Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1426

Browse all 1426 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

CVE ID Title CVSS Severity Published
CVE-2026-93493 Io.netty/netty-handler-ssl-ocsp: netty: ocsp validation silently skipped when a response omits the optional nextupdate field — Red Hat build of Apache Camel for Spring Boot 4 CWE-299 5.9 Medium 2026-09-18
CVE-2026-93494 Io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when a frame body is never terminated — Red Hat build of Apache Camel for Spring Boot 4 CWE-1035 7.5 High 2026-09-18
CVE-2026-89058 Resteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wildcard config 7.4 High 2026-09-18
CVE-2026-89059 Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos) CWE-409 7.5 High 2026-09-18
CVE-2026-76781 Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attribute — Red Hat Hardened Images CWE-476 5.5 Medium 2026-09-17
CVE-2026-87742 Quarkus-websockets-next: denial of service (oom) in quarkus-websockets-next via unbounded message buffering — Exploit Intelligence CWE-770 7.5 High 2026-09-17
CVE-2026-81829 Smallrye-jwt: quarkus-smallrye-jwt: smallrye-jwt: unauthenticated same-origin ssrf via unsanitized jwt kid header in awsalbkeyresolver — Exploit Intelligence CWE-22 5.3 Medium 2026-09-17
CVE-2026-92904 Rubygem-foreman_remote_execution: job output readable without object-level view_job_invocations check — Red Hat Satellite 6 CWE-863 4.3 Medium 2026-09-17
CVE-2026-92925 Redis: redis: out-of-bounds read via crafted cluster bus packets — Red Hat Enterprise Linux 9 CWE-125 7.1 High 2026-09-17
CVE-2026-92893 Rubygem-foreman_ansible: ansible inventory api ignores view_hosts permission filters, exposes hidden parameters — Red Hat Satellite 6 CWE-863 4.3 Medium 2026-09-17
CVE-2026-92894 Rubygem-foreman_ansible: unscoped lookupvalue deletion allows cross-model override value destruction — Red Hat Satellite 6 CWE-863 4.3 Medium 2026-09-17
CVE-2026-86320 Flatpak-builder: host code execution via `git am` hook execution in patch source extraction (`use-git-am`) — Red Hat Enterprise Linux 10 CWE-94 7.8 High 2026-09-17
CVE-2026-85469 Quay-builder-qemu: quay-builder-qemu: release workflow uses third-party action pinned to mutable @master with registry credentials in scope — Red Hat Quay 3 CWE-1357 8.0 High 2026-09-16
CVE-2026-42784 Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusion — Red Hat Hardened Images CWE-347 7.4 High 2026-09-16
CVE-2026-19607 Keycloak-services: keycloak-services: broker-originated username collision causes account lockout — Red Hat build of Keycloak 26.4 CWE-287 5.3 Medium 2026-09-16
CVE-2026-17526 Keycloak-services: keycloak-services: privilege escalation via impersonation role allows takeover of realm administrator accounts — Red Hat build of Keycloak 26.4 CWE-862 7.2 High 2026-09-16
CVE-2026-92615 Flightctl: flightctl: package-global go-git https transport mutated per-repo -- cross-tenant tls-config bleed — Red Hat Advanced Cluster Management for Kubernetes 2 CWE-413 6.6 Medium 2026-09-16
CVE-2026-79651 Keycloak-services: keycloak-services: unauthenticated dos via unbounded locale caching — Red Hat build of Keycloak 26.4 CWE-400 7.5 High 2026-09-16
CVE-2026-74909 Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enforcer bypass via percent-encoded uri segments — Red Hat build of Keycloak 26.4 CWE-862 8.1 High 2026-09-16
CVE-2026-18212 Keycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib state — Red Hat build of Keycloak 26.4 CWE-401 7.5 High 2026-09-16
CVE-2026-92091 Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded jwk key_ops array — Red Hat Ansible Automation Platform 2 CWE-407 5.9 Medium 2026-09-16
CVE-2026-92358 Keycloak-services: keycloak-services: residual cross-browser account-link proof allows silent re-linking — Red Hat Build of Keycloak CWE-613 6.4 Medium 2026-09-16
CVE-2025-11395 Podman: arbitrary file write when importing oci archive — Red Hat Enterprise Linux 9 CWE-277 5.5 Medium 2026-09-15
CVE-2026-85234 Tftp: tftp-hpa: denial of service due to out-of-bounds read/write in remap engine — Red Hat Enterprise Linux 10 CWE-125 7.5 High 2026-09-15
CVE-2026-79699 Podman: buildah: skopeo: containers/storage: malicious tar whiteout header allows replacement of extraction destination directory — Red Hat Ansible Automation Platform 2 CWE-59 4.4 Medium 2026-09-15
CVE-2026-79705 Podman: buildah: buildah/copier: directory escape via crafted tar symlinks when used outside buildah by non-root callers — Red Hat Ansible Automation Platform 2 CWE-22 4.5 Medium 2026-09-15
CVE-2026-85013 Environment-modules: command injection in environment-modules bash completion via malicious module names containing shell metacharacters — Red Hat Hardened Images CWE-78 7.3 High 2026-09-15
CVE-2026-91926 Gss-ntlmssp: gss-ntlmssp: memory leak in ntlm_decode_target_info via duplicated av_pair entries in ntlm challenge — Red Hat Enterprise Linux 8 CWE-401 3.7 Low 2026-09-15
CVE-2026-91786 Gnome-shell: gnome-shell: out-of-bounds read in remote search icon rendering due to unvalidated icon-data buffer size — Red Hat Enterprise Linux 10 CWE-125 6.1 Medium 2026-09-15
CVE-2026-75092 Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld --validate-config as root and can load mysql-writable plugins — Red Hat Enterprise Linux 9 CWE-250 7.3 High 2026-09-15

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.