Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.1Red Hat

High [CVE-2026-12012] Use after free Network

Use after free Network. Red Hat rates this important (CVSS 8.1). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-12012
Unclassified
Jun 11, 2026
High8.3Red Hat

High [CVE-2026-12009] Insufficient validation of untrusted input Accessibility

Insufficient validation of untrusted input Accessibility. Red Hat rates this important (CVSS 8.3). Weakness: CWE-1286. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-12009
Unclassified
Jun 11, 2026
High8.8Red Hat

High [CVE-2026-12007] CVE-2026-12007

CVE-2026-12007. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-12007
Unclassified
Jun 11, 2026
High8.3Red Hat

High [CVE-2026-12008] Use after free DigitalCredentials

Use after free DigitalCredentials. Red Hat rates this important (CVSS 8.3). Weakness: CWE-772. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-12008
Unclassified
Jun 11, 2026
High8.1Red Hat

High [CVE-2026-44249] IPv6 subnet rule bypass due to incorrect masking operation

IPv6 subnet rule bypass due to incorrect masking operation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-1287. Affected package(s): netty-handler, offline-knowledge-portal/rhokp-rhel9:1782239370. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Offline Knowledge Portal 1.2.7; Red Hat OpenShift Dev Spaces 3.29; OpenShift Serverless; Red Hat AMQ Broker 7; and 23 more.

CVE-2026-44249
Unclassified
Jun 11, 2026
High8.0Red Hat

High [CVE-2026-52860] Arbitrary code execution through Python omni-completion.

Arbitrary code execution through Python omni-completion.. Red Hat rates this important (CVSS 8). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-52860
Unclassified
Jun 11, 2026
High7.3Red Hat

High [CVE-2026-47162] Arbitrary Code Execution via crafted directory names

Arbitrary Code Execution via crafted directory names. Red Hat rates this important (CVSS 7.3). Weakness: CWE-140. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more.

CVE-2026-47162
Unclassified
Jun 11, 2026
High7.5Red Hat

High [CVE-2026-44486] Information disclosure of proxy credentials via HTTP redirects

Information disclosure of proxy credentials via HTTP redirects. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, advanced-cluster-security/rhacs-main-rhel8:1779293013, discovery/discovery-ui-rhel9:1782166952, openshift4/ose-monitoring-plugin-rhel9:1781731914. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 44 more.

CVE-2026-44486
Unclassified
Jun 11, 2026
High7.5Red Hat

High [CVE-2026-44487] Information disclosure of proxy credentials via redirect flows

Information disclosure of proxy credentials via redirect flows. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, satellite/iop-advisor-frontend-rhel9:1782243376, openshift4/ose-monitoring-plugin-rhel9:1782171032, satellite/iop-host-inventory-frontend-rhel9:1782253070. Resolved in Red Hat advisory RHSA-2026:29864 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 46 more.

CVE-2026-44487
Unclassified
Jun 11, 2026
High7.5Red Hat

High [CVE-2026-44488] Denial of Service due to unenforced request and response size limits

Denial of Service due to unenforced request and response size limits. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, satellite/iop-advisor-frontend-rhel9:1782243376, satellite/iop-host-inventory-frontend-rhel9:1782253070, openshift-service-mesh/kiali-ossmc-rhel9:1782201894. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; and 46 more.

CVE-2026-44488
Unclassified
Jun 11, 2026
High7.5Red Hat

High [CVE-2026-44496] Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name

Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, quay/quay-rhel8:1782487717, quay/quay-rhel8:1781878070, advanced-cluster-security/rhacs-main-rhel8:1779293013. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 42 more.

CVE-2026-44496
Unclassified
Jun 11, 2026
High7.0Red Hat

High [CVE-2026-44495] Information disclosure due to prototype pollution vulnerability

Information disclosure due to prototype pollution vulnerability. Red Hat rates this important (CVSS 7). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, advanced-cluster-security/rhacs-main-rhel8:1779293013, discovery/discovery-ui-rhel9:1782166952, openshift4/ose-monitoring-plugin-rhel9:1781731914. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; and 49 more.

CVE-2026-44495
Unclassified
Jun 11, 2026
High8.7Red Hat

High [CVE-2026-44494] Man-in-the-Middle (MITM) attack via Prototype Pollution

Man-in-the-Middle (MITM) attack via Prototype Pollution. Red Hat rates this important (CVSS 8.7). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, satellite/iop-advisor-frontend-rhel9:1782243376, openshift4/ose-monitoring-plugin-rhel9:1782243791, openshift4/ose-monitoring-plugin-rhel9:1782313844. Resolved in Red Hat advisory RHSA-2026:29864 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 47 more.

CVE-2026-44494
Unclassified
Jun 11, 2026
High8.6Red Hat

High [CVE-2026-44492] Proxy bypass via IPv4-mapped IPv6 address non-normalization

Proxy bypass via IPv4-mapped IPv6 address non-normalization. Red Hat rates this important (CVSS 8.6). Weakness: CWE-289. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, advanced-cluster-security/rhacs-main-rhel8:1779293013, discovery/discovery-ui-rhel9:1782166952, openshift4/ose-monitoring-plugin-rhel9:1781731914. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 45 more.

CVE-2026-44492
Unclassified
Jun 11, 2026
High8.1Red Hat

High [CVE-2026-11816] Arbitrary file write via path traversal in archive extraction utilities

Arbitrary file write via path traversal in archive extraction utilities. Red Hat rates this important (CVSS 8.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift AI 2.25.

CVE-2026-11816
Unclassified
Jun 11, 2026
High7.5Red Hat

High [CVE-2026-5497] Denial of Service via unbounded video frame processing

Denial of Service via unbounded video frame processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-5497
Unclassified
Jun 11, 2026
High7.1Red Hat

High [CVE-2026-40987] Arbitrary file write via malicious server

Arbitrary file write via malicious server. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40987
Unclassified
Jun 11, 2026
High7.5Red Hat

High [CVE-2026-53461] Denial of Service via out-of-bounds heap write in ICON decoder

Denial of Service via out-of-bounds heap write in ICON decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-53461
Unclassified
Jun 10, 2026
High7.5Red Hat

High [CVE-2026-53460] Denial of Service via missing memory request check

Denial of Service via missing memory request check. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.

CVE-2026-53460
Unclassified
Jun 10, 2026
High7.5Red Hat

High [CVE-2026-49218] Denial of Service via crafted DCM image with invalid dimensions

Denial of Service via crafted DCM image with invalid dimensions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.

CVE-2026-49218
Unclassified
Jun 10, 2026

← All vendors