Red Hat Linux Security Advisories & CVEs
5466 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-54465] Denial of Service via unbounded memory consumption
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to implement a WebSocket server on top of a TCP server using WebSocket::Driver.server() or to complement a WebSocket client, a peer can make a single connection consume an unbounded amount of memory by sending an HTTP request or response with a never-ending list of headers. This can lead to the receiving process running out of memory. This issue is fixed in version 0.8.1. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Red Hat lists Red Hat Hardened Images as not affected.
High [CVE-2026-54463] Denial of Service via unbounded memory consumption in WebSocket length header
websocket-driver is a WebSocket protocol handler with pluggable I/O. This can make a WebSocket connection consume an unbounded amount of memory and lead to the host process running out of memory. This issue is fixed in version 0.8.1. A remote attacker could exploit a vulnerability in how draft versions of the WebSocket protocol handle length headers. By sending an indefinite sequence of specially crafted bytes, an attacker can cause the affected component to consume an unbounded amount of memory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Red Hat lists Red Hat Hardened Images as not affected.
High [CVE-2026-16118] heap-based buffer overflow in _xdg_mime_magic_parse_magic_line in xdgmimemagic.c
heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.c. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-122.
Medium [CVE-2026-45784] Heap Corruption from Incorrect Buffer Sizing
Heap Corruption from Incorrect Buffer Sizing. Red Hat rates this moderate (CVSS 5.1). Weakness: CWE-787.
Medium [CVE-2026-45309] Authentication bypass due to path traversal in username during pre-authentication
Authentication bypass due to path traversal in username during pre-authentication. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-22.
Medium [CVE-2026-48487] Data integrity vulnerability via malformed DNS records
Data integrity vulnerability via malformed DNS records. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-120.
Medium [CVE-2026-48045] Unauthenticated network attacker can cause Denial of Service
Unauthenticated network attacker can cause Denial of Service. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770.
Medium [CVE-2026-47184] Denial of Service via uncontrolled memory growth
Denial of Service via uncontrolled memory growth. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770.
Medium [CVE-2026-47183] Denial of Service via unbounded memory growth from mDNS messages
Denial of Service via unbounded memory growth from mDNS messages. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770.
Medium [CVE-2026-47180] Denial of Service via crafted mDNS packets
Denial of Service via crafted mDNS packets. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-835.
Medium [CVE-2026-53712] Authentication downgrade via TLS man-in-the-middle attack
Authentication downgrade via TLS man-in-the-middle attack. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-303.
Medium [CVE-2026-16104] Authenticator config endpoint exposes raw reCAPTCHA secrets to view-only admins
Authenticator config endpoint exposes raw reCAPTCHA secrets to view-only admins. Red Hat rates this moderate (CVSS 4.3).
Medium [CVE-2026-16103 +1] Incomplete fix for CIBA brute-force lockout bypass at token redemption
Incomplete fix for CIBA brute-force lockout bypass at token redemption. Red Hat rates this moderate (CVSS 4.3).
Medium [CVE-2026-16106] Incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles
Incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles. Red Hat rates this moderate (CVSS 4.9).
Medium [CVE-2026-16108] Realm default-group reads disclose hidden groups under FGAP v2
Realm default-group reads disclose hidden groups under FGAP v2. Red Hat rates this moderate (CVSS 4.3).
Medium [CVE-2026-16093] Required signed-JWT assertion policy can be bypassed with unsigned assertion headers
Required signed-JWT assertion policy can be bypassed with unsigned assertion headers. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-807.
Medium [CVE-2026-16089] Authorization codes can be retargeted to another client session
Authorization codes can be retargeted to another client session. Red Hat rates this moderate (CVSS 5.4).
Medium [CVE-2026-16072] Organization invitation link exposure allows unauthorized member creation
Organization invitation link exposure allows unauthorized member creation. Red Hat rates this moderate (CVSS 4.9).
Medium [CVE-2026-15943] OIDC IdP update reuses masked client secret after token URL change
OIDC IdP update reuses masked client secret after token URL change. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1288.
Medium [CVE-2026-52584] Information disclosure via Buffer Overflow in DecodeImageAPNG function
Information disclosure via Buffer Overflow in DecodeImageAPNG function. Red Hat rates this moderate (CVSS 5). Weakness: CWE-120.