Red Hat Linux Security Advisories & CVEs
5455 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
Low [CVE-2026-61858] Policy bypass allows unauthorized file writing via APNG encoder
Policy bypass allows unauthorized file writing via APNG encoder. Red Hat rates this low (CVSS 3.3). Weakness: CWE-22.
Critical [CVE-2026-57211] Information disclosure via path validation bypass in management plugin
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extension plugins are enabled, causing outbound DNS and SMB requests to attacker-controlled UNC paths. This issue is fixed in versions 4.1.11 and 4.2.6. A flaw was found in RabbitMQ. This can lead to outbound DNS and Server Message Block (SMB) requests to attacker-controlled network paths, potentially disclosing sensitive information. Red Hat severity: Critical — CVSS 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-76. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0 as not affected. Red Hat fixing advisory: RHSA-2026:35939, RHSA-2026:35940.
Critical [CVE-2026-15143] SSRF and local file read via user-supplied XML Schema (xml-with-schema:)
SSRF and local file read via user-supplied XML Schema (xml-with-schema:). Red Hat rates this important (CVSS 9.3). Weakness: CWE-918.
High [CVE-2026-55810] Object Injection Vulnerability
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This could enable an attacker to manipulate application data or potentially execute unauthorized code. This risk is heightened by the network-based attack vector and lack of user interaction required for exploitation, impacting the confidentiality and integrity of Red Hat products such as Ansible Services and Red Hat OpenShift AI. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-915. Red Hat lists Red Hat OpenShift AI (RHOAI) as not affected.
High [CVE-2026-57215] Persistent foreign bindings allow unauthorized message routing
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations because volatile direct-reply-to queues can be accepted at bind and route time but are missing from Khepri-backed deletion checks, leaving persistent route entries after unbind. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6. This occurs because temporary queues are not properly removed, leaving behind active routing entries. This can lead to unauthorized message routing and potential exposure of sensitive information. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-459. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0 as not affected. Red Hat fixing advisory: RHSA-2026:35939, RHSA-2026:35940.
High [CVE-2026-57219] OAuth 2 client secret disclosure via obsolete API endpoint
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and that OAuth configuration are enabled. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-477. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0 as not affected. Red Hat fixing advisory: RHSA-2026:35939, RHSA-2026:35940.
High [CVE-2026-57220] Denial of Service via oversized stream frames
RabbitMQ is a messaging and streaming broker. This issue is fixed in version 4.2.6. A flaw was found in RabbitMQ. The stream listener in RabbitMQ does not properly enforce frame-size limits during authentication and before negotiation. This allows an unauthenticated remote client to send oversized stream frames, which can consume excessive broker memory. This can lead to a denial of service (DoS) condition, making the service unavailable to legitimate users. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0 as not affected. Red Hat fixing advisory: RHSA-2026:35939, RHSA-2026:35940.
High [CVE-2026-57212] Denial of Service via oversized JSON bodies in HTTP API
RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request paths because read_complete_body checks the accumulated size before the final chunk but not the final combined size. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5. The API's body size check is incomplete, allowing the final combined size to exceed limits. This could lead to a Denial of Service (DoS) due to excessive resource consumption. Red Hat severity: Moderate — CVSS 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0 as not affected. Red Hat fixing advisory: RHSA-2026:35939, RHSA-2026:35940.
High [CVE-2026-57156] Arbitrary code execution or denial of service via integer overflow in RDP message processing
Arbitrary code execution or denial of service via integer overflow in RDP message processing. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.
High [CVE-2026-55827] Remote code execution via heap out-of-bounds write in RemoteFX decoding
Remote code execution via heap out-of-bounds write in RemoteFX decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.
High [CVE-2026-53450] Localhost services exposed via IPv4-mapped IPv6 address bypass
Localhost services exposed via IPv4-mapped IPv6 address bypass. Red Hat rates this important (CVSS 7.4). Weakness: CWE-289.
High [CVE-2026-53448] Arbitrary code execution via SQL injection in HTTPS admin panel
Arbitrary code execution via SQL injection in HTTPS admin panel. Red Hat rates this important (CVSS 7.2). Weakness: CWE-89.
High [CVE-2026-15574] Authorization header and full chat payloads logged at hard-coded DEBUG default
Authorization header and full chat payloads logged at hard-coded DEBUG default. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-538.
High [CVE-2026-43701] A malicious website may process restricted web content outside the sandbox
A malicious website may process restricted web content outside the sandbox. Red Hat rates this important (CVSS 7.1). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-43705] Maliciously crafted web content may lead to memory corruption
Maliciously crafted web content may lead to memory corruption. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-43715] Maliciously crafted web content may lead to memory corruption
Maliciously crafted web content may lead to memory corruption. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-43725] A malicious website may process restricted web content outside the sandbox
A malicious website may process restricted web content outside the sandbox. Red Hat rates this important (CVSS 7.1). Weakness: CWE-20. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-52747] Security rule bypass due to incorrect handling of line breaks in form data
Security rule bypass due to incorrect handling of line breaks in form data. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-179.
Medium [CVE-2026-52761] Web Application Firewall rules bypass due to incorrect UTF-8 to Unicode transformation
Web Application Firewall rules bypass due to incorrect UTF-8 to Unicode transformation. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-131.
Medium [CVE-2026-49844] Malformed JSON output due to improper encoding of floating-point values
Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing. Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values. This can corrupt log records or disrupt downstream log ingestion and parsing, potentially leading to a Denial of Service (DoS) or information integrity issues.