Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11398 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Low2.2Red Hat

Low [CVE-2026-93601] Name Constraint Bypass in wildcard certificate validation

Name Constraint Bypass in wildcard certificate validation. Red Hat rates this low (CVSS 2.2). Weakness: CWE-1289. Affected products named by the advisory: Ansible Automation Orchestrator 2026; Confidential Cluster Operator; Confidential Compute Attestation; Logging Subsystem for Red Hat OpenShift; and 32 more. Affected products named by the advisory: Migration Toolkit for Applications 8; OpenShift Lightspeed; OpenShift Service Mesh 3; Pen Drive Powered by Red Hat Lightspeed; and 28 more.

CVE-2026-93601
Red Hat Enterprise Linux
Sep 18, 2026
Low2.2Red Hat

Low [CVE-2026-93600] URI Name Constraint Bypass via X.509 Certificate Misissue

URI Name Constraint Bypass via X.509 Certificate Misissue. Red Hat rates this low (CVSS 2.2). Weakness: CWE-295. Affected products named by the advisory: Confidential Cluster Operator; Confidential Compute Attestation; Logging Subsystem for Red Hat OpenShift; Migration Toolkit for Applications 8; and 16 more. Affected products named by the advisory: OpenShift Lightspeed; OpenShift Service Mesh 3; Pen Drive Powered by Red Hat Lightspeed; Red Hat Ansible Automation Platform 2; and 12 more.

CVE-2026-93600
Red Hat Enterprise Linux
Sep 18, 2026
Low3.7Red Hat

Low [CVE-2026-93590] Denial of Service via UHDR encoder policy bypass

Denial of Service via UHDR encoder policy bypass. Red Hat rates this low (CVSS 3.7). Weakness: CWE-131. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: imagemagick.

CVE-2026-93590
Red Hat Enterprise Linux
Sep 18, 2026
Low3.1Red Hat

Low [CVE-2026-93588] Denial of Service via Null Pointer Dereference in PNM Coder

Denial of Service via Null Pointer Dereference in PNM Coder. Red Hat rates this low (CVSS 3.1). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: imagemagick.

CVE-2026-93588
Red Hat Enterprise Linux
Sep 18, 2026
Low2.9Red Hat

Low [CVE-2026-93586] Denial of Service via Use After Free in ImagesToBlob

Denial of Service via Use After Free in ImagesToBlob. Red Hat rates this low (CVSS 2.9). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: imagemagick.

CVE-2026-93586
Red Hat Enterprise Linux
Sep 18, 2026
Low3.3Red Hat

Low [CVE-2026-93587] Local user can cause denial of service via policy bypass in image decoders

Local user can cause denial of service via policy bypass in image decoders. Red Hat rates this low (CVSS 3.3). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: imagemagick.

CVE-2026-93587
Red Hat Enterprise Linux
Sep 18, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-93373] Arbitrary code execution outside the sandbox via crafted extension

Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High) This vulnerability is caused by a use-after-free condition, where the application attempts to access system memory after it has already been released. A remote attacker could exploit this flaw by enticing a user to install or run a specially crafted browser extension. Successful exploitation allows the attacker to bypass browser security boundaries (sandbox) and execute arbitrary code on the target system. In Red Hat Enterprise Linux environments, chromium-browser is primarily deployed on graphical workstation systems. Exploitation requires user interaction to load or run an untrusted extension. Server installations lacking graphical environments or browser packages do not expose this attack surface. Red Hat severity: Important — CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-93373
Unclassified
Sep 17, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-92957] vm2 before 3.11.7 Authentication Bypass via node: Prefix

vm2 before 3.11.7 Authentication Bypass via node: Prefix. Red Hat rates this important (CVSS 9.9). Weakness: CWE-269. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92957
Unclassified
Sep 17, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-92956] vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming

vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming. Red Hat rates this important (CVSS 9.9). Weakness: CWE-693. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92956
Unclassified
Sep 17, 2026
Critical10.0Vendor: HighRed Hat Updated

Critical [CVE-2026-92955] vm2 before 3.11.8 Sandbox Escape via NodeVM

vm2 before 3.11.8 Sandbox Escape via NodeVM. Red Hat rates this important (CVSS 10). Weakness: CWE-913. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92955
Unclassified
Sep 17, 2026
Critical9.3Vendor: HighRed Hat Updated

Critical [CVE-2026-92953] vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray

vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray. Red Hat rates this important (CVSS 9.3). Weakness: CWE-913. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92953
Unclassified
Sep 17, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-92951] vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver

vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver. Red Hat rates this important (CVSS 9.9). Weakness: CWE-706. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92951
Unclassified
Sep 17, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-92948] vm2 3.9.6 through 3.11.5 Sandbox Escape via node:test

vm2 3.9.6 through 3.11.5 Sandbox Escape via node:test. Red Hat rates this important (CVSS 9.9). Weakness: CWE-693. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92948
Unclassified
Sep 17, 2026
Critical9.8Vendor: HighRed Hat Updated

Critical [CVE-2026-92944] vm2 3.10.2 through 3.11.6 Sandbox Escape via Promise Protector

vm2 3.10.2 through 3.11.6 Sandbox Escape via Promise Protector. Red Hat rates this important (CVSS 9.8). Weakness: CWE-693. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92944
Unclassified
Sep 17, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-92941] vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation

vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation. Red Hat rates this important (CVSS 9.9). Weakness: CWE-732. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92941
Unclassified
Sep 17, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-92939] vm2 3.11.3 through 3.11.6 Native Code Execution via crypto.setEngine

vm2 3.11.3 through 3.11.6 Native Code Execution via crypto.setEngine. Red Hat rates this important (CVSS 9.9). Weakness: CWE-114. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92939
Unclassified
Sep 17, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-92938] vm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqlite

vm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqlite. Red Hat rates this important (CVSS 9.9). Weakness: CWE-693. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92938
Unclassified
Sep 17, 2026
Critical9.0Vendor: HighRed Hat Updated

Critical [CVE-2026-92935] vm2 NodeVM Remote Code Execution via Array-Shaped Require

vm2 NodeVM Remote Code Execution via Array-Shaped Require. Red Hat rates this important (CVSS 9). Weakness: CWE-913. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92935
Unclassified
Sep 17, 2026
Critical9.0Vendor: HighRed Hat Updated

Critical [CVE-2026-92934] vm2 before 3.11.8 Sandbox Escape RCE via AggregateError

vm2 before 3.11.8 Sandbox Escape RCE via AggregateError. Red Hat rates this important (CVSS 9). Weakness: CWE-693. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92934
Unclassified
Sep 17, 2026
High7.5Red Hat

High [CVE-2026-93452] Denial of Service due to buffer overflow in Snappy.compress

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's remaining capacity, corrupting off-heap memory and causing JVM termination. An attacker can trigger a buffer overflow vulnerability in the `Snappy.compress(ByteBuffer, ByteBuffer)` function by providing specially crafted, incompressible data. The corruption ultimately leads to the termination of the Java Virtual Machine (JVM), resulting in a denial of service. A flaw in snappy-java allows an attacker to terminate an application JVM when attacker-controlled, incompressible data is passed to Snappy.compress(ByteBuffer, ByteBuffer) with an undersized destination buffer. The native compression path can write beyond the supplied buffer and corrupt off-heap memory. SELinux, non-root execution, and container isolation may limit impact outside the application boundary but do not prevent application-level denial of service. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-787. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; and 8 more.

CVE-2026-93452
Unclassified
Sep 17, 2026

← All vendors