Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1426

Browse all 1426 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

CVE ID Title CVSS Severity Published
CVE-2026-84837 Rpm: command injection in `rpmbuild -t*` (`gettarspec`) via unescaped tarball path — Red Hat Enterprise Linux 10 CWE-78 7.8 High 2026-09-02
CVE-2026-78409 Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape via intermediate symlinks — Red Hat Hardened Images CWE-59 7.0 High 2026-09-02
CVE-2026-78408 Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority — Red Hat Hardened Images CWE-775 7.9 High 2026-09-02
CVE-2026-78410 Util-linux: util-linux: restricted bind mounts do not pin the source, allowing x-mount.owner/group/mode redirection — Red Hat Hardened Images CWE-367 7.8 High 2026-09-02
CVE-2026-53683 Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html — Red Hat Enterprise Linux 10 CWE-601 4.3 Medium 2026-09-02
CVE-2026-82968 Keycloak-services: keycloak-services: cross-session email verification proof not bound to upstream identity for social providers — Red Hat Build of Keycloak CWE-639 6.4 Medium 2026-09-02
CVE-2026-84470 Automation-controller: automation-controller-container: automation-controller/awx: bulk job launch checks instance_groups at read level instead of use level, allowing execution-placement authorization bypass — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-862 6.4 Medium 2026-09-01
CVE-2026-49329 Openshift/oauth-server: openshift/oauth-server: quadratic-time dos via accept-language header underscore bypass on unauthenticated login endpoints — Red Hat OpenShift Container Platform 4 CWE-407 7.5 High 2026-09-01
CVE-2026-84232 Pulpcore: python-pulpcore: stored cross-site scripting via inline rendering of uploaded html/svg content — Red Hat Ansible Automation Platform 2 CWE-79 5.4 Medium 2026-09-01
CVE-2026-84233 Rpm: command execution via macro expansion in `rpmuncompress -x` for crafted `.gem` filenames — Red Hat Enterprise Linux 10 CWE-78 7.0 High 2026-09-01
CVE-2026-84218 Org.jolokia/jolokia-core: incomplete jndi denylist in jolokia jsr-160 proxy (bypass of cve-2018-1000130 fix) — Red Hat AMQ Broker 7 CWE-184 8.1 High 2026-09-01
CVE-2026-53682 Pki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security domain hosts — Red Hat Certificate System 9 CWE-497 5.3 Medium 2026-09-01
CVE-2026-11873 Pki-core: dogtag-pki: empty request to dogtag /ca/rest/certrequests causes http 500, java exception, and stacktrace disclosure — Red Hat Certificate System 9 CWE-209 6.5 Medium 2026-09-01
CVE-2026-13732 Gdb: gdb: out-of-bounds write in stabs parser read_member_functions() via crafted elf — Red Hat Enterprise Linux 10 CWE-787 7.0 High 2026-08-31
CVE-2026-17615 Resteasy-core: resteasy sourceprovider remote unauthenticated file read — Red Hat build of Keycloak 26.6 CWE-611 7.5 High 2026-08-31
CVE-2026-76763 Io.smallrye/smallrye-graphql: smallrye graphql: unauthenticated denial of service via large exponent float literals — Red Hat build of Quarkus CWE-1284 7.5 High 2026-08-31
CVE-2026-81624 Undertow-core: undertow: websocketcontainer defaults for buffers and timeouts are infinite — Red Hat build of Apache Camel for Spring Boot 4 CWE-770 7.5 High 2026-08-31
CVE-2026-82327 Libsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directory id from vertical/paged .solv filelist data — Red Hat Enterprise Linux 10 CWE-129 5.5 Medium 2026-08-28
CVE-2026-18393 Ffmpeg: ffmpeg: heap buffer overflow in tdsc_load_cursor() via cur_fmt_mono cursor — Red Hat Enterprise Linux AI (RHEL AI) 3 CWE-787 5.4 Medium 2026-08-28
CVE-2026-80179 Jwcrypto: jwcrypto: denial of service via malformed jwe tokens — Red Hat Ansible Automation Platform 2 CWE-770 5.9 Medium 2026-08-27
CVE-2026-81893 Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error recovery — Red Hat Enterprise Linux 10 CWE-787 4.7 Medium 2026-08-27
CVE-2026-5680 Undertow-core: undertow: denial of service via websocket permessage-deflate processing — Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10 CWE-770 7.5 High 2026-08-27
CVE-2026-78002 Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() function — Red Hat Enterprise Linux 10 CWE-131 7.5 High 2026-08-27
CVE-2026-81668 Rubygem-katello: cross-tenant content view filter rule access and modification via unauthorized parent filter lookup — Red Hat Satellite 6 CWE-639 5.4 Medium 2026-08-27
CVE-2026-81658 Foreman: cross-tenant disclosure of template revisions via unauthorized audit lookup — Red Hat Satellite 6 CWE-639 6.5 Medium 2026-08-27
CVE-2026-80158 Ansible-collection-community-general: community.general: ipa_getkeytab does not set no_log on the bind_pw parameter, disclosing the ipa bind password in logs and process listings — Red Hat Ceph Storage 5 CWE-214 5.5 Medium 2026-08-26
CVE-2026-79654 Ketello: katello content view history api cross-organization authorization bypass — Red Hat Satellite 6 CWE-639 4.3 Medium 2026-08-26
CVE-2026-80186 Bluez: stack overflow in name2utf8 causes dos and potential code execution — Red Hat Enterprise Linux 10 CWE-120 7.6 High 2026-08-25
CVE-2026-80185 Bluez: sdp-xml: bluez 5.86: unprivileged-local and adjacent-le-peer leads to arbitrary code execution as root — Red Hat Enterprise Linux 10 CWE-843 5.7 Medium 2026-08-25
CVE-2026-77680 Libsoup3: libsoup: quadratic cpu denial of service in http range coalescing after cve-2025-32907 fix — Red Hat Enterprise Linux 10 CWE-407 5.3 Medium 2026-08-25

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.