Red Hat 厂商相关 1440 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。
Red Hat 主要提供企业级 Linux 操作系统及中间件解决方案,其开源生态广泛支撑全球关键业务。历史漏洞多集中于远程代码执行、权限提升及信息泄露,部分源于底层组件集成缺陷。值得关注的是,其通过 Red Hat Security Response 团队提供长期安全支持,并集成 SELinux 强制访问控制机制以增强系统隔离性。尽管漏洞数量较多,但官方响应迅速,持续推动补丁更新以保障企业环境稳定性。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-84724 | Automation-controller systemjob额外参数注入控制平面 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-88 | 6.6 | Medium | 2026-09-23 |
| CVE-2026-84720 | Automation Controller 祖先工件缺少防止搜索,通过ORM遍历暴露no_log设置的统计信息 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-639 | 6.5 | Medium | 2026-09-23 |
| CVE-2026-84718 | Automation-controller IP欺骗致日志伪造漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-348 | 4.3 | Medium | 2026-09-23 |
| CVE-2026-84717 | Automation Controller Bitbucket数据中台Webhook接收器未授权枚举漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-204 | 5.3 | Medium | 2026-09-23 |
| CVE-2026-84716 | Automation-controller 证书颁发漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-266 | 6.6 | Medium | 2026-09-23 |
| CVE-2026-84712 | Automation-controller 未授权 API 漏洞暴露实例拓扑与成员信息 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-497 | 5.3 | Medium | 2026-09-23 |
| CVE-2026-84714 | Automation Controller Jinja模板注入漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-184 | 7.1 | High | 2026-09-23 |
| CVE-2026-84706 | Ansible Automation Controller 凭据类型环境变量注入器绕过漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-184 | 7.6 | High | 2026-09-23 |
| CVE-2026-84691 | Automation-controller 格式化字符串注入漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-134 | 8.7 | High | 2026-09-23 |
| CVE-2026-84683 | Automation-controller 存储型 XSS 漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-79 | 8.7 | High | 2026-09-23 |
| CVE-2026-84499 | 自动化控制器明文泄露密码漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-209 | 7.7 | High | 2026-09-23 |
| CVE-2026-71465 | Ansible Automation Controller 命令行参数注入漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-88 | 3.1 | Low | 2026-09-23 |
| CVE-2026-71464 | 自动化控制器 Git参数前导破折号防护绕过漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-88 | 3.1 | Low | 2026-09-23 |
| CVE-2026-71463 | Automation-controller Jinja模板白名单绕过 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-209 | 2.7 | Low | 2026-09-23 |
| CVE-2026-71462 | Automation-controller 容器自定义路径存在性漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-204 | 4.1 | Medium | 2026-09-23 |
| CVE-2026-71460 | Red Hat 自动化控制器认证用户读取订阅详情漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-862 | 4.3 | Medium | 2026-09-23 |
| CVE-2026-71459 | Automation-controller 跨租户作业事件树 RBAC 绕过漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-862 | 5.0 | Medium | 2026-09-23 |
| CVE-2026-71458 | Automation Controller named-url租户资源枚举漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-204 | 5.0 | Medium | 2026-09-23 |
| CVE-2026-84470 | Red Hat Ansible Automation Platform 授权问题漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-862 | 6.4 | Medium | 2026-09-01 |
| CVE-2026-71366 | Ansible AWX 服务端请求伪造漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-918 | 7.7 | High | 2026-08-24 |
| CVE-2026-71364 | Ansible AWX 路径遍历漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-22 | 7.2 | High | 2026-08-24 |
| CVE-2026-71365 | Ansible AWX 服务端请求伪造漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-918 | 7.7 | High | 2026-08-18 |
| CVE-2026-12383 | Eda-server subject header未验证泄露 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-345 | 7.5 | High | 2026-07-27 |
| CVE-2026-12701 | Pulp Project Pulp 路径遍历漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-22 | 9.0 | Critical | 2026-07-20 |
| CVE-2026-12382 | Red Hat Ansible Automation Platform 授权问题漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-290 | 8.2 | High | 2026-07-15 |
| CVE-2026-11807 | Red Hat Ansible Automation Platform 授权问题漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-862 | 9.6 | Critical | 2026-06-23 |
| CVE-2026-52902 | awxkit 路径遍历漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-22 | 4.7 | Medium | 2026-06-09 |
| CVE-2026-11332 | Ansible 参数注入漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-88 | 7.8 | High | 2026-06-05 |
| CVE-2025-9909 | Red Hat Ansible Automation Platform 安全漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-647 | 6.7 | Medium | 2026-02-27 |
| CVE-2025-9908 | Red Hat Ansible Automation Platform 安全漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-200 | 6.7 | Medium | 2026-02-27 |
本页汇总了 Red Hat 厂商截至目前公开的全部 1440 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。