Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1444

Browse all 1444 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

CVE ID Title CVSS Severity Published
CVE-2026-15945 Keycloak-services: keycloak-services: group hierarchy search discloses hidden parent groups under fgap v2 — Red Hat build of Keycloak 26.6 CWE-639 4.3 Medium 2026-07-16
CVE-2026-12382 Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-290 8.2 High 2026-07-15
CVE-2026-15779 Samba-winbind: samba: pam_winbind mkhomedir chowns critical system paths without validation — Red Hat Enterprise Linux 10 CWE-732 6.1 Medium 2026-07-15
CVE-2026-15809 Github.com/cri-o/cri-o: fix bypass for cve-2022-4318 — /etc/passwd injection via home env — Red Hat OpenShift Container Platform 4.12 CWE-134 7.8 High 2026-07-15
CVE-2026-14251 Gitops-operator: gitops-operator: missing allowednamespace check in reconcilerhook for clusterrole/role cases enables potential privilege escalation and dos — Red Hat OpenShift GitOps CWE-862 7.7 High 2026-07-15
CVE-2026-15714 Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary string — Red Hat Enterprise Linux 10 CWE-125 6.5 Medium 2026-07-14
CVE-2026-15713 Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via memory leak — Red Hat Enterprise Linux 10 CWE-772 5.9 Medium 2026-07-14
CVE-2026-15711 Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol violation — Red Hat Enterprise Linux 10 CWE-770 7.5 High 2026-07-14
CVE-2026-15709 Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of service — Red Hat Enterprise Linux 10 CWE-409 7.5 High 2026-07-14
CVE-2026-15712 Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over-read via invalid nul-termination assumption — Red Hat Enterprise Linux 10 CWE-125 5.9 Medium 2026-07-14
CVE-2026-12478 Libsoup: incomplete fix for cve-2026-0716: out-of-bounds read in libsoup websocket frame processing (unmasked path) — Red Hat Enterprise Linux 10 CWE-125 4.8 Medium 2026-07-14
CVE-2026-15584 Redhatinsights/incluster-checks: incluster-checks: privileged host-chroot debug pods created in shared default namespace enable privilege escalation to node root — Pen Drive Powered by Red Hat Lightspeed CWE-250 7.5 High 2026-07-13
CVE-2026-62147 Tempo-operator: tempo operator: query rbac bypass — Red Hat OpenShift distributed tracing 3 CWE-863 6.5 Medium 2026-07-13
CVE-2026-15574 Vllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header and full chat payloads logged at hard-coded debug default — Red Hat OpenShift AI (RHOAI) CWE-538 7.5 High 2026-07-13
CVE-2026-15028 Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header — Red Hat Enterprise Linux 10 CWE-805 3.9 Low 2026-07-10
CVE-2026-15378 Guardrails-detectors: guardrails-detectors: ssrf and local file read via user-supplied xml schema (xml-with-schema:) — Red Hat OpenShift AI 2.25 CWE-918 9.3 Critical 2026-07-10
CVE-2026-59692 Gstreamer1-plugins-bad-free: gstreamer: dtls certificate subject dn stack buffer overflow in openssl_verify_callback — Red Hat Enterprise Linux 10 CWE-121 7.5 High 2026-07-09
CVE-2026-59691 Gstreamer1-plugins-bad-free: gstreamer: rfbsrc/librfb hextile heap out-of-bounds write with 16bpp framebuffer — Red Hat Enterprise Linux 10 CWE-787 7.1 High 2026-07-09
CVE-2026-15041 389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 password verification — Red Hat Directory Server 11 CWE-208 3.7 Low 2026-07-08
CVE-2025-12799 Jastow: jastow cross-site scripting attack due to unsanitized uri — Red Hat JBoss Enterprise Application Platform 8.1.7.GA CWE-79 6.5 Medium 2026-07-07
CVE-2026-14969 389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryption — Red Hat Directory Server 11 CWE-329 4.4 Medium 2026-07-07
CVE-2026-14935 Gstreamer1-plugins-bad-free: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due to inverted presence check — Red Hat Enterprise Linux 10 CWE-670 3.7 Low 2026-07-07
CVE-2026-14940 389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted multivalued rdn — Red Hat Directory Server 11 CWE-122 5.3 Medium 2026-07-07
CVE-2026-14476 Sssd: sssd: gpo cache path traversal via unsanitized gpcfilesyspath allows kerberos authentication bypass — Red Hat Enterprise Linux 10 CWE-23 8.0 High 2026-07-07
CVE-2026-14474 Sssd: sssd: sudo ldap provider searches entire directory tree for sudorole objects by default, enabling privilege escalation — Red Hat Enterprise Linux 10 CWE-1188 8.8 High 2026-07-07
CVE-2026-58384 Gimp: gimp: integer overflow in read_rle_channel() — Red Hat Enterprise Linux 9 CWE-190 7.3 High 2026-07-07
CVE-2026-58380 Gimp: gimp: stack buffer overflow in pnmscanner_gettoken() — Red Hat Enterprise Linux 8 CWE-193 7.3 High 2026-07-06
CVE-2026-9165 Stackrox: stackrox: unbounded graphql query depth allows authenticated denial of service — Red Hat Advanced Cluster Security 4.9 CWE-400 7.7 High 2026-07-06
CVE-2026-14781 Keycloak-services: keycloak-services: oidc email_verified claim incorrectly applied to userinfo email — Red Hat Build of Keycloak CWE-1288 4.8 Medium 2026-07-05
CVE-2026-58379 Gimp: gimp: heap buffer overflow in read_channel_data() — Red Hat Enterprise Linux 9 CWE-122 7.3 High 2026-07-03

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.