Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Red Hat

High [CVE-2026-50011] Denial of Service via malicious Redis array header

Denial of Service via malicious Redis array header. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Data Grid 8.6.2; and 3 more.

CVE-2026-50011
Unclassified
Jun 12, 2026
High7.5Red Hat

High [CVE-2026-50010] Improper trust manager handling leads to hostname verification bypass

Improper trust manager handling leads to hostname verification bypass. Red Hat rates this important (CVSS 7.5). Weakness: CWE-347. Affected package(s): netty-handler, offline-knowledge-portal/rhokp-rhel9:1782239370. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Offline Knowledge Portal 1.2.7; OpenShift Serverless; Red Hat AMQ Broker 7; Red Hat AMQ Clients; and 22 more.

CVE-2026-50010
Unclassified
Jun 12, 2026
High8.1Red Hat

High [CVE-2026-45830] Unauthorized data manipulation due to improper authorization validation

Unauthorized data manipulation due to improper authorization validation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-266. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-45830
Unclassified
Jun 12, 2026
High7.5Red Hat

High [CVE-2026-48748] Denial of Service due to memory exhaustion in HTTP/3 codec

Denial of Service due to memory exhaustion in HTTP/3 codec. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-48748
Unclassified
Jun 12, 2026
High7.5Red Hat

High [CVE-2026-48059] Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers

Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1286. Affected package(s): netty-codec-haproxy. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1; Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat build of Quarkus 3.27.4.SP1; Red Hat build of Quarkus 3.33.2.SP1; and 17 more.

CVE-2026-48059
Unclassified
Jun 12, 2026
High7.5Red Hat

High [CVE-2026-48043] Denial of Service due to resource leak

Denial of Service due to resource leak. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected package(s): netty-codec-http2. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1; Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat build of Quarkus 3.27.4.SP1; Red Hat build of Quarkus 3.33.2.SP1; and 17 more.

CVE-2026-48043
Unclassified
Jun 12, 2026
High7.5Red Hat

High [CVE-2026-48006] Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator

Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Data Grid 8.6.2; and 3 more.

CVE-2026-48006
Unclassified
Jun 12, 2026
High8.7Red Hat

High [CVE-2026-47691] Netty has Insufficient Bailiwick Validation for NS Records

Netty has Insufficient Bailiwick Validation for NS Records. Red Hat rates this important (CVSS 8.7). Weakness: CWE-346. Affected package(s): netty-resolver-dns. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1; Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat build of Quarkus 3.27.4.SP1; Red Hat build of Quarkus 3.33.2.SP1; and 18 more.

CVE-2026-47691
Unclassified
Jun 12, 2026
High7.5Red Hat

High [CVE-2026-46340] Denial of Service due to unbounded memory growth from SctpMessage fragments

Denial of Service due to unbounded memory growth from SctpMessage fragments. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Data Grid 8.6.2; and 3 more.

CVE-2026-46340
Unclassified
Jun 12, 2026
High8.7Red Hat

High [CVE-2026-45674] Information disclosure and data manipulation due to improper CNAME record validation

Information disclosure and data manipulation due to improper CNAME record validation. Red Hat rates this important (CVSS 8.7). Weakness: CWE-346. Affected package(s): netty-resolver-dns. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1; Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat build of Quarkus 3.27.4.SP1; Red Hat build of Quarkus 3.33.2.SP1; and 18 more.

CVE-2026-45674
Unclassified
Jun 12, 2026
High8.6Vendor: MediumRed Hat

High [CVE-2026-47141] NodeVM observability builtins leak host process and HTTP request data

NodeVM observability builtins leak host process and HTTP request data. Red Hat rates this moderate (CVSS 8.6). Weakness: CWE-653. Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-47141
Unclassified
Jun 12, 2026
High8.6Vendor: MediumRed Hat

High [CVE-2026-47139] Sandbox escape via internal HTTP built-ins leading to network restriction bypass

Sandbox escape via internal HTTP built-ins leading to network restriction bypass. Red Hat rates this moderate (CVSS 8.6). Weakness: CWE-1100. Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-47139
Unclassified
Jun 12, 2026
High8.7Vendor: MediumRed Hat

High [CVE-2026-47135] Sandbox escape allows arbitrary code execution on the host system

Sandbox escape allows arbitrary code execution on the host system. Red Hat rates this moderate (CVSS 8.7). Weakness: CWE-1100. Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-47135
Unclassified
Jun 12, 2026
High8.6Vendor: MediumRed Hat

High [CVE-2026-47209] Integrity bypass via incorrect property assignment leading to potential arbitrary code execution

Integrity bypass via incorrect property assignment leading to potential arbitrary code execution. Red Hat rates this moderate (CVSS 8.6). Weakness: CWE-915. Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-47209
Unclassified
Jun 12, 2026
High7.5Red Hat

High [CVE-2026-45416] Denial of Service due to eager buffer allocation in TLS handshake

Denial of Service due to eager buffer allocation in TLS handshake. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): netty-handler, offline-knowledge-portal/rhokp-rhel9:1782239370. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Offline Knowledge Portal 1.2.7; OpenShift Serverless; Red Hat AMQ Broker 7; Red Hat AMQ Clients; and 22 more.

CVE-2026-45416
Unclassified
Jun 12, 2026
High7.5Red Hat

High [CVE-2026-44894] Denial of Service amplification via improper QUIC token validation

Denial of Service amplification via improper QUIC token validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-346. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat build of Apache Camel - HawtIO 4.

CVE-2026-44894
Unclassified
Jun 12, 2026
High7.5Red Hat

High [CVE-2026-44893] Denial of Service via malformed HAProxy message

Denial of Service via malformed HAProxy message. Red Hat rates this important (CVSS 7.5). Weakness: CWE-805. Affected package(s): netty-codec-haproxy. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1; Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat build of Quarkus 3.27.4.SP1; Red Hat build of Quarkus 3.33.2.SP1; and 17 more.

CVE-2026-44893
Unclassified
Jun 12, 2026
High8.1Red Hat

High [CVE-2026-50633] Arbitrary code execution via JNDI Injection

Arbitrary code execution via JNDI Injection. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat Fuse 7.

CVE-2026-50633
Unclassified
Jun 12, 2026
High8.8Red Hat

High [CVE-2026-50632] Arbitrary code execution via untrusted JMS configuration

Arbitrary code execution via untrusted JMS configuration. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; and 1 more.

CVE-2026-50632
Unclassified
Jun 12, 2026
High7.4Red Hat

High [CVE-2026-50628] Unauthorized access due to logic error in OAuthRequestFilter

Unauthorized access due to logic error in OAuthRequestFilter. Red Hat rates this important (CVSS 7.4). Weakness: CWE-358. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat Fuse 7; Red Hat JBoss Web Server 5.

CVE-2026-50628
Unclassified
Jun 12, 2026

← All vendors