Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.8Red Hat

High [CVE-2026-11687] Use after free in Dawn

Use after free in Dawn. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11687
Unclassified
Jun 8, 2026
High8.7Red Hat

High [CVE-2026-11653] Insufficient validation of untrusted input in Extensions

Insufficient validation of untrusted input in Extensions. Red Hat rates this important (CVSS 8.7). Weakness: CWE-653. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11653
Unclassified
Jun 8, 2026
High8.3Red Hat

High [CVE-2026-11667] Out of bounds read in WebRTC

Out of bounds read in WebRTC. Red Hat rates this important (CVSS 8.3). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11667
Unclassified
Jun 8, 2026
High8.2Red Hat

High [CVE-2026-11682] Insufficient validation of untrusted input in Views

Insufficient validation of untrusted input in Views. Red Hat rates this important (CVSS 8.2). Weakness: CWE-653. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11682
Unclassified
Jun 8, 2026
High8.8Red Hat

High [CVE-2026-11636] Use after free in Autofill

Use after free in Autofill. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11636
Unclassified
Jun 8, 2026
High8.8Red Hat

High [CVE-2026-11630] Use after free in File Input

Use after free in File Input. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11630
Unclassified
Jun 8, 2026
High8.8Red Hat

High [CVE-2026-11698] Use after free in Bluetooth

Use after free in Bluetooth. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1341. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11698
Unclassified
Jun 8, 2026
High8.8Red Hat

High [CVE-2026-11651] Use after free in Network

Use after free in Network. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11651
Unclassified
Jun 8, 2026
High7.3Red Hat

High [CVE-2026-11677] Race in Network

Race in Network. Red Hat rates this important (CVSS 7.3). Weakness: CWE-368. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11677
Unclassified
Jun 8, 2026
High8.8Red Hat

High [CVE-2026-11688] Object lifecycle issue in SVG

Object lifecycle issue in SVG. Red Hat rates this important (CVSS 8.8). Weakness: CWE-823. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11688
Unclassified
Jun 8, 2026
High8.7Red Hat

High [CVE-2026-11689] Insufficient validation of untrusted input in Passwords

Insufficient validation of untrusted input in Passwords. Red Hat rates this important (CVSS 8.7). Weakness: CWE-1100. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11689
Unclassified
Jun 8, 2026
High8.7Red Hat

High [CVE-2026-11693] Inappropriate implementation in Plugins

Inappropriate implementation in Plugins. Red Hat rates this important (CVSS 8.7). Weakness: CWE-653. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11693
Unclassified
Jun 8, 2026
High8.2Red Hat

High [CVE-2026-11656] Use after free in ServiceWorker

Use after free in ServiceWorker. Red Hat rates this important (CVSS 8.2). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11656
Unclassified
Jun 8, 2026
High8.8Red Hat

High [CVE-2026-11639] Use after free in Compositing

Use after free in Compositing. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11639
Unclassified
Jun 8, 2026
High7.3Red Hat

High [CVE-2026-11463] Type confusion vulnerability in Shared Pointer Handler

Type confusion vulnerability in Shared Pointer Handler. Red Hat rates this important (CVSS 7.3). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11463
Unclassified
Jun 7, 2026
High7.3Red Hat

High [CVE-2026-53473] Stored XSS via javascript: URL in Agent Credential Link

Stored XSS via javascript: URL in Agent Credential Link. Red Hat rates this important (CVSS 7.3). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-53473
Unclassified
Jun 7, 2026
High7.8Red Hat

High [CVE-2026-11332] argument injection in ansible-galaxy role install leads to arbitrary code execution

argument injection in ansible-galaxy role install leads to arbitrary code execution. Red Hat rates this important (CVSS 7.8). Weakness: CWE-88. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Discovery 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; and 11 more.

CVE-2026-11332
Unclassified
Jun 5, 2026
High7.5Red Hat

High [CVE-2026-10732] Arbitrary file write leading to remote code execution via crafted ZIP archive (Zip Slip)

Arbitrary file write leading to remote code execution via crafted ZIP archive (Zip Slip). Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Build of Keycloak; Red Hat Hardened Images.

CVE-2026-10732
Unclassified
Jun 5, 2026
High7.5Red Hat

High [CVE-2026-41567] Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload

Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload. Red Hat rates this important (CVSS 7.5). Weakness: CWE-427. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Openshift Data Foundation 4.22; OpenShift Lightspeed; OpenShift Source-to-Image (S2I); Red Hat Advanced Cluster Management for Kubernetes 2; and 18 more.

CVE-2026-41567
Unclassified
Jun 5, 2026
High7.5Red Hat

High [CVE-2026-50589] Denial of Service via crafted JSON string

Denial of Service via crafted JSON string. Red Hat rates this important (CVSS 7.5). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-50589
Unclassified
Jun 4, 2026

← All vendors