Red Hat Red Hat Linux OS and other open source products

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Red Hat product.

RSS Feeds for Red Hat security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Red Hat products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Red Hat Sorted by Most Security Vulnerabilities since 2018

Red Hat Enterprise Linux (RHEL)2568 vulnerabilities

Red Hat Enterprise Linux Server1534 vulnerabilities
RedHat Enterprise Linux (RHEL) Server. Includes software bundeled with RHEL server.

Red Hat Enterprise Linux Workstation1504 vulnerabilities
RedHat Enterprise Linux (RHEL) Workstation. Includes software bundled with RHEL Workstation.

Red Hat Enterprise Linux Desktop1493 vulnerabilities
RedHat Enterprise Linux (RHEL) Desktop. Includes software bundled with RHEL desktop

Red Hat Enterprise Linux Eus1082 vulnerabilities

Red Hat Openshift561 vulnerabilities

Red Hat Rhel Eus540 vulnerabilities

Red Hat Rhel E4s441 vulnerabilities

Red Hat Rhel Tus397 vulnerabilities

Red Hat Rhel Aus392 vulnerabilities

Red Hat Satellite359 vulnerabilities

Red Hat Rhel Eus Long Life307 vulnerabilities

Red Hat Openshift Ai304 vulnerabilities

Red Hat Rhel Els297 vulnerabilities

Red Hat Openstack275 vulnerabilities

Red Hat Hummingbird254 vulnerabilities

Red Hat Jboss Fuse203 vulnerabilities

Red Hat Rhivos199 vulnerabilities

Red Hat Jbosseapxp193 vulnerabilities

Red Hat Build Keycloak188 vulnerabilities

Red Hat Jboss Data Grid169 vulnerabilities

Red Hat Enterprise Linux Ai154 vulnerabilities

Red Hat Openshift Devspaces149 vulnerabilities

Red Hat Quay142 vulnerabilities

Red Hat Single Sign On139 vulnerabilities

Red Hat Rhdh123 vulnerabilities

Red Hat Keycloak123 vulnerabilities

Red Hat Software Collections123 vulnerabilities

Red Hat Cryostat119 vulnerabilities

Red Hat Acm117 vulnerabilities

Red Hat Virtualization115 vulnerabilities

Red Hat Discovery106 vulnerabilities

Red Hat Ai Inference Server104 vulnerabilities

Red Hat Single Sign On95 vulnerabilities

Red Hat Openshift Pipelines93 vulnerabilities

Red Hat Ceph Storage92 vulnerabilities

Red Hat Apache Camel Hawtio91 vulnerabilities

Red Hat Multicluster Engine85 vulnerabilities

Red Hat Amq Streams84 vulnerabilities

Red Hat Service Mesh84 vulnerabilities

Red Hat Logging81 vulnerabilities

Red Hat Camel Spring Boot80 vulnerabilities

Red Hat Amq Broker77 vulnerabilities

Red Hat Ansible Portal77 vulnerabilities

Red Hat Openshift Lightspeed74 vulnerabilities

Red Hat Serverless74 vulnerabilities

Red Hat Ansible Tower69 vulnerabilities

Red Hat Openshift Gitops67 vulnerabilities

Red Hat Kafka66 vulnerabilities

Red Hat Rhui64 vulnerabilities

Red Hat Quarkus63 vulnerabilities

Red Hat 3scale Amp61 vulnerabilities

Red Hat Podman Desktop58 vulnerabilities

Red Hat Libvirt55 vulnerabilities

Red Hat Apicurio Registry55 vulnerabilities

Red Hat Camel Quarkus54 vulnerabilities

Red Hat Service Registry54 vulnerabilities

Red Hat Rhmt54 vulnerabilities

Red Hat Virtualization Host53 vulnerabilities

Red Hat Multicluster Globalhub50 vulnerabilities

Red Hat Network Observ Optr50 vulnerabilities

Red Hat Satellite Capsule49 vulnerabilities

Red Hat Jboss Core Services44 vulnerabilities

Red Hat Ansible42 vulnerabilities

Red Hat Http Server42 vulnerabilities

Red Hat Directory Server41 vulnerabilities

Red Hat Enterprise Linux Aus41 vulnerabilities

Red Hat Undertow40 vulnerabilities
Java HTTP Server and Servlet Container

Recent Red Hat Security Advisories

Advisory Title Published
RHSA-2026:42694 (RHSA-2026:42694) Moderate: glibc security update July 21, 2026
RHSA-2026:42692 (RHSA-2026:42692) Important: evince security update July 21, 2026
RHSA-2026:42668 (RHSA-2026:42668) Important: libtiff security update July 21, 2026
RHSA-2026:40768 (RHSA-2026:40768) OpenShift Container Platform 4.22.6 bug fix and security update July 21, 2026
RHSA-2026:42644 (RHSA-2026:42644) RHOAI 2.25.9 - Red Hat OpenShift AI July 21, 2026
RHSA-2026:40792 (RHSA-2026:40792) OpenShift Container Platform 4.21.25 bug fix and security update July 21, 2026
RHSA-2026:42241 (RHSA-2026:42241) Red Hat Hardened Images RPMs bug fix and enhancement update July 21, 2026
RHSA-2026:42555 (RHSA-2026:42555) Important: postgresql:13 security update July 21, 2026
RHSA-2026:42552 (RHSA-2026:42552) Important: kernel security, bug fix, and enhancement update July 21, 2026
RHSA-2026:42550 (RHSA-2026:42550) Important: kernel-rt security, bug fix, and enhancement update July 21, 2026

By the Year

In 2026 there have been 2191 vulnerabilities in Red Hat with an average score of 7.2 out of ten. Last year, in 2025 Red Hat had 1167 security vulnerabilities published. That is, 1024 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.65.




Year Vulnerabilities Average Score
2026 2191 7.24
2025 1167 6.59
2024 1688 6.57
2023 1206 6.75
2022 1362 6.97
2021 1123 6.61
2020 664 6.39
2019 772 6.98
2018 760 7.16

It may take a day or so for new Red Hat vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Red Hat Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-59846 Jul 21, 2026
CVE-2026-59846: Shell Metacharacter Injection via %r ProxyCommand in libssh A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-16445 Jul 21, 2026
Dracut DHCP Option Injection: Command Injection in initrd Network Module A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-16461 Jul 21, 2026
Buffer Overflow in rpcbind rpcinfo -s (rpcbdump) A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply are written into a fixed-size stack buffer without bounds checking. A user or administrator who runs `rpcinfo -s` against a malicious or compromised rpcbind endpoint could experience a crash or denial of service of the rpcinfo client.
Enterprise Linux (RHEL)
Openshift
CVE-2026-59844 Jul 21, 2026
libssh SFTP Excessive Memory Allocation via SSH_FXP_READ (CVE-2026-59844) A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-59845 Jul 21, 2026
Local DoS via unchecked fork() in libssh ProxyCommand A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-59843 Jul 21, 2026
DoS in Libssh: Zero Max Packet Size Loop in SSH_MSG_CHANNEL_OPEN A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-59842 Jul 21, 2026
libssh GSSAPI Key Exchange CVE-2026-59842: OOB Heap Read Vulnerability A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-15370 Jul 21, 2026
Unsafe SFTP Longname Buffer Overflow in libssh (CVE-2026-15370) A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-15811 Jul 21, 2026
kronosnet <=1.34 mem residual key leak, missing zeroout A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this flaw to retrieve the active encryption key, allowing them to decrypt cluster network communications or inject malicious packets to cause severe high-availability cluster instability.
Enterprise Linux (RHEL)
Openshift
CVE-2026-15812 Jul 21, 2026
kronosnet ACL Bypass via Unvalidated Link ID in Versions <=1.34 A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP address) without network payload encryption, the validation architecture implicitly trusts the link ID provided within incoming data packets. A remote, unauthenticated attacker can exploit this lack of validation by spoofing a legitimate link ID inside crafted network frames. This allows the attacker to fully bypass the ACL framework and inject arbitrary data packets into the application layer, potentially leading to data corruption or service instabilities.
Enterprise Linux (RHEL)
Openshift
CVE-2026-15927 Jul 21, 2026
Red Hat Quay SSRF via External Reference in Repo Mirror A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror handlers which apply validate_external_registry_url(). A repository administrator can supply a crafted hostname that causes the Quay mirror worker to make requests via Skopeo to internal network services, cloud metadata endpoints, or other resources not intended to be reachable from the Quay application.
Mirror Registry
Quay
CVE-2026-64612 Jul 20, 2026
Unprivileged DoS via malformed PNG in cups-filters A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job.
Enterprise Linux (RHEL)
CVE-2026-12701 Jul 20, 2026
Pulpcore Path Traversal in FilesystemExport Enables Arbitrary File Write A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../" anywhere in the path. An authenticated administrator can craft a relative_path containing embedded traversal sequences (e.g., "looking/normal/../../../../etc/shadow") that escapes the intended export directory during FilesystemExport operations. Because the file content is also user-controlled (uploaded artifact), this allows arbitrary file write to any location writable by the Pulp service user, potentially leading to service compromise or further system exploitation.
Ansible Automation Platform
Satellite
Rhui
And others...
CVE-2026-16277 Jul 20, 2026
Stack buffer overflow in rpcbind's rpcinfo utility A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Enterprise Linux (RHEL)
Openshift
CVE-2026-12080 Jul 20, 2026
QEMU Guest Agent symlink exploit in guest-ssh-add-authorized-keys enables root A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race. Successful exploitation allows the attacker to gain ownership of arbitrary root-owned files or directories, leading to root access. This vulnerability requires an external management layer (e.g., libvirt) to trigger the affected code path.
Enterprise Linux (RHEL)
Enterprise Linux Nvidia
Openshift
And others...
CVE-2026-15588 Jul 20, 2026
GLib GDBus gdbusauth DoS via Input Length Misvalidation A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-16254 Jul 20, 2026
Claircore APK Scanner OOB Access CVE-2026-16254 A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an out-of-bounds access that panics the scanner. If that panic is not recovered, the Clair indexer process can crash, leading to a denial of service.
Advanced Cluster Security
Quay
CVE-2026-15813 Jul 20, 2026
OOB Heap Corruption in KronosNet <=1.34 via Malformed Packets A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence numbers of incoming payload fragments. An attacker can exploit this lack of verification by transmitting malformed packets with corrupted sequence parameters. Under specific conditions, this forces the packet processing layer to parse data outside the designated bounds of the internal memory structures, causing an out-of-bounds memory access or heap corruption. This behavior can result in sudden application crashes or system instability.
Enterprise Linux (RHEL)
Openshift
CVE-2026-16242 Jul 20, 2026
Konnectivity Proxy-Server: Unauthenticated Agent via Missing CA Cert A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.
Logging
Multicluster Engine
Openshift Api Data Protection
And others...
CVE-2026-16118 Jul 17, 2026
XDGMIME Heap Buffer Overflow via MIME Magic File (CVE-2026-16118) A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.
Enterprise Linux (RHEL)
CVE-2026-49852 Jul 17, 2026
Python library joserfc - HMAC auth bug before 1.6.8 joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attacker-forged HMAC-signed tokens when the caller-supplied verification key is the empty string or None, because HMACAlgorithm.sign and HMACAlgorithm.verify in src/joserfc/_rfc7518/jws_algs.py pass the output of OctKey.get_op_key(...) to hmac.new(...) and OctKey.import_key in src/joserfc/_rfc7518/oct_key.py only emits a SecurityWarning for keys shorter than 14 bytes without rejecting zero-length input. This issue is fixed in version 1.6.8.
CVE-2026-16104 Jul 17, 2026
KeycloakServices auth endpoint leaks recaptcha keys via config VIEW only A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive configuration values, such as reCAPTCHA secret keys, when they are requested by administrators with view-only permissions. This can lead to the exposure of third-party service credentials to unauthorized personnel or through administrative logs.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-16103 Jul 17, 2026
Brute-Force Token Redemption Loophole in Keycloak CIBA (keycloak-services) A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were omitted from the token redemption handler. This allows an attacker with valid client credentials to obtain access and refresh tokens for a user account that has been locked due to brute-force protection, provided the authentication request was started before the lockout occurred and was approved by the user.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-16106 Jul 17, 2026
Keycloak Admin API: RBAC Bypass Removing Composite Roles A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker with limited administrative permissions can remove privileged roles they are not authorized to manage, leading to a loss of access for other users and administrators.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-16108 Jul 17, 2026
Keycloak Default-Group Disclosure via Delegated Admin A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with realm-viewing permissions to see the names and identifiers of hidden default groups, even if they lack the specific permissions to view those groups. This can lead to the exposure of sensitive organizational structures or internal group names.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-16093 Jul 17, 2026
Bypass Keycloak Client Policies Signed JWT Enforcement Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met. This allows the attacker to authenticate using simpler methods like a client secret even when the administrator has mandated more secure, signed assertions.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-63308 Jul 17, 2026
Helm 4.2.3 Files.Lines OOB Crash DoS Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to trigger an index out of range panic by including zero-length byte slices in chart files. Attackers can include empty files in Helm charts to cause deterministic render failures across template, install, upgrade, lint, and SDK Engine.Render operations.
CVE-2026-16089 Jul 17, 2026
Keycloak Services OAuth 2.0 Code Binding Flaw (Red Hat) A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be redeemed by their own client, potentially allowing them to obtain access tokens for a victim's identity.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-16072 Jul 17, 2026
Keycloak OrgMgmt API Bypass: Unauthorized Injection via Invitation Link A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application programming interface. By using this link, the administrator can create new user accounts and add them to the organization without having the required user management permissions or access to the invited email account. This allows an administrator to bypass security boundaries and add unauthorized members to an organization.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-15943 Jul 17, 2026
Keycloak keycloak-services: OIDC IDP Secret Leakage via Masked Client Secret A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to improper validation, Keycloak reuses the existing real secret even if security-sensitive fields like the token URL have been changed, allowing an attacker to redirect and capture the secret.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-15945 Jul 16, 2026
Keycloak FGAP v2 Bypass: Delegated Admin Exposes Parent Group Data A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-5674 Jul 16, 2026
PipeWire Sandbox Escape via PulseAudio Compat Layer A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.
Enterprise Linux (RHEL)
CVE-2026-48863 Jul 16, 2026
libsolv PGP EdDSA Buffer Overflow (CVE-2026-48863) A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-1609 Jul 16, 2026
Keycloak JWT grant bypass for disabled users due to missing validation A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the users disabled status during JWT authorization grant processing. A remote attacker with low privileges can exploit this improper access control vulnerability by presenting a valid assertion token from an external identity provider to obtain a JWT for a disabled user. This allows unauthorized access to sensitive resources.
Jboss Enterprise Application Platform
Jbosseapxp
CVE-2026-3842 Jul 16, 2026
QEMU OOB Write via cpu_physical_mem Map Length Mismatch A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond its allocated memory. This occurs when cpu_physical_memory_map() returns a shorter length than expected, leading to an out-of-bounds write. Successful exploitation could result in unauthorized access to guest memory or corruption of heap-allocated objects, potentially causing information disclosure, data integrity issues, or a denial of service.
Enterprise Linux (RHEL)
Openshift
CVE-2026-23538 Jul 16, 2026
Feast Feature Server /ws/chat WS Auth Bypass Enables DOS A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establish persistent WebSocket connections without any authentication. By opening a large number of simultaneous connections, an attacker can exhaust server resourcessuch as memory, CPU, and file descriptorsleading to a complete denial of service for legitimate users.
Openshift Ai
CVE-2026-12382 Jul 15, 2026
RedHat AAP Gateway: Envoy Proxy Subject header bypass via non-mTLS route A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.
Ansible Automation Platform
Ansible Automation Platform Developer
Ansible Automation Platform Inside
And others...
CVE-2026-15779 Jul 15, 2026
Samba pam_winbind: chown / via mkhomedir Availability loss A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this triggered not only by root, but by a non-root user holding a narrow sudo delegation to run commands as that account, causing ownership of / to change and resulting in severe denial of service (SSH, sudo, and package-manager failures). The change does not grant write access to / (which ships with restrictive 0555 permissions on RHEL), so the impact is availability loss rather than further privilege escalation.
Enterprise Linux (RHEL)
CVE-2026-15809 Jul 15, 2026
CRI-O Env Injection: Bypass CVE-2022-4318, Add /etc/passwd Entries A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
Confidential Compute Attestation
Openshift
CVE-2026-14251 Jul 15, 2026
OpenShift GitOps Argo CD ClusterRole Reconciliation Ownership Bypass (DoS) A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a denial of service.
Openshift Gitops
CVE-2026-38753 Jul 15, 2026
BusyBox v1.38 DoS via use-after-free in awk_sub (AWK) A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
CVE-2026-38755 Jul 15, 2026
BusyBox 1.38.0 Heap Overflow in evalcommand() Shell Enables DoS A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
CVE-2026-38752 Jul 15, 2026
BusyBox AWK evaluate() stack overflow DoS A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
CVE-2026-38754 Jul 15, 2026
Busybox 1.38.0 ash Shell Heap Overflow DoS A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
CVE-2026-15767 Jul 14, 2026
libyuv Heap Buffer Overflow in Chrome Windows <150.0.7871.125 Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High)
CVE-2026-53486 Jul 14, 2026
decompress Node.js v<10.2.1 & 11.0.011.1.3 Path Traversal via Symlink/Hardlink The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits. This issue is fixed in @xhmikosr/decompress versions 10.2.1 and 11.1.3.
CVE-2026-15714 Jul 14, 2026
libsoup OOB Read in multipart boundary parsing An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_multipart_input_stream_read_headers() function inside soup-multipart-input-stream.c, which does not adequately restrict or validate the size of incoming multipart boundary strings. When processing a crafted HTTP response containing a malformed or oversized boundary parameter, the internal stream reader reads past the allocated buffer bounds. A remote, unauthenticated attacker can exploit this behavior to cause a service denial (DoS) through application failure or potentially read fragments of unauthorized memory metadata.
Enterprise Linux (RHEL)
CVE-2026-15713 Jul 14, 2026
libsoup HTTP/2 Memory Leak Causing OOM DoS by Remote Peer A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory context blocks under specific stream termination conditions, such as when an HTTP/2 connection encounters window exhaustion or explicit stream resets. A remote, unauthenticated attacker acting as a malicious network peer can trick the connection engine into allocating stream states that are subsequently leaked during cleanup. Over a sustained period, this flaw allows the remote attacker to consume the system's heap allocations incrementally, triggering a denial of service (DoS) through an ultimate Out-of-Memory (OOM) application crash.
Enterprise Linux (RHEL)
CVE-2026-15711 Jul 14, 2026
libsoup WebSocket Frame Length Validation DoS A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a payload of 125 bytes or less. A remote, unauthenticated attacker can exploit this by sending a non-compliant, oversized control frame. Because the parser handles this protocol violation improperly instead of throwing an immediate connection termination error, it triggers a internal processing crash, resulting in a remote denial of service (DoS) for applications utilizing libsoup WebSockets.
Enterprise Linux (RHEL)
CVE-2026-15709 Jul 14, 2026
libsoup WebSocket permessage-deflate OOM DoS via decompression bomb A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compressed frame size via max_incoming_payload_size, it fails to track or limit memory allocation during decompression. A separate check for decompressed size (max_total_message_size) exists but executes only after inflation is complete, and it is entirely disabled by default for client connections. A remote, unauthenticated attacker can exploit this by sending a small, highly compressed payload (a decompression bomb), causing unbounded memory allocation that triggers an Out-of-Memory (OOM) crash and a Denial of Service (DoS).
Enterprise Linux (RHEL)
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.