Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

465 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Low3.1Red Hat

Low [CVE-2026-40204] lda_mailbox_autocreate can bypass acl restrictions

lda_mailbox_autocreate can bypass acl restrictions. Red Hat rates this low (CVSS 3.1). Weakness: CWE-1220. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-40204
Red Hat Enterprise Linux
Aug 28, 2026
Low3.7Red Hat

Low [CVE-2026-40203] Information disclosure via IMAP compression side-channel

Information disclosure via IMAP compression side-channel. Red Hat rates this low (CVSS 3.7). Weakness: CWE-205. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-40203
Red Hat Enterprise Linux
Aug 28, 2026
Low3.7Red Hat

Low [CVE-2026-59277] org.springframework.security/spring-security-core: Spring Security: Information disclosure due to incomplete internal network classification

org.springframework.security/spring-security-core: Spring Security: Information disclosure due to incomplete internal network classification. Red Hat rates this low (CVSS 3.7). Weakness: CWE-184. Affected products named by the advisory: OpenShift Developer Tools and Services; Red Hat Fuse 7; Red Hat OpenShift Dev Spaces; Red Hat Single Sign-On 7.

CVE-2026-59277
Unclassified
Aug 27, 2026
Low2.7Red Hat

Low [CVE-2026-66422] Improper Authorization allows bypass of declarative role constraints

Improper Authorization allows bypass of declarative role constraints. Red Hat rates this low (CVSS 2.7). Weakness: CWE-386. Red Hat lists fixing advisory RHSA-2026:56039 with package tomcat10-main-10.1.59-0.1.hum1, tomcat11-main-11.0.25-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7.

CVE-2026-66422
Unclassified
Aug 25, 2026
Low2.5Red Hat

Low [CVE-2026-65183] Local information disclosure via Unix domain socket TOCTOU race condition

Local information disclosure via Unix domain socket TOCTOU race condition. Red Hat rates this low (CVSS 2.5). Weakness: CWE-367. Red Hat lists fixing advisory RHSA-2026:56039 with package tomcat10-main-10.1.59-0.1.hum1, tomcat11-main-11.0.25-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7.

CVE-2026-65183
Unclassified
Aug 25, 2026
Low3.5Red Hat

Low [CVE-2026-79112] Out of bounds read in Skia

Out of bounds read in Skia. Red Hat rates this low (CVSS 3.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: firefox; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-79112
Red Hat Enterprise Linux
Aug 25, 2026
Low3.9Red Hat

Low [CVE-2026-79060] Incorrect authorization in StorageAccessAPI

Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Weakness: CWE-346.

CVE-2026-79060
Unclassified
Aug 25, 2026
Low3.5Red Hat

Low [CVE-2026-78968] Missing authorization in Core

Missing authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially spoof address bar via a crafted HTML page. (Chromium security severity: Low) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Weakness: CWE-290.

CVE-2026-78968
Unclassified
Aug 25, 2026
Low3.1Red Hat

Low [CVE-2026-79040] Uninitialized resource in GPU

Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Weakness: CWE-908.

CVE-2026-79040
Unclassified
Aug 25, 2026
Low3.6Red Hat

Low [CVE-2026-79783] Privilege Escalation via setuid/setgid metadata

Privilege Escalation via setuid/setgid metadata. Red Hat rates this low (CVSS 3.6). Weakness: CWE-281. Affected products named by the advisory: Cryostat 4; Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-79783
Unclassified
Aug 25, 2026
Low2.7Red Hat

Low [CVE-2026-79777] Information Disclosure via RC API error responses

Information Disclosure via RC API error responses. Red Hat rates this low (CVSS 2.7). Weakness: CWE-209. Affected products named by the advisory: Cryostat 4; Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-79777
Unclassified
Aug 25, 2026
Low2.9Red Hat

Low [CVE-2025-71346] Heap buffer under-read in XML Schema validation

Nokogiri before 1.18.8 packages a vulnerable version of libxml2 (before 2.13.8) that contains a heap-based buffer under-read (CVE-2025-32415) in the xmlSchemaIDCFillNodeTables function in xmlschemas.c. The issue can be triggered when validating against an untrusted XML Schema, or when validating untrusted documents against trusted schemas that use xsd:keyref in combination with recursively defined types that have additional identity constraints. Upstream and MITRE rate this issue as low severity. This heap-based buffer under-read vulnerability, located in the xmlSchemaIDCFillNodeTables function, can be triggered when processing untrusted XML Schemas or documents. A remote attacker could exploit this by providing specially crafted XML input, which may lead to unexpected application behavior or a limited denial of service (DoS). This flaw has a Low impact as it requires applications utilizing Nokogiri to process specially crafted, untrusted XML schemas or documents that include specific identity constraints. Exploitation is limited to scenarios where vulnerable applications perform XML validation on untrusted input, potentially leading to a denial of service. Red Hat severity: Low — CVSS 2.9 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat 3scale API Management Platform 2; Red Hat Satellite 6.

CVE-2025-71346
Unclassified
Aug 25, 2026
Low0.0Red Hat

Low [CVE-2024-58377] Nokogiri before 1.16.5 libxml2 Dependency Update

Nokogiri before 1.16.5 libxml2 Dependency Update. Red Hat rates this a security issue. Weakness: CWE-126.

CVE-2024-58377
Unclassified
Aug 25, 2026
Low3.7Red Hat

Low [CVE-2026-75803] AEAD forgeries possible with empty ciphertext in EVP_Cipher

Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and expecting the call to check the AEAD tag may accept forged messages. CWE: CWE-354 (Improper Validation of Integrity Check Value) Description: The EVP_Cipher() API call for AEAD ciphers behaves like a one shot encryption and decryption call. However for AES-OCB and ChaCha20-Poly1305 ciphers it skipped the AEAD tag verification when an empty ciphertext was passed to the function. The callers of this function might believe that a successful return indicates a valid AEAD tag for these ciphers, even when that has not truly been validated in this case. FIPS impact: no The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE as the affected algorithms are not FIPS approved and thus not implemented in the FIPS module. This allows remote attackers to submit forged messages that affected applications incorrectly accept as valid. Red Hat rates this as Low since exploitation requires a rare API misuse pattern using EVP_Cipher() with empty ChaCha20-Poly1305 or AES-OCB ciphertexts.

CVE-2026-75803
Red Hat Enterprise Linux
Aug 25, 2026
Low2.5Red Hat

Low [CVE-2026-71514] Information disclosure via path traversal in CrubadanCorpusReader

Information disclosure via path traversal in CrubadanCorpusReader. Red Hat rates this low (CVSS 2.5). Weakness: CWE-22.

CVE-2026-71514
Unclassified
Aug 22, 2026
Low2.2Red Hat

Low [CVE-2026-77648] Server-Side Request Forgery allows internal URL access by administrators

In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases. A privileged administrator could exploit a vulnerability in the `/v2/tasks` API by crafting a specific import task. This action bypasses security filtering, enabling the administrator to perform Server-Side Request Forgery (SSRF). As a result, an attacker could access and retrieve sensitive information from internal URLs within the Glance service network. Red Hat severity: Low — CVSS 2.2 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-918. Red Hat lists Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 18.0 as not affected.

CVE-2026-77648
Unclassified
Aug 20, 2026
Low3.3Red Hat

Low [CVE-2026-70653] Information disclosure via heap-based buffer read overflow

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-style Radiance RLE decoder in libvips/foreign/radiance.c can process a repeat marker at the beginning of a scanline in scanline_read_old and read q[-1] before any prior pixel exists. A crafted Radiance image loaded through VipsForeignLoadRad can therefore disclose four bytes of adjacent heap data, most likely other image data. This issue is fixed in version 8.18.3. A flaw was found in libvips. A remote attacker could exploit this by providing a specially crafted Radiance image. This could lead to the disclosure of four bytes of adjacent heap data, potentially revealing sensitive image information. This issue is a local out-of-bounds read of four bytes of adjacent heap data in libvips when decoding a crafted Radiance HDR image. Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. Red Hat severity: Low — CVSS 3.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-125.

CVE-2026-70653
Unclassified
Aug 20, 2026
Low3.5Red Hat

Low [CVE-2026-53584] Submodule path traversal allows arbitrary directory creation

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 does not reject traversal components in a submodule path loaded from.gitmodules. The affected src/libgit2/submodule.c paths include git_submodule_lookup and git_submodule_add_setup. A crafted repository can specify a path such as../escape-target, and applications that initialize the submodule can create directories outside the repository working tree. This issue is fixed in versions 1.8.6 and 1.9.5. A flaw was found in libgit2. By crafting a malicious repository that specifies traversal components in a submodule path, applications initializing the submodule can be tricked into creating directories in arbitrary locations on the file system. This could lead to unintended file system modifications or potentially further compromise. Red Hat severity: Low — CVSS 3.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N). Weakness: CWE-22. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3. Red Hat fixing advisory: RHSA-2026:59361. Affected products named by the advisory: Red Hat package: rust; Red Hat package: libgit2.

CVE-2026-53584
Red Hat Enterprise Linux
Aug 20, 2026
Low3.7Vendor: HighRed Hat

Low [CVE-2026-66788] Dockerfile build stages use end-of-life Fedora 40 referenced by mutable tag

A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to inject unauthorized EndpointSlices and ServiceImports into any namespace on peer clusters, including critical system namespaces like kube-system and openshift-*. This could lead to privilege escalation or other forms of system compromise within the cluster. Important: This flaw in Red Hat Advanced Cluster Management for Kubernetes allows a compromised spoke cluster to inject EndpointSlices and ServiceImports into arbitrary namespaces on peer clusters, including critical system namespaces. The `lighthouse-agent` service account uses an attacker-controlled label for the destination namespace without validation, enabling potential privilege escalation or service disruption across the cluster federation. Red Hat severity: Important — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N). Weakness: CWE-1104. Red Hat fixing advisory: RHSA-2026:63016. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-66788
Unclassified
Aug 20, 2026
Low2.5Vendor: HighRed Hat

Low [CVE-2026-66785] IPsec PSK secrets file created with default world-readable permissions

A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted network endpoint. The system fails to properly validate the network subnets provided by the malicious cluster, enabling it to declare arbitrary network ranges. Consequently, all network traffic intended for these arbitrary ranges from peer clusters will be rerouted through the attacker's tunnel, potentially leading to unauthorized information disclosure or network disruption. This is an Important vulnerability in Red Hat Advanced Cluster Management for Kubernetes. This could lead to unauthorized data interception or redirection within the multi-cluster environment. Red Hat severity: Important — CVSS 2.5 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-732. Red Hat fixing advisory: RHSA-2026:63016. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-66785
Unclassified
Aug 20, 2026

← All vendors