Red Hat Linux Security Advisories & CVEs
284 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Low [CVE-2026-56140] Apache Camel AWS SNS Component: Defense-in-depth hardening due to improper input validation
Apache Camel AWS SNS Component: Defense-in-depth hardening due to improper input validation. Red Hat rates this low.
Low [CVE-2026-14788] Denial of Service via use-after-free in r_core_bin_load function
Denial of Service via use-after-free in r_core_bin_load function. Red Hat rates this low (CVSS 3.3). Weakness: CWE-825.
Low [CVE-2026-14760] Denial of Service via local use-after-free vulnerability
Denial of Service via local use-after-free vulnerability. Red Hat rates this low (CVSS 3.3). Weakness: CWE-825.
Low [CVE-2026-14759] Denial of Service via heap-based buffer overflow
Denial of Service via heap-based buffer overflow. Red Hat rates this low (CVSS 3.3). Weakness: CWE-131.
Low [CVE-2026-14742] Information Disclosure via Weak Hash in Task Result Cache
Information Disclosure via Weak Hash in Task Result Cache. Red Hat rates this low (CVSS 3.1). Weakness: CWE-328.
Low [CVE-2026-14686] Data integrity impact due to incorrect comparison
Data integrity impact due to incorrect comparison. Red Hat rates this low (CVSS 3.3). Weakness: CWE-839. Red Hat lists fixing advisory RHSA-2026:26989 with package rust-main-1.96.1-1.hum1, netavark-main-2.0.0-1.hum1.
Low [CVE-2026-14685] Local state issue via 'Count' argument manipulation
Local state issue via 'Count' argument manipulation. Red Hat rates this low (CVSS 3.3). Weakness: CWE-1284. Red Hat lists fixing advisory RHSA-2026:26989 with package rust-main-1.96.1-1.hum1, netavark-main-2.0.0-1.hum1.
Low [CVE-2026-14683] Denial of Service via uncontrolled memory allocation
Denial of Service via uncontrolled memory allocation. Red Hat rates this low (CVSS 3.3). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:26989 with package rust-main-1.96.1-1.hum1, netavark-main-2.0.0-1.hum1.
Low [CVE-2026-14651] Denial of Service vulnerability via local manipulation of compiler functions
Denial of Service vulnerability via local manipulation of compiler functions. Red Hat rates this low (CVSS 3.3). Weakness: CWE-835.
Low [CVE-2026-14650] Denial of Service in UTF-8 Character Handler
Denial of Service in UTF-8 Character Handler. Red Hat rates this low (CVSS 3.3). Weakness: CWE-1050.
Low [CVE-2026-54891] Unauthenticated data injection during TLS handshake
Unauthenticated data injection during TLS handshake. Red Hat rates this low (CVSS 3.7). Weakness: CWE-924.
Low [CVE-2026-48978] Information disclosure and TLS downgrade via malicious registry realm
Information disclosure and TLS downgrade via malicious registry realm. Red Hat rates this low (CVSS 3.1). Weakness: CWE-918.
Low [CVE-2026-54786] Leak in WASIp1 `fd_renumber` implementation
Leak in WASIp1 `fd_renumber` implementation. Red Hat rates this low. Weakness: CWE-772.
Low [CVE-2026-58038] Cross-site Scripting vulnerability
Cross-site Scripting vulnerability. Red Hat rates this low (CVSS 3.7). Weakness: CWE-79.
Low [CVE-2026-56377] ImageMagick - Policy Bypass via Incorrect Path Validation
ImageMagick - Policy Bypass via Incorrect Path Validation. Red Hat rates this low (CVSS 3.3). Weakness: CWE-22.
Low [CVE-2026-56369] Information disclosure due to AES-CTR nonce reuse
Information disclosure due to AES-CTR nonce reuse. Red Hat rates this low (CVSS 3.7). Weakness: CWE-323.
Low [CVE-2026-56365] Magick.NET-Q8-AnyCPU: Magick.NET-Q8-OpenMP-arm6…
Magick.NET-Q8-AnyCPU: Magick.NET-Q8-OpenMP-arm64: Magick.NET-Q8-OpenMP-x64: Magick.NET-Q8-arm64: Magick.NET-Q8-x64: Magick.NET-Q8-x86: ImageMagick: Denial of Service due to memory leak in PNG encoder when processing MNG images. Red Hat rates this low (CVSS 3.7). Weakness: CWE-401.
Low [CVE-2026-56364] Magick.NET-Q16-HDRI-arm64: Magick.NET-Q16-HDRI-…
Magick.NET-Q16-HDRI-arm64: Magick.NET-Q16-HDRI-x86: Magick.NET-Q16-HDRI-OpenMP-x64: Magick.NET-Q16-HDRI-OpenMP-arm64: Magick.NET-Q8-AnyCPU: Magick.NET-Q16-AnyCPU: Magick.NET-Q16-HDRI-AnyCPU: ImageMagick: Denial of Service via memory leak in OpenCL device profile XML parsing. Red Hat rates this low (CVSS 1.9). Weakness: CWE-401.
Low [CVE-2026-56363] ImageMagick - Division by Zero in Binomial Kernel Processing
ImageMagick - Division by Zero in Binomial Kernel Processing. Red Hat rates this low (CVSS 3.3). Weakness: CWE-190.
Low [CVE-2026-56361] Heap buffer overflow via incorrect morphology parameters
Heap buffer overflow via incorrect morphology parameters. Red Hat rates this low (CVSS 3.3). Weakness: CWE-125.