Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11398 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Red Hat

High [CVE-2026-93436] Denial of Service via memory exhaustion from rejected requests

Denial of Service via memory exhaustion from rejected requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-93436
Unclassified
Sep 17, 2026
High7.5Red Hat

High [CVE-2026-54451] Elixir protobuf: Denial of Service via unbounded recursion in message decoding

Elixir protobuf: Denial of Service via unbounded recursion in message decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-54451
Unclassified
Sep 17, 2026
High7.5Red Hat

High [CVE-2026-85721] Denial of Service via unbounded HTTP response decompression

Denial of Service via unbounded HTTP response decompression. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat Fuse 7.

CVE-2026-85721
Unclassified
Sep 17, 2026
High7.5Red Hat

High [CVE-2026-85719] SOCKS proxy credentials exposed to origin server

SOCKS proxy credentials exposed to origin server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected product named by the advisory: Red Hat Fuse 7.

CVE-2026-85719
Unclassified
Sep 17, 2026
High8.8Red Hat

High [CVE-2026-86864] argument and connection-string injection via the database field in the Backup tool

argument and connection-string injection via the database field in the Backup tool. Red Hat rates this important (CVSS 8.8). Weakness: CWE-88.

CVE-2026-86864
Unclassified
Sep 17, 2026
High7.5Red Hat

High [CVE-2026-87742] Denial of Service (OOM) in quarkus-websockets-next via unbounded message buffering

Denial of Service (OOM) in quarkus-websockets-next via unbounded message buffering. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Exploit Intelligence; Red Hat Enterprise Linux AI (RHEL AI) 3.

CVE-2026-87742
Unclassified
Sep 17, 2026
High8.2Red Hat

High [CVE-2026-85078] Request smuggling via incomplete chunked-body handling

Request smuggling via incomplete chunked-body handling. Red Hat rates this important (CVSS 8.2). Weakness: CWE-444. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-85078
Unclassified
Sep 17, 2026
High8.2Red Hat

High [CVE-2026-85077] HTTP response header injection leading to session fixation or cache poisoning

HTTP response header injection leading to session fixation or cache poisoning. Red Hat rates this important (CVSS 8.2). Weakness: CWE-93. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-85077
Unclassified
Sep 17, 2026
High7.5Red Hat

High [CVE-2026-92987] Denial of Service via Quadratic Parsing

Denial of Service via Quadratic Parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Affected products named by the advisory: Confidential Compute Attestation; Logging Subsystem for Red Hat OpenShift; Red Hat Trusted Artifact Signer; Red Hat Trusted Profile Analyzer.

CVE-2026-92987
Unclassified
Sep 17, 2026
High7.5Red Hat Updated

High [CVE-2026-89059] IIOImageProvider Unbounded Image Decode (Decompression-Bomb DoS)

IIOImageProvider Unbounded Image Decode (Decompression-Bomb DoS). Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; and 12 more. Affected products named by the advisory: Red Hat build of Quarkus; Red Hat Certificate System 10; Red Hat Certificate System 11; Red Hat Enterprise Linux 10; and 8 more.

CVE-2026-89059
Unclassified
Sep 17, 2026
High7.4Vendor: MediumRed Hat Updated

High [CVE-2026-89058] CorsFilter Reflects Arbitrary Origin with Credentials under Wildcard Config

CorsFilter Reflects Arbitrary Origin with Credentials under Wildcard Config. Red Hat rates this moderate (CVSS 7.4). Weakness: CWE-346. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; and 12 more. Affected products named by the advisory: Red Hat build of Quarkus; Red Hat Certificate System 10; Red Hat Certificate System 11; Red Hat Enterprise Linux 10; and 8 more.

CVE-2026-89058
Unclassified
Sep 17, 2026
High7.5Red Hat Updated

High [CVE-2026-92961] Denial of Service via memory exhaustion

Denial of Service via memory exhaustion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282, ansible-automation-platform/automation-portal:1790254963, ansible-automation-platform/automation-portal:1790256405. Affected products named by the advisory: Self-service automation portal 2.

CVE-2026-92961
Unclassified
Sep 17, 2026
High7.1Red Hat Updated

High [CVE-2026-92959] Asynchronous code execution bypass via Promise thenable assimilation

Asynchronous code execution bypass via Promise thenable assimilation. Red Hat rates this important (CVSS 7.1). Weakness: CWE-358. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282, ansible-automation-platform/automation-portal:1790254963, ansible-automation-platform/automation-portal:1790256405. Affected products named by the advisory: Self-service automation portal 2.

CVE-2026-92959
Unclassified
Sep 17, 2026
High8.3Red Hat Updated

High [CVE-2026-92960] vm2 before 3.11.6 Process-wide State Exposure via os and dns

vm2 before 3.11.6 Process-wide State Exposure via os and dns. Red Hat rates this important (CVSS 8.3). Weakness: CWE-200. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92960
Unclassified
Sep 17, 2026
High8.5Red Hat Updated

High [CVE-2026-92958] Sandbox escape via denylist bypass in NodeVM

Sandbox escape via denylist bypass in NodeVM. Red Hat rates this important (CVSS 8.5). Weakness: CWE-1220. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282, ansible-automation-platform/automation-portal:1790254963, ansible-automation-platform/automation-portal:1790256405. Affected products named by the advisory: Self-service automation portal 2.

CVE-2026-92958
Unclassified
Sep 17, 2026
High8.6Red Hat Updated

High [CVE-2026-92954] vm2 3.10.0 through 3.11.5 Denial of Service via Host Promise

vm2 3.10.0 through 3.11.5 Denial of Service via Host Promise. Red Hat rates this important (CVSS 8.6). Weakness: CWE-248. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92954
Unclassified
Sep 17, 2026
High8.6Red Hat Updated

High [CVE-2026-92950] vm2 before 3.11.7 Sandbox Escape via CLI require

vm2 before 3.11.7 Sandbox Escape via CLI require. Red Hat rates this important (CVSS 8.6). Weakness: CWE-453. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92950
Unclassified
Sep 17, 2026
High8.3Red Hat Updated

High [CVE-2026-92947] vm2 before 3.11.7 Memory Disclosure via Buffer Pool

vm2 before 3.11.7 Memory Disclosure via Buffer Pool. Red Hat rates this important (CVSS 8.3). Weakness: CWE-200. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92947
Unclassified
Sep 17, 2026
High8.3Red Hat Updated

High [CVE-2026-92946] vm2 before 3.11.7 Remote Code Execution via require.external

vm2 before 3.11.7 Remote Code Execution via require.external. Red Hat rates this important (CVSS 8.3). Weakness: CWE-913. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282. Affected products named by the advisory: Red Hat Developer Hub 1.10; Self-service automation portal 2.

CVE-2026-92946
Unclassified
Sep 17, 2026
High7.5Red Hat Updated

High [CVE-2026-92942] Denial of Service via timeout bypass in sandboxed code

Denial of Service via timeout bypass in sandboxed code. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1100. Red Hat lists fixing advisory RHSA-2026:76788 with package rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282, ansible-automation-platform/automation-portal:1790254963, ansible-automation-platform/automation-portal:1790256405. Affected products named by the advisory: Self-service automation portal 2.

CVE-2026-92942
Unclassified
Sep 17, 2026

← All vendors