Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

275 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Low3.4Red Hat Updated

Low [CVE-2026-74983] Mitigation bypass in the Data Loss Prevention component

Mitigation bypass in the Data Loss Prevention component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-807. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-74983
Red Hat Enterprise Linux
Aug 18, 2026
Low3.4Red Hat Updated

Low [CVE-2026-74976] JIT miscompilation in the JavaScript Engine: JIT component

JIT miscompilation in the JavaScript Engine: JIT component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-733. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-74976
Red Hat Enterprise Linux
Aug 18, 2026
Low2.7Red Hat Updated

Low [CVE-2026-23938] Denial of Service via crafted JavaScript scripts

Denial of Service via crafted JavaScript scripts. Red Hat rates this low (CVSS 2.7). Weakness: CWE-770.

CVE-2026-23938
Unclassified
Aug 18, 2026
Low3.7Vendor: MediumRed Hat

Low [CVE-2026-60589] Improve Resource Resolving (2026-08 Security Update)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Red Hat severity: Moderate — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Affected Red Hat products: Red Hat Build of OpenJDK 17.0.20.1; Red Hat Build of OpenJDK 21.0.12.1; Red Hat Build of OpenJDK 25.0.4.1; Red Hat Build of OpenJDK 8u504; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat OpenJDK 11 els for RHEL 7; Red Hat OpenJDK 11 els for RHEL 8; Red Hat OpenJDK 11 els for RHEL 9; Red Hat Hardened Images; Exploit Intelligence; Red Hat build of OpenJDK 11 ELS; Red Hat build of OpenJDK 25; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.

CVE-2026-60589
Red Hat Enterprise Linux
Aug 18, 2026
Low3.1Red Hat Updated

Low [CVE-2026-74797] Denial of Service via malicious zip archives

Denial of Service via malicious zip archives. Red Hat rates this low (CVSS 3.1). Weakness: CWE-400.

CVE-2026-74797
Unclassified
Aug 16, 2026
Low3.1Red Hat Updated

Low [CVE-2026-63650] User misidentification via ignored X.509 identity field

User misidentification via ignored X.509 identity field. Red Hat rates this low (CVSS 3.1). Weakness: CWE-303.

CVE-2026-63650
Unclassified
Aug 14, 2026
Low3.1Red Hat

Low [CVE-2026-66807] potential XSS via dangerouslySetInnerHTML with unescaped resource name in getCodeSpan

potential XSS via dangerouslySetInnerHTML with unescaped resource name in getCodeSpan. Red Hat rates this low (CVSS 3.1). Weakness: CWE-79. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66807
Unclassified
Aug 14, 2026
Low3.5Red Hat Updated

Low [CVE-2026-55987] Administrator-deactivated accounts can be reactivated via OAuth2 sign-in

Administrator-deactivated accounts can be reactivated via OAuth2 sign-in. Red Hat rates this low (CVSS 3.5). Weakness: CWE-807.

CVE-2026-55987
Unclassified
Aug 13, 2026
Low2.7Red Hat Updated

Low [CVE-2026-55984] Denial of Service via Null Pointer Dereference in AddTime API

Denial of Service via Null Pointer Dereference in AddTime API. Red Hat rates this low (CVSS 2.7). Weakness: CWE-476.

CVE-2026-55984
Unclassified
Aug 13, 2026
Low0.0Red Hat

Low [CVE-2026-73626] Extension allowlist bypass allows unauthorized installations

Extension allowlist bypass allows unauthorized installations. Red Hat rates this low. Weakness: CWE-358.

CVE-2026-73626
Unclassified
Aug 13, 2026
Low3.7Red Hat

Low [CVE-2026-73492] Arbitrary code execution due to URI scheme bypass

Arbitrary code execution due to URI scheme bypass. Red Hat rates this low (CVSS 3.7). Weakness: CWE-76. Affected products named by the advisory: Red Hat 3scale API Management Platform 2; Red Hat Satellite 6.

CVE-2026-73492
Unclassified
Aug 12, 2026
Low3.7Red Hat

Low [CVE-2026-73491] Cross-Site Scripting via malformed `javascript:` URI parsing

Cross-Site Scripting via malformed `javascript:` URI parsing. Red Hat rates this low (CVSS 3.7). Weakness: CWE-1289.

CVE-2026-73491
Unclassified
Aug 12, 2026
Low3.5Red Hat

Low [CVE-2026-73281] ssh-agent allows remote execution of local operations

ssh-agent allows remote execution of local operations. Red Hat rates this low (CVSS 3.5). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: openssh.

CVE-2026-73281
Red Hat Enterprise Linux
Aug 11, 2026
Low3.3Red Hat

Low [CVE-2026-73071] Denial of Service via Use-After-Free in JSON Decoding

Denial of Service via Use-After-Free in JSON Decoding. Red Hat rates this low (CVSS 3.3). Weakness: CWE-416.

CVE-2026-73071
Unclassified
Aug 11, 2026
Low2.8Red Hat Updated

Low [CVE-2026-18503] Denial of Service via super-linear regular expression work in csv.Sniffer.sniff

Denial of Service via super-linear regular expression work in csv. Sniffer.sniff(). Red Hat rates this low (CVSS 2.8). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:57010 with package python3-10-main-3.10.21-1.hum1.

CVE-2026-18503
Unclassified
Aug 10, 2026
Low3.3Red Hat

Low [CVE-2026-66484] GNU cpio: Path Traversal allows creating hard links outside intended directory via malicious tar archives.

GNU cpio: Path Traversal allows creating hard links outside intended directory via malicious tar archives. Red Hat rates this low (CVSS 3.3). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:54508 with package cpio-main-2.15-10.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: cpio.

CVE-2026-66484
Red Hat Enterprise Linux
Aug 10, 2026
Low3.3Red Hat

Low [CVE-2026-71391] off-by-one error via a malicious font file

off-by-one error via a malicious font file. Red Hat rates this low (CVSS 3.3). Weakness: CWE-193.

CVE-2026-71391
Unclassified
Aug 10, 2026
Low3.9Red Hat

Low [CVE-2026-19411] shim/dp.c library: NULL-pointer dereference in is_removable_media_path when DevicePathToStr returns NULL

shim/dp.c library: NULL-pointer dereference in is_removable_media_path() when DevicePathToStr() returns NULL. Red Hat rates this low (CVSS 3.9). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-19411
Unclassified
Aug 10, 2026
Low3.7Red Hat

Low [CVE-2026-12372] Server-Side Request Forgery via improper network URL validation

Server-Side Request Forgery via improper network URL validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-918. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-12372
Unclassified
Aug 9, 2026
Low2.3Red Hat

Low [CVE-2026-61477] newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection

newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection. Red Hat rates this low (CVSS 2.3). Weakness: CWE-93. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26.

CVE-2026-61477
Unclassified
Aug 7, 2026

← All vendors