Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5466 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High8.8Linux

High [CVE-2026-15719] Site isolation issue in the DOM: Navigation component

Site isolation issue in the DOM: Navigation component. Red Hat rates this important (CVSS 8.8). Weakness: CWE-501. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10, firefox-0:140.13.0-1.el9_8, thunderbird-0:140.13.0-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-15719
Red Hat Enterprise Linux
Jul 14, 2026
High8.8Vendor: MediumLinux

High [CVE-2026-15718] Invalid pointer in the JavaScript: WebAssembly component

Invalid pointer in the JavaScript: WebAssembly component. Red Hat rates this moderate (CVSS 8.8). Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10, firefox-0:140.13.0-1.el9_8, thunderbird-0:140.13.0-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-15718
Red Hat Enterprise Linux
Jul 14, 2026
High8.9Linux

High [CVE-2026-15416] Argo CD unauthenticated remote code execution in repo-server via GenerateManifest gRPC endpoint

Argo CD unauthenticated remote code execution in repo-server via GenerateManifest gRPC endpoint. Red Hat rates this important (CVSS 8.9). Weakness: CWE-306.

CVE-2026-15416
Unclassified
Jul 14, 2026
High7.5Linux

High [CVE-2026-15075] Information disclosure via improper handling of HTTP 30x redirects

Information disclosure via improper handling of HTTP 30x redirects. Red Hat rates this important (CVSS 7.5). Weakness: CWE-346. Red Hat lists fixing advisory RHSA-2026:47172 with package smallrye-mutiny-vertx-core, vertx-core.

CVE-2026-15075
Unclassified
Jul 14, 2026
High7.5Linux

High [CVE-2026-15076] Information disclosure via improper cookie domain validation

Information disclosure via improper cookie domain validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-346. Red Hat lists fixing advisory RHSA-2026:47172 with package vertx-web-client.

CVE-2026-15076
Unclassified
Jul 14, 2026
High8.8Linux

High [CVE-2026-59674] Privilege escalation via symbolic link following

Privilege escalation via symbolic link following. Red Hat rates this important (CVSS 8.8). Weakness: CWE-59.

CVE-2026-59674
Unclassified
Jul 14, 2026
High7.8Linux

High [CVE-2026-64600] XFS data corruption using reflink

XFS data corruption using reflink. Red Hat rates this important (CVSS 7.8). Weakness: CWE-362. Red Hat lists fixing advisory RHSA-2026:47981 with package kernel-0:6.12.0-55.89.1.el10_0, kernel-0:4.18.0-553.144.1.el8_10, kpatch-patch, kernel-0:5.14.0-284.182.1.el9_2. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-64600
Red Hat Enterprise Linux
Jul 14, 2026
Medium5.0Linux

Medium [CVE-2026-59732] File overwrite via path traversal during archive extraction

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone archive extract can write extracted files outside the user-selected destination prefix when extracting a crafted archive containing parent path components such as../, allowing creation or overwrite of sibling objects in the same bucket or path scope. This issue is fixed in version 1.74.4. An attacker could craft a malicious archive that, when extracted by a user, allows files to be written outside the intended destination directory. This path traversal vulnerability could lead to the creation or overwrite of other files within the same storage location, potentially compromising data integrity. Red Hat ships rclone in the VolSync component of Red Hat Advanced Cluster Management for Kubernetes (RHACM). All shipped versions are affected by this path traversal vulnerability in rclone's archive extraction functionality. Exploitation requires a user to actively run `rclone archive extract` on an attacker-supplied malicious archive. Red Hat severity: Moderate — CVSS 5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L). Weakness: CWE-22. Will not fix / out of support: Red Hat Advanced Cluster Management for Kubernetes 2. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-59732
Unclassified
Jul 14, 2026
Medium5.3Linux

Medium [CVE-2026-48125] Denial of Service via crafted Client Hints header

Denial of Service via crafted Client Hints header. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1333.

CVE-2026-48125
Unclassified
Jul 14, 2026
Medium5.9Vendor: HighLinux

Medium [CVE-2026-49476] Denial of Service via crafted CSS selector string

Denial of Service via crafted CSS selector string. Red Hat rates this important (CVSS 5.9). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:34119 with package python-rpds-py-main-2026.6.3-1.hum1, python-attrs-main-26.1.0-3.hum1.

CVE-2026-49476
Unclassified
Jul 14, 2026
Medium5.3Linux

Medium [CVE-2026-49854] Information disclosure via out-of-bounds read in websocket_mask

Information disclosure via out-of-bounds read in websocket_mask. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125.

CVE-2026-49854
Unclassified
Jul 14, 2026
Medium4.6Linux

Medium [CVE-2026-15778] Insufficient validation of untrusted input in Navigation

Insufficient validation of untrusted input in Navigation. Red Hat rates this moderate (CVSS 4.6). Weakness: CWE-1289.

CVE-2026-15778
Unclassified
Jul 14, 2026
Medium5.3Vendor: HighLinux

Medium [CVE-2026-15771] Insufficient validation of untrusted input in Media

Insufficient validation of untrusted input in Media. Red Hat rates this important (CVSS 5.3). Weakness: CWE-125.

CVE-2026-15771
Unclassified
Jul 14, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-15770] Uninitialized Use in V8

Uninitialized Use in V8. Red Hat rates this important (CVSS 6.5). Weakness: CWE-824.

CVE-2026-15770
Unclassified
Jul 14, 2026
Medium4.7Linux

Medium [CVE-2026-49459] Cross-site scripting bypass allows arbitrary script execution

Cross-site scripting bypass allows arbitrary script execution. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-79.

CVE-2026-49459
Unclassified
Jul 14, 2026
Medium6.1Linux

Medium [CVE-2026-49458] Cross-site scripting due to improper sanitization of DOM nodes

Cross-site scripting due to improper sanitization of DOM nodes. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-79.

CVE-2026-49458
Unclassified
Jul 14, 2026
Medium5.9Linux

Medium [CVE-2026-47423] Cross-site scripting vulnerability allows information disclosure

Cross-site scripting vulnerability allows information disclosure. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:10999 with package ruff-main-0.15.11-1.hum1.

CVE-2026-47423
Unclassified
Jul 14, 2026
Medium6.5Linux

Medium [CVE-2026-15714] Out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary string

Out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary string. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125.

CVE-2026-15714
Unclassified
Jul 14, 2026
Medium5.9Vendor: LowLinux

Medium [CVE-2026-15713] HTTP/2 frame window exhaustion remote denial of service via memory leak

HTTP/2 frame window exhaustion remote denial of service via memory leak. Red Hat rates this low (CVSS 5.9). Weakness: CWE-772.

CVE-2026-15713
Unclassified
Jul 14, 2026
Medium6.5Linux

Medium [CVE-2026-50659] .NET:.NET: Network Spoofing Vulnerability

.NET:.NET: Network Spoofing Vulnerability. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-838. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet9-0-main-9.0.119-1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50659
Red Hat Enterprise Linux
Jul 14, 2026

← All vendors