Red Hat Red Hat Linux OS and other open source products

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Red Hat product.

RSS Feeds for Red Hat security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Red Hat products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Red Hat Sorted by Most Security Vulnerabilities since 2018

Red Hat Enterprise Linux (RHEL)2773 vulnerabilities

Red Hat Enterprise Linux Server1534 vulnerabilities
RedHat Enterprise Linux (RHEL) Server. Includes software bundeled with RHEL server.

Red Hat Enterprise Linux Workstation1504 vulnerabilities
RedHat Enterprise Linux (RHEL) Workstation. Includes software bundled with RHEL Workstation.

Red Hat Enterprise Linux Desktop1493 vulnerabilities
RedHat Enterprise Linux (RHEL) Desktop. Includes software bundled with RHEL desktop

Red Hat Enterprise Linux Eus1168 vulnerabilities

Red Hat Openshift629 vulnerabilities

Red Hat Rhel Eus624 vulnerabilities

Red Hat Rhel E4s531 vulnerabilities

Red Hat Rhel Tus459 vulnerabilities

Red Hat Rhel Aus446 vulnerabilities

Red Hat Satellite369 vulnerabilities

Red Hat Rhel Eus Long Life363 vulnerabilities

Red Hat Rhel Els352 vulnerabilities

Red Hat Openshift Ai329 vulnerabilities

Red Hat Hummingbird303 vulnerabilities

Red Hat Openstack283 vulnerabilities

Red Hat Jbosseapxp241 vulnerabilities

Red Hat Build Keycloak226 vulnerabilities

Red Hat Jboss Fuse213 vulnerabilities

Red Hat Rhivos199 vulnerabilities

Red Hat Jboss Data Grid199 vulnerabilities

Red Hat Single Sign On185 vulnerabilities

Red Hat Acm157 vulnerabilities

Red Hat Enterprise Linux Ai155 vulnerabilities

Red Hat Quay154 vulnerabilities

Red Hat Openshift Devspaces154 vulnerabilities

Red Hat Rhdh127 vulnerabilities

Red Hat Discovery125 vulnerabilities

Red Hat Software Collections123 vulnerabilities

Red Hat Keycloak123 vulnerabilities

Red Hat Cryostat120 vulnerabilities

Red Hat Virtualization115 vulnerabilities

Red Hat Ai Inference Server105 vulnerabilities

Red Hat Kafka104 vulnerabilities

Red Hat Ceph Storage99 vulnerabilities

Red Hat Apache Camel Hawtio96 vulnerabilities

Red Hat Multicluster Engine96 vulnerabilities

Red Hat Single Sign On95 vulnerabilities

Red Hat Openshift Pipelines95 vulnerabilities

Red Hat Rhui94 vulnerabilities

Red Hat Logging91 vulnerabilities

Red Hat Camel Spring Boot88 vulnerabilities

Red Hat Amq Streams84 vulnerabilities

Red Hat Service Mesh84 vulnerabilities

Red Hat Amq Broker79 vulnerabilities

Red Hat Ansible Portal77 vulnerabilities

Red Hat Openshift Lightspeed75 vulnerabilities

Red Hat Serverless75 vulnerabilities

Red Hat Http Server72 vulnerabilities

Red Hat Ansible Tower69 vulnerabilities

Red Hat Openshift Gitops68 vulnerabilities

Red Hat Quarkus67 vulnerabilities

Red Hat 3scale Amp62 vulnerabilities

Red Hat Camel Quarkus59 vulnerabilities

Red Hat Podman Desktop58 vulnerabilities

Red Hat Apicurio Registry57 vulnerabilities

Red Hat Rhmt56 vulnerabilities

Red Hat Satellite Capsule56 vulnerabilities

Red Hat Libvirt55 vulnerabilities

Red Hat Multicluster Globalhub54 vulnerabilities

Red Hat Service Registry54 vulnerabilities

Red Hat Directory Server53 vulnerabilities

Red Hat Virtualization Host53 vulnerabilities

Red Hat Network Observ Optr51 vulnerabilities

Red Hat Jboss Core Services48 vulnerabilities

Red Hat Insights Proxy44 vulnerabilities

Red Hat Ansible42 vulnerabilities

Red Hat Satellite Utils42 vulnerabilities

Recent Red Hat Security Advisories

Advisory Title Published
RHSA-2026:66545 (RHSA-2026:66545) Important: Red Hat AMQ Broker 7.13.6 release and security update September 10, 2026
RHSA-2026:66542 (RHSA-2026:66542) Important: nginx security update September 10, 2026
RHSA-2026:66488 (RHSA-2026:66488) Important: Red Hat AMQ Broker 7.14.1 release and security update September 10, 2026
RHSA-2026:66460 (RHSA-2026:66460) Moderate: gstreamer1-plugins-base security update September 10, 2026
RHSA-2026:66459 (RHSA-2026:66459) Important: grafana-pcp security update September 10, 2026
RHSA-2026:66432 (RHSA-2026:66432) Important: osbuild-composer security update September 10, 2026
RHSA-2026:66410 (RHSA-2026:66410) Important: openssh security update September 10, 2026
RHSA-2026:66407 (RHSA-2026:66407) Important: gstreamer1-plugins-bad-free security update September 10, 2026
RHSA-2026:66406 (RHSA-2026:66406) Important: gstreamer1-plugins-bad-free security update September 10, 2026
RHSA-2026:66405 (RHSA-2026:66405) Important: rsyslog security update September 10, 2026

By the Year

In 2026 there have been 3179 vulnerabilities in Red Hat with an average score of 7.2 out of ten. Last year, in 2025 Red Hat had 1178 security vulnerabilities published. That is, 2001 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.35.




Year Vulnerabilities Average Score
2026 3179 7.21
2025 1178 6.86
2024 1694 6.82
2023 1207 6.74
2022 1362 6.96
2021 1123 6.61
2020 664 6.39
2019 772 6.98
2018 760 7.16

It may take a day or so for new Red Hat vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Red Hat Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-89329 Sep 11, 2026
Red Hat multipathd IPC DoS via blocked listener thread A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.
Enterprise Linux (RHEL)
Openshift
CVE-2026-18495 Sep 11, 2026
libtiff tiff2pdf Heap-BUF Overflow via Truncated StripByteCounts A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.
Hummingbird
Ceph Storage
Enterprise Linux (RHEL)
And others...
CVE-2026-89298 Sep 11, 2026
Keycloak DCR Service Leak: Admin Role Reveals Client Secret A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution. The issue occurs when a user with the view-clients role accesses the client registration endpoint to retrieve client details. Due to a failure to mask sensitive information, the service returns the client's confidential secret in cleartext. This could allow a read-only administrator to obtain full access to the affected client's account and potentially escalate their privileges within the realm.
Build Keycloak
Red Hat Single Sign On
CVE-2026-77159 Sep 11, 2026
Privilege Escalation via Symlink Chown in libvirt qemuTPMEmulatorPrepareHost A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can replace the logfile with a symlink, causing libvirtd (running as root) to transfer ownership of an arbitrary file to the swtpm user.
Enterprise Linux (RHEL)
CVE-2026-89060 Sep 11, 2026
CVE-2026-89060: multicluster-observability-addon Namespace Escalation A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed clusters ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster.
Acm
CVE-2026-88914 Sep 11, 2026
GStreamer gst-plugins-good isomp4 Integer Overflow in Closed-Caption Parser A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes, which is then included in the downstream caption output. An attacker could exploit this by tricking a user into opening a malicious media file, potentially resulting in disclosure of adjacent heap memory or application crash.
Enterprise Linux (RHEL)
CVE-2026-88924 Sep 10, 2026
Local Privilege Escalation via TOCTOU in gvfsd-admin (Red Hat) A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root.
Enterprise Linux (RHEL)
CVE-2026-88859 Sep 10, 2026
Evolution JS Execution via Spoofed vCard Control in HTML Email A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler incorrectly assigns an attacker-controlled JavaScript URL to an iframe's source. This action leads to arbitrary JavaScript execution within the mail-viewing context, effectively bypassing the security measures designed to prevent script execution in email content.
Enterprise Linux (RHEL)
CVE-2026-84828 Sep 10, 2026
PCS: Local File Disclosure via pcs host auth --token A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the files are shorter than 256 bytes. The file contents are read with root privileges by the pcsd daemon and can be exfiltrated by the attacker through subsequent cluster node communication. This allows disclosure of sensitive data such as API keys, tokens, or configuration secrets that would otherwise be inaccessible to the attacker.
Enterprise Linux (RHEL)
Openshift
Openstack
And others...
CVE-2026-88265 Sep 10, 2026
CVE-2026-88265: crun 1.29.1 and below pivot_root stdio symlink issue A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.
Hummingbird
CVE-2026-88264 Sep 10, 2026
crun 1.29.1: /dev Console Redirect via Terminal Setup Insecure Bind-Mount A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.
Hummingbird
CVE-2026-84042 Sep 10, 2026
crun 1.29+ Priv Esc via PassNet (libkrun) A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The issue is a regression in crun 1.29. It affects crun >= 1.29
Hummingbird
CVE-2026-44950 Sep 10, 2026
Heap buffer overflow in libXfont2 fs_read_glyphs() fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination cursor has exceeded the allocation. A malicious font server can send overlapping source offsets -- for example 1000 glyphs each referencing {position:0, length:64} with nbytes=64. Each individual source range passes the existing validation, but the cumulative writes total 64000 bytes into a 64-byte destination buffer. This is a heap buffer overflow with attacker-controlled content.
CVE-2026-59679 Sep 10, 2026
OOB Heap Read in libXfont2 query glyphs (CVE-2026-59679) fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked. A malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. This causes attacker-controlled out-of-bounds heap read and writes.
CVE-2026-88770 Sep 10, 2026
Keycloak Device Auth Grant Brute-Force Bypass for Locked Accounts A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue occurs because the token redemption process fails to check if a user account is currently locked due to brute-force protection. If an attacker has an active session for a locked account, they can complete the device login process and receive new security tokens. This allows the attacker to maintain access to the account even when it should be temporarily disabled to prevent unauthorized entry.
Build Keycloak
Red Hat Single Sign On
CVE-2026-88763 Sep 10, 2026
SkupperRouter AMQP Parser Recursion DoS (Stack Overflow) A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message using its AMQP field parser. Due to a lack of bounds on recursion during parsing, the router can run out of stack memory and crash, leading to a denial of service for the interconnected network.
Service Interconnect
CVE-2026-49362 Sep 10, 2026
Apache Artemis/ActiveMQ Artemis CORE Protocol Durable Queue RCE 2.50.0-2.57.0 An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
CVE-2026-49363 Sep 10, 2026
Apache Artemis CORE Protocol Topology Disclosure 2.50.0-2.57.0 An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
CVE-2026-49364 Sep 10, 2026
Apache Artemis: Unauth Capture via Cluster Handshake (2.50-2.56, 1.0-2.44) An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
CVE-2026-57822 Sep 10, 2026
Apache Artemis 2.44-2.57 OSS: Java Deserialization DOS in Management Requests When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that the broker will not utilise. The permitted types allow to craft a payload causing excessive computation and pinning the processing thread, leading to denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.3.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
CVE-2026-57967 Sep 10, 2026
Apache Artemis SESSION_REATTACH RCE 2.50.0-2.56.0 An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
CVE-2026-67593 Sep 10, 2026
Artemis OpenWire RemoveSubscriptionInfo Queue Deletion pre-auth (v2.50.02.56.0) A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
CVE-2026-18147 Sep 09, 2026
FreeIPA Web UI DOM XSS in Password Reset A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inject and execute arbitrary JavaScript code. This allows the attacker to perform actions within the victim's authenticated session, potentially leading to full administrative control if an IdM administrator is targeted.
Enterprise Linux (RHEL)
CVE-2026-87876 Sep 09, 2026
CUPS Username ACL Bypass via Case-Insensitive Comparisons Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-87872 Sep 09, 2026
Ansible community.general OCAPI Modules Disable TLS Validation (CVE-2026-87872) A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re-enable it, while sending HTTP Basic-Auth credentials to an https endpoint. An attacker positioned on the network path between the Ansible controller and the OCAPI-managed storage/enclosure device can present any certificate, intercept the session, capture the credentials, and tamper with responses.
Ceph Storage
Openstack
CVE-2026-87875 Sep 09, 2026
CUPS UTF32ToUTF8 Heap OOB Read via SNMP The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-87853 Sep 09, 2026
SSSD IdP OIDC Subject Prefix Auth Flaw A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP identifier is a strict prefix of a target user's identifier can authenticate as the target user.
Enterprise Linux (RHEL)
Openshift
CVE-2026-87874 Sep 09, 2026
Ansible community.general memcached cache plugin RCE via pickle deserialization A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached is unauthenticated and cache keys are predictable, an attacker able to reach a network-exposed or shared memcached instance can write a crafted pickle payload that is deserialized and executed on the Ansible controller when the poisoned fact cache is next read, leading to remote code execution.
Ceph Storage
Openstack
CVE-2026-87766 Sep 09, 2026
Bubblewrap <0.12.0: Symlink Escape via /oldroot During Sandbox Setup A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-19729 Sep 09, 2026
Keycloak Services Path Probing Flaw Allows File System Disclosure A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm administrator to still submit arbitrary filesystem paths as keystore parameters. This can be used to determine the existence and readability of files on the server, potentially exposing sensitive system information.
Build Keycloak
Red Hat Single Sign On
CVE-2026-86564 Sep 08, 2026
DPDK lib/vhost OOB read in virtio-net controlqueue crash A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.
Enterprise Linux (RHEL)
Openshift
CVE-2026-18090 Sep 08, 2026
gdk-pixbuf ICNS RLE Heap OOB Read/Info Disclosure via Crafted .icns A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.
Enterprise Linux (RHEL)
CVE-2026-19625 Sep 08, 2026
Quarkus OIDC Introspection Cache Enables CrossTenant Token Use When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2.
CVE-2026-19651 Sep 08, 2026
IBM Quarkus 3.27.x-3.27.5 / 3.33.x Auth Bypass via URL Query IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.
CVE-2026-80219 Sep 08, 2026
OAuth Redirect URI Tampering in hawtio-operator Cluster Mode A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: auto) and no client secret (public client). The redirect URIs are derived from the operator-created Route, whose hostname is tenant-controlled via the Hawtio CR spec.routeHostName field. A malicious tenant can register an arbitrary hostname as a valid OAuth redirect target and, because grants are auto-approved, obtain OpenShift access tokens of any cluster user who visits the crafted authorization URL without any consent prompt.
Apache Camel Hawtio
CVE-2026-78234 Sep 08, 2026
Privilege Escalation in hawtio-operator: Service-CA Signed Cert Abuse A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource. Because the operator ships a ClusterRole that aggregates Hawtio CR permissions into the edit and admin roles, any user with edit access in any namespace can obtain a Service-CA-signed certificate with an arbitrary subject. This certificate can be used to impersonate any in-cluster service identity to peers that trust the Service CA for client authentication, including Jolokia agents and other Service-CA-trusting components.
Apache Camel Hawtio
CVE-2026-77968 Sep 08, 2026
RedHat hawtio-operator IAM Escalation via widescope ClusterRole A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the ServiceAccount token authorizes read access to every Secret in the cluster. The operator also bypasses the cache via direct API calls. Compromise of the operator pod would yield read access to every Secret in the cluster, including bootstrap tokens, cloud credentials, and other operators' secrets.
Apache Camel Hawtio
CVE-2026-74860 Sep 08, 2026
libxml2 Python SAX Binding Double-Free DoS CVE-2026-74860 A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-74859 Sep 08, 2026
GnomeTweaks ZIP Extraction Path Traversal in Theme Installer The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files outside ~/.themes by using ../ path traversal, absolute paths, or symlink entries.
Enterprise Linux (RHEL)
CVE-2026-76561 Sep 08, 2026
Dogtag PKI ExternalProcessConstraint RCE via Unvalidated Profile Import A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account.
Certificate System
Enterprise Linux (RHEL)
CVE-2026-86469 Sep 07, 2026
Race Condition in GLib2 g_file_replace() Enables File Redirect A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-19843 Sep 07, 2026
Privilege Escalation via LDAP Shell Injection in 389 Console A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host.
Directory Server
Enterprise Linux (RHEL)
Directory Server E2s
And others...
CVE-2026-18922 Sep 07, 2026
389 DS Stale Identity Exploit via SASL PLAIN Auth A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.
Directory Server
Enterprise Linux (RHEL)
Rhel Els
And others...
CVE-2026-18453 Sep 07, 2026
389 Directory Server NULL Pointer Crash via USE_ONE_BACKEND Control A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service.
Directory Server
Enterprise Linux (RHEL)
Rhel Els
And others...
CVE-2026-18355 Sep 07, 2026
389-DS SASL I/O Heap Overflow via Small-Length Underflow A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed encrypted_buffer_offset, causing an unsigned subtraction underflow in sasl_io_read_packet(). PR_Recv is then requested to read approximately 4 GiB into a 1024-byte heap buffer, resulting in a heap buffer overflow with attacker-controlled content. After a successful SASL bind with integrity protection (SSF > 0), a remote authenticated attacker can cause a denial of service or potentially achieve remote code execution. This flaw is distinct from CVE-2026-11774, whose fix only guards against upper-bound overflow.
Directory Server
Enterprise Linux (RHEL)
Rhel Els
And others...
CVE-2026-76560 Sep 07, 2026
Unauth LDAP Client Bypasses SELFDN ACI in 389 DS A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.
Directory Server
Enterprise Linux (RHEL)
Rhel Els
And others...
CVE-2026-79678 Sep 07, 2026
FreeIPA idp-add Eval() RCE & DoS via Unvalidated --organization A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via memory exhaustion.
Enterprise Linux (RHEL)
CVE-2026-76578 Sep 07, 2026
FreeIPA LDAP ACI Flaw Grants Unauth Admin Privileges A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it added to the administrators group. This allows a remote, unauthenticated attacker to obtain genuine FreeIPA administrator-group membership and perform administrative operations against the directory and, on SID-enabled deployments, other IdM services.
Enterprise Linux (RHEL)
CVE-2026-86404 Sep 07, 2026
Red Hat EAP Artemis deserialization allows all classes by default EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method. However, by default both allow-list and block-list are empty. When the allow-list is empty (size == 0), isTrustedType() returns true for ALL classes. This means all classes are deserializable by default.
Amq Broker
Camel Quarkus
Camel Spring Boot
And others...
CVE-2026-86332 Sep 07, 2026
Red Hat OpenShift AI odh-dashboard: Unchecked K8s Secret read via BFF A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the cluster NVIDIA NGC API key Secret (apiKeySecret) and the NIM image pull secret (nimPullSecret). Create and delete of the same NIM credential are admin-gated; the read path is not. This is missing authorization (CWE-862) and insufficiently protected credentials (CWE-522). It is distinct from CVE-2026-5483 (service-account token leak in the Kubernetes client response wrapper on the same route) and CVE-2026-16456 (odh-model-controller cross-namespace confused deputy).
Openshift Ai
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.