. Red Hat rates this low (CVSS 6.5). Weakness: CWE-130. Red Hat lists fixing advisory RHSA-2026:68257 with package tomcat11-main-11.0.26-0.1.hum1, tomcat10-main-10.1.60-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 8 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 6; and 4 more.

CVE-2026-87022
Red Hat Enterprise Linux
Sep 23, 2026

← All vendors