Red Hat Linux Security Advisories & CVEs
3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-46520] Denial of Service via out-of-bounds write when processing multiple images
Denial of Service via out-of-bounds write when processing multiple images. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-45664] Denial of Service due to excessive resource use in MNG coder
Denial of Service due to excessive resource use in MNG coder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-46522] Denial of Service via crafted MIFF file
Denial of Service via crafted MIFF file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-45359] Information Disclosure via Invalid Connected-Components Value
Information Disclosure via Invalid Connected-Components Value. Red Hat rates this important (CVSS 7.1). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-45031] Denial of Service due to resource policy bypass in PSD decoder
Denial of Service due to resource policy bypass in PSD decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-2049] Remote Code Execution via HDR File Parsing Heap-based Buffer Overflow
Remote Code Execution via HDR File Parsing Heap-based Buffer Overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-46523] Denial of Service via crafted MSL image leading to heap-use-after-free
Denial of Service via crafted MSL image leading to heap-use-after-free. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-46625] Cookie attribute manipulation via prototype pollution
Cookie attribute manipulation via prototype pollution. Red Hat rates this important (CVSS 7.5). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift-service-mesh/kiali-rhel9:1782201466. Resolved in Red Hat advisory RHSA-2026:33183 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat OpenShift Service Mesh 3.3; OpenShift Lightspeed; Red Hat 3scale API Management Platform 2; and 10 more.
High [CVE-2026-10143] Denial of Service via excessive SCRAM authentication iteration count
Denial of Service via excessive SCRAM authentication iteration count. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Affected package(s): quay/quay-rhel8:1782487717, quay/quay-rhel8:1781878070, quay/quay-rhel8:1781937357. Resolved in Red Hat advisory RHSA-2026:28571 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: kafka-python; Red Hat Quay 3.10; Red Hat Quay 3.12; Red Hat Quay 3.9; and 2 more.
High [CVE-2026-46529] PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen
PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen. Red Hat rates this important (CVSS 7.8). Weakness: CWE-77. Affected package(s): evince. Resolved in Red Hat advisory RHSA-2026:33416 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux AppStream (v. 8); Red Hat Enterprise Linux AppStream E4S (v.9.2); Red Hat Enterprise Linux AppStream E4S (v.9.4); Red Hat Enterprise Linux AppStream EUS (v.9.6); and 13 more.
High [CVE-2026-1220] Race in V8
Race in V8. Red Hat rates this important (CVSS 7.5). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-6893] Root code execution via DHCP options command injection
Root code execution via DHCP options command injection. Red Hat rates this important (CVSS 7.5). Weakness: CWE-78. Affected package(s): dracut, dracut-main. Resolved in Red Hat advisory RHSA-2026:26713 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Hardened Images; Red Hat Enterprise Linux 7; Red Hat OpenShift Container Platform 4; and 4 more.
High [CVE-2026-49759] Denial of Service via crafted SCTP ERROR chunk
Denial of Service via crafted SCTP ERROR chunk. Red Hat rates this important (CVSS 8.2). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-53437] Phishing attack via improper redirect URL validation
Phishing attack via improper redirect URL validation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-601. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: OpenShift Developer Tools and Services.
High [CVE-2026-53435] Arbitrary code execution via deserialization of attacker-controlled configuration
Arbitrary code execution via deserialization of attacker-controlled configuration. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: OpenShift Developer Tools and Services.
High [CVE-2026-12975] Unhardened SAXParser in content-type detection leads to blind XXE / SSRF / billion-laughs DoS
Unhardened SAXParser in content-type detection leads to blind XXE / SSRF / billion-laughs DoS. Red Hat rates this important (CVSS 8.5). Weakness: CWE-611. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat build of Apicurio Registry 3.
High [CVE-2026-12992] SSRF via wsdl4j import dereference in WSDL FULL validation
SSRF via wsdl4j import dereference in WSDL FULL validation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-918. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat build of Apicurio Registry 3.
High [CVE-2026-11837] ansible.posix authorized_key: local privilege escalation via symlink-following chown
ansible.posix authorized_key: local privilege escalation via symlink-following chown. Red Hat rates this important (CVSS 7.3). Weakness: CWE-59. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.
High [CVE-2026-54099] WICD CSR extra-Organization allows privilege escalation to system:masters
WICD CSR extra-Organization allows privilege escalation to system:masters. Red Hat rates this important (CVSS 8.8). Weakness: CWE-269. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat OpenShift for Windows Containers 10.22.
High [CVE-2026-54100] SSH host key not verified enables credential theft
SSH host key not verified enables credential theft. Red Hat rates this important (CVSS 8.3). Weakness: CWE-295. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat OpenShift for Windows Containers 10.22.