Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1440

Browse all 1440 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

Found 27 results / 1440 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-17615 Resteasy-core: resteasy sourceprovider remote unauthenticated file read — Red Hat build of Keycloak 26.6 CWE-611 7.5 High 2026-08-31
CVE-2026-79652 Keycloak-services: keycloak-services: jwt bearer authorization grant does not enforce consentrequired — Red Hat build of Keycloak 26.6 CWE-862 5.9 Medium 2026-08-25
CVE-2026-15571 Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc client — Red Hat build of Keycloak 26.6 CWE-341 7.3 High 2026-08-18
CVE-2026-16100 Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics via request-controlled error text — Red Hat build of Keycloak 26.6 CWE-770 6.5 Medium 2026-08-05
CVE-2026-18573 Keycloak-services: keycloak-services: client access-type policy condition bypass during client update — Red Hat build of Keycloak 26.6 CWE-862 6.5 Medium 2026-08-02
CVE-2026-18572 Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes — Red Hat build of Keycloak 26.6 CWE-863 6.5 Medium 2026-08-02
CVE-2026-18571 Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation — Red Hat build of Keycloak 26.6 CWE-862 6.6 Medium 2026-08-02
CVE-2026-18570 Keycloak-services: keycloak-services: full-scope-disabled client policy validation bypass via omitted fullscopeallowed — Red Hat build of Keycloak 26.6 CWE-862 5.4 Medium 2026-08-02
CVE-2026-18209 Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter pollution check — Red Hat build of Keycloak 26.6 CWE-1288 3.4 Low 2026-07-31
CVE-2026-18214 Keycloak-services: keycloak-services: google external access-token exchange bypasses hosted-domain restriction — Red Hat build of Keycloak 26.6 CWE-862 6.8 Medium 2026-07-31
CVE-2026-16105 Keycloak-services: keycloak-services: missing per-role authorization on rolecontainerresource composite endpoints — Red Hat build of Keycloak 26.6 CWE-639 4.9 Medium 2026-07-31
CVE-2026-18215 Keycloak-services: keycloak-services: microsoft external access-token exchange bypasses configured tenant — Red Hat build of Keycloak 26.6 CWE-287 6.8 Medium 2026-07-31
CVE-2026-18218 Keycloak-services: keycloak-services: client not-before revocation ignored when realm not-before is older but nonzero — Red Hat build of Keycloak 26.6 CWE-862 4.2 Medium 2026-07-31
CVE-2026-18201 Keycloak-services: keycloak-services: generic identity-provider creation can bind brokers to organizations without manage-organizations — Red Hat build of Keycloak 26.6 CWE-862 5.5 Medium 2026-07-29
CVE-2026-17059 Keycloak-services: keycloak-services: information disclosure via role-users endpoint bypasses per-user view filter — Red Hat build of Keycloak 26.6 CWE-639 6.5 Medium 2026-07-24
CVE-2026-17048 Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest api — Red Hat build of Keycloak 26.6 CWE-200 5.5 Medium 2026-07-24
CVE-2026-16104 Keycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptcha secrets to view-only admins — Red Hat build of Keycloak 26.6 CWE-212 4.3 Medium 2026-07-17
CVE-2026-16106 Keycloak-services: keycloak-services: incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles — Red Hat build of Keycloak 26.6 CWE-1220 4.9 Medium 2026-07-17
CVE-2026-16108 Keycloak-services: keycloak-services: realm default-group reads disclose hidden groups under fgap v2 — Red Hat build of Keycloak 26.6 CWE-1220 4.3 Medium 2026-07-17
CVE-2026-16093 Keycloak-services: keycloak-services: required signed-jwt assertion policy can be bypassed with unsigned assertion headers — Red Hat build of Keycloak 26.6 CWE-807 5.4 Medium 2026-07-17
CVE-2026-16089 Keycloak-services: keycloak-services: authorization codes can be retargeted to another client session — Red Hat build of Keycloak 26.6 CWE-472 5.4 Medium 2026-07-17
CVE-2026-16072 Keycloak-services: keycloak-services: organization invitation link exposure allows unauthorized member creation — Red Hat build of Keycloak 26.6 CWE-497 4.9 Medium 2026-07-17
CVE-2026-15945 Keycloak-services: keycloak-services: group hierarchy search discloses hidden parent groups under fgap v2 — Red Hat build of Keycloak 26.6 CWE-639 4.3 Medium 2026-07-16
CVE-2026-14613 Keycloak-services: keycloak-services: keycloak: fgap v2 role groups endpoint discloses hidden group metadata without group view permission — Red Hat build of Keycloak 26.6 CWE-1220 4.3 Medium 2026-07-03
CVE-2026-11800 Org.keycloak:keycloak-services: keycloak: authentication bypass via jwt algorithm confusion — Red Hat build of Keycloak 26.6 CWE-347 8.1 High 2026-06-25
CVE-2026-11986 Keycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of keycloak — Red Hat build of Keycloak 26.6 CWE-425 4.9 Medium 2026-06-11
CVE-2026-9796 Keycloak: keycloak: privilege escalation via time-of-check to time-of-use (toctou) vulnerability — Red Hat build of Keycloak 26.6 CWE-367 6.5 Medium 2026-05-28

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.