Red Hat Linux Security Advisories & CVEs
11398 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-93436] Denial of Service via memory exhaustion from rejected requests
Denial of Service via memory exhaustion from rejected requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-54451] Elixir protobuf: Denial of Service via unbounded recursion in message decoding
Elixir protobuf: Denial of Service via unbounded recursion in message decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-85721] Denial of Service via unbounded HTTP response decompression
Denial of Service via unbounded HTTP response decompression. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat Fuse 7.
High [CVE-2026-85719] SOCKS proxy credentials exposed to origin server
SOCKS proxy credentials exposed to origin server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected product named by the advisory: Red Hat Fuse 7.
High [CVE-2026-86864] argument and connection-string injection via the database field in the Backup tool
argument and connection-string injection via the database field in the Backup tool. Red Hat rates this important (CVSS 8.8). Weakness: CWE-88.
High [CVE-2026-87742] Denial of Service (OOM) in quarkus-websockets-next via unbounded message buffering
Denial of Service (OOM) in quarkus-websockets-next via unbounded message buffering. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Exploit Intelligence; Red Hat Enterprise Linux AI (RHEL AI) 3.
High [CVE-2026-85078] Request smuggling via incomplete chunked-body handling
Request smuggling via incomplete chunked-body handling. Red Hat rates this important (CVSS 8.2). Weakness: CWE-444. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-85077] HTTP response header injection leading to session fixation or cache poisoning
HTTP response header injection leading to session fixation or cache poisoning. Red Hat rates this important (CVSS 8.2). Weakness: CWE-93. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-92987] Denial of Service via Quadratic Parsing
Denial of Service via Quadratic Parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Affected products named by the advisory: Confidential Compute Attestation; Logging Subsystem for Red Hat OpenShift; Red Hat Trusted Artifact Signer; Red Hat Trusted Profile Analyzer.
High [CVE-2026-89059] IIOImageProvider Unbounded Image Decode (Decompression-Bomb DoS)
IIOImageProvider Unbounded Image Decode (Decompression-Bomb DoS). Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; and 12 more. Affected products named by the advisory: Red Hat build of Quarkus; Red Hat Certificate System 10; Red Hat Certificate System 11; Red Hat Enterprise Linux 10; and 8 more.
High [CVE-2026-89058] CorsFilter Reflects Arbitrary Origin with Credentials under Wildcard Config
CorsFilter Reflects Arbitrary Origin with Credentials under Wildcard Config. Red Hat rates this moderate (CVSS 7.4). Weakness: CWE-346. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; and 12 more. Affected products named by the advisory: Red Hat build of Quarkus; Red Hat Certificate System 10; Red Hat Certificate System 11; Red Hat Enterprise Linux 10; and 8 more.
High [CVE-2026-92961] Denial of Service via memory exhaustion
Denial of Service via memory exhaustion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282, ansible-automation-platform/automation-portal:1790254963, ansible-automation-platform/automation-portal:1790256405. Affected products named by the advisory: Self-service automation portal 2.
High [CVE-2026-92959] Asynchronous code execution bypass via Promise thenable assimilation
Asynchronous code execution bypass via Promise thenable assimilation. Red Hat rates this important (CVSS 7.1). Weakness: CWE-358. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282, ansible-automation-platform/automation-portal:1790254963, ansible-automation-platform/automation-portal:1790256405. Affected products named by the advisory: Self-service automation portal 2.
High [CVE-2026-92960] vm2 before 3.11.6 Process-wide State Exposure via os and dns
vm2 before 3.11.6 Process-wide State Exposure via os and dns. Red Hat rates this important (CVSS 8.3). Weakness: CWE-200. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.
High [CVE-2026-92958] Sandbox escape via denylist bypass in NodeVM
Sandbox escape via denylist bypass in NodeVM. Red Hat rates this important (CVSS 8.5). Weakness: CWE-1220. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282, ansible-automation-platform/automation-portal:1790254963, ansible-automation-platform/automation-portal:1790256405. Affected products named by the advisory: Self-service automation portal 2.
High [CVE-2026-92954] vm2 3.10.0 through 3.11.5 Denial of Service via Host Promise
vm2 3.10.0 through 3.11.5 Denial of Service via Host Promise. Red Hat rates this important (CVSS 8.6). Weakness: CWE-248. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.
High [CVE-2026-92950] vm2 before 3.11.7 Sandbox Escape via CLI require
vm2 before 3.11.7 Sandbox Escape via CLI require. Red Hat rates this important (CVSS 8.6). Weakness: CWE-453. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.
High [CVE-2026-92947] vm2 before 3.11.7 Memory Disclosure via Buffer Pool
vm2 before 3.11.7 Memory Disclosure via Buffer Pool. Red Hat rates this important (CVSS 8.3). Weakness: CWE-200. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.
High [CVE-2026-92946] vm2 before 3.11.7 Remote Code Execution via require.external
vm2 before 3.11.7 Remote Code Execution via require.external. Red Hat rates this important (CVSS 8.3). Weakness: CWE-913. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.
High [CVE-2026-92942] Denial of Service via timeout bypass in sandboxed code
Denial of Service via timeout bypass in sandboxed code. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1100. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282, ansible-automation-platform/automation-portal:1790254963, ansible-automation-platform/automation-portal:1790256405. Affected products named by the advisory: Self-service automation portal 2.