Red Hat Linux Security Advisories & CVEs
465 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Low [CVE-2026-84355] Incorrect authorization in Navigation
Incorrect authorization in Navigation. Red Hat rates this moderate (CVSS 3.7). Weakness: CWE-346.
Low [CVE-2026-84358] Improper privilege management in Downloads
Improper privilege management in Downloads. Red Hat rates this moderate (CVSS 2.8). Weakness: CWE-451.
Low [CVE-2026-84641] Information disclosure due to malicious IMAP server response
Information disclosure due to malicious IMAP server response. Red Hat rates this low (CVSS 3.4). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: thunderbird.
Low [CVE-2026-84642] Allowed UNC hostnames for attachments interpreted as a regular expression
The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this could allow certain unintended hostnames to also match and serve remote attachments. This vulnerability was fixed in Thunderbird 155 and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Low — CVSS 3.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N). Weakness: CWE-624. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Low [CVE-2026-84368] @hapi/joi: joi: Prototype pollution via untrusted input in schema configuration
@hapi/joi: joi: Prototype pollution via untrusted input in schema configuration. Red Hat rates this low (CVSS 3.7). Weakness: CWE-915. Affected products named by the advisory: Gatekeeper 3; Migration Toolkit for Containers; Red Hat Build of Podman Desktop; Red Hat Data Grid 8; and 9 more. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; and 5 more.
Low [CVE-2026-83608] @xmldom/xmldom: xmldom: XML Markup Injection via DocType Name Bypass
@xmldom/xmldom: xmldom: XML Markup Injection via DocType Name Bypass. Red Hat rates this important (CVSS 3.1). Weakness: CWE-91. Red Hat lists fixing advisory RHSA-2026:69248 with package rhdh/rhdh-hub-rhel9:1789554285. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 4 more. Affected products named by the advisory: Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Red Hat package: grafana.
Low [CVE-2026-84141] Integer overflow in the Graphics: ImageLib component
Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Low — CVSS 3.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N). Weakness: CWE-190. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Low [CVE-2026-84140] Site isolation issue in the DOM: Navigation component
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Low — CVSS 3.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N). Weakness: CWE-1100. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Low [CVE-2026-84139] Clickjacking issue in the DOM: Events component
Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Low — CVSS 3.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N). Weakness: CWE-1021. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Low [CVE-2026-84138] Denial-of-service in the PDF Viewer component
Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Low — CVSS 3.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N). Weakness: CWE-835. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Low [CVE-2026-84137] Spoofing issue in the DOM: Core & HTML component
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Low — CVSS 3.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N). Weakness: CWE-290. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Low [CVE-2026-84136] Other issue in the DOM: Navigation component
Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Low — CVSS 3.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N). Weakness: CWE-368. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Low [CVE-2026-84135] Other issue in Firefox Focus for Android
Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Low — CVSS 3.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N). Weakness: CWE-252. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Low [CVE-2026-84134] Other issue in the Profile Backup component
Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Low — CVSS 3.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N). Weakness: CWE-915. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Low [CVE-2026-84133] Site isolation issue in the DOM: Push Subscriptions component
Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Low — CVSS 3.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N). Weakness: CWE-653. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Low [CVE-2026-18743] Popt-devel: popt-static: short realloc in poptconfigfiletostring
A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service). This Low impact heap overflow in `popt` occurs when processing specially crafted configuration files through an explicit call to `poptConfigFileToString()`. Red Hat products are less exposed as this function is not utilized by internal sources, limiting the attack surface to scenarios where untrusted `popt` configuration content is explicitly loaded. Red Hat severity: Low — CVSS 2.5 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-131. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:56984. Affected products named by the advisory: Red Hat package: popt.
Low [CVE-2026-82631] Use-after-free vulnerability in Blocked-on-keys subsystem
A security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlockedOnKey of the file src/blocked.c of the component Blocked-on-keys Subsystem. The manipulation results in use after free. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit has been released to the public and may be used for attacks. The patch is identified as b2fb0e13f5b4c8c2fb63dcfc2c37a067a0d6d20b. Applying a patch is advised to resolve this issue. A flaw was found in Valkey. A remote attacker could exploit this flaw, leading to a denial of service. The complexity of exploiting this vulnerability is high. Red Hat severity: Low. Weakness: CWE-825. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:61884. Affected products named by the advisory: Red Hat package: valkey.
Low [CVE-2026-82562] Denial of Service via array limit bypass in query string parsing
Denial of Service via array limit bypass in query string parsing. Red Hat rates this low (CVSS 3.7). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:63164 with package grafana13-1-main-13.1.3-0.4.hum1, grafana13-2-main-13.2.1-0.1.hum1, grafana12-4-main-12.4.9-0.4.hum1. Affected products named by the advisory: Red Hat Hardened Images; Cost Management On Premise; Cryostat 4; Gatekeeper 3; and 47 more. Affected products named by the advisory: Migration Toolkit for Applications 8; Migration Toolkit for Containers; Multicluster Engine for Kubernetes; Node HealthCheck Operator; and 43 more.
Low [CVE-2026-52681] Denial of Service via Sieve script manipulation
Denial of Service via Sieve script manipulation. Red Hat rates this low (CVSS 3.1). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: dovecot.
Low [CVE-2026-42393] Information disclosure via timing attack on `doveadm` password/API key comparison
Information disclosure via timing attack on `doveadm` password/API key comparison. Red Hat rates this low (CVSS 3.1). Weakness: CWE-208. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.