Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1426

Browse all 1426 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

CVE ID Title CVSS Severity Published
CVE-2026-81320 Hawtio-operator: hawtio-operator: tls private key written to operator log at debug level — Red Hat build of Apache Camel - HawtIO 4 CWE-532 5.5 Medium 2026-09-15
CVE-2026-81303 Hawtio-operator: hawtio-operator: routes/custom-host confused-deputy via spec.routehostname — Red Hat build of Apache Camel - HawtIO 4 CWE-441 6.3 Medium 2026-09-15
CVE-2026-90996 Sssd: sssd: denial of service in nss responder via crafted zero-length requests — Red Hat Enterprise Linux 10 CWE-191 4.0 Medium 2026-09-14
CVE-2026-90995 Sssd: sssd: local denial of service due to null pointer dereference in pam responder — Red Hat Enterprise Linux 10 CWE-476 5.5 Medium 2026-09-14
CVE-2026-90994 Sssd: sssd: denial of service via malformed pam v1 requests — Red Hat Enterprise Linux 10 CWE-125 4.0 Medium 2026-09-14
CVE-2026-90463 Sssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / `sss_nss_protocol_parse_svc_port`) — Red Hat Enterprise Linux 10 CWE-125 4.0 Medium 2026-09-14
CVE-2026-90947 Gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset file — Red Hat Enterprise Linux 6 CWE-787 7.8 High 2026-09-14
CVE-2026-90949 Gimp: gimp: heap-based buffer overflow in psp loader due to selection-channel geometry mismatch — Red Hat Enterprise Linux 6 CWE-787 7.8 High 2026-09-14
CVE-2026-90948 Gimp: gimp: heap-based buffer overflow in ico loader via integer overflow in embedded png dimensions — Red Hat Enterprise Linux 6 CWE-787 7.8 High 2026-09-14
CVE-2026-89329 Device-mapper-multipath: local denial of service via blocking ipc send operations — Red Hat Enterprise Linux 10 CWE-1322 6.2 Medium 2026-09-11
CVE-2026-18495 Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthrough — Red Hat Hardened Images CWE-122 6.1 Medium 2026-09-11
CVE-2026-89298 Keycloak-services: keycloak-services: confidential client secret disclosed to view-clients role via client registration get — Red Hat Build of Keycloak CWE-200 4.9 Medium 2026-09-11
CVE-2026-77159 Libvirt: unsafe chown in qemutpmemulatorpreparehost() allows arbitrary file ownership change via symlink — Red Hat Enterprise Linux 10 CWE-61 5.5 Medium 2026-09-11
CVE-2026-88914 Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea-608 closed-caption parser — Red Hat Enterprise Linux 10 CWE-190 4.4 Medium 2026-09-11
CVE-2026-88859 Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restriction — Red Hat Enterprise Linux 6 CWE-84 6.3 Medium 2026-09-10
CVE-2026-84828 Pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth --token — Red Hat Enterprise Linux 10 CWE-732 6.5 Medium 2026-09-10
CVE-2026-88265 Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and chown — Red Hat Enterprise Linux 10 CWE-59 5.6 Medium 2026-09-10
CVE-2026-84042 Crun: crun: rootful krun with passt executes container payload as host root — Red Hat Enterprise Linux 10 CWE-269 7.8 High 2026-09-10
CVE-2026-88770 Keycloak-services: keycloak-services: device authorization grant issues tokens to brute-force-locked accounts — Red Hat Build of Keycloak CWE-307 6.5 Medium 2026-09-10
CVE-2026-88763 Skupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial of service — Red Hat Service Interconnect 2 CWE-674 5.9 Medium 2026-09-10
CVE-2026-18147 Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrary code execution via crafted url — Red Hat Enterprise Linux 10 CWE-79 8.1 High 2026-09-09
CVE-2026-87876 Cups: openprinting cups: remaining case-insensitive username matching in scheduler side paths (cve-2026-27447 follow-up) — Red Hat Hardened Images CWE-178 3.0 Low 2026-09-09
CVE-2026-87872 Community.general: community.general: ocapi module_utils (ocapi_command, ocapi_info) hardcode validate_certs=false with no override, enabling tls man-in-the-middle and credential disclosure — Red Hat Ceph Storage 5 CWE-295 6.8 Medium 2026-09-09
CVE-2026-87875 Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-length bound — Red Hat Hardened Images CWE-125 4.3 Medium 2026-09-09
CVE-2026-87853 Sssd: sssd: idp authentication prefix comparison allows cross-user impersonation — Red Hat Enterprise Linux 10 CWE-187 7.5 High 2026-09-09
CVE-2026-87874 Community.general: community.general: memcached cache plugin deserializes untrusted pickle data from memcached, enabling cache-poisoning remote code execution on the ansible controller — Red Hat Ceph Storage 5 CWE-502 8.1 High 2026-09-09
CVE-2026-87766 Bubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files outside sandbox during setup — Red Hat Enterprise Linux 10 CWE-59 8.8 High 2026-09-09
CVE-2026-19729 Keycloak-services: keycloak-services: incomplete fix for arbitrary filesystem path probing via keystore parameters — Red Hat build of Keycloak 26.4 CWE-22 4.9 Medium 2026-09-09
CVE-2026-86564 Dpdk: dpdk: missing length validation before reading command_data in virtio-net control queue handler — Fast Datapath for RHEL 10 CWE-125 3.3 Low 2026-09-08
CVE-2026-18090 Gdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted icns rle block — Red Hat Enterprise Linux 10 CWE-125 6.1 Medium 2026-09-08

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.