Red Hat Linux Security Advisories & CVEs
10918 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-103754] path traversal and symlink escape in unstream_dir allows file write outside the target directory
path traversal and symlink escape in unstream_dir() allows file write outside the target directory. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-22. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.
Medium [CVE-2026-103263] Information disclosure via symlink path traversal in StaticFileHandler
Information disclosure via symlink path traversal in StaticFileHandler. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-59. Affected products named by the advisory: Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 10 more. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; and 6 more.
Medium [CVE-2026-103261] Denial of Service (DoS) via unbounded query string parsing
Denial of Service (DoS) via unbounded query string parsing. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected products named by the advisory: Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 10 more. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; and 6 more.
Medium [CVE-2026-103641] out-of-bounds read in the Radiance HDR uncompressed scanline decoder
out-of-bounds read in the Radiance HDR uncompressed scanline decoder. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 6 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: gegl04-tools; Red Hat package: gegl04.src; Red Hat package: gegl-devel; and 2 more.
Medium [CVE-2026-103531] Arbitrary code execution via stack-based buffer overflow in card-setcos
Arbitrary code execution via stack-based buffer overflow in card-setcos. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: opensc.
Low [CVE-2026-56449] Denial of Service via crafted HTTP response bodies in mod_proxy_html
Denial of Service via crafted HTTP response bodies in mod_proxy_html. Red Hat rates this low (CVSS 3.7). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: httpd.
Low [CVE-2026-48005] Denial of service via forged Authorization headers in mod_auth_digest
Denial of service via forged Authorization headers in mod_auth_digest. Red Hat rates this low (CVSS 3.7). Weakness: CWE-303. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: httpd.
Low [CVE-2026-47360] Information disclosure via session cookie leakage during internal redirects
Information disclosure via session cookie leakage during internal redirects. Red Hat rates this low (CVSS 3.7). Weakness: CWE-212. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: httpd.
Low [CVE-2026-42356] arbitrary code execution via incorrect handler assignment during internal CGI redirects
arbitrary code execution via incorrect handler assignment during internal CGI redirects. Red Hat rates this low (CVSS 3.7). Weakness: CWE-430. Red Hat lists fixing advisory RHSA-2026:74858 with package httpd-main-2.4.69-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: httpd.
Low [CVE-2026-103004] Information disclosure via cache key omission in nested cache handlers
Information disclosure via cache key omission in nested cache handlers. Red Hat rates this low (CVSS 3.7). Weakness: CWE-524. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Trusted Artifact Signer; Red Hat package: firefox; Red Hat package: thunderbird.
High [CVE-2026-103000] Denial of Service via large alphabetical page labels
Denial of Service via large alphabetical page labels. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Ansible Automation Orchestrator 2026; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat Quay 3.
High [CVE-2026-102999] Denial of Service via crafted PDF with numerous embedded files
Denial of Service via crafted PDF with numerous embedded files. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Affected products named by the advisory: Ansible Automation Orchestrator 2026; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat Quay 3.
High [CVE-2026-102998] Denial of Service via crafted PDF form fields
Denial of Service via crafted PDF form fields. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Affected products named by the advisory: Ansible Automation Orchestrator 2026; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat Quay 3.
High [CVE-2026-102997] Denial of Service via crafted FlateDecode stream
Denial of Service via crafted FlateDecode stream. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected products named by the advisory: Ansible Automation Orchestrator 2026; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat Quay 3.
High [CVE-2026-102996] Denial of Service via excessive memory consumption during font parsing
Denial of Service via excessive memory consumption during font parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Ansible Automation Orchestrator 2026; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat Quay 3.
High [CVE-2026-102994] Denial of Service via crafted indirect object tokens in PDF files
Denial of Service via crafted indirect object tokens in PDF files. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Affected products named by the advisory: Ansible Automation Orchestrator 2026; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat Quay 3.
High [CVE-2026-102990] Denial of Service via crafted Unix directory listings
Denial of Service via crafted Unix directory listings. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 6 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift GitOps; Self-service automation portal 2; and 2 more.
High [CVE-2026-103500] Heap buffer overflow via opening large emails
Heap buffer overflow via opening large emails. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: thunderbird.
High [CVE-2026-19553] Certificate verification bypass via missing server_hostname validation in SSLContext.wrap_bio
Certificate verification bypass via missing server_hostname validation in SSLContext.wrap_bio(). Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:74594 with package python3-12-main-3.12.14-1.4.hum1, python3-13-main-3.13.15-1.4.hum1, python3-11-main-3.11.16-1.5.hum1, python3-14-main-3.14.7-1.3.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 8 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift Virtualization 4; and 4 more.
High [CVE-2026-47496] Privilege escalation via crafted RPC in Virtual GPU Manager
Privilege escalation via crafted RPC in Virtual GPU Manager. Red Hat rates this important (CVSS 7.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.