Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1444

Browse all 1444 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

Found 40 results / 1444 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-103884 Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read — Red Hat Build of Keycloak CWE-22 6.5 Medium 2026-10-01
CVE-2026-101333 Keycloak-services: keycloak-services: unbounded metric series creation via idp tag on broker login endpoint — Red Hat Build of Keycloak CWE-770 3.7 Low 2026-09-28
CVE-2026-96448 Keycloak-services: keycloak-services: fgap v2 composite-blind role mapping allows privilege escalation — Red Hat Build of Keycloak CWE-285 6.6 Medium 2026-09-25
CVE-2026-97846 Keycloak-services: keycloak-services: standard token exchange v2 bypasses mtls holder-of-key binding — Red Hat Build of Keycloak CWE-287 6.8 Medium 2026-09-25
CVE-2026-97311 Keycloak-services: keycloak-services: admin rest api role-groups endpoint discloses groups without authorization — Red Hat Build of Keycloak CWE-862 4.3 Medium 2026-09-24
CVE-2026-97177 Keycloak-services: keycloak-services: generic user update bypasses denied reset-password permission — Red Hat Build of Keycloak CWE-862 6.6 Medium 2026-09-24
CVE-2026-97176 Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cookie authenticator — Red Hat Build of Keycloak CWE-862 4.2 Medium 2026-09-24
CVE-2026-96445 Keycloak-services: keycloak-services: conditional otp skip-header policy evaluated against untrusted proxy headers — Red Hat Build of Keycloak CWE-287 6.8 Medium 2026-09-23
CVE-2026-96446 Keycloak-services: keycloak-services: par single-use bypass via prompt=none silent authentication path — Red Hat Build of Keycloak CWE-862 4.2 Medium 2026-09-23
CVE-2026-95503 Keycloak-services: keycloak-services: potential kdc spoofing bypass when kerberos password authentication is enabled — Red Hat Build of Keycloak CWE-347 6.8 Medium 2026-09-22
CVE-2026-94218 Keycloak-services: keycloak-services: 2fa setup enforcement bypass via authentication session restart endpoint — Red Hat Build of Keycloak CWE-862 3.1 Low 2026-09-21
CVE-2026-94217 Keycloak-services: keycloak-services: uma scope merge across resource owners via resource name collision — Red Hat Build of Keycloak CWE-862 3.5 Low 2026-09-21
CVE-2026-94215 Keycloak-services: keycloak-services: cross-realm client read/write via request-level cache missing realm ownership check — Red Hat Build of Keycloak CWE-862 5.5 Medium 2026-09-21
CVE-2026-94213 Keycloak-services: keycloak-services: authorization services policy evaluation endpoint leaks user identity — Red Hat Build of Keycloak CWE-862 4.9 Medium 2026-09-21
CVE-2026-94001 Keycloak-services: keycloak-services: admin credential delete bypasses denied reset-password permission — Red Hat Build of Keycloak CWE-862 6.5 Medium 2026-09-19
CVE-2026-94000 Keycloak-services: keycloak-services: delegated admin with manage-users can escalate to realm-admin via group membership — Red Hat Build of Keycloak CWE-862 6.6 Medium 2026-09-19
CVE-2026-93999 Keycloak-services: keycloak-services: token refresh continues issuing tokens for disabled audience clients — Red Hat Build of Keycloak CWE-862 4.2 Medium 2026-09-19
CVE-2026-92358 Keycloak-services: keycloak-services: residual cross-browser account-link proof allows silent re-linking — Red Hat Build of Keycloak CWE-613 6.4 Medium 2026-09-16
CVE-2026-89298 Keycloak-services: keycloak-services: confidential client secret disclosed to view-clients role via client registration get — Red Hat Build of Keycloak CWE-200 4.9 Medium 2026-09-11
CVE-2026-88770 Keycloak-services: keycloak-services: device authorization grant issues tokens to brute-force-locked accounts — Red Hat Build of Keycloak CWE-307 6.5 Medium 2026-09-10
CVE-2026-82968 Keycloak-services: keycloak-services: cross-session email verification proof not bound to upstream identity for social providers — Red Hat Build of Keycloak CWE-639 6.4 Medium 2026-09-02
CVE-2026-19608 Keycloak-services: keycloak-services: name-only group claims let same-name groups satisfy path-specific group policies — Red Hat Build of Keycloak CWE-285 5.3 Medium 2026-08-18
CVE-2026-18967 Keycloak-services: keycloak-services: saml onetimeuse assertion replay in idp-initiated broker flow — Red Hat Build of Keycloak CWE-294 6.4 Medium 2026-08-06
CVE-2026-18569 Keycloak-services: keycloak-services: oidc backchannel logout accepts unsigned forged logout tokens — Red Hat Build of Keycloak CWE-347 3.7 Low 2026-08-04
CVE-2026-18206 Keycloak-services: keycloak-services: client policy source-host wildcard domain matching bypass — Red Hat Build of Keycloak CWE-20 3.7 Low 2026-07-31
CVE-2026-18203 Keycloak-services: keycloak-services: group policy extendchildren matches sibling group path prefixes — Red Hat Build of Keycloak CWE-863 6.5 Medium 2026-07-31
CVE-2026-18211 Keycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefixed domains — Red Hat Build of Keycloak CWE-20 4.2 Medium 2026-07-31
CVE-2026-18208 Keycloak-services: keycloak-services: inactive out-of-audience token introspection leaks signed jwt claim — Red Hat Build of Keycloak CWE-862 6.5 Medium 2026-07-31
CVE-2026-18217 Keycloak-services: keycloak-services: saml http-redirect binding response preserves query string leading to parameter pollution — Red Hat Build of Keycloak CWE-20 3.4 Low 2026-07-31
CVE-2026-18207 Keycloak-services: keycloak-services: client policy source-group condition bypass via duplicate group name matching — Red Hat Build of Keycloak CWE-285 6.5 Medium 2026-07-29

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.