Red Hat Linux Security Advisories & CVEs
11217 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-71461] Verbose internal exception disclosure via HostList bare-Exception handler
HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated user triggers Django FieldError (leaking complete Host model relation graph including internal reverse accessors) or PostgreSQL DataError (leaking raw database error strings). Two primitives: credential__search=x dumps ORM schema, name__regex=[bad reflects PostgreSQL errors. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-209. Affected Red Hat products: Red Hat Ansible Automation Platform 2.7; Red Hat Ansible Automation Platform 2. Red Hat fixing advisory: RHSA-2026:71177.
Medium [CVE-2026-71460] Any authenticated user reads Red Hat subscription/license details via /config/
/api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_id, sku, support_level, instance counts) returned to any authenticated user. The superuser/auditor gate only covers project_base_dir/project_local_paths/custom_virtualenvs, not license_info. Enables social engineering against Red Hat support and estate sizing reconnaissance. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-862. Affected Red Hat products: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.6; Red Hat Ansible Automation Platform 2.7. Red Hat fixing advisory: RHSA-2026:71114, RHSA-2026:71113, RHSA-2026:71179, RHSA-2026:71177.
Medium [CVE-2026-77420] Denial of Service vulnerability in history configuration processing
Denial of Service vulnerability in history configuration processing. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 13 (Queens).
Medium [CVE-2026-71459] JobJobEventsChildrenSummary RBAC bypass exposes cross-tenant job event tree structure
JobJobEventsChildrenSummary view has no model/parent_model. ModelAccessPermission.check_get_permissions() falls through (returns True) for any authenticated user. The view uses raw get_object_or_404(Job, pk) without DRF object-level permission check. Zero-privilege user reads event tree structure, event_processing_finished status, and enumerates Job IDs platform-wide via 200/404 oracle. Sibling endpoint /jobs/{id}/job_events/ correctly returns 403. Red Hat severity: Moderate — CVSS 5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N). Weakness: CWE-862. Affected Red Hat products: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.6; Red Hat Ansible Automation Platform 2.7. Red Hat fixing advisory: RHSA-2026:71114, RHSA-2026:71113, RHSA-2026:71179, RHSA-2026:71177.
Medium [CVE-2026-71458] Named-URL 404 body oracle enables cross-tenant resource name enumeration
URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before RBAC. The 403→404 shim only rewrites 403 responses, leaving the pk=0 miss path with a different 404 detail string. Differential "Not found." vs "No matches..." reveals whether a named resource (org, credential, inventory, host) exists anywhere on the platform. Enables cross-tenant internal hostname enumeration. Red Hat severity: Moderate — CVSS 5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N). Weakness: CWE-204. Affected Red Hat products: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.6; Red Hat Ansible Automation Platform 2.7. Red Hat fixing advisory: RHSA-2026:71114, RHSA-2026:71113, RHSA-2026:71179, RHSA-2026:71177.
Medium [CVE-2026-77421] Denial of Service in Nano Editor Regex Search
Denial of Service in Nano Editor Regex Search. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-1333. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 13 (Queens).
Medium [CVE-2026-88840] TLS ssl_server reads one byte out of bounds when parsing truncated ClientHello
TLS ssl_server reads one byte out of bounds when parsing truncated ClientHello. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125.
Medium [CVE-2026-88839] passwd/group parser writes heap pointers out of bounds due to stale tokenize endpoint
passwd/group parser writes heap pointers out of bounds due to stale tokenize() endpoint. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:72111 with package busybox-main-1.37.0-9.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-88837] httpd misidentifies yescrypt password hashes as plaintext, inverting authentication
httpd misidentifies yescrypt password hashes as plaintext, inverting authentication. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-305. Red Hat lists fixing advisory RHSA-2026:72111 with package busybox-main-1.37.0-9.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-88835] dpkg read_package_field steps past NUL terminator, causing out-of-bounds read on malformed.deb packages
dpkg read_package_field() steps past NUL terminator, causing out-of-bounds read on malformed.deb packages. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:72111 with package busybox-main-1.37.0-9.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-88831] httpd silently fails open when IP deny rules contain invalid CIDR prefix lengths
httpd silently fails open when IP deny rules contain invalid CIDR prefix lengths. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-636. Red Hat lists fixing advisory RHSA-2026:72111 with package busybox-main-1.37.0-9.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-96807] Low integrity or availability impact via symlink manipulation
Low integrity or availability impact via symlink manipulation. Red Hat rates this moderate (CVSS 4.5). Weakness: CWE-22. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: flatpak.
Medium [CVE-2026-6669] Denial of Service via unbounded SCRAM iteration count
Denial of Service via unbounded SCRAM iteration count. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:70698 with package pgbouncer-main-1.26.0-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-96675] Denial of Service via malicious ALSA configuration file
Denial of Service via malicious ALSA configuration file. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: alsa-lib.
Medium [CVE-2026-96674] Integer Overflow via Crafted Topology Files
Integer Overflow via Crafted Topology Files. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: alsa-lib.
Medium [CVE-2026-96276] Flatpak: flatpak: arbitrary write in host context via flatpak build-init
If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows `..` traversal. Red Hat estimates the CVSSv3.1 vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N. The SDK content is retrieved from a remote registry, so no local access to the victim's system is required by the attacker (AV:N), and the attacker needs no privileges of their own (PR:N). Once the developer builds against the malicious SDK, exploitation is deterministic: the extension point's directory field is resolved via g_file_resolve_relative_path, which does not reject.. components, allowing a crafted value such as directory=../../ to redirect the copy operation outside the build tree (AC:L). Meaningful user interaction is required, as the developer must actively choose to build against the untrusted SDK (UI:R). flatpak build-init runs entirely with the invoking developer's own privileges, so the impact is bounded by that user's existing filesystem access and no privilege boundary is crossed (S:U). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.
Medium [CVE-2026-96611] Data corruption and information disclosure via signed integer overflow in HEIF processing
Data corruption and information disclosure via signed integer overflow in HEIF processing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-86247] Client certificate verification requirements can be down-graded via race condition
Client certificate verification requirements can be down-graded via race condition. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-366. Affected products named by the advisory: Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7.
Medium [CVE-2026-78253] Denial of Service via uncontrolled recursion in XML processing
Denial of Service via uncontrolled recursion in XML processing. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-776. Red Hat lists fixing advisory RHSA-2026:59393 with package qt6-qtbase-main-6.11.2-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat package: qt6.
Medium [CVE-2026-87022] WebSocket message smuggling via improper length handling
WebSocket message smuggling via improper length handling. Red Hat rates this low (CVSS 6.5). Weakness: CWE-130. Red Hat lists fixing advisory RHSA-2026:68257 with package tomcat11-main-11.0.26-0.1.hum1, tomcat10-main-10.1.60-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 8 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 6; and 4 more.