Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5455 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.5Linux

High [CVE-2026-58250] Denial of Service via repeated leafnode INFO messages during pre-authentication

Denial of Service via repeated leafnode INFO messages during pre-authentication. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476.

CVE-2026-58250
Unclassified
Jul 8, 2026
High8.8Linux

High [CVE-2026-58253] Authentication bypass and privilege escalation via parser fast path

Authentication bypass and privilege escalation via parser fast path. Red Hat rates this important (CVSS 8.8). Weakness: CWE-551.

CVE-2026-58253
Unclassified
Jul 8, 2026
High7.5Linux

High [CVE-2026-59939] Denial of Service via unbounded decompression of HTTP response bodies

Denial of Service via unbounded decompression of HTTP response bodies. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Red Hat lists fixing advisory RHSA-2026:43038 with package mta/mta-solution-server-rhel9:1784109883.

CVE-2026-59939
Unclassified
Jul 8, 2026
High8.1Linux

High [CVE-2026-59820] Directory traversal via crafted skill archive upload

Directory traversal via crafted skill archive upload. Red Hat rates this important (CVSS 8.1). Weakness: CWE-22.

CVE-2026-59820
Unclassified
Jul 8, 2026
High7.2Linux

High [CVE-2026-59821] Arbitrary code execution and information disclosure via custom code guardrails

Arbitrary code execution and information disclosure via custom code guardrails. Red Hat rates this important (CVSS 7.2). Weakness: CWE-94.

CVE-2026-59821
Unclassified
Jul 8, 2026
High7.5Linux

High [CVE-2026-14362] HashiCorp memberlist: Denial of Service via push/pull state handling

HashiCorp memberlist: Denial of Service via push/pull state handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-14362
Unclassified
Jul 8, 2026
High7.5Linux

High [CVE-2026-59892] @opentelemetry/propagator-jaeger: OpenTelemetry JavaScript: Denial of Service via malformed HTTP header decoding

@opentelemetry/propagator-jaeger: OpenTelemetry JavaScript: Denial of Service via malformed HTTP header decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-248.

CVE-2026-59892
Unclassified
Jul 8, 2026
High7.8Linux

High [CVE-2026-39822] Go os.Root: Symlink following vulnerability allows directory traversal

Go os.Root: Symlink following vulnerability allows directory traversal. Red Hat rates this important (CVSS 7.8). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:44624 with package podman-6:5.8.2-5.el9_8, rhosdt/tempo-query-rhel9:1784775793, golang-0:1.26.5-1.el10_2, buildah-2:1.43.1-4.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-39822
Red Hat Enterprise Linux
Jul 8, 2026
High7.5Linux

High [CVE-2026-59725] Denial of Service via invalid binary POST requests

Denial of Service via invalid binary POST requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Red Hat lists fixing advisory RHSA-2026:37577 with package dotnet8-0-main-8.0.128-1.1.hum1.

CVE-2026-59725
Unclassified
Jul 8, 2026
High7.5Linux

High [CVE-2026-59724] Denial of Service via crafted WebTransport session ID

Denial of Service via crafted WebTransport session ID. Red Hat rates this important (CVSS 7.5). Weakness: CWE-843. Red Hat lists fixing advisory RHSA-2026:26994 with package dotnet8-0-main-8.0.128-1.hum1.

CVE-2026-59724
Unclassified
Jul 8, 2026
High7.5Linux

High [CVE-2026-59877] Denial of Service via crafted.proto schema

Denial of Service via crafted.proto schema. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835.

CVE-2026-59877
Unclassified
Jul 8, 2026
High7.5Linux

High [CVE-2026-59874] Denial of Service via malformed tar archive header

Denial of Service via malformed tar archive header. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Red Hat lists fixing advisory RHSA-2026:42815 with package nodejs:22-8100020260724100938.6d880403, ansible-automation-platform/automation-portal:1784622951, nodejs:24-8100020260724132848.6d880403.

CVE-2026-59874
Unclassified
Jul 8, 2026
High7.5Linux

High [CVE-2026-59873] Denial of Service via crafted gzip bomb

Denial of Service via crafted gzip bomb. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:44263 with package nodejs:22-8100020260724100938.6d880403, openshift4/ose-agent-installer-ui-rhel9:1784724699, ansible-automation-platform/automation-portal:1784622951, openshift4/ose-agent-installer-ui-rhel9:1784713741.

CVE-2026-59873
Unclassified
Jul 8, 2026
High7.5Linux

High [CVE-2026-59868] Denial of Service via quadratic CPU time parsing with merge keys

Denial of Service via quadratic CPU time parsing with merge keys. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:35272 with package nodejs20-main-20.20.2-1.hum1, dotnet8-0-main-8.0.128-1.hum1, rust-main-1.96.1-1.hum1, nodejs25-main-25.9.0-1.1.hum1.

CVE-2026-59868
Unclassified
Jul 8, 2026
High7.5Linux

High [CVE-2026-59869] Denial of Service via crafted YAML documents

Denial of Service via crafted YAML documents. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Red Hat lists fixing advisory RHSA-2026:47451 with package rust-main-1.97.0-1.1.hum1, openshift4/ose-agent-installer-ui-rhel9:1784724699, container-native-virtualization/kubevirt-console-plugin:1784710594, nodejs22-main-22.23.1-2.1.hum1.

CVE-2026-59869
Unclassified
Jul 8, 2026
High7.5Linux

High [CVE-2026-59870] Denial of Service via crafted YAML ordered-map document

Denial of Service via crafted YAML ordered-map document. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:35272 with package nodejs20-main-20.20.2-1.hum1, dotnet8-0-main-8.0.128-1.hum1, rust-main-1.96.1-1.hum1, nodejs25-main-25.9.0-1.1.hum1.

CVE-2026-59870
Unclassified
Jul 8, 2026
High8.7Linux

High [CVE-2026-44918] Prevent rehoming resources to nodes with different owner

Prevent rehoming resources to nodes with different owner. Red Hat rates this important (CVSS 8.7). Weakness: CWE-1220.

CVE-2026-44918
Unclassified
Jul 8, 2026
High7.7Linux

High [CVE-2026-55874] Information disclosure via S3 API gateway path traversal

Information disclosure via S3 API gateway path traversal. Red Hat rates this important (CVSS 7.7). Weakness: CWE-22.

CVE-2026-55874
Unclassified
Jul 8, 2026
High7.7Linux

High [CVE-2026-60002] Use-after-free vulnerability during host key re-exchange on the client side

Use-after-free vulnerability during host key re-exchange on the client side. Red Hat rates this important (CVSS 7.7). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:37382 with package openssh-main-10.4p1-1.hum1.

CVE-2026-60002
Unclassified
Jul 8, 2026
High7.5Linux

High [CVE-2026-55999] glamor Font Atlas Heap Buffer Overflow

glamor Font Atlas Heap Buffer Overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-805. Red Hat lists fixing advisory RHSA-2026:38486 with package xorg-x11-server-0:1.20.11-34.el9_8.3, xorg-x11-server-Xwayland-0:21.1.3-20.el8_10.3, xorg-x11-server-Xwayland-0:24.1.9-4.el9_8.3, xorg-x11-server-0:1.20.11-28.el8_10.3. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-55999
Red Hat Enterprise Linux
Jul 8, 2026

← All vendors