Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

RED HAT — Vulnerabilities & Security Advisories 1138

Browse all 1138 CVE security advisories affecting RED HAT. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

Found 20 results / 1138Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-18620 Data-sciences-pipeline: user-controlled serviceaccount for workflow pods without authorization check — confused deputy — Red Hat OpenShift AI 2.25CWE-639 7.1 High2026-08-10
CVE-2026-18618 Ml-metdata: bundled grpc 1.46.3 (2022) with published http/2 dos cves — directly reachable on listener — Red Hat OpenShift AI 2.25CWE-770 7.5 High2026-08-10
CVE-2026-18611 Data-science-pipelines-operator: dspo: cryptographically weak secret generation (math/rand) for db and s3 credentials — Red Hat OpenShift AI 2.25CWE-338 7.5 High2026-08-10
CVE-2026-18982 Odh-training-operator-rhel9: rhoai fork aggregates training job create onto native edit/admin clusterroles — Red Hat OpenShift AI 2.25CWE-250 8.8 High2026-08-10
CVE-2026-18950 Odh-dashboard: odh-dashboard: confused-deputy privilege escalation via unchecked roleref in rolebinding creation — Red Hat OpenShift AI 2.25 8.8 High2026-08-10
CVE-2026-18949 Odh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac management resources — Red Hat OpenShift AI 2.25CWE-250 8.8 High2026-08-10
CVE-2026-18948 Feast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server and registry server — Red Hat OpenShift AI 2.25 9.9 Critical2026-08-10
CVE-2026-18947 Feast: feast: authorization bypass in /materialize endpoints enables dos via unauthorized full re-materialization — Red Hat OpenShift AI 2.25 8.5 High2026-08-10
CVE-2026-18942 Feast-operator: feast: feast apply cronjob runs user python with feature-server sa — tenant code to sa token escalation — Red Hat OpenShift AI 2.25 5.5 Medium2026-08-10
CVE-2026-18941 Feast: feast-operator: feast: default authentication mode is no_auth — shared multi-tenant instances deployed without authentication — Red Hat OpenShift AI 2.25CWE-306 7.7 High2026-08-10
CVE-2026-18621 Data-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow spec, bypassing all v2 security hardening — Red Hat OpenShift AI 2.25CWE-266 7.6 High2026-08-10
CVE-2026-18617 Data-science-pipelines-operator: dspo: mysql dsn parameter injection via customextraparams enables local infile file exfiltration from operator pod — Red Hat OpenShift AI 2.25CWE-915 8.8 High2026-08-10
CVE-2026-18608 Data-science-pipelines-operator: dspo: operator clusterrole grants pods/exec:*, kubeflow.org */*, and clusterrole/binding crud cluster-wide — Red Hat OpenShift AI 2.25CWE-250 8.7 High2026-08-10
CVE-2026-16456 Odh-model-controller: odh-model-controller: cross-namespace secret read via nim account crd confused deputy — Red Hat OpenShift AI 2.25CWE-441 6.5 Medium2026-08-10
CVE-2026-15581 Trustyai-service-operator: trustyai-service-operator: tas internal service bypasses kube-rbac-proxy, exposing unauthenticated quarkus api cluster-wide — Red Hat OpenShift AI 2.25CWE-306 8.0 High2026-08-10
CVE-2026-15467 Trustyai-service-operator: trustyai-service-operator: lmevaljob sidecar containers bypass protected environment variable filtering, allowing trust_remote_code policy override — Red Hat OpenShift AI 2.25CWE-266 8.1 High2026-08-10
CVE-2026-16745 Odh-dashboard: odh-dashboard: backend port 8080 trusts x-forwarded-access-token without origin validation — Red Hat OpenShift AI 2.25CWE-346 8.8 High2026-07-23
CVE-2026-15154 Guardrails-detectors: guardrails-detectors: unauthenticated regular-expression denial of service (redos) via detector_params.regex — Red Hat OpenShift AI 2.25CWE-1333 6.5 Medium2026-07-08
CVE-2025-12805 Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy — Red Hat OpenShift AI 2.25CWE-653 8.1 High2026-03-26
CVE-2025-12103 Openshift-ai: trusty ai grants all authenticated users to list pods in any namespace — Red Hat OpenShift AI 2.25CWE-266 5.0 Medium2025-10-28

This page lists every published CVE security advisory associated with RED HAT. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.