Red Hat Linux Security Advisories & CVEs
284 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Low [CVE-2026-60082] Denial of Service via out-of-bounds read
Denial of Service via out-of-bounds read. Red Hat rates this moderate (CVSS 3.3). Weakness: CWE-125.
Low [CVE-2026-60081] DBI::ProfileData: Denial of Service due to unbounded path index
DBI::ProfileData: Denial of Service due to unbounded path index. Red Hat rates this moderate (CVSS 2.8). Weakness: CWE-770.
Low [CVE-2026-59084] Insufficient documentation for EncryptInterceptor may lead to insecure configurations
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue. Insufficient technical documentation regarding the secure configuration of the EncryptInterceptor component may lead to deployments with insecure settings. This vulnerability could allow an attacker to exploit misconfigurations that arise from unclear guidance, potentially compromising the confidentiality or integrity of data processed by the affected system. Without clear guidance on secure configuration, administrators might inadvertently deploy the interceptor in a way that weakens security, rather than a direct code flaw. This issue affects Red Hat products utilizing Apache Tomcat, including Red Hat Enterprise Linux and Red Hat JBoss Web Server. Red Hat severity: Low — CVSS 3.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-1188. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.
Low [CVE-2026-59083] Security constraint bypass via improper URL encoding in rewrite valve
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue. A remote attacker could exploit this to bypass security constraints in certain configurations, potentially gaining unauthorized access or performing actions that should be restricted. Exploitation requires specific configurations and has high attack complexity, limiting its overall risk to Red Hat products. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-807. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat JBoss Web Server 5. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat fixing advisory: RHSA-2026:36872, RHSA-2026:37767.
Low [CVE-2026-15605] Information disclosure due to weak hash in artifact integrity validation
Information disclosure due to weak hash in artifact integrity validation. Red Hat rates this low (CVSS 3.1). Weakness: CWE-328.
Low [CVE-2026-40469] Denial of Service due to integer overflow
Denial of Service due to integer overflow. Red Hat rates this moderate (CVSS 2.8). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:40041 with package gawk-main-5.4.0-3.1.hum1.
Low [CVE-2026-61870] Denial of Service via specially crafted VIFF images
Denial of Service via specially crafted VIFF images. Red Hat rates this low (CVSS 2.9). Weakness: CWE-772.
Low [CVE-2026-61858] Policy bypass allows unauthorized file writing via APNG encoder
Policy bypass allows unauthorized file writing via APNG encoder. Red Hat rates this low (CVSS 3.3). Weakness: CWE-22.
Low [CVE-2026-59180] Information disclosure via HTTP redirect following with credential resending
Information disclosure via HTTP redirect following with credential resending. Red Hat rates this low (CVSS 3.1). Weakness: CWE-201.
Low [CVE-2026-56366] Denial of Service via memory leak in APP1JPEG image processing
Denial of Service via memory leak in APP1JPEG image processing. Red Hat rates this low (CVSS 3.3). Weakness: CWE-772.
Low [CVE-2026-15168] Information disclosure in BLF file parser
Information disclosure in BLF file parser. Red Hat rates this low (CVSS 2.5). Weakness: CWE-237.
Low [CVE-2026-6352] Auditor-level users can modify compliance records via improper authorization in GraphQL
Auditor-level users can modify compliance records via improper authorization in GraphQL. Red Hat rates this low (CVSS 2.7). Weakness: CWE-639.
Low [CVE-2026-56362] Magick.NET-Q16-x64: Magick.NET-Q16-x86: Ma…
Magick.NET-Q16-x64: Magick.NET-Q16-x86: Magick.NET-Q8-AnyCPU: Magick.NET-Q8-OpenMP-arm64: Magick.NET-Q8-OpenMP-x64: Magick.NET-Q8-arm64: Magick.NET-Q8-x64: Magick.NET-Q8-x86: ImageMagick: Information disclosure via heap-buffer-overflow read. Red Hat rates this low (CVSS 3.3). Weakness: CWE-125.
Low [CVE-2026-56374] Denial of Service and Information Disclosure via heap buffer overflow in FTXT encoder
Denial of Service and Information Disclosure via heap buffer overflow in FTXT encoder. Red Hat rates this low (CVSS 3.3). Weakness: CWE-125.
Low [CVE-2026-15028] heap overflow OOB read while parsing a tar archive contains a PAX extended header
heap overflow OOB read while parsing a tar archive contains a PAX extended header. Red Hat rates this low (CVSS 3.9). Red Hat lists fixing advisory RHSA-2026:38279 with package libarchive-main-3.8.8-2.1.hum1.
Low [CVE-2026-15041] Non-constant-time comparison in PBKDF2-SHA256 password verification
Non-constant-time comparison in PBKDF2-SHA256 password verification. Red Hat rates this low (CVSS 3.7). Weakness: CWE-208.
Low [CVE-2026-28378] Unauthorized public dashboard deletion across organizations
Unauthorized public dashboard deletion across organizations. Red Hat rates this low (CVSS 3.1). Weakness: CWE-1220.
Low [CVE-2026-14935] webrtcbin accepts remote SDP without a=fingerprint due to inverted presence check
webrtcbin accepts remote SDP without a=fingerprint due to inverted presence check. Red Hat rates this low (CVSS 3.7). Weakness: CWE-670.
Low [CVE-2026-48588] Information disclosure due to improper caching of Set-Cookie responses
Information disclosure due to improper caching of Set-Cookie responses. Red Hat rates this low (CVSS 3.1). Weakness: CWE-524.
Low [CVE-2026-53878] HTTP header injection via DomainNameValidator accepting newlines
HTTP header injection via DomainNameValidator accepting newlines. Red Hat rates this low (CVSS 3.7). Weakness: CWE-113.