Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5812 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.9Red Hat

Medium [CVE-2026-86138] Arbitrary code execution via heap-based buffer overflow

Arbitrary code execution via heap-based buffer overflow. Red Hat rates this moderate (CVSS 6.9). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-0:2.12.5-10.el10_2.4, libxml2-0:2.9.13-14.el9_8.5, libxml2-0:2.9.7-21.el8_10.9, libxml2-main-2.15.4-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-86138
Unclassified
Sep 5, 2026
Medium6.5Red Hat

Medium [CVE-2026-53769] Unauthorized attachment modification via authorization bypass

Unauthorized attachment modification via authorization bypass. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-639. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift GitOps; and 2 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0; Red Hat package: golang.

CVE-2026-53769
Red Hat Enterprise Linux
Sep 4, 2026
Medium6.5Red Hat

Medium [CVE-2026-85769] heap out-of-bounds read in TPM2 state unmarshalling via unchecked block_skip_read blocksize

heap out-of-bounds read in TPM2 state unmarshalling via unchecked block_skip_read() blocksize. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-85769
Unclassified
Sep 4, 2026
Medium5.9Red Hat

Medium [CVE-2026-18149] Denial of Service due to orphaned response body in retry handler

Denial of Service due to orphaned response body in retry handler. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-911. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; OpenShift Pipelines; Red Hat Build of Podman Desktop; Red Hat Developer Hub; and 6 more. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; and 2 more.

CVE-2026-18149
Red Hat Enterprise Linux
Sep 4, 2026
Medium5.9Red Hat

Medium [CVE-2026-84890] Denial of Service via unbounded decompression of compressed responses

Denial of Service via unbounded decompression of compressed responses. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-409. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.

CVE-2026-84890
Red Hat Enterprise Linux
Sep 4, 2026
Medium6.5Red Hat

Medium [CVE-2026-84933] Cross-user cookie disclosure via Set-Cookie caching

Cross-user cookie disclosure via Set-Cookie caching. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-524. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.

CVE-2026-84933
Red Hat Enterprise Linux
Sep 4, 2026
Medium6.5Red Hat

Medium [CVE-2026-84947] Response truncation and connection termination

Response truncation and connection termination. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-130. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.

CVE-2026-84947
Red Hat Enterprise Linux
Sep 4, 2026
Medium5.9Red Hat

Medium [CVE-2026-85014] Denial of Service via WebSocketStream unclean close

Denial of Service via WebSocketStream unclean close. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-390. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.

CVE-2026-85014
Red Hat Enterprise Linux
Sep 4, 2026
Medium5.9Red Hat

Medium [CVE-2026-85024] Denial of Service via unhandled error in WebSocket permessage-deflate decompression

Denial of Service via unhandled error in WebSocket permessage-deflate decompression. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-431. Red Hat lists fixing advisory RHSA-2026:63782 with package nodejs26-main-26.8.2-0.1.hum1, grafana12-4-main-12.4.9-0.6.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.

CVE-2026-85024
Red Hat Enterprise Linux
Sep 4, 2026
Medium5.9Red Hat

Medium [CVE-2026-85534] HTTP/2 client crash in on_data_source_read_callback when SETTINGS INITIAL_WINDOW_SIZE shrinks during deferred body read

HTTP/2 client crash in on_data_source_read_callback when SETTINGS INITIAL_WINDOW_SIZE shrinks during deferred body read. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: libsoup3.

CVE-2026-85534
Red Hat Enterprise Linux
Sep 4, 2026
Medium6.5Red Hat

Medium [CVE-2026-81666] integer overflow in check_memb_commit_token_sanity may bypass message length validation on 32-bit systems

integer overflow in check_memb_commit_token_sanity may bypass message length validation on 32-bit systems. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: corosync.

CVE-2026-81666
Red Hat Enterprise Linux
Sep 4, 2026
Medium4.3Red Hat

Medium [CVE-2026-71197] SSRF blocklist bypass via hostname-to-IP resolution gap in web-download

SSRF blocklist bypass via hostname-to-IP resolution gap in web-download. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-918. Affected products named by the advisory: Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.

CVE-2026-71197
Unclassified
Sep 4, 2026
Medium6.5Red Hat

Medium [CVE-2026-85505] Denial of Service via stack-based buffer over-read in ipmi-oem

Denial of Service via stack-based buffer over-read in ipmi-oem. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freeipmi.

CVE-2026-85505
Red Hat Enterprise Linux
Sep 4, 2026
Medium6.2Red Hat

Medium [CVE-2026-80788] Do not WARN on remotely-controlled oversized SGL allocations

Do not WARN on remotely-controlled oversized SGL allocations. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-1285. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-80788
Linux Kernel
Sep 4, 2026
Medium5.9Red Hat

Medium [CVE-2026-84185] General JSON JWS kid binding bypass during JWKSet verification

General JSON JWS kid binding bypass during JWKSet verification. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-347. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: python-jwcrypto.

CVE-2026-84185
Red Hat Enterprise Linux
Sep 3, 2026
Medium6.5Red Hat

Medium [CVE-2026-85063] Prototype pollution via malicious CSV header

Prototype pollution via malicious CSV header. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-915. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Fuse 7; Self-service automation portal 2.

CVE-2026-85063
Unclassified
Sep 3, 2026
Medium5.3Red Hat

Medium [CVE-2026-85062] Denial of Service via oversized malformed color strings

Denial of Service via oversized malformed color strings. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 5 more. Affected products named by the advisory: Self-service automation portal 2; Red Hat package: grafana-pcp; Red Hat package: dotnet6.0; Red Hat package: dotnet7.0; and 1 more.

CVE-2026-85062
Red Hat Enterprise Linux
Sep 3, 2026
Medium6.2Red Hat

Medium [CVE-2026-71429] Denial of Service due to inefficient processing of deeply nested JSON

Denial of Service due to inefficient processing of deeply nested JSON. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-1046. Affected product named by the advisory: Red Hat Build of Podman Desktop.

CVE-2026-71429
Unclassified
Sep 3, 2026
Medium5.3Red Hat

Medium [CVE-2026-85242] Server-Side Request Forgery via favicon redirect

Server-Side Request Forgery via favicon redirect. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-918. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 9 more. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; Red Hat Ansible Automation Platform Ansible Core 2; Red Hat Discovery 2; and 5 more.

CVE-2026-85242
Unclassified
Sep 3, 2026
Medium6.5Red Hat

Medium [CVE-2026-19475] OOM DoS via $__timeGroup macro

OOM DoS via $__timeGroup macro. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-400. Affected products named by the advisory: Multicluster Global Hub; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; and 6 more. Affected products named by the advisory: Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; Red Hat Enterprise Linux 10; and 2 more.

CVE-2026-19475
Red Hat Enterprise Linux
Sep 3, 2026

← All vendors