Red Hat Linux Security Advisories & CVEs
4701 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-5917] Arbitrary code execution via shell command injection in SSH backend
libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metacharacters such as single quotes, semicolons, or pipes. The gen_proto() function in ssh_libssh2.c inserts the repository path directly into a shell command string without escaping special characters before passing it to libssh2_channel_exec(), enabling an attacker to craft a malicious submodule URL in a.gitmodules file that, when processed during a recursive clone, causes the remote server's shell to interpret injected commands under the victim's SSH user account. By crafting a malicious repository path containing unescaped shell metacharacters, an attacker can inject commands that are then interpreted by the remote server's shell during operations like a recursive clone. This could lead to arbitrary code execution under the victim's SSH user account. This is an Important flaw. Red Hat products utilizing libgit2 with the libssh2 SSH backend are susceptible to remote arbitrary code execution. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-78. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux AI (RHEL AI) 3.
High [CVE-2026-29036] Data corruption and unauthorized modification via JSON Pointer escape decoding
cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong object keys by supplying crafted JSON Pointer escape sequences (~0 or ~1) in patch paths. Attackers can submit malicious RFC 6902 JSON Patch input to applications using cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() to silently corrupt data or delete unintended keys, potentially bypassing authorization controls in applications that rely on JSON Patch for access-controlled data modification. A flaw was found in cJSON, a JSON parser and generator. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-386. Affected Red Hat products: Red Hat Satellite 6. Red Hat lists Red Hat Enterprise Linux 8; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4 as not affected. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-19560] Arbitrary code execution via use-after-free in Blink
Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) A flaw was found in chromium-browser. A remote attacker could exploit a use-after-free vulnerability in the Blink component by enticing a user to visit a specially crafted HTML page. This could lead to arbitrary code execution within the sandbox environment, potentially compromising the affected system. This vulnerability requires user interaction, typically by visiting a specially crafted HTML page, making it a significant risk for users who process untrusted web content. The ability to execute arbitrary code, even within a sandbox, elevates the severity due to potential for further system compromise. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825.
High [CVE-2026-19559] Arbitrary code execution via use after free in HTML
Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) This can be exploited by enticing a user to visit a specially crafted HTML page. This is an Important flaw affecting Chromium-based browsers, such as chromium-browser in Red Hat products. A use-after-free vulnerability in the HTML component allows a remote attacker to achieve arbitrary code execution within the browser's sandbox. This requires user interaction, typically by visiting a specially crafted web page, but can lead to significant compromise of the affected system. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-416.
High [CVE-2026-19557] Sandbox escape via use-after-free in TabStrip
Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) This could potentially allow the attacker to escape the browser's sandbox, leading to further system compromise. This vulnerability presents a significant security risk for users of affected Red Hat systems. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.
High [CVE-2026-19558] Arbitrary code execution via malicious extension installation
Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High) This Important flaw in Google Chrome Extensions allows for arbitrary code execution within the browser's sandbox. Exploitation requires a user to be convinced to install a malicious extension, limiting the attack vector to user interaction rather than remote, unauthenticated access. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-416.
High [CVE-2026-19556] Arbitrary code execution via use-after-free in V8
Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) A flaw was found in chromium-browser. Exploitation occurs when a user visits a specially crafted HTML page, leading to a compromise of the affected system. This allows for significant system compromise, elevating its severity beyond Moderate. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-416.
High [CVE-2026-19550] trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes
A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory. This flaw only affects Identity Management (IdM/FreeIPA) servers where a cross-forest trust with Active Directory has been established (via ipa-adtrust-install and ipa trust-add). Servers without an active AD trust are not affected, since the trust object and the ADTRUST component required to reach the vulnerable code path do not exist in that configuration. Exploitation requires an ordinary, non-administrative IdM user account to trigger the vulnerable trust-fetch-domains command against a server of the attacker's choosing — no delegated administrative privilege of any kind is required. On its own, this lets an authenticated non-admin user force the IdM server to launch a privileged helper process and initiate a network connection to attacker-controlled infrastructure.
High [CVE-2026-71290] Server impersonation via improper TLS hostname verification
Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain. Please note the classic version of HttpClient is not affected by this vulnerability. Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue. A flaw was found in the asynchronous version of Apache HttpComponents Client. This improper Transport Layer Security (TLS) hostname verification vulnerability allows a remote attacker to intercept and modify network traffic. An attacker positioned to intercept and alter network traffic can present a fraudulent server certificate, bypassing TLS hostname verification and potentially leading to man-in-the-middle attacks. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-295. Affected Red Hat products: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat OpenShift Dev Spaces. Under investigation: OpenShift Serverless; Red Hat Enterprise Linux 9; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-29035] Arbitrary code execution via crafted WebSocket frames
CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that allows unauthenticated remote attackers to corrupt memory by sending compressed WebSocket frames when both USE_ZLIB and MG_EXPERIMENTAL_INTERFACES are defined. Attackers can negotiate permessage-deflate during the WebSocket handshake and send a crafted frame with the RSV1 bit set, causing the server to write a 4-byte zlib sync trailer out-of-bounds past the allocated buffer, leading to heap metadata corruption, denial of service, or potential code execution. A flaw was found in CivetWeb. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution. The vulnerability occurs during the `permessage-deflate` decompression process when specific experimental interfaces are enabled. Exploitation requires the `USE_ZLIB` and `MG_EXPERIMENTAL_INTERFACES` features to be enabled, which are not default configurations in Red Hat products. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-787.
High [CVE-2026-73241] Authentication bypass via incorrect RDSTLS PDU handling
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES PDU while rdstls_server_authenticate is waiting for RDSTLS_TYPE_AUTHREQ, leaving resultCode at RDSTLS_RESULT_SUCCESS and allowing a remote unauthenticated client to bypass the RedirectionGuid, username, domain, or password checks. This issue is fixed in version 3.30.0. By sending a crafted capabilities PDU instead of the expected authentication request, an attacker can gain an authenticated session without valid credentials. An Important flaw in FreeRDP 3.0+ allows remote, unauthenticated attackers to bypass authentication and gain session access. This vulnerability only affects servers explicitly configured with the non-default RdstlsSecurity = TRUE setting. Because RDSTLS was introduced in version 3.0, RHEL 9 and older releases are completely unaffected. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-287. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat fixing advisory: RHSA-2026:61378. Affected products named by the advisory: Red Hat package: freerdp.
High [CVE-2026-73231] @faker-js/faker: Faker: Arbitrary Code Execution via attacker-controlled fake templates
Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method in src/modules/helpers/eval.ts allows attacker-controlled fake templates to access the Function constructor through fakeEval.resolveProperty when a function returns another function, enabling arbitrary JavaScript code execution. This issue is fixed in version 10.5.0. A flaw was found in Faker, a library for generating fake data. This could allow an attacker to run malicious code within the application. Red Hat products ship @faker-js/faker as a bundled dependency. Faker is typically used for test data generation rather than in production code paths, which limits the practical attack surface. Upgrade to @faker-js/faker version 10.5.0 or later. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-94. Red Hat lists Cryostat 4; Red Hat AMQ Broker 7; Red Hat Build of Keycloak; Red Hat Enterprise Linux 10; Red Hat Hardened Images; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack as not affected.
High [CVE-2026-71474] Pull-secret bearer token written to logs on non-200 CCX response
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential. This information disclosure could grant unauthorized access to Red Hat cloud services. This vulnerability is rated as Moderate rather than Important because credential leakage requires elevated debug logging enabled alongside an upstream service failure, and access is constrained to users with log-reading permissions on the hub cluster. In standard Red Hat Advanced Cluster Management environments, default logging levels do not expose HTTP headers during regular operations. If high verbosity is activated and server communication fails, an authenticated user capable of reading container output could retrieve the cloud authentication token, allowing unauthorized interaction with associated Red Hat hosted services. Red Hat severity: Moderate — CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N). Weakness: CWE-532. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more.
High [CVE-2026-71467] Authentication bypass on /federated via Upgrade: websocket header spoofing
A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includes an `Upgrade: websocket` header. An unauthenticated attacker can exploit this by sending a specially crafted HTTP POST request to the `/federated` endpoint with the `Upgrade: websocket` header. This allows the attacker to bypass authentication and access federated search results across all configured remote managed hubs, leading to information disclosure. This is an Important flaw in Red Hat Advanced Cluster Management for Kubernetes. An unauthenticated attacker can bypass authentication by spoofing a WebSocket upgrade header when the `FEATURE_FEDERATED_SEARCH` is enabled, which is the default for Global Hub deployments. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-287. Red Hat fixing advisory: RHSA-2026:60386. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.17.
High [CVE-2026-48804] Denial of Service via binary attachment accumulation
python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. Prior to version 5.16.4, an attacker can submit a binary message and intentionally omit sending one or more of its attachments to cause the message along with the partial list of received attachments to stay in memory for a long time. Version 5.16.4 takes the following measures to address this issue: Binary packets are only accepted from authenticated clients and, when a client disconnects, the server checks if there is a partial binary message being held for the client and deletes it. This causes the incomplete messages to persist in memory, leading to excessive memory consumption and ultimately a Denial of Service (DoS) for the server. A denial of service flaw exists in python-socketio's binary packet assembly mechanism. An unauthenticated remote attacker can submit binary headers while deliberately withholding attachment streams, causing untracked memory accumulation until memory exhaustion occurs. When python-socketio processes unauthenticated websocket connections, malformed payload streams can degrade or crash the service, posing an Important impact to availability.
High [CVE-2026-73214] Denial of Service via unverified DTLS session state
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket() in src/apps/relay/dtls_listener.c retain OpenSSL dtls1_reassemble_fragment() state for a 35-byte fragmented ClientHello declaring a 650,000-byte handshake before cookie validation, allowing an unauthenticated remote sender using fresh UDP tuples to exhaust memory without TURN credentials, a completed handshake, a valid cookie, or source spoofing. This issue is fixed in version 4.16.0. A flaw was found in coturn. This vulnerability allows an unauthenticated remote attacker to cause a Denial of Service (DoS) by sending specially crafted fragmented ClientHello messages. The coturn server retains OpenSSL Datagram Transport Layer Security (DTLS) session state for these messages before validating the DTLS cookie, leading to excessive memory consumption and resource exhaustion. This flaw affects the community-maintained coturn TURN/STUN server as shipped in Fedora and EPEL. Red Hat does not ship coturn in any core Red Hat product. Fedora and EPEL currently ship coturn 4.16.0 which already includes the fix. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770.
High [CVE-2026-73212] Server-Side Request Forgery and Remote Code Execution via IP address canonicalization bypass
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_in_range() in src/client/ns_turn_ioaddr.c without canonicalizing IPv4-compatible, 6to4, and 64:ff9b::/96 NAT64 address forms, allowing an authenticated RFC 6062 TCP CONNECT relay client to bypass an IPv4 denied-peer-ip range when the Coturn host has a useful translation route. This issue is fixed in version 4.13.1. A flaw was found in Coturn. This vulnerability can lead to Server-Side Request Forgery (SSRF) and potentially remote code execution (RCE) within the internal network. Coturn is not shipped in any Red Hat product. Red Hat severity: Important — CVSS 7.7 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L). Weakness: CWE-1389.
High [CVE-2026-73089] Denial of Service via unbounded memory growth from distinct query results
Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache without a size cap, TTL, or eviction, allowing an attacker who can influence repeated browserslist() query values, including valid since `--` queries, to bypass the caller-controlled BROWSERSLIST_DISABLE_CACHE mitigation and cause linear memory growth followed by an out-of-memory process crash. This issue is fixed in version 4.28.7. This issue can cause the application to consume excessive memory, resulting in an out-of-memory process crash and a Denial of Service (DoS) for affected systems. This is an Important denial of service vulnerability in the `browserslist` library, which is used across several Red Hat products and services. The flaw allows an attacker to trigger unbounded memory growth by influencing query values, potentially leading to an out-of-memory crash and service unavailability. This is considered Important due to the potential for remote exploitation and significant impact on service stability. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770.
High [CVE-2026-73088] Prototype pollution leading to denial of service
Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist() call, processes untrusted browserslist-stats.json, opts.stats, and CLI --stats data with an unguarded for...in loop and plain-object bracket access and assignment, allowing inherited Object.prototype keys including __proto__, toString, valueOf, constructor, hasOwnProperty, and isPrototypeOf to cause an uncaught TypeError or modify the prototype of the returned normalized object. This issue is fixed in version 4.28.7. An attacker could provide specially crafted statistics data, which the tool processes without proper validation. This improper handling of untrusted data can lead to prototype pollution, potentially causing the application to crash and resulting in a denial of service. This is an Important vulnerability. The browserslist package, a front-end development tool, is vulnerable to prototype pollution when processing untrusted statistics data. This flaw can lead to a denial of service, as malicious input can crash applications that use the affected library. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-915.
High [CVE-2026-73086] Predictable ID generation due to integer overflow
nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the nanoid(size) function in index.js and index.cjs coerces the user-influenced size parameter to a signed 32-bit integer, allowing a value of 2147483648 to become -2147483648 and corrupt the process-wide CSPRNG poolOffset in fillPool(), which causes subsequent session tokens, CSRF tokens, API keys, and unique identifiers to become the deterministic string "uuuuuuuuuuuuuuuuuuuuu" until the process restarts. This issue is fixed in versions 3.3.12 and 5.1.11. A flaw was found in nanoid, a JavaScript library for generating unique string IDs. A remote attacker could exploit an integer overflow vulnerability by providing a specific input to the `nanoid(size)` function. This issue causes the internal random number generator to become predictable, leading to the generation of identical identifiers for session tokens, security tokens (Cross-Site Request Forgery (CSRF) tokens), and API keys. Such predictability could allow an attacker to bypass security measures that rely on unique and random identifiers. The attack requires specific conditions, contributing to its Important severity rather than Critical. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-1241.