Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1440

Browse all 1440 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

CVE ID Title CVSS Severity Published
CVE-2026-18218 Keycloak-services: keycloak-services: client not-before revocation ignored when realm not-before is older but nonzero — Red Hat build of Keycloak 26.6 CWE-862 4.2 Medium 2026-07-31
CVE-2026-68563 Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure of postgresql data via insecure backup permissions — Red Hat Enterprise Linux 10 CWE-732 5.5 Medium 2026-07-30
CVE-2026-68562 Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure via leapp report tampering — Red Hat Enterprise Linux 10 CWE-610 6.2 Medium 2026-07-30
CVE-2026-58216 Samba: kpasswd service: kpasswd packet that contains malformed asn.1 might cause the server to access 6 bytes of unallocated memory leading server to crash — Red Hat Enterprise Linux 10 CWE-125 5.3 Medium 2026-07-30
CVE-2026-58222 Samba: samba ad ldap compare filter injection and trusted-request confusion disclose protected attributes — Red Hat Enterprise Linux 10 CWE-90 8.8 High 2026-07-30
CVE-2026-58218 Samba: dns signing dos via tkey name cache exhaustion — Red Hat Enterprise Linux 10 CWE-410 5.3 Medium 2026-07-30
CVE-2026-18382 Project-koku/koku-metrics-operator: koku-metrics-operator: service-account client credentials sent to user-controlled token_url — Cost Management Metrics Operator CWE-918 6.8 Medium 2026-07-30
CVE-2026-18378 Project-koku/koku-metrics-operator: koku-metrics-operator: cluster pull-secret token exfiltration via user-controlled api_url (ssrf / confused deputy) — Cost Management Metrics Operator CWE-918 7.6 High 2026-07-30
CVE-2026-18381 Project-koku/koku-metrics-operator: koku-metrics-operator: operator service-account token exfiltration via user-controlled prometheus service_address — Cost Management Metrics Operator CWE-918 7.6 High 2026-07-30
CVE-2026-18369 Dogtag-pki: pki-core: redhat-pki: pki: acme http-01 validation ssrf via ip literal identifiers and unvalidated redirects — Red Hat Certificate System 10.4 EUS for RHEL-8 CWE-918 5.8 Medium 2026-07-30
CVE-2026-16531 Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servlet — Red Hat Enterprise Linux 10 CWE-22 5.3 Medium 2026-07-30
CVE-2026-16530 Pcp: pcp: remote denial of service and information leakage — Red Hat Enterprise Linux 10 CWE-125 6.5 Medium 2026-07-30
CVE-2026-16529 Pcp: pcp: denial of service due to signed integer overflow — Red Hat Enterprise Linux 10 CWE-190 7.5 High 2026-07-30
CVE-2026-16527 Pcp: pcp pmproxy: unauthenticated access to /store endpoint allows bypassing pmcd access rules — Red Hat Enterprise Linux 10 CWE-306 7.3 High 2026-07-30
CVE-2026-16526 Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability — Red Hat Enterprise Linux 10 CWE-403 8.8 High 2026-07-30
CVE-2026-16524 Pcp: pcp linux_sockets pmda: arbitrary command execution via command injection — Red Hat Enterprise Linux 10 CWE-78 7.8 High 2026-07-30
CVE-2026-18255 Quay: quay: global read-only superuser can view robot account tokens — Red Hat Quay 3.10 CWE-863 7.2 High 2026-07-29
CVE-2026-18220 Binutils: binutils: out-of-bounds write in bfd dlx elf backend relocation processing — Red Hat Enterprise Linux 10 CWE-787 7.8 High 2026-07-29
CVE-2026-18201 Keycloak-services: keycloak-services: generic identity-provider creation can bind brokers to organizations without manage-organizations — Red Hat build of Keycloak 26.6 CWE-862 5.5 Medium 2026-07-29
CVE-2026-18207 Keycloak-services: keycloak-services: client policy source-group condition bypass via duplicate group name matching — Red Hat Build of Keycloak CWE-285 6.5 Medium 2026-07-29
CVE-2026-18107 Criu: criu: container escape via rseq critical section hijack during checkpoint/restore — Red Hat Enterprise Linux 10 CWE-269 7.8 High 2026-07-28
CVE-2026-16313 Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export — Red Hat Enterprise Linux 10 CWE-93 7.6 High 2026-07-28
CVE-2026-18047 Dogtag-pki: pki-core: redhat-pki: pki: acme admin enable/disable endpoint authentication bypass via trailing slash — Red Hat Certificate System 10 CWE-288 6.5 Medium 2026-07-28
CVE-2026-49332 Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on wsgi/php upstreams — Red Hat OpenShift Container Platform 4.12 CWE-436 8.5 High 2026-07-28
CVE-2026-17072 Gstreamer1-plugins-good: gst-plugins-good: 4-byte heap over-read in gst_matroska_parse_flac_stream_headers when parsing flac codec data in matroska containers — Red Hat Enterprise Linux 10 CWE-125 3.3 Low 2026-07-28
CVE-2026-12383 Eda-server: externaleventstreamviewset trusts subject header without validation and leaks expected dn — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-345 7.5 High 2026-07-27
CVE-2026-15003 Binutils: gnu binutils: heap-buffer-overflow in linker leads to information disclosure and denial of service — Red Hat Hardened Images CWE-125 5.6 Medium 2026-07-27
CVE-2026-17527 Virt-cdi-operator: containerized-data-importer: cdi.kubevirt.io:view aggregated clusterrole grants create on datavolumes/source, allowing unauthorized pvc clone — Red Hat Container Native Virtualization 4.14 CWE-639 7.7 High 2026-07-27
CVE-2026-66337 Libsoup: libsoup: heap buffer over-read via integer underflow in soup_filter_input_stream_read_until() — Red Hat Enterprise Linux 10 CWE-125 6.5 Medium 2026-07-24
CVE-2026-66338 Libsoup: libsoup: http request smuggling via permissive chunk-size parsing in soup_body_input_stream_read_chunked() — Red Hat Enterprise Linux 10 CWE-444 5.4 Medium 2026-07-24

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.