Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1426

Browse all 1426 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

CVE ID Title CVSS Severity Published
CVE-2026-84691 Automation-controller: automation-controller-container: automation-controller: format string injection in the api 4xx error log setting discloses django secret_key and database credentials to an administrator — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-134 8.7 High 2026-09-23
CVE-2026-84683 Automation-controller: automation-controller-container: automation-controller: stored cross-site scripting in the job stdout html view via ansi osc 8 hyperlink sequences (javascript: anchor) enabling session takeover — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-79 8.7 High 2026-09-23
CVE-2026-84499 Automation-controller: automation-controller-container: automation-controller: write-only survey password recovered in plaintext via schedule/workflowjobtemplatenode survey min/max validation error message — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-209 7.7 High 2026-09-23
CVE-2026-84502 Automation-controller: automation-controller-container: automation-controller: project scm_url argument injection into `git ls-remote --upload-pack` yields rce on the controller-task control-plane pod — Red Hat Ansible Automation Platform 2.4 for RHEL 8 CWE-88 9.9 Critical 2026-09-23
CVE-2026-84474 Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and x-forwarded-for spoofing of provisioning-callback host match — Red Hat Ansible Automation Platform 2.4 for RHEL 8 CWE-807 9.9 Critical 2026-09-23
CVE-2026-84486 Automation-controller: automation-controller-container: automation-controller: unauthenticated debug scheduler-trigger endpoints (allowany, routed without debug guard) allow advisory-lock starvation of job dispatch (dos) — Red Hat Ansible Automation Platform 2.6 for RHEL 9 CWE-489 8.2 High 2026-09-23
CVE-2026-96546 Gimp: gimp: one-byte out-of-bounds heap read in the uncompressed dds loader — Red Hat Enterprise Linux 10 CWE-125 2.5 Low 2026-09-23
CVE-2026-71465 Automation-controller: automation-controller-container: automation-controller: ad-hoc command limit field allows cli argument injection into ansible executable — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-88 3.1 Low 2026-09-23
CVE-2026-71464 Automation-controller: automation-controller-container: automation-controller: schedule and workflowjobtemplatenode scm_branch prompt bypasses leading-dash git-argument guard — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-88 3.1 Low 2026-09-23
CVE-2026-71463 Automation-controller: automation-controller-container: automation-controller: notification template jinja whitelist bypass via conditional gating leaks tracebacks — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-209 2.7 Low 2026-09-23
CVE-2026-96545 Gimp: gimp: out-of-bounds heap read in the 4bpp tim image loader — Red Hat Enterprise Linux 10 CWE-125 4.4 Medium 2026-09-23
CVE-2026-71462 Automation-controller: automation-controller-container: automation-controller: custom_venv_path setting provides filesystem path-existence oracle on control pod — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-204 4.1 Medium 2026-09-23
CVE-2026-71461 Automation-controller: automation-controller-container: automation-controller: verbose internal exception disclosure via hostlist bare-exception handler — Red Hat Ansible Automation Platform 2.7 CWE-209 4.3 Medium 2026-09-23
CVE-2026-71460 Automation-controller: automation-controller-container: automation-controller: any authenticated user reads red hat subscription/license details via /config/ — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-862 4.3 Medium 2026-09-23
CVE-2026-76648 Automation-controller: automation-controller-container: aap controller: copyapiview.post() missing read authorization check enables job template secret recovery — Red Hat Ansible Automation Platform 2.7 CWE-862 8.5 High 2026-09-23
CVE-2026-96541 Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake deadline — Red Hat Enterprise Linux 10 CWE-400 7.5 High 2026-09-23
CVE-2026-71459 Automation-controller: automation-controller-container: automation-controller: jobjobeventschildrensummary rbac bypass exposes cross-tenant job event tree structure — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-862 5.0 Medium 2026-09-23
CVE-2026-71458 Automation-controller: automation-controller-container: automation-controller: named-url 404 body oracle enables cross-tenant resource name enumeration — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-204 5.0 Medium 2026-09-23
CVE-2026-88840 Busybox: busybox: tls ssl_server reads one byte out of bounds when parsing truncated clienthello — Red Hat Hardened Images CWE-125 5.3 Medium 2026-09-23
CVE-2026-88839 Busybox: busybox: passwd/group parser writes heap pointers out of bounds due to stale tokenize() endpoint — Red Hat Hardened Images CWE-787 6.7 Medium 2026-09-23
CVE-2026-88837 Busybox: busybox: httpd misidentifies yescrypt password hashes as plaintext, inverting authentication — Red Hat Hardened Images CWE-305 6.5 Medium 2026-09-23
CVE-2026-88835 Busybox: busybox: dpkg read_package_field() steps past nul terminator, causing out-of-bounds read on malformed .deb packages — Red Hat Hardened Images CWE-125 6.1 Medium 2026-09-23
CVE-2026-88831 Busybox: busybox: httpd silently fails open when ip deny rules contain invalid cidr prefix lengths — Red Hat Hardened Images CWE-636 5.3 Medium 2026-09-23
CVE-2026-88832 Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label buffer, causing heap overflow — Red Hat Hardened Images CWE-787 7.3 High 2026-09-23
CVE-2026-88830 Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pre-auth heap buffer overflow — Red Hat Hardened Images CWE-131 7.5 High 2026-09-23
CVE-2026-96276 Flatpak: flatpak: arbitrary write in host context via flatpak build-init — Red Hat Enterprise Linux 10 CWE-22 6.5 Medium 2026-09-23
CVE-2026-96275 Flatpak: flatpak: arbitrary write access as root via extra-data extraction — Red Hat Enterprise Linux 10 CWE-22 8.8 High 2026-09-23
CVE-2026-96512 Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authorization — Red Hat Hardened Images CWE-863 7.8 High 2026-09-23
CVE-2026-96445 Keycloak-services: keycloak-services: conditional otp skip-header policy evaluated against untrusted proxy headers — Red Hat Build of Keycloak CWE-287 6.8 Medium 2026-09-23
CVE-2026-96446 Keycloak-services: keycloak-services: par single-use bypass via prompt=none silent authentication path — Red Hat Build of Keycloak CWE-862 4.2 Medium 2026-09-23

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.