Red Hat Linux Security Advisories & CVEs
5547 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-67861] Denial of Service via UA_Client_getRemoteDataTypes component
Denial of Service via UA_Client_getRemoteDataTypes component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-67860] Heap-based buffer overflow in HistoryRead path
Heap-based buffer overflow in HistoryRead path. Red Hat rates this important (CVSS 8.2). Weakness: CWE-120.
Medium [CVE-2026-18103] Persistent denial of service due to buffer overflow via OMAPI
Persistent denial of service due to buffer overflow via OMAPI. Red Hat rates this low (CVSS 4.9). Weakness: CWE-120.
Medium [CVE-2026-18785] Use-after-free vulnerability via local manipulation
A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after free. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. The project closed the issue report, stating that this is not the official way to report a security vulnerability. This could potentially lead to limited information disclosure, data corruption, or a Denial of Service (DoS). This Moderate severity use-after-free flaw in open62541 allows a local attacker to trigger a crash or potentially corrupt data through specific manipulation of the UA_Client_getRemoteDataTypes function. While publicly disclosed, exploitation requires local access and specific conditions, limiting its broader impact on typical Red Hat deployments. Red Hat severity: Moderate. Weakness: CWE-825.
Medium [CVE-2026-15920] Cross-site scripting via unvalidated URLField values in the admin
Cross-site scripting via unvalidated URLField values in the admin. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79.
Medium [CVE-2026-15830] Denial of Service via parsing deeply nested geometry collections
Denial of Service via parsing deeply nested geometry collections. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-606.
Medium [CVE-2026-15337] Denial-of-service vulnerability due to excessive memory consumption
Denial-of-service vulnerability due to excessive memory consumption. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1050.
Medium [CVE-2026-18401] Denial of Service due to number length bypass in asynchronous JSON parser
Denial of Service due to number length bypass in asynchronous JSON parser. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770.
Medium [CVE-2026-70368] Stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message
A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with network access to a stunnel service can send protocol inputs that trigger a log message longer than 1024 bytes, leading to an out-of-bounds stack read and a potential crash. In certain corner cases, the same vulnerability could be used to replace a series of trailing "\n" characters with "\0". This Moderate impact vulnerability affects stunnel services if their configuration allows long attacker-controlled log messages. Server-side IMAP protocol negotiation ("protocol = imap") is known to be affected, where a remote, unauthenticated attacker can trigger a denial-of-service by sending an oversized IMAP command. Reliable integrity impact or code execution as a result of this issue would be very difficult and likely impractical. This issue specifically affects "stunnel" 5.79 and lower when exposed to untrusted networks. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-70367] SSRF bypass in stunnel SOCKS proxy via IPv4-mapped IPv6 loopback and unspecified addresses allows access to loopback-only services
A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses (e.g., “::ffff:127.0.0.1”) or unspecified addresses ("0.0.0.0", "::"), enabling access to loopback-only services on the "stunnel" host that should not be network-reachable. When configured with "protocol = socks", which is a non-default setting, an attacker able to reach the SOCKS server can send requests that will get proxied to localhost. This potentially exposes services bound to the local interface of the "stunnel" host. Exploitation depends on the presence and security of such local services. A SOCKS proxy is intentionally a general-purpose network access facility and should always be deployed with appropriate firewall policies and client authorization, i.e., there should be no untrusted users accessing a SOCKS proxy. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-918. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-17614] Path Traversal on WildFly Domain Controller
Path Traversal on WildFly Domain Controller. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-22.
Medium [CVE-2026-58044] Request smuggling via HTTP client header truncation
Request smuggling via HTTP client header truncation. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-444.
Medium [CVE-2026-58042] Denial of Service via DNS responses with excessive A records
Denial of Service via DNS responses with excessive A records. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-770.
Medium [CVE-2026-58045] Denial of Service vulnerability
Denial of Service vulnerability. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-617.
Medium [CVE-2026-58041] Node.js node:sqlite: Unintended data modification due to stale statement iterator
Node.js node:sqlite: Unintended data modification due to stale statement iterator. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-367.
Medium [CVE-2026-51400] Arbitrary code execution via vms_fixfilename function
An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c A flaw was found in Vim. A local attacker can exploit improper handling of filenames within the `vms_fixfilename()` function to achieve arbitrary code execution. This vulnerability enables a local user to escalate privileges or impact system integrity. Red Hat products are unaffected because the vulnerable code is absent from Red Hat's supported packages. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-94. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4 as not affected.
Critical [CVE-2026-69240] SQL Injection via improper handling of Oracle date functions
Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. An attacker can inject arbitrary SQL expressions through an application value that reaches this escape path. This issue is fixed in version 6.37.4. A flaw was found in Sequelize. This oversight allows a remote attacker to bypass security filters. By injecting malicious SQL commands, an attacker can gain unauthorized access to sensitive data, modify database content, or potentially take full control of the affected database system. The requirement here is that dialect for backend database engine is set to 'oracle'. However, by default, PCCS uses SQLite as its backend database engine to store platform PCK certificates and TCB collaterals locally. This makes Red Hat products not vulnerable out-of-the-box. Red Hat severity: Critical — CVSS 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-89. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Satellite 6. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-69192] Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. new Address4('012.0.0.1') reports correctForm() of 12.0.0.1 and isPrivate() of false, but fetch(' ) connects to 10.0.0.1. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, will classify an internal target as external and allow the request. The defect is in the parse gate rather than in any one classifier, so every consumer of Address4 inherits it: isPrivate(), isLoopback(), isLinkLocal(), isCGNAT(), isInSubnet(), isHostInSubnet(), and correctForm() are all computed from the mis-decoded octets. This issue is fixed in version 10.3.1. A flaw was found in the `ip-address` library. This library incorrectly interprets IPv4 address octets with leading zeros as decimal, while standard network parsers interpret them as octal. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Exploit Intelligence; Migration Toolkit for Containers; and 18 more.
High [CVE-2026-69185] Denial of Service via memory exhaustion from crafted packets
Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6. A flaw was found in Socket.IO. This can lead to the server running out of memory, resulting in a denial of service (DoS). Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux AI (RHEL AI) 3. Red Hat lists Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-69153] Information disclosure via crafted sourceMappingURL
Information disclosure via crafted sourceMappingURL. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:50287 with package prometheus3-13-main-3.13.2-0.2.hum1, grafana12-4-main-12.4.6-0.4.hum1, grafana13-1-main-13.1.1-0.5.2.hum1, grafana13-1-main-13.1.1-0.5.1.hum1.