Red Hat Linux Security Advisories & CVEs
5455 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-58250] Denial of Service via repeated leafnode INFO messages during pre-authentication
Denial of Service via repeated leafnode INFO messages during pre-authentication. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476.
High [CVE-2026-58253] Authentication bypass and privilege escalation via parser fast path
Authentication bypass and privilege escalation via parser fast path. Red Hat rates this important (CVSS 8.8). Weakness: CWE-551.
High [CVE-2026-59939] Denial of Service via unbounded decompression of HTTP response bodies
Denial of Service via unbounded decompression of HTTP response bodies. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Red Hat lists fixing advisory RHSA-2026:43038 with package mta/mta-solution-server-rhel9:1784109883.
High [CVE-2026-59820] Directory traversal via crafted skill archive upload
Directory traversal via crafted skill archive upload. Red Hat rates this important (CVSS 8.1). Weakness: CWE-22.
High [CVE-2026-59821] Arbitrary code execution and information disclosure via custom code guardrails
Arbitrary code execution and information disclosure via custom code guardrails. Red Hat rates this important (CVSS 7.2). Weakness: CWE-94.
High [CVE-2026-14362] HashiCorp memberlist: Denial of Service via push/pull state handling
HashiCorp memberlist: Denial of Service via push/pull state handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-59892] @opentelemetry/propagator-jaeger: OpenTelemetry JavaScript: Denial of Service via malformed HTTP header decoding
@opentelemetry/propagator-jaeger: OpenTelemetry JavaScript: Denial of Service via malformed HTTP header decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-248.
High [CVE-2026-39822] Go os.Root: Symlink following vulnerability allows directory traversal
Go os.Root: Symlink following vulnerability allows directory traversal. Red Hat rates this important (CVSS 7.8). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:44624 with package podman-6:5.8.2-5.el9_8, rhosdt/tempo-query-rhel9:1784775793, golang-0:1.26.5-1.el10_2, buildah-2:1.43.1-4.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-59725] Denial of Service via invalid binary POST requests
Denial of Service via invalid binary POST requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Red Hat lists fixing advisory RHSA-2026:37577 with package dotnet8-0-main-8.0.128-1.1.hum1.
High [CVE-2026-59724] Denial of Service via crafted WebTransport session ID
Denial of Service via crafted WebTransport session ID. Red Hat rates this important (CVSS 7.5). Weakness: CWE-843. Red Hat lists fixing advisory RHSA-2026:26994 with package dotnet8-0-main-8.0.128-1.hum1.
High [CVE-2026-59877] Denial of Service via crafted.proto schema
Denial of Service via crafted.proto schema. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835.
High [CVE-2026-59874] Denial of Service via malformed tar archive header
Denial of Service via malformed tar archive header. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Red Hat lists fixing advisory RHSA-2026:42815 with package nodejs:22-8100020260724100938.6d880403, ansible-automation-platform/automation-portal:1784622951, nodejs:24-8100020260724132848.6d880403.
High [CVE-2026-59873] Denial of Service via crafted gzip bomb
Denial of Service via crafted gzip bomb. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:44263 with package nodejs:22-8100020260724100938.6d880403, openshift4/ose-agent-installer-ui-rhel9:1784724699, ansible-automation-platform/automation-portal:1784622951, openshift4/ose-agent-installer-ui-rhel9:1784713741.
High [CVE-2026-59868] Denial of Service via quadratic CPU time parsing with merge keys
Denial of Service via quadratic CPU time parsing with merge keys. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:35272 with package nodejs20-main-20.20.2-1.hum1, dotnet8-0-main-8.0.128-1.hum1, rust-main-1.96.1-1.hum1, nodejs25-main-25.9.0-1.1.hum1.
High [CVE-2026-59869] Denial of Service via crafted YAML documents
Denial of Service via crafted YAML documents. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Red Hat lists fixing advisory RHSA-2026:47451 with package rust-main-1.97.0-1.1.hum1, openshift4/ose-agent-installer-ui-rhel9:1784724699, container-native-virtualization/kubevirt-console-plugin:1784710594, nodejs22-main-22.23.1-2.1.hum1.
High [CVE-2026-59870] Denial of Service via crafted YAML ordered-map document
Denial of Service via crafted YAML ordered-map document. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:35272 with package nodejs20-main-20.20.2-1.hum1, dotnet8-0-main-8.0.128-1.hum1, rust-main-1.96.1-1.hum1, nodejs25-main-25.9.0-1.1.hum1.
High [CVE-2026-44918] Prevent rehoming resources to nodes with different owner
Prevent rehoming resources to nodes with different owner. Red Hat rates this important (CVSS 8.7). Weakness: CWE-1220.
High [CVE-2026-55874] Information disclosure via S3 API gateway path traversal
Information disclosure via S3 API gateway path traversal. Red Hat rates this important (CVSS 7.7). Weakness: CWE-22.
High [CVE-2026-60002] Use-after-free vulnerability during host key re-exchange on the client side
Use-after-free vulnerability during host key re-exchange on the client side. Red Hat rates this important (CVSS 7.7). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:37382 with package openssh-main-10.4p1-1.hum1.
High [CVE-2026-55999] glamor Font Atlas Heap Buffer Overflow
glamor Font Atlas Heap Buffer Overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-805. Red Hat lists fixing advisory RHSA-2026:38486 with package xorg-x11-server-0:1.20.11-34.el9_8.3, xorg-x11-server-Xwayland-0:21.1.3-20.el8_10.3, xorg-x11-server-Xwayland-0:24.1.9-4.el9_8.3, xorg-x11-server-0:1.20.11-28.el8_10.3. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.