Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1440

Browse all 1440 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

Found 67 results / 1440 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-19607 Keycloak-services: keycloak-services: broker-originated username collision causes account lockout — Red Hat build of Keycloak 26.4 CWE-287 5.3 Medium 2026-09-16
CVE-2026-17526 Keycloak-services: keycloak-services: privilege escalation via impersonation role allows takeover of realm administrator accounts — Red Hat build of Keycloak 26.4 CWE-862 7.2 High 2026-09-16
CVE-2026-79651 Keycloak-services: keycloak-services: unauthenticated dos via unbounded locale caching — Red Hat build of Keycloak 26.4 CWE-400 7.5 High 2026-09-16
CVE-2026-74909 Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enforcer bypass via percent-encoded uri segments — Red Hat build of Keycloak 26.4 CWE-862 8.1 High 2026-09-16
CVE-2026-18212 Keycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib state — Red Hat build of Keycloak 26.4 CWE-401 7.5 High 2026-09-16
CVE-2026-19729 Keycloak-services: keycloak-services: incomplete fix for arbitrary filesystem path probing via keystore parameters — Red Hat build of Keycloak 26.4 CWE-22 4.9 Medium 2026-09-09
CVE-2026-18963 Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass — Red Hat build of Keycloak 26.4 CWE-640 9.1 Critical 2026-08-18
CVE-2026-15572 Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows privilege escalation — Red Hat build of Keycloak 26.4 CWE-843 8.8 High 2026-08-05
CVE-2026-16442 Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restriction — Red Hat build of Keycloak 26.4 CWE-346 7.4 High 2026-08-05
CVE-2026-16071 Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary — Red Hat build of Keycloak 26.4 CWE-90 5.4 Medium 2026-08-05
CVE-2026-16102 Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers — Red Hat build of Keycloak 26.4 CWE-551 8.1 High 2026-08-05
CVE-2026-15573 Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher — Red Hat build of Keycloak 26.4 CWE-551 8.1 High 2026-08-05
CVE-2026-16443 Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation — Red Hat build of Keycloak 26.4 CWE-347 7.4 High 2026-08-05
CVE-2026-14615 Keycloak-services: keycloak: fgap v2 parent group children endpoint bypasses per-child view permission filter — Red Hat build of Keycloak 26.4 CWE-1220 4.3 Medium 2026-07-03
CVE-2026-14614 Keycloak-services: keycloak-services: fgap v2 client scope assignment bypass via clientresource — Red Hat build of Keycloak 26.4 CWE-639 5.4 Medium 2026-07-03
CVE-2026-4629 Keycloak: keycloak: privilege escalation through hardcoded role mapper injection — Red Hat build of Keycloak 26.4 CWE-266 6.5 Medium 2026-06-30
CVE-2026-14209 Keycloak-admin-ui: keycloak-admin-ui:admin ui extension brute-force-user endpoint bypasses fgapv2 user view restrictions — Red Hat build of Keycloak 26.4 CWE-639 4.3 Medium 2026-06-30
CVE-2026-9083 Keycloak: keycloak: information disclosure through arbitrary filesystem path probing — Red Hat build of Keycloak 26.4 CWE-22 4.9 Medium 2026-06-25
CVE-2026-9799 Keycloak: keycloak: unauthorized access to resources via uma permission ticket bypass — Red Hat build of Keycloak 26.4 CWE-639 4.6 Medium 2026-06-25
CVE-2026-9705 Keycloak: keycloak: attacker can re-enable and take over disabled clients via registration access token — Red Hat build of Keycloak 26.4 CWE-613 6.5 Medium 2026-06-25
CVE-2026-9086 Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validation bypass — Red Hat build of Keycloak 26.4 CWE-79 7.3 High 2026-06-25
CVE-2026-9099 Keycloak: group-admin escalation to realm-admin — Red Hat build of Keycloak 26.4 CWE-639 7.7 High 2026-06-25
CVE-2026-9800 Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via incorrect uri comparison — Red Hat build of Keycloak 26.4 CWE-1025 8.1 High 2026-06-25
CVE-2026-9088 Keycloak: keycloak: information disclosure due to user profile permission bypass — Red Hat build of Keycloak 26.4 CWE-1220 2.7 Low 2026-06-05
CVE-2026-9802 Keycloak: keycloak: unauthorized account access via replayed refresh tokens after cluster restart — Red Hat build of Keycloak 26.4 CWE-613 6.8 Medium 2026-05-28
CVE-2026-9803 Keycloak: keycloak: denial of service via malformed authorization header — Red Hat build of Keycloak 26.4 CWE-125 5.3 Medium 2026-05-28
CVE-2026-9801 Keycloak: keycloak: denial of service via malformed ldap password policy response — Red Hat build of Keycloak 26.4 CWE-1284 4.9 Medium 2026-05-28
CVE-2026-9798 Keycloak: keycloak: brute-force protection bypass in ciba flow — Red Hat build of Keycloak 26.4 CWE-305 4.3 Medium 2026-05-28
CVE-2026-9795 Keycloak: keycloak: privilege escalation via improper scope mapping enforcement — Red Hat build of Keycloak 26.4 CWE-266 7.3 High 2026-05-28
CVE-2026-9794 Keycloak: keycloak: information disclosure via saml ecp endpoint — Red Hat build of Keycloak 26.4 CWE-209 5.3 Medium 2026-05-28

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.