Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1444

Browse all 1444 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

CVE ID Title CVSS Severity Published
CVE-2026-2733 Org.keycloak/keycloak-services: keycloak: missing check on disabled client for docker registry protocol — Red Hat build of Keycloak 26.4 CWE-285 3.8 Low 2026-02-19
CVE-2026-2443 Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure — Red Hat Enterprise Linux 10 CWE-125 5.3 Medium 2026-02-13
CVE-2026-26158 Busybox: busybox: arbitrary file modification and privilege escalation via unvalidated tar archive entries — Red Hat Hardened Images CWE-73 7.0 High 2026-02-11
CVE-2026-26157 Busybox: busybox: arbitrary file overwrite and potential code execution via incomplete path sanitization — Red Hat Hardened Images CWE-73 7.0 High 2026-02-11
CVE-2025-11537 Keycloak-services: sensitive headers shown in the http access logs — Red Hat Build of Keycloak CWE-117 5.0 Medium 2026-02-10
CVE-2025-14778 Keycloak: incorrect ownership checks in /uma-policy/ — Red Hat build of Keycloak 26.2 CWE-266 5.4 Medium 2026-02-09
CVE-2026-1529 Org.keycloak.services.resources.organizations: keycloak: unauthorized organization registration via improper invitation token validation — Red Hat build of Keycloak 26.2 CWE-347 8.1 High 2026-02-09
CVE-2026-1486 Org.keycloak.protocol.oidc.grants: disabled identity providers are still accepted for jwt authorization grant — Red Hat build of Keycloak 26.4 CWE-358 8.8 High 2026-02-09
CVE-2026-1709 Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authentication — Red Hat Enterprise Linux 10 CWE-322 9.4 Critical 2026-02-06
CVE-2026-0598 Ansible-lightspeed: broken object level authorization leading to cross-user ai conversation context injection in ansible lightspeed api — Red Hat Ansible Automation Platform 2.6 CWE-283 4.2 Medium 2026-02-06
CVE-2026-1801 Libsoup: libsoup: http request smuggling via malformed chunk headers — Red Hat Enterprise Linux 10 CWE-444 5.3 Medium 2026-02-03
CVE-2026-1760 Libsoup: soupserver: denial of service via http request smuggling — Red Hat Enterprise Linux 10 CWE-444 5.3 Medium 2026-02-02
CVE-2026-1761 Libsoup: stack-based buffer overflow in libsoup multipart response parsingmultipart http response — Red Hat Enterprise Linux 10 CWE-121 8.6 High 2026-02-02
CVE-2026-1757 Libxml2: memory leak leading to local denial of service in xmllint interactive shell — Red Hat Hardened Images CWE-401 6.2 Medium 2026-02-02
CVE-2026-1531 Foreman-kubevirt: foreman_kubevirt: man-in-the-middle due to insecure default ssl verification — Red Hat Satellite 6.16 for RHEL 8 CWE-295 8.1 High 2026-02-02
CVE-2026-1530 Fog-kubevirt: fog-kubevirt: man-in-the-middle vulnerability due to disabled certificate validation — Red Hat Satellite 6.16 for RHEL 8 CWE-295 8.1 High 2026-02-02
CVE-2025-13881 Org.keycloak.services.resources.admin: keycloak: limited administrator can retrieve sensitive user attributes via admin api — Red Hat build of Keycloak 26.4 CWE-266 2.7 Low 2026-02-02
CVE-2024-4027 Undertow: outofmemoryerror in httpservletrequestimpl.getparameternames() can cause remote dos attacks — Red Hat build of Apicurio Registry 2 CWE-20 7.5 High 2026-01-30
CVE-2026-1616 osim: Path Traversal via query parameters in Nginx configuration — osim CWE-22 7.5 High 2026-01-29
CVE-2026-1539 Libsoup: libsoup: credential leakage via http redirects — Red Hat Enterprise Linux 10 CWE-201 5.8 Medium 2026-01-28
CVE-2026-1536 Libsoup: libsoup: http header injection or response splitting via crlf injection in content-disposition header — Red Hat Enterprise Linux 10 CWE-93 5.8 Medium 2026-01-28
CVE-2026-1489 Glib: glib: memory corruption via integer overflow in unicode case conversion — Red Hat Enterprise Linux 10 CWE-787 5.4 Medium 2026-01-27
CVE-2026-1485 Glib: glib: local denial of service via buffer underflow in content type parsing — Red Hat Enterprise Linux 10 CWE-124 2.8 Low 2026-01-27
CVE-2026-1484 Glib: integer overflow leading to buffer underflow and out-of-bounds write in glib g_base64_encode() — Red Hat Enterprise Linux 10 CWE-787 4.2 Medium 2026-01-27
CVE-2026-1467 Libsoup: libsoup: http header injection via specially crafted urls when an http proxy is configured — Red Hat Enterprise Linux 10 CWE-93 5.8 Medium 2026-01-27
CVE-2025-9615 Networkmanager: networkmanager file access — Red Hat Enterprise Linux 10 CWE-281 8.1AI High AI 2026-01-26
CVE-2026-1190 Org.keycloak/keycloak-services: keycloak saml brokering: response delay due to unchecked notonorafter in subjectconfirmationdata — Red Hat build of Keycloak 26.4 CWE-112 3.1 Low 2026-01-26
CVE-2025-14525 Kubevirt: kubevirt: vm administration denial of service via guest agent — Red Hat OpenShift Virtualization 4 CWE-770 6.4 Medium 2026-01-26
CVE-2025-14969 Hibernate-reactive-core: hibernate reactive: denial of service due to connection leak on http client disconnect — Red Hat build of Quarkus 3.27.2 CWE-772 4.3 Medium 2026-01-26
CVE-2025-14459 Virt-cdi-controller: unauthorized pvc cloning via dataimportcron — RHEL-9-CNV-4.19 CWE-639 8.5 High 2026-01-26

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.