Red Hat Linux Security Advisories & CVEs
5812 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-86138] Arbitrary code execution via heap-based buffer overflow
Arbitrary code execution via heap-based buffer overflow. Red Hat rates this moderate (CVSS 6.9). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-0:2.12.5-10.el10_2.4, libxml2-0:2.9.13-14.el9_8.5, libxml2-0:2.9.7-21.el8_10.9, libxml2-main-2.15.4-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
Medium [CVE-2026-53769] Unauthorized attachment modification via authorization bypass
Unauthorized attachment modification via authorization bypass. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-639. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift GitOps; and 2 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0; Red Hat package: golang.
Medium [CVE-2026-85769] heap out-of-bounds read in TPM2 state unmarshalling via unchecked block_skip_read blocksize
heap out-of-bounds read in TPM2 state unmarshalling via unchecked block_skip_read() blocksize. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-18149] Denial of Service due to orphaned response body in retry handler
Denial of Service due to orphaned response body in retry handler. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-911. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; OpenShift Pipelines; Red Hat Build of Podman Desktop; Red Hat Developer Hub; and 6 more. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; and 2 more.
Medium [CVE-2026-84890] Denial of Service via unbounded decompression of compressed responses
Denial of Service via unbounded decompression of compressed responses. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-409. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.
Medium [CVE-2026-84933] Cross-user cookie disclosure via Set-Cookie caching
Cross-user cookie disclosure via Set-Cookie caching. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-524. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.
Medium [CVE-2026-84947] Response truncation and connection termination
Response truncation and connection termination. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-130. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.
Medium [CVE-2026-85014] Denial of Service via WebSocketStream unclean close
Denial of Service via WebSocketStream unclean close. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-390. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.
Medium [CVE-2026-85024] Denial of Service via unhandled error in WebSocket permessage-deflate decompression
Denial of Service via unhandled error in WebSocket permessage-deflate decompression. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-431. Red Hat lists fixing advisory RHSA-2026:63782 with package nodejs26-main-26.8.2-0.1.hum1, grafana12-4-main-12.4.9-0.6.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.
Medium [CVE-2026-85534] HTTP/2 client crash in on_data_source_read_callback when SETTINGS INITIAL_WINDOW_SIZE shrinks during deferred body read
HTTP/2 client crash in on_data_source_read_callback when SETTINGS INITIAL_WINDOW_SIZE shrinks during deferred body read. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: libsoup3.
Medium [CVE-2026-81666] integer overflow in check_memb_commit_token_sanity may bypass message length validation on 32-bit systems
integer overflow in check_memb_commit_token_sanity may bypass message length validation on 32-bit systems. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: corosync.
Medium [CVE-2026-71197] SSRF blocklist bypass via hostname-to-IP resolution gap in web-download
SSRF blocklist bypass via hostname-to-IP resolution gap in web-download. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-918. Affected products named by the advisory: Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-85505] Denial of Service via stack-based buffer over-read in ipmi-oem
Denial of Service via stack-based buffer over-read in ipmi-oem. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freeipmi.
Medium [CVE-2026-80788] Do not WARN on remotely-controlled oversized SGL allocations
Do not WARN on remotely-controlled oversized SGL allocations. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-1285. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-84185] General JSON JWS kid binding bypass during JWKSet verification
General JSON JWS kid binding bypass during JWKSet verification. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-347. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: python-jwcrypto.
Medium [CVE-2026-85063] Prototype pollution via malicious CSV header
Prototype pollution via malicious CSV header. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-915. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Fuse 7; Self-service automation portal 2.
Medium [CVE-2026-85062] Denial of Service via oversized malformed color strings
Denial of Service via oversized malformed color strings. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 5 more. Affected products named by the advisory: Self-service automation portal 2; Red Hat package: grafana-pcp; Red Hat package: dotnet6.0; Red Hat package: dotnet7.0; and 1 more.
Medium [CVE-2026-71429] Denial of Service due to inefficient processing of deeply nested JSON
Denial of Service due to inefficient processing of deeply nested JSON. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-1046. Affected product named by the advisory: Red Hat Build of Podman Desktop.
Medium [CVE-2026-85242] Server-Side Request Forgery via favicon redirect
Server-Side Request Forgery via favicon redirect. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-918. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 9 more. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; Red Hat Ansible Automation Platform Ansible Core 2; Red Hat Discovery 2; and 5 more.
Medium [CVE-2026-19475] OOM DoS via $__timeGroup macro
OOM DoS via $__timeGroup macro. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-400. Affected products named by the advisory: Multicluster Global Hub; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; and 6 more. Affected products named by the advisory: Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; Red Hat Enterprise Linux 10; and 2 more.