Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4669 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.1Red Hat

High [CVE-2026-56858] Go html/template: Cross-Site Scripting via pathological input

Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS. A flaw was found in the `html/template` component of Go (golang). This could lead to Cross-Site Scripting (XSS), where malicious scripts are executed in a user's browser, potentially compromising user data or actions. This is an Important cross-site scripting (XSS) vulnerability in the Go `html/template` package. Applications utilizing this package to render untrusted input are susceptible to arbitrary content injection due to a flaw in how pathological inputs are handled, potentially leading to client-side script execution. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N). Weakness: CWE-79. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; and 53 more. Affected products named by the advisory: Red Hat Enterprise Linux 9.6 Extended Update Support; Custom Metric Autoscaler 2.19; external secrets operator for Red Hat OpenShift 1.2; Logging Subsystem for Red Hat OpenShift 6.6; and 49 more.

CVE-2026-56858
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-56862] Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. A flaw was found in the `crypto/tls` package, part of `golang`. This forces the server to perform indefinite key derivation operations, leading to resource exhaustion and a Denial of Service (DoS) condition. A remote, unauthenticated attacker can exploit this flaw by continuously sending `KeyUpdate` messages during a TLS handshake, forcing the server to perform indefinite key derivation operations. This resource exhaustion can lead to a denial of service for applications and services in Red Hat products that use the affected `crypto/tls` library and are exposed to untrusted network clients. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1050. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; and 52 more.

CVE-2026-56862
Red Hat Enterprise Linux
Aug 13, 2026
High8.8Red Hat

High [CVE-2026-56865] Supply chain compromise via transparency log tile verification bypass

A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious module content that cannot be detected by evaluating the transparency log. All tiles are now correctly verified against their parents. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ && go mod tidy A flaw was found in golang.org/x/mod/sumdb/tlog. This allowed the proxy to bypass integrity checks and serve malicious module content to a local Go module cache, which would then go undetected by the transparency log. This could lead to a supply chain compromise where users unknowingly incorporate compromised modules. Exploitation of this vulnerability requires the victim to use a malicious or compromised Go module proxy (GOPROXY). The default GOPROXY (proxy.golang.org) is operated by Google. Users of custom or third-party Go proxies are at higher risk. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-347. Affected Red Hat products: Red Hat Advanced Cluster Security for Kubernetes 4.11; ExternalDNS Operator; OpenShift Pipelines; Red Hat OpenShift distributed tracing 3.

CVE-2026-56865
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-33818] Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal

Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. A flaw was found in the `encoding/asn1` package in Go. An attacker could provide a specially crafted, deeply-nested Abstract Syntax Notation One (ASN.1) structure, leading to excessive recursion during the `Unmarshal` operation. This could result in stack exhaustion and a Denial of Service (DoS) condition. An attacker can provide a malformed ASN.1 structure, causing excessive recursion during unmarshalling and leading to stack exhaustion, which can render the service unavailable. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-776. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; and 51 more. Affected products named by the advisory: Red Hat Enterprise Linux 9.6 Extended Update Support; Custom Metric Autoscaler 2.19; external secrets operator for Red Hat OpenShift 1.2; Logging Subsystem for Red Hat OpenShift 6.6; and 47 more.

CVE-2026-33818
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-56859] Denial of Service via XML decoding recursion depth issue

Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion. A flaw was found in the `encoding/xml` package of Go. The `DecodeElement` function failed to correctly track recursion depth, which could lead to stack exhaustion. A remote attacker could exploit this vulnerability by providing a specially crafted XML input, resulting in a Denial of Service (DoS) for the affected application. This vulnerability arises from an issue in XML decoding where a recursion depth counter fails to reset, potentially leading to stack exhaustion when processing malicious XML input. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-776. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; and 53 more. Affected products named by the advisory: Red Hat Enterprise Linux 9.6 Extended Update Support; Custom Metric Autoscaler 2.19; Logging Subsystem for Red Hat OpenShift 6.6; OpenShift API for Data Protection 1.5; and 49 more.

CVE-2026-56859
Red Hat Enterprise Linux
Aug 13, 2026
High7.2Red Hat

High [CVE-2026-73662] FreePBX Music on Hold: Arbitrary command execution by authenticated administrator

FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg123 and other allowed players in validateCustomConfiguration() in Music.class.php. An authenticated administrator can use options that write files, open control channels, or create Asterisk call files because applicationUsesDisallowedPlayerOption() does not reject those arguments, resulting in arbitrary command execution as the asterisk service user. This issue is fixed in version 17.0.7. An authenticated administrator can exploit dangerous command-line options when configuring media players, such as /usr/bin/mpg123. The CVE-2026-73662 vulnerability is in the FreePBX Music on Hold module's PHP code (Music.class.php), which fails to sanitize command-line options passed to media players. The Red Hat mpg123 and asterisk packages are not affected because the vulnerable code is solely in FreePBX's web interface, which is not shipped in any Red Hat product. mpg123 is merely invoked by FreePBX and behaves as designed. Red Hat severity: Important — CVSS 7.2 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-78. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2026-73662
Unclassified
Aug 13, 2026
High7.4Red Hat

High [CVE-2026-45774] Arbitrary file read via path traversal in profile import

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the compliance-trestle library's profile import mechanism resolves `trestle://` URIs and relative file paths by joining them with `trestle_root` and calling `.resolve()`, but performs no boundary check to ensure the resolved path stays within the trestle workspace. An attacker can craft a malicious OSCAL profile YAML with `imports[].href` containing path traversal sequences to read arbitrary files from the server filesystem. Successful exploitation could enable the attacker to read arbitrary files from the server's filesystem, potentially leading to sensitive information disclosure. This Important vulnerability in `compliance-trestle`, utilized by the File Integrity Operator, allows an unauthenticated attacker to read arbitrary files from the server filesystem. By crafting a malicious OSCAL profile YAML with path traversal sequences, an attacker can exploit improper path validation during profile import, leading to significant information disclosure. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N). Weakness: CWE-22. Affected Red Hat products: File Integrity Operator. Red Hat lists Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-45774
Unclassified
Aug 13, 2026
High7.4Red Hat

High [CVE-2026-45725] Arbitrary file write via path traversal in remote fetching mechanism

compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library's remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache file path from the URL path component without sanitizing path traversal sequences (`../`). When a remote OSCAL profile references a URL with traversal in its path, the HTTP response body is written to a location outside the intended cache directory, enabling arbitrary file write with attacker-controlled content to the filesystem. This enables arbitrary file write with attacker-controlled content, leading to potential system compromise. An attacker could exploit this by providing a malicious URL within an OSCAL profile, leading to the writing of attacker-controlled content to arbitrary locations on the filesystem. This poses a significant risk to the integrity of the system where the File Integrity Operator is deployed. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N). Weakness: CWE-22. Affected Red Hat products: File Integrity Operator. Red Hat lists Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-45725
Unclassified
Aug 13, 2026
High7.1Red Hat

High [CVE-2026-48099] Filesystem path traversal via encoded dot segments

WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path layout. The issue is fixed with version 4.3.4. A remote attacker could exploit this vulnerability by sending a specially crafted WebDAV request path containing encoded parent-directory segments. This could allow the attacker to escape the configured filesystem share root, potentially leading to unauthorized access to sensitive files or directories outside the intended scope. Red Hat products do not ship WsgiDAV. The vulnerable code path is therefore not present in any Red Hat-shipped build, and no Red Hat product is affected by this flaw. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L). Weakness: CWE-22.

CVE-2026-48099
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-73643] Denial of Service via exponential parsing in flow collections

js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2, parsing a small YAML document can take exponential time when an application calls load() or loadAll() on untrusted input. In src/parser/parser.ts, readFlowCollection uses restoreState and calls parseNode a second time when a flow-sequence entry is recognized as a key: value pair. If the key is a nested flow sequence of the same shape, every level is parsed twice, causing O(2^n) work and allowing an input under 200 bytes to keep one CPU busy for minutes, block the Node.js event loop, and stall the process. No anchors, aliases, merges, tags, or nondefault options are required. This issue is fixed in version 5.2.2. A remote attacker could exploit this vulnerability by providing specially crafted YAML input containing nested flow collections. This can lead to exponential parsing time when the application processes untrusted input, consuming excessive CPU resources. This resource exhaustion can block the Node.js event loop and cause a Denial of Service (DoS) for the affected process. This is an Important denial-of-service flaw in the `js-yaml` library, where processing specially crafted YAML input can lead to exponential parsing time.

CVE-2026-73643
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-73569] Denial of Service via repeated DOCTYPE declarations

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/OrderedObjParser.js processes multiple DOCTYPE declarations within a single XML document and passes each declaration's entities through addInputEntities(). addInputEntities() resets maxTotalExpansions and maxExpandedLength every time it is called, allowing additional DOCTYPE declarations to repeatedly reset the configured entity-expansion limits during one parse operation. A crafted XML document can then cause excessive CPU use, event-loop blocking, memory exhaustion, and process termination. This issue is fixed in version 5.10.1. A remote attacker could exploit this by submitting a specially crafted XML document containing multiple DOCTYPE declarations. This is an Important denial of service vulnerability affecting Red Hat products that process untrusted XML input using the `fast-xml-parser` library versions 5.9.3 through 5.10.0. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-776. Affected Red Hat products: Red Hat Ansible Automation Platform 2.2; Red Hat Openshift Data Foundation 4.22; Migration Toolkit for Applications 8; Red Hat OpenShift GitOps.

CVE-2026-73569
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-73566] Denial of Service via crafted long-path tar archive

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) or tar.x(...) receives a non-empty member-selection list. A crafted GNU L or PAX x long-path header with thousands of slash-separated segments reaches this.filter(entry.path, entry) in Parser[CONSUMEHEADER] in src/parse.ts before Unpack[CHECKPATH] applies maxDepth, causing an uncatchable RangeError stack overflow that terminates asynchronous and streaming Node.js consumers. This issue is fixed in version 7.5.21. A remote attacker could provide a specially crafted tar archive with a long-path header. When processing this archive with a non-empty member-selection list, an uncontrolled recursion in the `filesFilter` function can lead to a stack overflow. This issue results in a denial of service (DoS) by terminating Node.js applications that consume these archives. Important: A denial of service vulnerability exists in the `node-tar` library, affecting Node.js applications that process untrusted tar archives with member selection. This is considered Important due to the potential for service disruption in applications handling untrusted archive content. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVE-2026-73566
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-58440] Information disclosure via incomplete webhook revocation

Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`) A flaw was found in Gitea. Webhooks created by a collaborator continue to function even after their repository access is revoked. This incomplete revocation allows for the ongoing, real-time exfiltration of private repository content, leading to information disclosure. An attacker who previously held collaborator permissions can leverage these orphaned webhooks to continuously exfiltrate event payloads and sensitive private repository content without authorization. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-459. Affected Red Hat products: OpenShift Pipelines. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-58440
Unclassified
Aug 13, 2026
High7.7Red Hat

High [CVE-2026-58439] Branch protection bypass via stale approval flag in PR retargeting

Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag A flaw was found in Gitea. This could lead to unauthorized code being merged into a protected branch, compromising code integrity. This is considered Important due to the potential for unauthorized code execution within a controlled environment, despite requiring specific user interaction. Red Hat severity: Important — CVSS 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N). Weakness: CWE-472. Red Hat lists OpenShift Pipelines as not affected.

CVE-2026-58439
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-58436] Denial of Service via ParseAcceptLanguage and Locale middleware on unauthenticated requests

ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests A flaw was found in Gitea. This vulnerability allows an attacker to send specially crafted requests, leading to excessive resource consumption and a Denial of Service (DoS) condition, making the service unavailable to legitimate users. This is an Important denial of service vulnerability in Gitea. An unauthenticated remote attacker can exploit a quadratic-time algorithm in the ParseAcceptLanguage function, leading to excessive resource consumption and service unavailability. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1333. Red Hat lists OpenShift Pipelines as not affected.

CVE-2026-58436
Unclassified
Aug 13, 2026
High7.1Red Hat

High [CVE-2026-58437] Repository visibility manipulation via Git push options

Repository Visibility Manipulation via Git Push Options A flaw was found in Gitea. This could lead to unauthorized disclosure of repository information or unintended access control changes. This could lead to unauthorized disclosure of private repository contents or disruption of access to public repositories. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N). Weakness: CWE-1220. Affected Red Hat products: OpenShift Pipelines. Will not fix / out of support: OpenShift Pipelines. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-58437
Unclassified
Aug 13, 2026
High8.6Red Hat

High [CVE-2026-58314] Server-Side Request Forgery via webhooks, repository migration, and OpenID discovery

Two SSRF findings in Gitea 1.26.2 A flaw was found in Gitea. This vulnerability, known as Server-Side Request Forgery (SSRF), allows an attacker to trick the server into making requests to internal network resources. A logged-in user can exploit this by crafting malicious webhooks or repository migration configurations, leading to the disclosure of sensitive information from internal hosts. Additionally, if OpenID sign-in is enabled, an unauthenticated attacker can trigger blind GET requests to internal IPs through the OpenID discovery process, which can be used for internal network reconnaissance. A flaw in Gitea's URL parsing logic allows both authenticated users (via webhooks or repository migrations) and unauthenticated users (via OpenID discovery) to trigger HTTP GET requests to internal endpoints. By manipulating these parameters, an attacker can bypass boundary controls to perform Server-Side Request Forgery (SSRF), allowing internal network reconnaissance and disclosure of sensitive information from internal hosts. Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N). Weakness: CWE-918. Affected Red Hat products: OpenShift Pipelines. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-58314
Unclassified
Aug 13, 2026
High8.1Red Hat

High [CVE-2026-56750] Unauthorized access due to remember-me token theft not invalidating attacker sessions.

Gitea Remember-Me Token Theft Not Invalidating Attacker Session A flaw was found in Gitea. An attacker who steals a user's "Remember Me" token can maintain unauthorized access to the user's account. This occurs because the system fails to invalidate the attacker's session even after the legitimate user logs out or changes their password. This vulnerability can lead to persistent unauthorized access and potential compromise of user data. This allows an attacker to retain unauthorized access to a user's account even after the legitimate user has logged out or changed their password, extending the window of compromise. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-613. Affected Red Hat products: OpenShift Pipelines. Will not fix / out of support: OpenShift Pipelines. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-56750
Unclassified
Aug 13, 2026
High8.8Red Hat

High [CVE-2026-56654] Privilege Escalation via API Access Token Scope Escalation

Privilege Escalation via Access Token Scope Escalation in API A flaw was found in Gitea. This vulnerability allows an attacker to escalate their privileges by manipulating the scope of an access token within the API. This means an attacker could gain unauthorized access to sensitive functions or data, potentially leading to full control over affected resources. This is due to a flaw in how Gitea's API processes basic authentication with tokens, allowing the creation of new tokens with elevated scopes beyond the original token's permissions. Red Hat OpenShift Pipelines does not deploy Gitea web servers. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-266. Red Hat lists OpenShift Pipelines as not affected.

CVE-2026-56654
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-54481] Insecure TLS verification in internal API client

Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295) A flaw was found in Gitea. The internal API HTTP client is configured to skip Transport Layer Security (TLS) certificate verification, which is an insecure practice. A remote attacker on the same network segment could exploit this vulnerability to perform man-in-the-middle (MITM) attacks. This allows the attacker to intercept and potentially alter communications with the internal API, leading to unauthorized information disclosure or data manipulation. This is an Important Man-in-the-Middle attack vulnerability in Gitea's internal API client. This flaw, caused by hardcoded InsecureSkipVerify:true, allows an attacker on an adjacent network to intercept and potentially manipulate internal communications, compromising data integrity and confidentiality. Red Hat products do not use the affected modules/private/internal.go component. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-295. Affected Red Hat products: OpenShift Pipelines. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-54481
Unclassified
Aug 13, 2026

← All vendors