Red Hat Linux Security Advisories & CVEs
11223 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-93433] Denial of Service via stack buffer overflow in SCSI VPD page parsing
Denial of Service via stack buffer overflow in SCSI VPD page parsing. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-121. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: libstoragemgmt.
Medium [CVE-2026-94571] HAProxy configuration injection via L7 policy redirect_url and redirect_prefix
HAProxy configuration injection via L7 policy redirect_url and redirect_prefix. Red Hat rates this moderate (CVSS 5). Weakness: CWE-94. Affected products named by the advisory: Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-94215] Cross-realm client read/write via request-level cache missing realm ownership check
Cross-realm client read/write via request-level cache missing realm ownership check. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-862. Affected product named by the advisory: Red Hat Build of Keycloak.
Medium [CVE-2026-94213] Authorization Services policy evaluation endpoint leaks user identity
Authorization Services policy evaluation endpoint leaks user identity. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-862. Affected product named by the advisory: Red Hat Build of Keycloak.
Low [CVE-2026-94218] 2FA setup enforcement bypass via authentication session restart endpoint
2FA setup enforcement bypass via authentication session restart endpoint. Red Hat rates this low (CVSS 3.1). Weakness: CWE-862. Affected product named by the advisory: Red Hat Build of Keycloak.
Low [CVE-2026-94217] UMA scope merge across resource owners via resource name collision
UMA scope merge across resource owners via resource name collision. Red Hat rates this moderate (CVSS 3.5). Weakness: CWE-862. Affected product named by the advisory: Red Hat Build of Keycloak.
Critical [CVE-2026-94084] use-after-free in HTTP/2 response header inspection
use-after-free in HTTP/2 response header inspection. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-416.
Critical [CVE-2026-94083] type confusion and invalid free in DoH2 protocol handling
type confusion and invalid free in DoH2 protocol handling. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-843.
High [CVE-2026-93990] XML Injection via Malformed UTF-16 Input
XML Injection via Malformed UTF-16 Input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-176. Red Hat lists fixing advisory RHSA-2026:74001 with package expat-main-2.8.4-0.2.hum1, expat-0:2.7.3-1.el10_2.5, expat-0:2.5.0-4.el8_10, expat-0:2.5.0-6.el9_8.5. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-96543] out-of-bounds heap write when loading non-square PVR images
out-of-bounds heap write when loading non-square PVR images. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787.
Medium [CVE-2026-96544] integer overflow in the PVR image loader leads to an out-of-bounds heap read
integer overflow in the PVR image loader leads to an out-of-bounds heap read. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-190.
Medium [CVE-2026-94001] Admin credential DELETE bypasses denied reset-password permission
Admin credential DELETE bypasses denied reset-password permission. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-862. Affected product named by the advisory: Red Hat Build of Keycloak.
Medium [CVE-2026-94000] Delegated admin with manage-users can escalate to realm-admin via group membership
Delegated admin with manage-users can escalate to realm-admin via group membership. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-862. Affected product named by the advisory: Red Hat Build of Keycloak.
Medium [CVE-2026-93999] Token refresh continues issuing tokens for disabled audience clients
Token refresh continues issuing tokens for disabled audience clients. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-862. Affected product named by the advisory: Red Hat Build of Keycloak.
Medium [CVE-2026-93981] Cross-Site Scripting via Unescaped Strings
Cross-Site Scripting via Unescaped Strings. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:71906 with package grafana13-1-main-13.1.6-0.6.hum1, grafana12-4-main-12.4.10-0.10.hum1, grafana13-2-main-13.2.1-0.7.hum1, grafana13-1-main-13.1.6-0.5.hum1. Affected products named by the advisory: Red Hat Hardened Images; Migration Toolkit for Applications 8; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; and 3 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces; Red Hat package: grafana.
Low [CVE-2026-93989] Cross-request logits corruption via out-of-bounds token indices
Cross-request logits corruption via out-of-bounds token indices. Red Hat rates this low (CVSS 3.1). Weakness: CWE-787. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Low [CVE-2026-94055] Use-after-free vulnerability in GnuTLS TLS settings leading to denial of service
Use-after-free vulnerability in GnuTLS TLS settings leading to denial of service. Red Hat rates this low. Weakness: CWE-416.
Low [CVE-2026-93986] Path traversal vulnerability
Path traversal vulnerability. Red Hat rates this low (CVSS 3.1). Weakness: CWE-22. Affected products named by the advisory: Cryostat 4; Red Hat Advanced Cluster Management for Kubernetes 2.
Critical [CVE-2026-75885] Unauthenticated SSRF and resource exhaustion via devfile parser endpoint
Unauthenticated SSRF and resource exhaustion via devfile parser endpoint. Red Hat rates this important (CVSS 9.3). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:70647 with package openshift4/ose-console-rhel9:1789939565, openshift4/ose-console-rhel9:1789904865, openshift4/ose-console-rhel9:1790130905, openshift4/ose-console:1790102793. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.12; Red Hat OpenShift Container Platform 4.17; Red Hat OpenShift Container Platform 4.18; Red Hat OpenShift Container Platform 4.19; and 3 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.20; Red Hat OpenShift Container Platform 4.21; Red Hat OpenShift Container Platform 4.22.
Critical [CVE-2026-93606] vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species
vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-653. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Self-service automation portal 2.