Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1442

Browse all 1442 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

Found 13 results / 1442 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-83589 Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect — Red Hat OpenShift Container Platform 4 CWE-601 6.1 Medium 2026-10-01
CVE-2026-62146 Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socket — Red Hat OpenShift Container Platform 4 CWE-501 7.8 High 2026-09-30
CVE-2026-75939 Openshift/oc-mirror: release signature verification: openpgp signatureerror checked before signed body is consumed — Red Hat OpenShift Container Platform 4 CWE-347 7.4 High 2026-09-21
CVE-2026-15801 Cri-o: cri-o: insufficient validation during container checkpoint restore — Red Hat OpenShift Container Platform 4 CWE-22 8.0 High 2026-09-21
CVE-2026-49329 Openshift/oauth-server: openshift/oauth-server: quadratic-time dos via accept-language header underscore bypass on unauthenticated login endpoints — Red Hat OpenShift Container Platform 4 CWE-407 7.5 High 2026-09-01
CVE-2026-77176 Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy — Red Hat OpenShift Container Platform 4 CWE-73 8.1 High 2026-08-20
CVE-2026-19078 Ose-oauth-server: oauth-server: open redirect vulnerability enables phishing via unvalidated parameter. — Red Hat OpenShift Container Platform 4 CWE-601 4.3 Medium 2026-08-11
CVE-2026-49331 Openshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header injection on whitelisted paths — Red Hat OpenShift Container Platform 4 CWE-345 6.5 Medium 2026-08-05
CVE-2026-10843 Cloud-credential-operator: cco mint-mode credentialsrequest manifests grant account-wide iam access beyond cluster scope on aws — Red Hat OpenShift Container Platform 4 CWE-250 7.2 High 2026-06-04
CVE-2026-10533 Openshift: openshift: non-admin user can bypass resourcequota and flood etcd with events causing cluster-wide api degradation — Red Hat OpenShift Container Platform 4 CWE-770 5.0 Medium 2026-06-01
CVE-2026-7309 Openshift-controller-manager: openshift container platform: information disclosure via environment variable injection — Red Hat OpenShift Container Platform 4 CWE-426 4.3 Medium 2026-04-28
CVE-2025-14443 Ose-openshift-apiserver: openshift api server: server-side request forgery (ssrf) vulnerability in imagestreamimport mechanism — Red Hat OpenShift Container Platform 4 CWE-918 6.4 Medium 2025-12-16
CVE-2025-4437 Cri-o: large /etc/passwd file may lead to denial of service — Red Hat OpenShift Container Platform 4 CWE-770 5.7 Medium 2025-08-20

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.