Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5547 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.5Linux

High [CVE-2026-67861] Denial of Service via UA_Client_getRemoteDataTypes component

Denial of Service via UA_Client_getRemoteDataTypes component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-67861
Unclassified
Aug 4, 2026
High8.2Linux

High [CVE-2026-67860] Heap-based buffer overflow in HistoryRead path

Heap-based buffer overflow in HistoryRead path. Red Hat rates this important (CVSS 8.2). Weakness: CWE-120.

CVE-2026-67860
Unclassified
Aug 4, 2026
Medium4.9Vendor: LowLinux Updated

Medium [CVE-2026-18103] Persistent denial of service due to buffer overflow via OMAPI

Persistent denial of service due to buffer overflow via OMAPI. Red Hat rates this low (CVSS 4.9). Weakness: CWE-120.

CVE-2026-18103
Unclassified
Aug 4, 2026
MediumLinux Updated

Medium [CVE-2026-18785] Use-after-free vulnerability via local manipulation

A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after free. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. The project closed the issue report, stating that this is not the official way to report a security vulnerability. This could potentially lead to limited information disclosure, data corruption, or a Denial of Service (DoS). This Moderate severity use-after-free flaw in open62541 allows a local attacker to trigger a crash or potentially corrupt data through specific manipulation of the UA_Client_getRemoteDataTypes function. While publicly disclosed, exploitation requires local access and specific conditions, limiting its broader impact on typical Red Hat deployments. Red Hat severity: Moderate. Weakness: CWE-825.

CVE-2026-18785
Unclassified
Aug 4, 2026
Medium5.4Linux Updated

Medium [CVE-2026-15920] Cross-site scripting via unvalidated URLField values in the admin

Cross-site scripting via unvalidated URLField values in the admin. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79.

CVE-2026-15920
Unclassified
Aug 4, 2026
Medium5.3Linux Updated

Medium [CVE-2026-15830] Denial of Service via parsing deeply nested geometry collections

Denial of Service via parsing deeply nested geometry collections. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-606.

CVE-2026-15830
Unclassified
Aug 4, 2026
Medium5.3Linux Updated

Medium [CVE-2026-15337] Denial-of-service vulnerability due to excessive memory consumption

Denial-of-service vulnerability due to excessive memory consumption. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1050.

CVE-2026-15337
Unclassified
Aug 4, 2026
Medium5.3Linux

Medium [CVE-2026-18401] Denial of Service due to number length bypass in asynchronous JSON parser

Denial of Service due to number length bypass in asynchronous JSON parser. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770.

CVE-2026-18401
Unclassified
Aug 4, 2026
Medium6.5Linux Updated

Medium [CVE-2026-70368] Stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message

A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with network access to a stunnel service can send protocol inputs that trigger a log message longer than 1024 bytes, leading to an out-of-bounds stack read and a potential crash. In certain corner cases, the same vulnerability could be used to replace a series of trailing "\n" characters with "\0". This Moderate impact vulnerability affects stunnel services if their configuration allows long attacker-controlled log messages. Server-side IMAP protocol negotiation ("protocol = imap") is known to be affected, where a remote, unauthenticated attacker can trigger a denial-of-service by sending an oversized IMAP command. Reliable integrity impact or code execution as a result of this issue would be very difficult and likely impractical. This issue specifically affects "stunnel" 5.79 and lower when exposed to untrusted networks. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-70368
Red Hat Enterprise Linux
Aug 4, 2026
Medium5.4Linux Updated

Medium [CVE-2026-70367] SSRF bypass in stunnel SOCKS proxy via IPv4-mapped IPv6 loopback and unspecified addresses allows access to loopback-only services

A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses (e.g., “::ffff:127.0.0.1”) or unspecified addresses ("0.0.0.0", "::"), enabling access to loopback-only services on the "stunnel" host that should not be network-reachable. When configured with "protocol = socks", which is a non-default setting, an attacker able to reach the SOCKS server can send requests that will get proxied to localhost. This potentially exposes services bound to the local interface of the "stunnel" host. Exploitation depends on the presence and security of such local services. A SOCKS proxy is intentionally a general-purpose network access facility and should always be deployed with appropriate firewall policies and client authorization, i.e., there should be no untrusted users accessing a SOCKS proxy. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-918. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-70367
Red Hat Enterprise Linux
Aug 4, 2026
Medium4.4Linux Updated

Medium [CVE-2026-17614] Path Traversal on WildFly Domain Controller

Path Traversal on WildFly Domain Controller. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-22.

CVE-2026-17614
Unclassified
Aug 4, 2026
Medium4.8Linux

Medium [CVE-2026-58044] Request smuggling via HTTP client header truncation

Request smuggling via HTTP client header truncation. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-444.

CVE-2026-58044
Unclassified
Aug 4, 2026
Medium5.9Linux

Medium [CVE-2026-58042] Denial of Service via DNS responses with excessive A records

Denial of Service via DNS responses with excessive A records. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-770.

CVE-2026-58042
Unclassified
Aug 4, 2026
Medium6.2Linux

Medium [CVE-2026-58045] Denial of Service vulnerability

Denial of Service vulnerability. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-617.

CVE-2026-58045
Unclassified
Aug 4, 2026
Medium5.3Linux

Medium [CVE-2026-58041] Node.js node:sqlite: Unintended data modification due to stale statement iterator

Node.js node:sqlite: Unintended data modification due to stale statement iterator. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-367.

CVE-2026-58041
Unclassified
Aug 4, 2026
Medium5.5Linux Updated

Medium [CVE-2026-51400] Arbitrary code execution via vms_fixfilename function

An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c A flaw was found in Vim. A local attacker can exploit improper handling of filenames within the `vms_fixfilename()` function to achieve arbitrary code execution. This vulnerability enables a local user to escalate privileges or impact system integrity. Red Hat products are unaffected because the vulnerable code is absent from Red Hat's supported packages. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-94. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4 as not affected.

CVE-2026-51400
Unclassified
Aug 4, 2026
Critical9.8Linux Updated

Critical [CVE-2026-69240] SQL Injection via improper handling of Oracle date functions

Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. An attacker can inject arbitrary SQL expressions through an application value that reaches this escape path. This issue is fixed in version 6.37.4. A flaw was found in Sequelize. This oversight allows a remote attacker to bypass security filters. By injecting malicious SQL commands, an attacker can gain unauthorized access to sensitive data, modify database content, or potentially take full control of the affected database system. The requirement here is that dialect for backend database engine is set to 'oracle'. However, by default, PCCS uses SQLite as its backend database engine to store platform PCK certificates and TCB collaterals locally. This makes Red Hat products not vulnerable out-of-the-box. Red Hat severity: Critical — CVSS 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-89. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Satellite 6. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-69240
Red Hat Enterprise Linux
Aug 3, 2026
High8.6Linux Updated

High [CVE-2026-69192] Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. new Address4('012.0.0.1') reports correctForm() of 12.0.0.1 and isPrivate() of false, but fetch(' ) connects to 10.0.0.1. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, will classify an internal target as external and allow the request. The defect is in the parse gate rather than in any one classifier, so every consumer of Address4 inherits it: isPrivate(), isLoopback(), isLinkLocal(), isCGNAT(), isInSubnet(), isHostInSubnet(), and correctForm() are all computed from the mis-decoded octets. This issue is fixed in version 10.3.1. A flaw was found in the `ip-address` library. This library incorrectly interprets IPv4 address octets with leading zeros as decimal, while standard network parsers interpret them as octal. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Exploit Intelligence; Migration Toolkit for Containers; and 18 more.

CVE-2026-69192
Red Hat Enterprise Linux
Aug 3, 2026
High7.5Linux Updated

High [CVE-2026-69185] Denial of Service via memory exhaustion from crafted packets

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6. A flaw was found in Socket.IO. This can lead to the server running out of memory, resulting in a denial of service (DoS). Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux AI (RHEL AI) 3. Red Hat lists Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-69185
Red Hat Enterprise Linux
Aug 3, 2026
High7.5Linux Updated

High [CVE-2026-69153] Information disclosure via crafted sourceMappingURL

Information disclosure via crafted sourceMappingURL. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:50287 with package prometheus3-13-main-3.13.2-0.2.hum1, grafana12-4-main-12.4.6-0.4.hum1, grafana13-1-main-13.1.1-0.5.2.hum1, grafana13-1-main-13.1.1-0.5.1.hum1.

CVE-2026-69153
Unclassified
Aug 3, 2026

← All vendors