Red Hat Linux Security Advisories & CVEs
3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-53433] Denial of Service via inefficient HTTP body processing
Denial of Service via inefficient HTTP body processing. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-1046.
High [CVE-2026-49434] Unauthorized broker instantiation via improper input validation in LDAP entries
Unauthorized broker instantiation via improper input validation in LDAP entries. Red Hat rates this important (CVSS 7.6). Weakness: CWE-90.
High [CVE-2026-49432] Denial of Service via improper input validation in STOMP connector
Denial of Service via improper input validation in STOMP connector. Red Hat rates this important (CVSS 7.5). Weakness: CWE-839.
High [CVE-2026-50734] Denial of Service via crafted WireFormatInfo frame
Denial of Service via crafted WireFormatInfo frame. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-50750] Denial of Service via repeated BrokerInfo commands
Denial of Service via repeated BrokerInfo commands. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-53916] Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec
Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec. Red Hat rates this important (CVSS 7.5). Weakness: CWE-789.
High [CVE-2026-54475] Information disclosure due to broken temporary destination isolation
Information disclosure due to broken temporary destination isolation. Red Hat rates this important (CVSS 8.2). Weakness: CWE-1220.
High [CVE-2026-13149] Denial of Service due to exponential-time complexity
Denial of Service due to exponential-time complexity. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:35272 with package nodejs26-main-26.4.0-1.3.hum1, nodejs22-main-22.23.1-2.hum1, nodejs24-main-24.18.0-0.2.hum1, rhmtc/openshift-migration-ui-rhel8:1783690532.
High [CVE-2026-45822] Denial of Service via crafted input
Denial of Service via crafted input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Red Hat lists fixing advisory RHSA-2026:42146 with package quay/quay-rhel9:1783955846, quay/quay-rhel8:1783750447, quay/quay-rhel8:1783751865, quay/quay-rhel8:1784125838.
High [CVE-2026-12243] Information disclosure via path traversal vulnerability
Information disclosure via path traversal vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22.
High [CVE-2026-55607] @anthropic-ai/claude-code: Claude Code: Arbitrary code execution through git directory confusion
@anthropic-ai/claude-code: Claude Code: Arbitrary code execution through git directory confusion. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59.
High [CVE-2026-13676] Security policy bypass due to improper Unicode hostname canonicalization
Security policy bypass due to improper Unicode hostname canonicalization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-551. Red Hat lists fixing advisory RHSA-2026:37186 with package rhem/flightctl-ui-rhel9:1784127736, quay/quay-rhel9:1783955846, openshift4/ose-monitoring-plugin-rhel9:1783596795, rhem/flightctl-ui-rhel10:1784194574.
High [CVE-2026-54369] Symlink traversal privilege escalation via libacl functions
Symlink traversal privilege escalation via libacl functions. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:34351 with package acl-main-2.4.0-0.1.hum1.
High [CVE-2026-12856] Command Injection vulnerability in the JavaDoc hover provider of the vscode-java extension
Command Injection vulnerability in the JavaDoc hover provider of the vscode-java extension. Red Hat rates this important (CVSS 8.8). Weakness: CWE-88. Red Hat lists fixing advisory RHSA-2026:36820 with package devspaces/pluginregistry-rhel9:1782989367.
High [CVE-2026-13500] Remote code injection vulnerability
Remote code injection vulnerability. Red Hat rates this important (CVSS 7.3). Weakness: CWE-94.
High [CVE-2026-13606] Memory corruption via crafted Photo CD (PCD) file
Memory corruption via crafted Photo CD (PCD) file. Red Hat rates this important (CVSS 8.1). Weakness: CWE-787.
High [CVE-2026-58050] Heap buffer overflow via integer overflow in publickey attribute allocation
libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. A flaw in libssh2 allows a malicious SSH server to trigger a memory overflow by sending a manipulated attribute count. This can cause the connecting client to crash or allow unauthorized code execution. By manipulating the publickey-subsystem response, an attacker could cause an integer overflow, potentially leading to denial of service or arbitrary code execution on Red Hat systems using libssh2 to establish SSH connections. Note: Red Hat Enterprise Linux (RHEL) 8 and newer are not affected by this flaw, as they do not ship the libssh2 package. Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Hardened Images. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-58049] Memory corruption via crafted RASC video stream
Memory corruption via crafted RASC video stream. Red Hat rates this important (CVSS 7.6). Weakness: CWE-787.
High [CVE-2026-47220] Denial of Service via missing host header in specific logging configurations
Denial of Service via missing host header in specific logging configurations. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476.
High [CVE-2026-48743] Request desynchronization allows security policy bypass via HTTP/3 to HTTP/1 translation
Request desynchronization allows security policy bypass via HTTP/3 to HTTP/1 translation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-444.