Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1440

Browse all 1440 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

Found 12 results / 1440 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-101292 Artemis-core-client: unsafe reflection in apache activemq artemis federation message deserialization — Red Hat JBoss Enterprise Application Platform 7.4.25 CWE-470 8.2 High 2026-09-28
CVE-2026-86404 Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging-activemq-subsystem: artemis messaging handlers in red hat eap permit deserialization by default — Red Hat JBoss Enterprise Application Platform 7.4.25 CWE-502 8.8 High 2026-09-07
CVE-2026-15567 Wildfly: wildfly-iiop: wildfly-jacorb: wildfly: pre-auth denial of service on the iiop listener — Red Hat JBoss Enterprise Application Platform 7.4.25 7.5 High 2026-08-11
CVE-2026-15565 Undertow: undertow-websockets: undertow: pre-auth dos on websocket endpoint with @serverendpoint class with any @onmessage method — Red Hat JBoss Enterprise Application Platform 7.4.25 CWE-120 7.5 High 2026-08-11
CVE-2026-15563 Wildfly-iiop-openjdk: missing authentication on eap's iiop nameservice leads to mitm or dos — Red Hat JBoss Enterprise Application Platform 7.4.25 CWE-306 7.4 High 2026-08-11
CVE-2026-15562 Jboss-remoting: jboss-remoting: integer overflow in messagereader leads to pre-authentication denial of service — Red Hat JBoss Enterprise Application Platform 7.4.25 CWE-190 7.5 High 2026-08-11
CVE-2026-15561 Undertow-core: oom via missing limits in chunked trailer in eap's undertow — Red Hat JBoss Enterprise Application Platform 7.4.25 CWE-770 7.5 High 2026-08-11
CVE-2026-15560 Openjdk-orb: unauthed class loading via iiop in eap — Red Hat JBoss Enterprise Application Platform 7.4.25 CWE-829 8.1 High 2026-08-11
CVE-2026-15556 Picketlink-federation: picketlink saml 2.0 auth bypass via missing assertions — Red Hat JBoss Enterprise Application Platform 7.4.25 CWE-347 8.1 High 2026-08-11
CVE-2026-15555 Jboss-marshalling-river: wildfly-clustering-infinispan-marshalling: jboss deserialization rce via unfiltered river unmarshaller — Red Hat JBoss Enterprise Application Platform 7.4.25 CWE-502 8.8 High 2026-08-11
CVE-2026-15554 Undertow-core: undertow: authentication bypass via ajp ssl_cert/is_ssl forgery — Red Hat JBoss Enterprise Application Platform 7.4.25 CWE-295 7.4 High 2026-08-11
CVE-2026-10579 Picketlink-federation: auth bypass in picketlink saml unsolicited-response — Red Hat JBoss Enterprise Application Platform 7.4.25 CWE-347 9.8 Critical 2026-08-11

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.