Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1444

Browse all 1444 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

CVE ID Title CVSS Severity Published
CVE-2026-3012 Samba: group policy certificate enrollment uses http:// without validation — Red Hat Enterprise Linux 10 CWE-345 8.0 High 2026-05-27
CVE-2026-48864 Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data — Red Hat Enterprise Linux 10 CWE-787 7.8 High 2026-05-26
CVE-2026-4480 Samba: samba: remote code execution in printing subsystem via unescaped job description — Red Hat Enterprise Linux 10 CWE-78 9.0 Critical 2026-05-26
CVE-2026-9149 Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file — Red Hat Enterprise Linux 10 CWE-122 6.5 Medium 2026-05-20
CVE-2026-9150 Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums — Red Hat Enterprise Linux 10 CWE-121 6.5 Medium 2026-05-20
CVE-2026-9087 Keycloak: cross-session email verification proof not bound to upstream identity in first-broker-login — Red Hat build of Keycloak 26.4 CWE-639 6.4 Medium 2026-05-20
CVE-2026-7571 Keycloak: keycloak: access token disclosure and implicit flow bypass via forged client data — Red Hat build of Keycloak 26.4 CWE-472 7.1 High 2026-05-19
CVE-2026-7507 Org.keycloak/keycloak-services: session fixation in oidc login flow that can lead to account takeover — Red Hat build of Keycloak 26.2 CWE-290 7.5 High 2026-05-19
CVE-2026-7504 Org.keycloak/keycloak-services: open redirect when using wildcard valid redirect uris in keycloak — Red Hat build of Keycloak 26.2 CWE-601 8.1 High 2026-05-19
CVE-2026-37982 Keycloak: org.keycloak.authentication: keycloak: unauthorized account takeover via webauthn token replay — Red Hat build of Keycloak 26.4 6.8 Medium 2026-05-19
CVE-2026-37979 Keycloak: keycloak: information disclosure via oidc token introspection endpoint audience bypass — Red Hat build of Keycloak 26.4 6.5 Medium 2026-05-19
CVE-2026-37978 Keycloak: org.keycloak.services: keycloak: information disclosure via evaluate-scopes admin api — Red Hat build of Keycloak 26.4 CWE-639 4.9 Medium 2026-05-19
CVE-2026-37981 Keycloak: org.keycloak.authorization: keycloak: information disclosure via broken access control in user lookup endpoint — Red Hat build of Keycloak 26.4 CWE-1220 4.3 Medium 2026-05-19
CVE-2026-4630 Keycloak: keycloak: unauthorized resource access and data modification via insecure direct object reference — Red Hat build of Keycloak 26.4 CWE-639 6.8 Medium 2026-05-19
CVE-2026-8922 Org.keycloak/keycloak-services: keycloak: org.keycloak.protocol.oidc: security flaw in org.keycloak/keycloak-services — Red Hat build of Keycloak 26.4 CWE-303 5.4 Medium 2026-05-19
CVE-2026-8830 Keycloak: org.keycloak/keycloak-services: keycloak: policy bypass during webauthn credential registration via client-side javascript manipulation — Red Hat build of Keycloak 26.4 CWE-603 4.3 Medium 2026-05-19
CVE-2026-4802 Cockpit: cockpit: arbitrary command execution via crafted links in system logs ui — Red Hat Enterprise Linux 10 CWE-78 8.0 High 2026-05-11
CVE-2026-34956 Openvswitch: open vswitch: denial of service via malformed ftp epasv command — Fast Datapath for RHEL 7 CWE-120 5.9 Medium 2026-05-05
CVE-2026-34002 Xorg: xwayland: x.org x server: information disclosure or denial of service via out-of-bounds read in xkb modifier map handling — Red Hat Enterprise Linux 10.0 Extended Update Support CWE-805 6.1 Medium 2026-05-05
CVE-2026-34000 Xwayland: xorg: x.org x server: information disclosure and denial of service via out-of-bounds read in xkb geometry processing. — Red Hat Enterprise Linux 10.0 Extended Update Support CWE-125 6.1 Medium 2026-05-05
CVE-2026-33846 Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly — Red Hat Enterprise Linux 10 CWE-130 7.5 High 2026-05-04
CVE-2026-7500 Org.keycloak.keycloak-services: improper access control on keycloak server when the account account api feature is disabled — Red Hat build of Keycloak 26.4 CWE-425 5.4 Medium 2026-04-30
CVE-2026-7309 Openshift-controller-manager: openshift container platform: information disclosure via environment variable injection — Red Hat OpenShift Container Platform 4 CWE-426 4.3 Medium 2026-04-28
CVE-2026-5265 Ovn: ovn: heap over-read in icmp error response generation — Fast Datapath for Red Hat Enterprise Linux 10 CWE-130 6.5 Medium 2026-04-24
CVE-2026-5367 Ovn: ovn: information disclosure via crafted dhcpv6 packets — Fast Datapath for Red Hat Enterprise Linux 10 CWE-130 8.6 High 2026-04-24
CVE-2026-6732 Libxml2: libxml2: denial of service via crafted xsd-validated document — Red Hat Hardened Images CWE-843 6.5 Medium 2026-04-23
CVE-2026-2708 Libsoup: libsoup: http request smuggling via duplicate content-length headers — Red Hat Enterprise Linux 10 CWE-444 3.7 Low 2026-04-23
CVE-2026-34003 Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access — Red Hat Enterprise Linux 10 CWE-125 7.8 High 2026-04-23
CVE-2026-34001 Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption — Red Hat Enterprise Linux 10 CWE-825 7.8 High 2026-04-23
CVE-2026-33999 Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling — Red Hat Enterprise Linux 10 CWE-191 7.8 High 2026-04-23

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.