Red Hat Linux Security Advisories & CVEs
3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-12012] Use after free Network
Use after free Network. Red Hat rates this important (CVSS 8.1). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-12009] Insufficient validation of untrusted input Accessibility
Insufficient validation of untrusted input Accessibility. Red Hat rates this important (CVSS 8.3). Weakness: CWE-1286. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-12007] CVE-2026-12007
CVE-2026-12007. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-12008] Use after free DigitalCredentials
Use after free DigitalCredentials. Red Hat rates this important (CVSS 8.3). Weakness: CWE-772. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-44249] IPv6 subnet rule bypass due to incorrect masking operation
IPv6 subnet rule bypass due to incorrect masking operation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-1287. Affected package(s): netty-handler, offline-knowledge-portal/rhokp-rhel9:1782239370. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Offline Knowledge Portal 1.2.7; Red Hat OpenShift Dev Spaces 3.29; OpenShift Serverless; Red Hat AMQ Broker 7; and 23 more.
High [CVE-2026-52860] Arbitrary code execution through Python omni-completion.
Arbitrary code execution through Python omni-completion.. Red Hat rates this important (CVSS 8). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-47162] Arbitrary Code Execution via crafted directory names
Arbitrary Code Execution via crafted directory names. Red Hat rates this important (CVSS 7.3). Weakness: CWE-140. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more.
High [CVE-2026-44486] Information disclosure of proxy credentials via HTTP redirects
Information disclosure of proxy credentials via HTTP redirects. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, advanced-cluster-security/rhacs-main-rhel8:1779293013, discovery/discovery-ui-rhel9:1782166952, openshift4/ose-monitoring-plugin-rhel9:1781731914. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 44 more.
High [CVE-2026-44487] Information disclosure of proxy credentials via redirect flows
Information disclosure of proxy credentials via redirect flows. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, satellite/iop-advisor-frontend-rhel9:1782243376, openshift4/ose-monitoring-plugin-rhel9:1782171032, satellite/iop-host-inventory-frontend-rhel9:1782253070. Resolved in Red Hat advisory RHSA-2026:29864 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 46 more.
High [CVE-2026-44488] Denial of Service due to unenforced request and response size limits
Denial of Service due to unenforced request and response size limits. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, satellite/iop-advisor-frontend-rhel9:1782243376, satellite/iop-host-inventory-frontend-rhel9:1782253070, openshift-service-mesh/kiali-ossmc-rhel9:1782201894. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; and 46 more.
High [CVE-2026-44496] Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, quay/quay-rhel8:1782487717, quay/quay-rhel8:1781878070, advanced-cluster-security/rhacs-main-rhel8:1779293013. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 42 more.
High [CVE-2026-44495] Information disclosure due to prototype pollution vulnerability
Information disclosure due to prototype pollution vulnerability. Red Hat rates this important (CVSS 7). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, advanced-cluster-security/rhacs-main-rhel8:1779293013, discovery/discovery-ui-rhel9:1782166952, openshift4/ose-monitoring-plugin-rhel9:1781731914. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; and 49 more.
High [CVE-2026-44494] Man-in-the-Middle (MITM) attack via Prototype Pollution
Man-in-the-Middle (MITM) attack via Prototype Pollution. Red Hat rates this important (CVSS 8.7). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, satellite/iop-advisor-frontend-rhel9:1782243376, openshift4/ose-monitoring-plugin-rhel9:1782243791, openshift4/ose-monitoring-plugin-rhel9:1782313844. Resolved in Red Hat advisory RHSA-2026:29864 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 47 more.
High [CVE-2026-44492] Proxy bypass via IPv4-mapped IPv6 address non-normalization
Proxy bypass via IPv4-mapped IPv6 address non-normalization. Red Hat rates this important (CVSS 8.6). Weakness: CWE-289. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, advanced-cluster-security/rhacs-main-rhel8:1779293013, discovery/discovery-ui-rhel9:1782166952, openshift4/ose-monitoring-plugin-rhel9:1781731914. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 45 more.
High [CVE-2026-11816] Arbitrary file write via path traversal in archive extraction utilities
Arbitrary file write via path traversal in archive extraction utilities. Red Hat rates this important (CVSS 8.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift AI 2.25.
High [CVE-2026-5497] Denial of Service via unbounded video frame processing
Denial of Service via unbounded video frame processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-40987] Arbitrary file write via malicious server
Arbitrary file write via malicious server. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-53461] Denial of Service via out-of-bounds heap write in ICON decoder
Denial of Service via out-of-bounds heap write in ICON decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-53460] Denial of Service via missing memory request check
Denial of Service via missing memory request check. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-49218] Denial of Service via crafted DCM image with invalid dimensions
Denial of Service via crafted DCM image with invalid dimensions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.