Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5466 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.5Linux

High [CVE-2026-54465] Denial of Service via unbounded memory consumption

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to implement a WebSocket server on top of a TCP server using WebSocket::Driver.server() or to complement a WebSocket client, a peer can make a single connection consume an unbounded amount of memory by sending an HTTP request or response with a never-ending list of headers. This can lead to the receiving process running out of memory. This issue is fixed in version 0.8.1. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Red Hat lists Red Hat Hardened Images as not affected.

CVE-2026-54465
Unclassified
Jul 17, 2026
High7.5Linux

High [CVE-2026-54463] Denial of Service via unbounded memory consumption in WebSocket length header

websocket-driver is a WebSocket protocol handler with pluggable I/O. This can make a WebSocket connection consume an unbounded amount of memory and lead to the host process running out of memory. This issue is fixed in version 0.8.1. A remote attacker could exploit a vulnerability in how draft versions of the WebSocket protocol handle length headers. By sending an indefinite sequence of specially crafted bytes, an attacker can cause the affected component to consume an unbounded amount of memory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Red Hat lists Red Hat Hardened Images as not affected.

CVE-2026-54463
Unclassified
Jul 17, 2026
High7.1Vendor: MediumLinux

High [CVE-2026-16118] heap-based buffer overflow in _xdg_mime_magic_parse_magic_line in xdgmimemagic.c

heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.c. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-122.

CVE-2026-16118
Unclassified
Jul 17, 2026
Medium5.1Linux

Medium [CVE-2026-45784] Heap Corruption from Incorrect Buffer Sizing

Heap Corruption from Incorrect Buffer Sizing. Red Hat rates this moderate (CVSS 5.1). Weakness: CWE-787.

CVE-2026-45784
Unclassified
Jul 17, 2026
Medium5.9Linux Updated

Medium [CVE-2026-45309] Authentication bypass due to path traversal in username during pre-authentication

Authentication bypass due to path traversal in username during pre-authentication. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-22.

CVE-2026-45309
Unclassified
Jul 17, 2026
Medium4.3Linux

Medium [CVE-2026-48487] Data integrity vulnerability via malformed DNS records

Data integrity vulnerability via malformed DNS records. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-120.

CVE-2026-48487
Unclassified
Jul 17, 2026
Medium6.5Linux

Medium [CVE-2026-48045] Unauthenticated network attacker can cause Denial of Service

Unauthenticated network attacker can cause Denial of Service. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770.

CVE-2026-48045
Unclassified
Jul 17, 2026
Medium6.5Linux

Medium [CVE-2026-47184] Denial of Service via uncontrolled memory growth

Denial of Service via uncontrolled memory growth. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770.

CVE-2026-47184
Unclassified
Jul 17, 2026
Medium6.5Linux

Medium [CVE-2026-47183] Denial of Service via unbounded memory growth from mDNS messages

Denial of Service via unbounded memory growth from mDNS messages. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770.

CVE-2026-47183
Unclassified
Jul 17, 2026
Medium6.5Linux

Medium [CVE-2026-47180] Denial of Service via crafted mDNS packets

Denial of Service via crafted mDNS packets. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-835.

CVE-2026-47180
Unclassified
Jul 17, 2026
Medium5.9Linux Updated

Medium [CVE-2026-53712] Authentication downgrade via TLS man-in-the-middle attack

Authentication downgrade via TLS man-in-the-middle attack. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-303.

CVE-2026-53712
Unclassified
Jul 17, 2026
Medium4.3Linux

Medium [CVE-2026-16104] Authenticator config endpoint exposes raw reCAPTCHA secrets to view-only admins

Authenticator config endpoint exposes raw reCAPTCHA secrets to view-only admins. Red Hat rates this moderate (CVSS 4.3).

CVE-2026-16104
Unclassified
Jul 17, 2026
Medium4.3Linux

Medium [CVE-2026-16103 +1] Incomplete fix for CIBA brute-force lockout bypass at token redemption

Incomplete fix for CIBA brute-force lockout bypass at token redemption. Red Hat rates this moderate (CVSS 4.3).

CVE-2026-16103CVE-2026-9798
Unclassified
Jul 17, 2026
Medium4.9Linux

Medium [CVE-2026-16106] Incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles

Incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles. Red Hat rates this moderate (CVSS 4.9).

CVE-2026-16106
Unclassified
Jul 17, 2026
Medium4.3Linux

Medium [CVE-2026-16108] Realm default-group reads disclose hidden groups under FGAP v2

Realm default-group reads disclose hidden groups under FGAP v2. Red Hat rates this moderate (CVSS 4.3).

CVE-2026-16108
Unclassified
Jul 17, 2026
Medium5.4Linux

Medium [CVE-2026-16093] Required signed-JWT assertion policy can be bypassed with unsigned assertion headers

Required signed-JWT assertion policy can be bypassed with unsigned assertion headers. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-807.

CVE-2026-16093
Unclassified
Jul 17, 2026
Medium5.4Linux

Medium [CVE-2026-16089] Authorization codes can be retargeted to another client session

Authorization codes can be retargeted to another client session. Red Hat rates this moderate (CVSS 5.4).

CVE-2026-16089
Unclassified
Jul 17, 2026
Medium4.9Linux

Medium [CVE-2026-16072] Organization invitation link exposure allows unauthorized member creation

Organization invitation link exposure allows unauthorized member creation. Red Hat rates this moderate (CVSS 4.9).

CVE-2026-16072
Unclassified
Jul 17, 2026
Medium5.5Linux

Medium [CVE-2026-15943] OIDC IdP update reuses masked client secret after token URL change

OIDC IdP update reuses masked client secret after token URL change. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1288.

CVE-2026-15943
Unclassified
Jul 17, 2026
Medium5.0Linux

Medium [CVE-2026-52584] Information disclosure via Buffer Overflow in DecodeImageAPNG function

Information disclosure via Buffer Overflow in DecodeImageAPNG function. Red Hat rates this moderate (CVSS 5). Weakness: CWE-120.

CVE-2026-52584
Unclassified
Jul 17, 2026

← All vendors