Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium4.4Red Hat

Medium [CVE-2026-50642] Terminal escape injection allows command execution

Terminal escape injection allows command execution. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-94.

CVE-2026-50642
Unclassified
Jul 29, 2026
Medium5.6Red Hat

Medium [CVE-2026-56390] Arbitrary file overwrite via grammar-defined output paths

Arbitrary file overwrite via grammar-defined output paths. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-22.

CVE-2026-56390
Unclassified
Jul 29, 2026
Medium5.5Red Hat

Medium [CVE-2026-56389] Arbitrary Code Execution via malicious grammar file

Arbitrary Code Execution via malicious grammar file. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: bison.

CVE-2026-56389
Red Hat Enterprise Linux
Jul 29, 2026
Medium5.5Red Hat

Medium [CVE-2026-18201] Generic identity-provider creation can bind brokers to organizations without manage-organizations

Generic identity-provider creation can bind brokers to organizations without manage-organizations. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-862.

CVE-2026-18201
Unclassified
Jul 29, 2026
Medium6.5Red Hat

Medium [CVE-2026-18207] CVE-2026-18207

CVE-2026-18207. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-285.

CVE-2026-18207
Unclassified
Jul 29, 2026
Medium4.5Red Hat

Medium [CVE-2026-54620] Use-After-Free vulnerability in SQLite aggregate function callbacks

Use-After-Free vulnerability in SQLite aggregate function callbacks. Red Hat rates this moderate (CVSS 4.5). Weakness: CWE-825.

CVE-2026-54620
Unclassified
Jul 28, 2026
Medium4.5Red Hat

Medium [CVE-2026-54619] Use-after-free when redefining SQLite functions with different arity

Use-after-free when redefining SQLite functions with different arity. Red Hat rates this moderate (CVSS 4.5). Weakness: CWE-825.

CVE-2026-54619
Unclassified
Jul 28, 2026
Medium6.5Red Hat

Medium [CVE-2026-71192] S3API cross-tenant object read via Swift-native header injection

S3API cross-tenant object read via Swift-native header injection. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-863.

CVE-2026-71192
Unclassified
Jul 28, 2026
Medium5.3Red Hat

Medium [CVE-2026-66299] Denial of Service via WebSocket chat example

Denial of Service via WebSocket chat example. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770.

CVE-2026-66299
Unclassified
Jul 28, 2026
Medium6.5Red Hat

Medium [CVE-2026-18047] ACME admin enable/disable endpoint authentication bypass via trailing slash

ACME admin enable/disable endpoint authentication bypass via trailing slash. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-288.

CVE-2026-18047
Unclassified
Jul 28, 2026
Medium5.3Red Hat

Medium [CVE-2026-58216] kpasswd service: kpasswd packet that contains malformed ASN.1 might cause the server to access 6 bytes of unallocated memory leading server to crash

kpasswd service: kpasswd packet that contains malformed ASN.1 might cause the server to access 6 bytes of unallocated memory leading server to crash. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125.

CVE-2026-58216
Unclassified
Jul 28, 2026
Medium5.3Red Hat

Medium [CVE-2026-58218] DNS signing DoS via TKEY name cache exhaustion

DNS signing DoS via TKEY name cache exhaustion. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-410.

CVE-2026-58218
Unclassified
Jul 28, 2026
Medium6.5Red Hat

Medium [CVE-2026-58224] CTDB fails to do integrity checking of received packets

CTDB fails to do integrity checking of received packets. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-353. Affected product named by the advisory: Red Hat Enterprise Linux 7.

CVE-2026-58224
Unclassified
Jul 28, 2026
Medium5.9Red Hat

Medium [CVE-2024-14041] Bouncy Castle for Java: Private key recovery via timing side-channel in ML-KEM (CRYSTALS-Kyber) routines

Bouncy Castle for Java: Private key recovery via timing side-channel in ML-KEM (CRYSTALS-Kyber) routines. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-208. Affected product named by the advisory: Red Hat JBoss Enterprise Application Platform Expansion Pack.

CVE-2024-14041
Unclassified
Jul 28, 2026
Medium5.4Red Hat

Medium [CVE-2026-53669] Open Redirect vulnerability via backslashes in navigation components

Open Redirect vulnerability via backslashes in navigation components. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-601. Red Hat lists fixing advisory RHSA-2026:48780 with package prometheus3-5-main-3.5.5-0.6.hum1, prometheus3-13-main-3.13.1-0.5.hum1.

CVE-2026-53669
Unclassified
Jul 27, 2026
Medium6.5Red Hat

Medium [CVE-2026-55685] @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests

@remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770.

CVE-2026-55685
Unclassified
Jul 27, 2026
Medium6.9Red Hat

Medium [CVE-2026-53668] Cross-Site Scripting (XSS) via open redirects

Cross-Site Scripting (XSS) via open redirects. Red Hat rates this moderate (CVSS 6.9). Weakness: CWE-601.

CVE-2026-53668
Unclassified
Jul 27, 2026
Medium6.9Red Hat

Medium [CVE-2026-53667] Untrusted redirects due to missing protocol validation

Untrusted redirects due to missing protocol validation. Red Hat rates this moderate (CVSS 6.9). Weakness: CWE-601.

CVE-2026-53667
Unclassified
Jul 27, 2026
Medium6.1Red Hat

Medium [CVE-2026-53666] Information disclosure via client-side constructor execution

Information disclosure via client-side constructor execution. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-502.

CVE-2026-53666
Unclassified
Jul 27, 2026
Medium5.5Red Hat

Medium [CVE-2026-66757] signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on RLE SGI images

A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a crafted file sets both dimensions to their maximum value (65535), the multiplication ysize * zsize overflows the standard 32-bit int boundary before being passed to calloc. This integer overflow issue results in undefined behavior, aborting the plugin and causing a denial of service. Due to this reason, this flaw has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-66757
Unclassified
Jul 27, 2026

← All vendors