Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1426

Browse all 1426 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

CVE ID Title CVSS Severity Published
CVE-2026-96281 Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimes — Red Hat Enterprise Linux 10 CWE-284 6.2 Medium 2026-09-27
CVE-2026-96280 Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems — Red Hat Enterprise Linux 10 CWE-197 7.5 High 2026-09-27
CVE-2026-96279 Flatpak: flatpak: path traversal issue in oci archive extraction via hardlinks — Red Hat Enterprise Linux 10 CWE-59 6.5 Medium 2026-09-27
CVE-2026-93834 Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape — Red Hat Enterprise Linux 10 CWE-416 8.8 High 2026-09-25
CVE-2026-96448 Keycloak-services: keycloak-services: fgap v2 composite-blind role mapping allows privilege escalation — Red Hat Build of Keycloak CWE-285 6.6 Medium 2026-09-25
CVE-2026-97846 Keycloak-services: keycloak-services: standard token exchange v2 bypasses mtls holder-of-key binding — Red Hat Build of Keycloak CWE-287 6.8 Medium 2026-09-25
CVE-2026-90959 Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enables arbitrary file read and pulp container registry signing key theft — Red Hat Ansible Automation Platform 2 CWE-22 8.1 High 2026-09-24
CVE-2026-95521 Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when installing a source rpm — Red Hat Enterprise Linux 10 CWE-78 7.8 High 2026-09-24
CVE-2026-95519 Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows) — Red Hat Enterprise Linux 10 CWE-78 7.8 High 2026-09-24
CVE-2026-94416 Aap-gateway: aap-gateway: authorization bypass via workload identity token forgery — Red Hat Ansible Automation Platform 2 CWE-290 6.8 Medium 2026-09-24
CVE-2026-97311 Keycloak-services: keycloak-services: admin rest api role-groups endpoint discloses groups without authorization — Red Hat Build of Keycloak CWE-862 4.3 Medium 2026-09-24
CVE-2026-97185 Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file — Red Hat Enterprise Linux 10 CWE-787 7.8 High 2026-09-24
CVE-2026-97177 Keycloak-services: keycloak-services: generic user update bypasses denied reset-password permission — Red Hat Build of Keycloak CWE-862 6.6 Medium 2026-09-24
CVE-2026-97176 Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cookie authenticator — Red Hat Build of Keycloak CWE-862 4.2 Medium 2026-09-24
CVE-2026-75887 Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handler — Red Hat OpenShift Container Platform 4.19 CWE-22 7.5 High 2026-09-23
CVE-2026-75886 Openshift/console: openshift/console: unauthenticated reverse proxy to in-cluster catalogd service with session token forwarding — Red Hat OpenShift Container Platform 4.19 CWE-441 7.2 High 2026-09-23
CVE-2026-84724 Automation-controller: automation-controller: systemjob extra_vars.days argument injection into uncontainerized control-plane awx-manage process — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-88 6.6 Medium 2026-09-23
CVE-2026-84721 Automation-controller: automation-controller: email notification backend allows ssrf via user-controlled smtp host/port (internal port-scan oracle, smtp password exfil) — Red Hat Ansible Automation Platform 2.7 CWE-918 6.4 Medium 2026-09-23
CVE-2026-84720 Automation-controller: automation-controller: workflowjobnode.ancestor_artifacts lacks prevent_search, exposing no_log set_stats artifacts via orm-traversal count-oracle — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-639 6.5 Medium 2026-09-23
CVE-2026-84718 Automation-controller: automation-controller: client ip spoofing in audit/access logs via unrestricted x-forwarded-for trust — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-348 4.3 Medium 2026-09-23
CVE-2026-84717 Automation-controller: automation-controller: unauthenticated 200-vs-403 oracle in bitbucket data center webhook receiver enumerates webhook-enabled job templates — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-204 5.3 Medium 2026-09-23
CVE-2026-84716 Automation-controller: automation-controller: instance install_bundle issues 10-year, non-revocable receptor mesh-ca certificates for caller-chosen (and case-variant impersonating) hostnames — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-266 6.6 Medium 2026-09-23
CVE-2026-84713 Automation-controller: automation-controller: notification.recipients/subject/error lack prevent_search, allowing zero-privilege cross-tenant recovery of notification recipient secrets via filter oracle — Red Hat Ansible Automation Platform 2.7 CWE-639 6.5 Medium 2026-09-23
CVE-2026-84712 Automation-controller: automation-controller: unauthenticated /api/v2/ping/ discloses automation-mesh instance topology and instance-group membership — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-497 5.3 Medium 2026-09-23
CVE-2026-96889 Librsvg: use-after-free when xml includes have duplicated entities — Red Hat Enterprise Linux 10 CWE-416 7.8 High 2026-09-23
CVE-2026-85475 Automation-controller: automation-controller-container: automation-controller: rsyslog configuration injection via log_aggregator_* settings leads to remote code execution in the control-plane rsyslog component — Red Hat Ansible Automation Platform 2.7 CWE-96 7.2 High 2026-09-23
CVE-2026-84719 Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitizer omits instance_groups authorization (instancegroup use_role bypass to control-plane) — Red Hat Ansible Automation Platform 2.4 for RHEL 8 CWE-862 9.9 Critical 2026-09-23
CVE-2026-84714 Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jinja template injection into ad-hoc module_args, machine-credential fields, and host names, reaching ansible-core templating in the execution environment — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-184 7.1 High 2026-09-23
CVE-2026-84706 Automation-controller: automation-controller-container: automation-controller: credential type env-injector deny-list omits process-hijacking variables (bash_env/ld_preload) allowing code execution in the execution environment — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-184 7.6 High 2026-09-23
CVE-2026-75884 Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in container groups — Red Hat Ansible Automation Platform 2.4 for RHEL 8 CWE-184 9.1 Critical 2026-09-23

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.