Red Hat Linux Security Advisories & CVEs
3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-50627] Token Confusion/Routing attacks due to improper validation of JWT audience claims
Token Confusion/Routing attacks due to improper validation of JWT audience claims. Red Hat rates this important (CVSS 8.1). Weakness: CWE-303. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat Fuse 7; Red Hat JBoss Web Server 5.
High [CVE-2026-49875] Information disclosure via out-of-band external entity resolution due to missing JAXP hardening
Information disclosure via out-of-band external entity resolution due to missing JAXP hardening. Red Hat rates this important (CVSS 7.5). Weakness: CWE-611. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; and 3 more.
High [CVE-2026-53705] Heap buffer overflow in WavPack decoder via integer overflow
Heap buffer overflow in WavPack decoder via integer overflow. Red Hat rates this important (CVSS 7.6). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; and 7 more.
High [CVE-2026-44890] Denial of Service via crafted Redis payloads
Denial of Service via crafted Redis payloads. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Data Grid 8.6.2; and 3 more.
High [CVE-2026-44250] Denial of Service via crafted Redis payload with deeply nested arrays
Denial of Service via crafted Redis payload with deeply nested arrays. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Data Grid 8.6.2; and 3 more.
High [CVE-2026-12034] Insufficient validation of untrusted input Linux Toolkit Theming
Insufficient validation of untrusted input Linux Toolkit Theming. Red Hat rates this important (CVSS 8.3). Weakness: CWE-1289. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-12035] Use after free Views
Use after free Views. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-12031] Inappropriate implementation Views
Inappropriate implementation Views. Red Hat rates this important (CVSS 8.3). Weakness: CWE-266. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-12030] Heap buffer overflow GPU
Heap buffer overflow GPU. Red Hat rates this important (CVSS 8.3). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-12029] Use after free Video
Use after free Video. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-12028] Use after free GPU
Use after free GPU. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-12027] Insufficient policy enforcement Headless
Insufficient policy enforcement Headless. Red Hat rates this important (CVSS 8.3). Weakness: CWE-266. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-12022] Race Safe Browsing
Race Safe Browsing. Red Hat rates this important (CVSS 8.3). Weakness: CWE-367. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-12019] Out of bounds write Codecs
Out of bounds write Codecs. Red Hat rates this important (CVSS 8.3). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-12020] Use after free Autofill
Use after free Autofill. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-12016] Insufficient validation of untrusted input DevTools
Insufficient validation of untrusted input DevTools. Red Hat rates this important (CVSS 8.3). Weakness: CWE-501. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-12017] Insufficient validation of untrusted input Extensions
Insufficient validation of untrusted input Extensions. Red Hat rates this important (CVSS 8). Weakness: CWE-653. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-12018] Inappropriate implementation Mojo
Inappropriate implementation Mojo. Red Hat rates this important (CVSS 8.8). Weakness: CWE-648. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-12014] Use after free Cast
Use after free Cast. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-12011] Use after free WebMIDI
Use after free WebMIDI. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.