Red Hat Linux Security Advisories & CVEs
11225 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Critical [CVE-2026-75885] Unauthenticated SSRF and resource exhaustion via devfile parser endpoint
Unauthenticated SSRF and resource exhaustion via devfile parser endpoint. Red Hat rates this important (CVSS 9.3). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:70647 with package openshift4/ose-console-rhel9:1789939565, openshift4/ose-console-rhel9:1789904865, openshift4/ose-console-rhel9:1790130905, openshift4/ose-console:1790102793. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.12; Red Hat OpenShift Container Platform 4.17; Red Hat OpenShift Container Platform 4.18; Red Hat OpenShift Container Platform 4.19; and 3 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.20; Red Hat OpenShift Container Platform 4.21; Red Hat OpenShift Container Platform 4.22.
Critical [CVE-2026-93606] vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species
vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-653. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Self-service automation portal 2.
Critical [CVE-2026-93605] vm2 NodeVM before 3.12.1 Remote Code Execution via child_process
vm2 NodeVM before 3.12.1 Remote Code Execution via child_process. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-184. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Self-service automation portal 2.
Critical [CVE-2026-93603] vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Function
vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Function. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-653. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Self-service automation portal 2.
High [CVE-2026-63447] Denial of Service via crafted FTP traffic
Denial of Service via crafted FTP traffic. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-92708] Cross-request process memory disclosure
Cross-request process memory disclosure. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat Trusted Artifact Signer.
High [CVE-2026-93752] Denial of Service due to improper property name validation
Denial of Service due to improper property name validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-93748] Information Disclosure via max-stale directive
Information Disclosure via max-stale directive. Red Hat rates this important (CVSS 7.5). Weakness: CWE-524. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-93749] Denial of Service via malformed indexed source maps
Denial of Service via malformed indexed source maps. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1285. Affected products named by the advisory: Cost Management On Premise; Gatekeeper 3; Migration Toolkit for Containers; Node HealthCheck Operator; and 36 more. Affected products named by the advisory: OpenShift Lightspeed; OpenShift Pipelines; Red Hat 3scale API Management Platform 2; Red Hat AMQ Broker 7; and 32 more.
High [CVE-2026-63199] Cross-scope secret disclosure due to missing authorization in datasource proxy
Cross-scope secret disclosure due to missing authorization in datasource proxy. Red Hat rates this important (CVSS 7.7). Weakness: CWE-1220. Red Hat lists fixing advisory RHSA-2026:74609 with package cluster-observability-operator/perses-rhel9:1790854501.
High [CVE-2026-69184] CPU exhaustion denial of service via unbounded DNS name compression pointer chains
CPU exhaustion denial of service via unbounded DNS name compression pointer chains. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:40574 with package c-ares-main-1.34.8-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.
High [CVE-2026-69186] Denial of Service via unvalidated DNS header record counts
Denial of Service via unvalidated DNS header record counts. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284. Red Hat lists fixing advisory RHSA-2026:40574 with package c-ares-main-1.34.8-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.
High [CVE-2026-61548] Denial of Service due to stack buffer overflow in mmpstrucdata plugin
Denial of Service due to stack buffer overflow in mmpstrucdata plugin. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-55556] Denial of Service via heap buffer overflow in imhttp module
Denial of Service via heap buffer overflow in imhttp module. Red Hat rates this important (CVSS 7.5). Weakness: CWE-131.
High [CVE-2026-91149] Denial of Service via unbounded connection thread spawning
Denial of Service via unbounded connection thread spawning. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat OpenShift Dev Spaces.
High [CVE-2026-84383] Heap buffer overflow in `scale_nearest_neighbor ` via duplicate Alpha planes from nested `iden`/`auxl` items
Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items. Red Hat rates this critical (CVSS 7.8). Weakness: CWE-787.
High [CVE-2026-93690] Denial of Service via malformed path segments
Denial of Service via malformed path segments. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected products named by the advisory: Cost Management On Premise; Multicluster Engine for Kubernetes; Node HealthCheck Operator; OpenShift Lightspeed; and 12 more. Affected products named by the advisory: OpenShift Pipelines; OpenShift Service Mesh 3; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Connectivity Link 1; and 8 more.
High [CVE-2026-93687] Denial of Service via Stack Overflow from Deeply Nested Patterns
Denial of Service via Stack Overflow from Deeply Nested Patterns. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-93568] HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests
HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-20. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; and 6 more. Affected products named by the advisory: Red Hat Build of Keycloak; Red Hat Data Grid 8; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; and 2 more.
High [CVE-2025-59419 +1] Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)
Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419). Red Hat rates this important (CVSS 7.5). Weakness: CWE-93. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7.