Red Hat Linux Security Advisories & CVEs
5615 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-92045] Sandbox escape due to incorrect boundary conditions in the WebRTC component
Sandbox escape due to incorrect boundary conditions in the WebRTC component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-653.
Medium [CVE-2026-92044] Information disclosure in the Networking: HTTP component
Information disclosure in the Networking: HTTP component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-201.
Medium [CVE-2026-92043] Privilege escalation due to incorrect boundary conditions in the Audio/Video component
Privilege escalation due to incorrect boundary conditions in the Audio/Video component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-787.
Medium [CVE-2026-92042] Race condition in the DOM: Content Processes component
Race condition in the DOM: Content Processes component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-366.
Medium [CVE-2026-92041] Mitigation bypass in the DOM: Networking component
Mitigation bypass in the DOM: Networking component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-807.
Medium [CVE-2026-92040] Use-after-free in the JavaScript: WebAssembly component
Use-after-free in the JavaScript: WebAssembly component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825.
Medium [CVE-2026-92039] Mitigation bypass in the DOM: Notifications component
Mitigation bypass in the DOM: Notifications component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-358.
Medium [CVE-2026-92032] Sandbox escape due to invalid pointer in the Graphics component
Sandbox escape due to invalid pointer in the Graphics component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.
Medium [CVE-2026-92031] Information disclosure in the Graphics: ImageLib component
Information disclosure in the Graphics: ImageLib component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-497. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.
Medium [CVE-2026-92030] Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component
Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-807. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.
Medium [CVE-2026-91786] out-of-bounds read in remote search icon rendering due to unvalidated icon-data buffer size
out-of-bounds read in remote search icon rendering due to unvalidated icon-data buffer size. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gnome-shell.
Medium [CVE-2026-86818] Mailto header injection via percent-encoded field-name desynchronization
Mailto header injection via percent-encoded field-name desynchronization. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-838. Affected product named by the advisory: Red Hat Satellite 6.
Medium [CVE-2026-86472] Security bypass due to inconsistent host case normalization
Security bypass due to inconsistent host case normalization. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-178. Red Hat lists fixing advisory RHSA-2026:71040 with package grafana12-4-main-12.4.10-0.4.hum1, grafana13-2-main-13.2.1-0.7.hum1, grafana13-1-main-13.1.6-0.3.hum1. Affected products named by the advisory: Red Hat Hardened Images; Cost Management On Premise; Migration Toolkit for Applications 8; Migration Toolkit for Containers; and 32 more. Affected products named by the advisory: Multicluster Engine for Kubernetes; Network Observability Operator; OpenShift Lightspeed; OpenShift Pipelines; and 28 more.
Medium [CVE-2026-17495] Path Traversal via crafted non-string input to locale function
Path Traversal via crafted non-string input to locale function. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-22. Affected products named by the advisory: Multicluster Engine for Kubernetes; OpenShift Pipelines; OpenShift Service Mesh 3; Red Hat 3scale API Management Platform 2; and 31 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; Red Hat build of Apache Camel for Spring Boot 4; and 27 more.
Medium [CVE-2026-81320] TLS private key written to operator log at debug level
TLS private key written to operator log at debug level. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-532. Affected product named by the advisory: Red Hat build of Apache Camel - HawtIO 4.
Medium [CVE-2026-81303] routes/custom-host confused-deputy via spec.routeHostName
routes/custom-host confused-deputy via spec.routeHostName. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-441. Affected product named by the advisory: Red Hat build of Apache Camel - HawtIO 4.
Medium [CVE-2026-90878] Denial of Service via Jinja Template Rendering
Denial of Service via Jinja Template Rendering. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-606. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-90831] Memory corruption via local manipulation of ELF String Table
Memory corruption via local manipulation of ELF String Table. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:47171 with package binutils-main-2.46.1-1.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-90830] Local denial of service via null pointer dereference in Section Merge
Local denial of service via null pointer dereference in Section Merge. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:47171 with package binutils-main-2.46.1-1.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-90829] Null pointer dereference via SHT_GROUP Section manipulation
Null pointer dereference via SHT_GROUP Section manipulation. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:47171 with package binutils-main-2.46.1-1.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.