Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1444

Browse all 1444 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

Found 34 results / 1444 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-84724 Automation-controller: automation-controller: systemjob extra_vars.days argument injection into uncontainerized control-plane awx-manage process — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-88 6.6 Medium 2026-09-23
CVE-2026-84720 Automation-controller: automation-controller: workflowjobnode.ancestor_artifacts lacks prevent_search, exposing no_log set_stats artifacts via orm-traversal count-oracle — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-639 6.5 Medium 2026-09-23
CVE-2026-84718 Automation-controller: automation-controller: client ip spoofing in audit/access logs via unrestricted x-forwarded-for trust — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-348 4.3 Medium 2026-09-23
CVE-2026-84717 Automation-controller: automation-controller: unauthenticated 200-vs-403 oracle in bitbucket data center webhook receiver enumerates webhook-enabled job templates — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-204 5.3 Medium 2026-09-23
CVE-2026-84716 Automation-controller: automation-controller: instance install_bundle issues 10-year, non-revocable receptor mesh-ca certificates for caller-chosen (and case-variant impersonating) hostnames — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-266 6.6 Medium 2026-09-23
CVE-2026-84712 Automation-controller: automation-controller: unauthenticated /api/v2/ping/ discloses automation-mesh instance topology and instance-group membership — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-497 5.3 Medium 2026-09-23
CVE-2026-84714 Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jinja template injection into ad-hoc module_args, machine-credential fields, and host names, reaching ansible-core templating in the execution environment — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-184 7.1 High 2026-09-23
CVE-2026-84706 Automation-controller: automation-controller-container: automation-controller: credential type env-injector deny-list omits process-hijacking variables (bash_env/ld_preload) allowing code execution in the execution environment — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-184 7.6 High 2026-09-23
CVE-2026-84691 Automation-controller: automation-controller-container: automation-controller: format string injection in the api 4xx error log setting discloses django secret_key and database credentials to an administrator — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-134 8.7 High 2026-09-23
CVE-2026-84683 Automation-controller: automation-controller-container: automation-controller: stored cross-site scripting in the job stdout html view via ansi osc 8 hyperlink sequences (javascript: anchor) enabling session takeover — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-79 8.7 High 2026-09-23
CVE-2026-84499 Automation-controller: automation-controller-container: automation-controller: write-only survey password recovered in plaintext via schedule/workflowjobtemplatenode survey min/max validation error message — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-209 7.7 High 2026-09-23
CVE-2026-71465 Automation-controller: automation-controller-container: automation-controller: ad-hoc command limit field allows cli argument injection into ansible executable — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-88 3.1 Low 2026-09-23
CVE-2026-71464 Automation-controller: automation-controller-container: automation-controller: schedule and workflowjobtemplatenode scm_branch prompt bypasses leading-dash git-argument guard — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-88 3.1 Low 2026-09-23
CVE-2026-71463 Automation-controller: automation-controller-container: automation-controller: notification template jinja whitelist bypass via conditional gating leaks tracebacks — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-209 2.7 Low 2026-09-23
CVE-2026-71462 Automation-controller: automation-controller-container: automation-controller: custom_venv_path setting provides filesystem path-existence oracle on control pod — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-204 4.1 Medium 2026-09-23
CVE-2026-71460 Automation-controller: automation-controller-container: automation-controller: any authenticated user reads red hat subscription/license details via /config/ — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-862 4.3 Medium 2026-09-23
CVE-2026-71459 Automation-controller: automation-controller-container: automation-controller: jobjobeventschildrensummary rbac bypass exposes cross-tenant job event tree structure — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-862 5.0 Medium 2026-09-23
CVE-2026-71458 Automation-controller: automation-controller-container: automation-controller: named-url 404 body oracle enables cross-tenant resource name enumeration — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-204 5.0 Medium 2026-09-23
CVE-2026-84470 Automation-controller: automation-controller-container: automation-controller/awx: bulk job launch checks instance_groups at read level instead of use level, allowing execution-placement authorization bypass — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-862 6.4 Medium 2026-09-01
CVE-2026-71366 Awx: notification backends allow ssrf and credential leakage — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-918 7.7 High 2026-08-24
CVE-2026-71364 Awx: project archive extraction allows path traversal file writes — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-22 7.2 High 2026-08-24
CVE-2026-71365 Awx: webhook status callback ssrf leaks the git pat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-918 7.7 High 2026-08-18
CVE-2026-12383 Eda-server: externaleventstreamviewset trusts subject header without validation and leaks expected dn — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-345 7.5 High 2026-07-27
CVE-2026-12701 Pulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemexport — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-22 9.0 Critical 2026-07-20
CVE-2026-12382 Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-290 8.2 High 2026-07-15
CVE-2026-11807 Eda-server: websocket missing authorization allows credential theft via activation_id spoofing — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-862 9.6 Critical 2026-06-23
CVE-2026-52902 Awxkit: path traversal via yaml !include directive — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-22 4.7 Medium 2026-06-09
CVE-2026-11332 Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-88 7.8 High 2026-06-05
CVE-2025-9909 Aap-gateway: improper path validation in gateway allows credential exfiltration — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-647 6.7 Medium 2026-02-27
CVE-2025-9908 Event-driven-ansible: sensitive internal headers disclosure in aap eda event streams — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-200 6.7 Medium 2026-02-27

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.