Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1426

Browse all 1426 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

CVE ID Title CVSS Severity Published
CVE-2026-79992 Emacs: emacs: command injection via crafted filenames in tramp — Red Hat Enterprise Linux 10 CWE-78 7.8 High 2026-08-25
CVE-2026-79717 Galaxy_ng: galaxy_ng: blind ssrf via namespace avatar_url with no private-address restriction — Red Hat Ansible Automation Platform 2 CWE-918 6.4 Medium 2026-08-25
CVE-2026-79655 Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file write — Red Hat Enterprise Linux 10 CWE-59 7.8 High 2026-08-25
CVE-2026-79652 Keycloak-services: keycloak-services: jwt bearer authorization grant does not enforce consentrequired — Red Hat build of Keycloak 26.6 CWE-862 5.9 Medium 2026-08-25
CVE-2026-78701 389-ds-base: 389-ds-base: cve-2026-11610 incomplete fix may introduce a connection-stall dos — Red Hat Enterprise Linux 10 CWE-787 6.5 Medium 2026-08-25
CVE-2026-78322 File-roller: file-roller: stack buffer overflow in parse_progress_line for 7z and rar handlers — Red Hat Enterprise Linux 6 CWE-120 6.5 Medium 2026-08-25
CVE-2026-19685 Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing wpa-enterprise server validation bypass (incomplete fix for cve-2025-9615) — Red Hat Enterprise Linux 10 CWE-863 7.1 High 2026-08-24
CVE-2026-71366 Awx: notification backends allow ssrf and credential leakage — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-918 7.7 High 2026-08-24
CVE-2026-71364 Awx: project archive extraction allows path traversal file writes — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-22 7.2 High 2026-08-24
CVE-2026-78367 Rpm: rpmbuild gettarspec() crafted tar member name → macro injection — Red Hat Enterprise Linux 10 CWE-94 7.0 High 2026-08-24
CVE-2026-78323 Jss: jss: jsstrustmanager does not verify nss trust flags on ca certificates — Red Hat Certificate System 10 CWE-295 6.5 Medium 2026-08-24
CVE-2026-73267 Clusterclaims-controller: managedcluster deletion keyed solely on clusterclaim.spec.namespace with no local ownership check — multicluster engine for Kubernetes 2.10 CWE-602 7.7 High 2026-08-21
CVE-2026-73137 Multicloud-operators-subscription: multicloud-operators-subscription: cross-namespace secret exfiltration via helmrelease.repo.secretref.namespace — Red Hat Advanced Cluster Management for Kubernetes 2.11 CWE-200 7.7 High 2026-08-20
CVE-2026-67567 Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction — Red Hat Advanced Cluster Management for Kubernetes 2.11 CWE-441 9.9 Critical 2026-08-20
CVE-2026-66788 Lighthouse: dockerfile build stages use end-of-life fedora 40 referenced by mutable tag — Red Hat Advanced Cluster Management for Kubernetes 2.17 CWE-1104 3.7 Low 2026-08-20
CVE-2026-66787 Lighthouse: go pprof profiling endpoint enabled unconditionally on lighthouse-agent :8082 — Red Hat Advanced Cluster Management for Kubernetes 2.17 CWE-489 5.4 Medium 2026-08-20
CVE-2026-66785 Submariner: ipsec psk secrets file created with default world-readable permissions — Red Hat Advanced Cluster Management for Kubernetes 2.17 CWE-732 2.5 Low 2026-08-20
CVE-2026-77176 Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy — Red Hat OpenShift Container Platform 4 CWE-73 8.1 High 2026-08-20
CVE-2026-19611 Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: password keyspace reduction via nfkc fullwidth folding — Red Hat build of Apache Camel 4 for Quarkus 3 CWE-173 7.4 High 2026-08-20
CVE-2026-73199 Ipa: freeipa: null pointer dereference in `ipa-enrollment` extended operation (`join_oid`) via missing request value — Red Hat Enterprise Linux 10 CWE-476 6.5 Medium 2026-08-20
CVE-2026-11861 Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships — Red Hat Enterprise Linux 10 CWE-266 9.6 Critical 2026-08-20
CVE-2026-73198 Ipa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body read — Red Hat Enterprise Linux 10 CWE-770 7.5 High 2026-08-20
CVE-2026-13097 Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore — Red Hat Enterprise Linux 10 CWE-706 8.7 High 2026-08-20
CVE-2026-73196 Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encoding — Red Hat Enterprise Linux 10 CWE-770 4.3 Medium 2026-08-20
CVE-2026-73197 Ipa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request body read — Red Hat Enterprise Linux 10 CWE-770 7.5 High 2026-08-20
CVE-2026-18917 Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow — Red Hat Enterprise Linux 10.0 Extended Update Support CWE-190 7.8 High 2026-08-20
CVE-2026-77014 Libsoup: libsoup: integer truncation in sort_ranges() comparator causes silent omission of http range responses — Red Hat Enterprise Linux 10 CWE-197 5.3 Medium 2026-08-20
CVE-2026-76827 Search-indexer: search-indexer: update/delete operations not scoped to caller's cluster (cross-tenant data tampering) — Red Hat Advanced Cluster Management for Kubernetes 2.11 CWE-693 6.8 Medium 2026-08-19
CVE-2026-76139 Acm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@master with full build credentials — Red Hat Advanced Cluster Management for Kubernetes 2.11 CWE-829 8.0 High 2026-08-19
CVE-2026-75569 Mce-operator-bundle: all github actions pinned by mutable tag, not commit sha — multicluster engine for Kubernetes 2.10 CWE-1357 7.7 High 2026-08-19

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.