Red Hat Red Hat Linux OS and other open source products

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Red Hat product.

RSS Feeds for Red Hat security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Red Hat products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Red Hat Sorted by Most Security Vulnerabilities since 2018

Red Hat Enterprise Linux (RHEL)2766 vulnerabilities

Red Hat Enterprise Linux Server1534 vulnerabilities
RedHat Enterprise Linux (RHEL) Server. Includes software bundeled with RHEL server.

Red Hat Enterprise Linux Workstation1504 vulnerabilities
RedHat Enterprise Linux (RHEL) Workstation. Includes software bundled with RHEL Workstation.

Red Hat Enterprise Linux Desktop1493 vulnerabilities
RedHat Enterprise Linux (RHEL) Desktop. Includes software bundled with RHEL desktop

Red Hat Enterprise Linux Eus1167 vulnerabilities

Red Hat Openshift627 vulnerabilities

Red Hat Rhel Eus624 vulnerabilities

Red Hat Rhel E4s528 vulnerabilities

Red Hat Rhel Tus459 vulnerabilities

Red Hat Rhel Aus444 vulnerabilities

Red Hat Satellite369 vulnerabilities

Red Hat Rhel Eus Long Life361 vulnerabilities

Red Hat Rhel Els352 vulnerabilities

Red Hat Openshift Ai329 vulnerabilities

Red Hat Hummingbird298 vulnerabilities

Red Hat Openstack282 vulnerabilities

Red Hat Jbosseapxp241 vulnerabilities

Red Hat Build Keycloak224 vulnerabilities

Red Hat Jboss Fuse213 vulnerabilities

Red Hat Rhivos199 vulnerabilities

Red Hat Jboss Data Grid199 vulnerabilities

Red Hat Single Sign On183 vulnerabilities

Red Hat Acm156 vulnerabilities

Red Hat Enterprise Linux Ai155 vulnerabilities

Red Hat Quay154 vulnerabilities

Red Hat Openshift Devspaces154 vulnerabilities

Red Hat Rhdh127 vulnerabilities

Red Hat Discovery125 vulnerabilities

Red Hat Software Collections123 vulnerabilities

Red Hat Keycloak123 vulnerabilities

Red Hat Cryostat120 vulnerabilities

Red Hat Virtualization115 vulnerabilities

Red Hat Ai Inference Server105 vulnerabilities

Red Hat Kafka104 vulnerabilities

Red Hat Ceph Storage98 vulnerabilities

Red Hat Apache Camel Hawtio96 vulnerabilities

Red Hat Multicluster Engine96 vulnerabilities

Red Hat Single Sign On95 vulnerabilities

Red Hat Openshift Pipelines95 vulnerabilities

Red Hat Logging91 vulnerabilities

Red Hat Rhui89 vulnerabilities

Red Hat Camel Spring Boot88 vulnerabilities

Red Hat Amq Streams84 vulnerabilities

Red Hat Service Mesh84 vulnerabilities

Red Hat Amq Broker79 vulnerabilities

Red Hat Ansible Portal77 vulnerabilities

Red Hat Openshift Lightspeed75 vulnerabilities

Red Hat Serverless75 vulnerabilities

Red Hat Http Server72 vulnerabilities

Red Hat Ansible Tower69 vulnerabilities

Red Hat Openshift Gitops68 vulnerabilities

Red Hat Quarkus67 vulnerabilities

Red Hat 3scale Amp62 vulnerabilities

Red Hat Camel Quarkus59 vulnerabilities

Red Hat Podman Desktop58 vulnerabilities

Red Hat Apicurio Registry57 vulnerabilities

Red Hat Rhmt56 vulnerabilities

Red Hat Satellite Capsule56 vulnerabilities

Red Hat Libvirt55 vulnerabilities

Red Hat Multicluster Globalhub54 vulnerabilities

Red Hat Service Registry54 vulnerabilities

Red Hat Directory Server53 vulnerabilities

Red Hat Virtualization Host53 vulnerabilities

Red Hat Network Observ Optr51 vulnerabilities

Red Hat Jboss Core Services48 vulnerabilities

Red Hat Insights Proxy44 vulnerabilities

Red Hat Ansible42 vulnerabilities

Red Hat Satellite Utils42 vulnerabilities

Recent Red Hat Security Advisories

Advisory Title Published
RHSA-2026:66026 (RHSA-2026:66026) Important: virtuoso-opensource security update September 9, 2026
RHSA-2026:66016 (RHSA-2026:66016) Important: osbuild-composer security update September 9, 2026
RHSA-2026:66000 (RHSA-2026:66000) Important: kernel security update September 9, 2026
RHSA-2026:65999 (RHSA-2026:65999) Moderate: gstreamer1-plugins-good security update September 9, 2026
RHSA-2026:65998 (RHSA-2026:65998) Moderate: gzip security update September 9, 2026
RHSA-2026:65993 (RHSA-2026:65993) Important: qt5-qtbase security update September 9, 2026
RHSA-2026:65959 (RHSA-2026:65959) Moderate: gstreamer1-plugins-good security update September 9, 2026
RHSA-2026:65918 (RHSA-2026:65918) Important: delve security update September 9, 2026
RHSA-2026:65900 (RHSA-2026:65900) Important: openssh security update September 9, 2026
RHSA-2026:65897 (RHSA-2026:65897) Important: qt5-qtbase security update September 9, 2026

By the Year

In 2026 there have been 3124 vulnerabilities in Red Hat with an average score of 7.2 out of ten. Last year, in 2025 Red Hat had 1177 security vulnerabilities published. That is, 1947 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.35.




Year Vulnerabilities Average Score
2026 3124 7.20
2025 1177 6.85
2024 1694 6.82
2023 1207 6.74
2022 1362 6.96
2021 1123 6.61
2020 664 6.39
2019 772 6.98
2018 760 7.16

It may take a day or so for new Red Hat vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Red Hat Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-18147 Sep 09, 2026
A flaw was found in FreeIPA A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inject and execute arbitrary JavaScript code. This allows the attacker to perform actions within the victim's authenticated session, potentially leading to full administrative control if an IdM administrator is targeted.
Enterprise Linux (RHEL)
CVE-2026-87876 Sep 09, 2026
Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-87872 Sep 09, 2026
A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re-enable it, while sending HTTP Basic-Auth credentials to an https endpoint. An attacker positioned on the network path between the Ansible controller and the OCAPI-managed storage/enclosure device can present any certificate, intercept the session, capture the credentials, and tamper with responses.
Ceph Storage
Openstack
CVE-2026-87875 Sep 09, 2026
The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.
Enterprise Linux (RHEL)
Hummingbird
Openshift
CVE-2026-87853 Sep 09, 2026
A flaw was found in SSSD's IdP authentication provider A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP identifier is a strict prefix of a target user's identifier can authenticate as the target user.
Enterprise Linux (RHEL)
Openshift
CVE-2026-87874 Sep 09, 2026
A flaw was found in the memcached cache plugin of the community.general Ansible collection A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached is unauthenticated and cache keys are predictable, an attacker able to reach a network-exposed or shared memcached instance can write a crafted pickle payload that is deserialized and executed on the Ansible controller when the poisoned fact cache is next read, leading to remote code execution.
Ceph Storage
Openstack
CVE-2026-87766 Sep 09, 2026
Bubblewrap <0.12.0: Symlink Escape via /oldroot During Sandbox Setup A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-19729 Sep 09, 2026
Keycloak Services Path Probing Flaw Allows File System Disclosure A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm administrator to still submit arbitrary filesystem paths as keystore parameters. This can be used to determine the existence and readability of files on the server, potentially exposing sensitive system information.
Build Keycloak
Red Hat Single Sign On
CVE-2026-86564 Sep 08, 2026
DPDK lib/vhost OOB read in virtio-net controlqueue crash A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.
Enterprise Linux (RHEL)
Openshift
CVE-2026-18090 Sep 08, 2026
gdk-pixbuf ICNS RLE Heap OOB Read/Info Disclosure via Crafted .icns A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.
Enterprise Linux (RHEL)
CVE-2026-19625 Sep 08, 2026
Quarkus OIDC Introspection Cache Enables CrossTenant Token Use When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2.
CVE-2026-19651 Sep 08, 2026
IBM Quarkus 3.27.x-3.27.5 / 3.33.x Auth Bypass via URL Query IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.
CVE-2026-80219 Sep 08, 2026
OAuth Redirect URI Tampering in hawtio-operator Cluster Mode A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: auto) and no client secret (public client). The redirect URIs are derived from the operator-created Route, whose hostname is tenant-controlled via the Hawtio CR spec.routeHostName field. A malicious tenant can register an arbitrary hostname as a valid OAuth redirect target and, because grants are auto-approved, obtain OpenShift access tokens of any cluster user who visits the crafted authorization URL without any consent prompt.
Apache Camel Hawtio
CVE-2026-78234 Sep 08, 2026
Privilege Escalation in hawtio-operator: Service-CA Signed Cert Abuse A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource. Because the operator ships a ClusterRole that aggregates Hawtio CR permissions into the edit and admin roles, any user with edit access in any namespace can obtain a Service-CA-signed certificate with an arbitrary subject. This certificate can be used to impersonate any in-cluster service identity to peers that trust the Service CA for client authentication, including Jolokia agents and other Service-CA-trusting components.
Apache Camel Hawtio
CVE-2026-77968 Sep 08, 2026
RedHat hawtio-operator IAM Escalation via widescope ClusterRole A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the ServiceAccount token authorizes read access to every Secret in the cluster. The operator also bypasses the cache via direct API calls. Compromise of the operator pod would yield read access to every Secret in the cluster, including bootstrap tokens, cloud credentials, and other operators' secrets.
Apache Camel Hawtio
CVE-2026-74860 Sep 08, 2026
libxml2 Python SAX Binding Double-Free DoS CVE-2026-74860 A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-74859 Sep 08, 2026
GnomeTweaks ZIP Extraction Path Traversal in Theme Installer The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files outside ~/.themes by using ../ path traversal, absolute paths, or symlink entries.
Enterprise Linux (RHEL)
CVE-2026-76561 Sep 08, 2026
Dogtag PKI ExternalProcessConstraint RCE via Unvalidated Profile Import A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account.
Certificate System
Enterprise Linux (RHEL)
CVE-2026-86469 Sep 07, 2026
Race Condition in GLib2 g_file_replace() Enables File Redirect A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-19843 Sep 07, 2026
Privilege Escalation via LDAP Shell Injection in 389 Console A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host.
Directory Server
Enterprise Linux (RHEL)
Directory Server E2s
And others...
CVE-2026-18922 Sep 07, 2026
389 DS Stale Identity Exploit via SASL PLAIN Auth A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.
Directory Server
Enterprise Linux (RHEL)
Rhel Els
And others...
CVE-2026-18453 Sep 07, 2026
389 Directory Server NULL Pointer Crash via USE_ONE_BACKEND Control A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service.
Directory Server
Enterprise Linux (RHEL)
Rhel Els
And others...
CVE-2026-18355 Sep 07, 2026
389-DS SASL I/O Heap Overflow via Small-Length Underflow A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed encrypted_buffer_offset, causing an unsigned subtraction underflow in sasl_io_read_packet(). PR_Recv is then requested to read approximately 4 GiB into a 1024-byte heap buffer, resulting in a heap buffer overflow with attacker-controlled content. After a successful SASL bind with integrity protection (SSF > 0), a remote authenticated attacker can cause a denial of service or potentially achieve remote code execution. This flaw is distinct from CVE-2026-11774, whose fix only guards against upper-bound overflow.
Directory Server
Enterprise Linux (RHEL)
Rhel Els
And others...
CVE-2026-76560 Sep 07, 2026
Unauth LDAP Client Bypasses SELFDN ACI in 389 DS A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.
Directory Server
Enterprise Linux (RHEL)
Rhel Els
And others...
CVE-2026-79678 Sep 07, 2026
FreeIPA idp-add Eval() RCE & DoS via Unvalidated --organization A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via memory exhaustion.
Enterprise Linux (RHEL)
CVE-2026-76578 Sep 07, 2026
FreeIPA LDAP ACI Flaw Grants Unauth Admin Privileges A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it added to the administrators group. This allows a remote, unauthenticated attacker to obtain genuine FreeIPA administrator-group membership and perform administrative operations against the directory and, on SID-enabled deployments, other IdM services.
Enterprise Linux (RHEL)
CVE-2026-86404 Sep 07, 2026
Red Hat EAP Artemis deserialization allows all classes by default EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method. However, by default both allow-list and block-list are empty. When the allow-list is empty (size == 0), isTrustedType() returns true for ALL classes. This means all classes are deserializable by default.
Amq Broker
Camel Quarkus
Camel Spring Boot
And others...
CVE-2026-86332 Sep 07, 2026
Red Hat OpenShift AI odh-dashboard: Unchecked K8s Secret read via BFF A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the cluster NVIDIA NGC API key Secret (apiKeySecret) and the NIM image pull secret (nimPullSecret). Create and delete of the same NIM credential are admin-gated; the read path is not. This is missing authorization (CWE-862) and insufficiently protected credentials (CWE-522). It is distinct from CVE-2026-5483 (service-account token leak in the Kubernetes client response wrapper on the same route) and CVE-2026-16456 (odh-model-controller cross-namespace confused deputy).
Openshift Ai
CVE-2026-76925 Sep 04, 2026
Flatpak SystemHelper TOCTOU Race in Deploy() File Manipulation A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occurs because a privileged `chmod` operation executes before the OSTree repository validation within the `Deploy()` function. An attacker can exploit this timing window to redirect symlinks to arbitrary files, potentially leading to unauthorized file manipulation or information disclosure.
Enterprise Linux (RHEL)
CVE-2026-85769 Sep 04, 2026
libtpms DoS via Oversized skip-block in TPM state restore A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migration restore), a malformed state blob can supply an oversized skip-block length that is not validated against the remaining size of the input buffer. This can drive an internal size counter negative, which bypasses a subsequent bounds check due to an unsafe signed-to-unsigned conversion, causing the parser to read memory outside the bounds of the heap buffer holding the state data. Successful exploitation can crash the process hosting libtpms (such as swtpm), resulting in a denial of service of the emulated TPM device and the virtual machine that depends on it. No data corruption or information disclosure was confirmed.
Enterprise Linux (RHEL)
CVE-2026-85534 Sep 04, 2026
libsoup HTTP/2 Flow Control Window Size Buffer Overflow A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in progress. The client then copies the full buffer into a smaller DATA callback without a runtime bounds check, which can abort the process or fail the HTTP/2 session.
Enterprise Linux (RHEL)
CVE-2026-81666 Sep 04, 2026
Corosync Int Overflow in Membership Commit Token Msg (CVE-2026-81666) An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems due to an integer overflow in the calculation of the expected message length, allowing a crafted network packet to trigger an out-of-bounds memory access that crashes the Corosync daemon. This results in a denial of service for the affected cluster node. The overflow does not occur on 64-bit systems, where the length calculation is correctly performed in 64-bit arithmetic.
Enterprise Linux (RHEL)
Openshift
CVE-2026-81665 Sep 04, 2026
Corosync TotemPG Heap Overflow (CVE-2026-81665) A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control.
Enterprise Linux (RHEL)
Openshift
CVE-2026-85197 Sep 04, 2026
libsoup HTTP/2 Heap UAF Arb. Code Exec A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution.
Enterprise Linux (RHEL)
CVE-2026-84185 Sep 03, 2026
jwcrypto General JWS Verification Bypass via Key ID Misidentification A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a coding error, the library fails to correctly identify the specific key ID (kid) and may instead accept a signature made by any valid key in the set. This can allow an attacker with a valid key to bypass authorization checks in applications that rely on the key ID to identify specific tenants or users.
Ansible Automation Platform
Enterprise Linux (RHEL)
Openshift Ai
And others...
CVE-2026-71224 Sep 03, 2026
Stack Overflow in gfs2-utils Metadata Walk via untrusted inode height A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata without bounds validation, causing stack exhaustion and a denial of service when processing crafted GFS2 filesystem images.
Enterprise Linux (RHEL)
CVE-2026-71222 Sep 03, 2026
Red Hat GFS2-Utils Heap OOB Read in ea_num_ptrs A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory contents or cause a crash when processing crafted GFS2 filesystem images.
Enterprise Linux (RHEL)
CVE-2026-71221 Sep 03, 2026
Stack OOB Write in RedHat gfs2-utils savemeta Arbitrary Code Execution A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.
Enterprise Linux (RHEL)
CVE-2026-71220 Sep 03, 2026
Stack OOB Write in gfs2-utils (Red Hat) A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.
Enterprise Linux (RHEL)
CVE-2026-71219 Sep 03, 2026
Stack Overflow in gfs2-utils via di_depth overflow DoS A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 filesystem image with a large di_depth value causes stack exhaustion and a denial of service when processed by fsck.gfs2, gfs2_edit, or savemeta.
Enterprise Linux (RHEL)
CVE-2026-85150 Sep 03, 2026
GStreamer RTSP Digest Auth NULL Deref DoS A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.
Enterprise Linux (RHEL)
CVE-2026-66786 Sep 02, 2026
Submariner RCE via unvalidated CRD CableName in cert-auth mode A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdown hooks, leading to remote code execution as root on the gateway node.
Acm
CVE-2026-84838 Sep 02, 2026
RedHat RPM rpmuncompress Command Injection via Unescaped Filename A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow invokes rpmuncompress on the malicious file, leading to high impact on the confidentiality, integrity, and availability of data accessible to the invoking user.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-84837 Sep 02, 2026
Command Injection in rpmbuild via Path Manipulation A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-78409 Sep 02, 2026
Linux Kernel 6.15+ X-mount.subdir Symlink Traversal Local PrivEsc The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-78410 Sep 02, 2026
util-linux Local Privilege Escalation via Redirected Restricted Bind Mount A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-78408 Sep 02, 2026
CVE-2026-78408: nsenter --join-cgroup root-FD leak allows cgroup migration The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-53683 Sep 02, 2026
Red Hat Password_Reset Unvalidated Redirect reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.
Enterprise Linux (RHEL)
CVE-2026-14957 Sep 02, 2026
Libreswan FIPS X.509 Cert Public Key Extraction Null Assertion DoS In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with no CA certificates loaded in the NSS database are not vulnerable.
CVE-2026-82968 Sep 02, 2026
Keycloak first-broker-login flow allows social ID hijacking A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generated is not strictly bound to the specific upstream identity being verified. This allows an attacker with a different account on the same social provider to intercept the process and link their own account to the victim's local profile, gaining unauthorized access.
Build Keycloak
Red Hat Single Sign On
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.