Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1444

Browse all 1444 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

CVE ID Title CVSS Severity Published
CVE-2026-12993 Apicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of service via internal dtd subset — Red Hat build of Apicurio Registry 3.3.1 CWE-776 6.5 Medium 2026-06-25
CVE-2026-12992 Apicurio/apicurio-registry: apicurio-registry: ssrf via wsdl4j import dereference in wsdl full validation — Red Hat build of Apicurio Registry 3.3.1 CWE-918 7.4 High 2026-06-25
CVE-2026-12975 Apicurio/apicurio-registry: apicurio-registry: unhardened saxparser in content-type detection leads to blind xxe / ssrf / billion-laughs dos — Red Hat build of Apicurio Registry 3.3.1 CWE-611 8.5 High 2026-06-25
CVE-2026-11800 Org.keycloak:keycloak-services: keycloak: authentication bypass via jwt algorithm confusion — Red Hat build of Keycloak 26.6 CWE-347 8.1 High 2026-06-25
CVE-2026-9083 Keycloak: keycloak: information disclosure through arbitrary filesystem path probing — Red Hat build of Keycloak 26.4 CWE-22 4.9 Medium 2026-06-25
CVE-2026-9799 Keycloak: keycloak: unauthorized access to resources via uma permission ticket bypass — Red Hat build of Keycloak 26.4 CWE-639 4.6 Medium 2026-06-25
CVE-2026-9705 Keycloak: keycloak: attacker can re-enable and take over disabled clients via registration access token — Red Hat build of Keycloak 26.4 CWE-613 6.5 Medium 2026-06-25
CVE-2026-9086 Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validation bypass — Red Hat build of Keycloak 26.4 CWE-79 7.3 High 2026-06-25
CVE-2026-9099 Keycloak: group-admin escalation to realm-admin — Red Hat build of Keycloak 26.4 CWE-639 7.7 High 2026-06-25
CVE-2026-9800 Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via incorrect uri comparison — Red Hat build of Keycloak 26.4 CWE-1025 8.1 High 2026-06-25
CVE-2026-13208 Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request body — Red Hat OpenShift Virtualization 4 CWE-287 6.5 Medium 2026-06-24
CVE-2026-13201 Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level vm disruption — Red Hat Container Native Virtualization 4.13 CWE-61 7.3 High 2026-06-24
CVE-2026-12892 Gstreamer1-plugins-bad-free: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in h.264 nal extension slice parser — Red Hat Enterprise Linux 10 CWE-125 4.4 Medium 2026-06-23
CVE-2026-12891 Gstreamer1-plugins-bad-free: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266/vvc vui parameter parser — Red Hat Enterprise Linux 10 CWE-125 4.3 Medium 2026-06-23
CVE-2026-11820 Community.general: community.general nexmo — api credentials exposed in get url query string[security] community.general nexmo — api credentials exposed in get url query string — Red Hat Enterprise Linux 10 CWE-532 6.5 Medium 2026-06-23
CVE-2026-11819 Community.general: community.general keyring_info — os keyring passphrase returned in plaintext — Red Hat Enterprise Linux 10 CWE-532 5.5 Medium 2026-06-23
CVE-2026-9073 Foreman-mcp-server: mcp server: insecure sensitive http header sanitization — Red Hat Satellite 6.18 CWE-532 6.2 Medium 2026-06-23
CVE-2026-12112 Foreman-mcp-server: mcp server: active session hijacking via insecure session state reuse — Red Hat Satellite 6.18 CWE-287 7.8 High 2026-06-23
CVE-2026-11807 Eda-server: websocket missing authorization allows credential theft via activation_id spoofing — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-862 9.6 Critical 2026-06-23
CVE-2026-12969 Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation — Red Hat Enterprise Linux 10 CWE-125 5.3 Medium 2026-06-23
CVE-2026-10609 Openshift/cluster-logging-operator: cluster logging operator creates and forwards serviceaccount tokens without verifying clf creator authorization — Logging Subsystem for Red Hat OpenShift CWE-862 6.8 Medium 2026-06-23
CVE-2026-55654 Openssh: heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi indicator cleanup due to missing null sentinel termination — Red Hat Enterprise Linux 10 CWE-125 3.7 Low 2026-06-23
CVE-2026-55655 Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions — Red Hat Enterprise Linux 10 CWE-923 5.0 Medium 2026-06-23
CVE-2026-55653 Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service — Red Hat Enterprise Linux 10 CWE-415 4.3 Medium 2026-06-23
CVE-2026-12549 Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserver — Red Hat Enterprise Linux 10 CWE-805 4.8 Medium 2026-06-22
CVE-2026-12725 Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies — Red Hat Enterprise Linux 10 CWE-122 5.9 Medium 2026-06-22
CVE-2026-54100 Windows-machine-config-operator: windows-machine-config-operator: ssh host key not verified enables credential theft — Red Hat OpenShift for Windows Containers 10.21 CWE-295 8.3 High 2026-06-22
CVE-2026-54099 Windows-machine-config-operator: windows-machine-config-operator: wicd csr extra-organization allows privilege escalation to system:masters — Red Hat OpenShift for Windows Containers 10.21 CWE-269 8.8 High 2026-06-22
CVE-2026-12726 Awx: automation-controller: awx: github webhook second-order ssrf via unvalidated statuses_url exfiltrates pat credential — Red Hat Ansible Automation Platform 2 CWE-918 6.3 Medium 2026-06-19
CVE-2026-56211 Libaom: libaom: remote code execution via svc layer context handling with attacker-controlled frames — Red Hat Enterprise Linux AI 3.3 for RHEL 9 CWE-787 7.1 High 2026-06-19

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.