Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11228 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-92956] vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming

vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming. Red Hat rates this important (CVSS 9.9). Weakness: CWE-693. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92956
Unclassified
Sep 17, 2026
Critical10.0Vendor: HighRed Hat Updated

Critical [CVE-2026-92955] vm2 before 3.11.8 Sandbox Escape via NodeVM

vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr. Attackers can overwrite EventEmitter.prototype.emit and trigger process events to execute code with process context, bypassing code generation restrictions. A flaw was found in vm2. This vulnerability allows an attacker running untrusted code within the sandbox to achieve arbitrary code execution on the host system. By accessing internal host properties through standard output streams, the untrusted code can manipulate process event handlers and escape the sandbox environment. Red Hat products that bundle vm2 do so only via typescript-json-schema, which uses the base VM class. The vulnerability requires NodeVM with the default console: 'inherit', which injects the host console object (exposing _stdout/_stderr) into the sandbox; the base VM class never provides a console. Red Hat products does not instantiates NodeVM by default so this vulnerability is an Important rather than a Critical. Red Hat severity: Important — CVSS 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-913. Affected Red Hat products: Red Hat Developer Hub 1.10; Red Hat Developer Hub; Self-service automation portal 2. Red Hat fixing advisory: RHSA-2026:76788.

CVE-2026-92955
Unclassified
Sep 17, 2026
Critical9.3Vendor: HighRed Hat Updated

Critical [CVE-2026-92953] vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray

vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray. Red Hat rates this important (CVSS 9.3). Weakness: CWE-913. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92953
Unclassified
Sep 17, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-92951] vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver

vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver. Red Hat rates this important (CVSS 9.9). Weakness: CWE-706. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92951
Unclassified
Sep 17, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-92948] vm2 3.9.6 through 3.11.5 Sandbox Escape via node:test

vm2 3.9.6 through 3.11.5 Sandbox Escape via node:test. Red Hat rates this important (CVSS 9.9). Weakness: CWE-693. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92948
Unclassified
Sep 17, 2026
Critical9.8Vendor: HighRed Hat Updated

Critical [CVE-2026-92944] vm2 3.10.2 through 3.11.6 Sandbox Escape via Promise Protector

vm2 3.10.2 through 3.11.6 Sandbox Escape via Promise Protector. Red Hat rates this important (CVSS 9.8). Weakness: CWE-693. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92944
Unclassified
Sep 17, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-92941] vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation

vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation. Red Hat rates this important (CVSS 9.9). Weakness: CWE-732. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92941
Unclassified
Sep 17, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-92939] vm2 3.11.3 through 3.11.6 Native Code Execution via crypto.setEngine

vm2 3.11.3 through 3.11.6 Native Code Execution via crypto.setEngine. Red Hat rates this important (CVSS 9.9). Weakness: CWE-114. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92939
Unclassified
Sep 17, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-92938] vm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqlite

vm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqlite. Red Hat rates this important (CVSS 9.9). Weakness: CWE-693. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92938
Unclassified
Sep 17, 2026
Critical9.0Vendor: HighRed Hat Updated

Critical [CVE-2026-92935] vm2 NodeVM Remote Code Execution via Array-Shaped Require

vm2 NodeVM Remote Code Execution via Array-Shaped Require. Red Hat rates this important (CVSS 9). Weakness: CWE-913. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92935
Unclassified
Sep 17, 2026
Critical9.0Vendor: HighRed Hat Updated

Critical [CVE-2026-92934] vm2 before 3.11.8 Sandbox Escape RCE via AggregateError

vm2 before 3.11.8 Sandbox Escape RCE via AggregateError. Red Hat rates this important (CVSS 9). Weakness: CWE-693. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92934
Unclassified
Sep 17, 2026
High7.5Red Hat

High [CVE-2026-93436] Denial of Service via memory exhaustion from rejected requests

Denial of Service via memory exhaustion from rejected requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-93436
Unclassified
Sep 17, 2026
High7.5Red Hat

High [CVE-2026-54451] Elixir protobuf: Denial of Service via unbounded recursion in message decoding

Elixir protobuf: Denial of Service via unbounded recursion in message decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-54451
Unclassified
Sep 17, 2026
High7.5Red Hat

High [CVE-2026-85721] Denial of Service via unbounded HTTP response decompression

Denial of Service via unbounded HTTP response decompression. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat Fuse 7.

CVE-2026-85721
Unclassified
Sep 17, 2026
High7.5Red Hat

High [CVE-2026-85719] SOCKS proxy credentials exposed to origin server

SOCKS proxy credentials exposed to origin server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected product named by the advisory: Red Hat Fuse 7.

CVE-2026-85719
Unclassified
Sep 17, 2026
High8.8Red Hat

High [CVE-2026-86864] argument and connection-string injection via the database field in the Backup tool

argument and connection-string injection via the database field in the Backup tool. Red Hat rates this important (CVSS 8.8). Weakness: CWE-88.

CVE-2026-86864
Unclassified
Sep 17, 2026
High7.5Red Hat

High [CVE-2026-87742] Denial of Service (OOM) in quarkus-websockets-next via unbounded message buffering

Denial of Service (OOM) in quarkus-websockets-next via unbounded message buffering. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Exploit Intelligence; Red Hat Enterprise Linux AI (RHEL AI) 3.

CVE-2026-87742
Unclassified
Sep 17, 2026
High8.2Red Hat

High [CVE-2026-85078] Request smuggling via incomplete chunked-body handling

Request smuggling via incomplete chunked-body handling. Red Hat rates this important (CVSS 8.2). Weakness: CWE-444. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-85078
Unclassified
Sep 17, 2026
High8.2Red Hat

High [CVE-2026-85077] HTTP response header injection leading to session fixation or cache poisoning

HTTP response header injection leading to session fixation or cache poisoning. Red Hat rates this important (CVSS 8.2). Weakness: CWE-93. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-85077
Unclassified
Sep 17, 2026
High7.5Red Hat

High [CVE-2026-92987] Denial of Service via Quadratic Parsing

Denial of Service via Quadratic Parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Affected products named by the advisory: Confidential Compute Attestation; Logging Subsystem for Red Hat OpenShift; Red Hat Trusted Artifact Signer; Red Hat Trusted Profile Analyzer.

CVE-2026-92987
Unclassified
Sep 17, 2026

← All vendors