Red Hat Linux Security Advisories & CVEs
5654 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-83530] Denial of Service via uncontrolled memory allocation
A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit would be checked / enforced. A flaw was found in cel-go. A user can trigger a Denial of Service (DoS) by submitting an expression that exceeds the configured parser expression size limit. Because memory is allocated proportional to the input length before the limit is validated, processing oversized inputs causes uncontrolled memory consumption. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-770. Affected Red Hat products: Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-87872] OCAPI module_utils (ocapi_command, ocapi_info) hardcode validate_certs=False with no override, enabling TLS man-in-the-middle and credential disclosure
OCAPI module_utils (ocapi_command, ocapi_info) hardcode validate_certs=False with no override, enabling TLS man-in-the-middle and credential disclosure. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-295. Affected products named by the advisory: Red Hat Ceph Storage 5; Red Hat Ceph Storage 9; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-87818] Information disclosure through arbitrary file read
Information disclosure through arbitrary file read. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-73. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenShift AI (RHOAI); Red Hat Satellite 6.
Medium [CVE-2026-73334] KMS token disclosure due to missing host validation
KMS token disclosure due to missing host validation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-918. Affected products named by the advisory: Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-61907] JMAP snooze bypasses destination-mailbox ACL
JMAP snooze bypasses destination-mailbox ACL. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-863. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: cyrus-imapd.
Medium [CVE-2026-19729] Keycloak-services: keycloak-services: incomplete fix for arbitrary filesystem path probing via keystore parameters
A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm administrator to still submit arbitrary filesystem paths as keystore parameters. This can be used to determine the existence and readability of files on the server, potentially exposing sensitive system information. The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that exploitation requires high-level administrative privileges (manage-realm role). Successful exploitation allows an attacker to probe arbitrary filesystem paths to determine the existence and readability of files on the host system. The vulnerabilitys root cause is an incomplete input validation fix in the key provider component of keycloak-services. Weakness: CWE-22. Affected Red Hat products: Red Hat build of Keycloak 26.4; Red Hat build of Keycloak 26.4.16; Red Hat build of Keycloak 26.6; Red Hat build of Keycloak 26.6.7. Red Hat lists Red Hat Single Sign-On 7 as not affected. Red Hat fixing advisory: RHSA-2026:68276, RHSA-2026:68280, RHSA-2026:68277, RHSA-2026:68278.
Medium [CVE-2026-87083] tile-ai tilelang: Remote deserialization vulnerability in Kernel Cache
tile-ai tilelang: Remote deserialization vulnerability in Kernel Cache. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-502. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-87602] ANGLE in Google Chrome: Information disclosure via crafted HTML page
ANGLE in Google Chrome: Information disclosure via crafted HTML page. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: webkitgtk4; and 1 more. Affected products named by the advisory: Red Hat package: webkit2gtk3.
Medium [CVE-2026-87619] Observable discrepancy in Prefetch
Observable discrepancy in Prefetch. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-204.
Medium [CVE-2026-87598] Incorrect authorization in ServiceWorker
Incorrect authorization in ServiceWorker. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-940.
Medium [CVE-2026-87626] Incorrect authorization in DeviceBoundSessionCredentials
Incorrect authorization in DeviceBoundSessionCredentials. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-346.
Medium [CVE-2026-87566] Observable discrepancy in Layout
Observable discrepancy in Layout. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-204.
Medium [CVE-2026-87635] UI misrepresentation in Payments
UI misrepresentation in Payments. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-1021.
Medium [CVE-2026-87574] Information leak in ServiceWorker
Information leak in ServiceWorker. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-346.
Medium [CVE-2026-87452] Incorrect authorization in GPU
Incorrect authorization in GPU. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-346.
Medium [CVE-2026-87501] UI misrepresentation in Passwords
UI misrepresentation in Passwords. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-1021.
Medium [CVE-2026-87475] Missing authorization in Omnibox
Missing authorization in Omnibox. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-551.
Medium [CVE-2026-87476] Incorrect authorization in Loader
Incorrect authorization in Loader. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-551.
Medium [CVE-2026-87497] Uninitialized resource in Codecs
Uninitialized resource in Codecs. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-824.
Medium [CVE-2026-87645] Improper state validation in Safebrowsing
Improper state validation in Safebrowsing. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79.