VulnSea

Red Hat has 1,289 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1047 in the last 90 days against 120 in the 90 before. The busiest recent month was September 2026 with 642. The median CVSS is 7.0 (high), with 57 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (97) and CWE-825 (89). Most affected products: Red Hat Enterprise Linux 9 (212), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
—(1)
Last 90 days
1047 prev 120

Products

  • Red Hat Enterprise Linux 9 212
  • Red Hat OpenShift Container Platform 4 95
  • Red Hat Enterprise Linux 10 62
  • Linux 57
  • Red Hat OpenShift AI (RHOAI) 45
  • Red Hat Enterprise Linux BaseOS (v. 10) 36
1289
Total CVEs
57
Critical
1
CISA KEV
1
Exploited

Red Hat vulnerabilities

CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.

1289 CVEsRSS

CVE-2026-19872Medium· 6.1
2w ago

HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message. The wrappers and renderers that emit a form's errors interpolate the error string straight into…

HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message. The wrappers and renderers that emit a form's errors interpolate the error string straight into…

▾ SunlitRed Hat · HTML-FormHandlerEPSS 0.26%via NVD
CVE-2026-80219High· 8.7
2w ago

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

▾ TwilightRed Hat · rhbac-4/hawtio-operator-bundleEPSS 0.23%via NVD
CVE-2026-78234Critical· 9.9
2w ago

A flaw was found in hawtio-operator

A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author o…

▾ MidnightRed Hat · rhbac-4/hawtio-gateway-rhel9EPSS 0.39%via NVD
CVE-2026-77968High· 8.2
2w ago

A flaw was found in hawtio-operator

A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the Ser…

▾ TwilightRed Hat · rhbac-4/hawtio-operator-bundleEPSS 0.42%via NVD
CVE-2026-74860High· 8.5
2w ago

A flaw was found in libxml2 with Python bindings enabled

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This…

▾ TwilightRed Hat · libxml2EPSS 0.38%via NVD
CVE-2026-74859Medium· 6.8
2w ago

The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths

The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files outside ~/.themes by using ../ path traversal, absolute paths, or…

▾ SunlitRed Hat · gnome-tweaksEPSS 0.17%via NVD
CVE-2026-76561High· 7.2
2w ago

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Admi…

▾ TwilightRed Hat · pki-coreEPSS 0.58%via NVD
CVE-2026-86404High· 8.8
2w ago

EAP's Artemis deserialization configuration permits deserialization by default

EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() met…

▾ TwilightRed Hat · eap7-activemq-artemisEPSS 0.85%via NVD
CVE-2026-86332Medium· 6.5
2w ago

A flaw was found in odh-dashboard in Red Hat OpenShift AI

A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data,…

▾ SunlitRed Hat · rhoai/odh-core-bff-rhel9EPSS 0.35%via NVD
CVE-2026-18355High· 7.5
2w ago

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base)

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, …

▾ TwilightRed Hat · redhat-ds:11EPSS 0.84%via NVD
CVE-2026-16028High· 7.5
2w ago

Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table. When a stream reaches the CLOSED state, stream_state returns the concurrency slot…

Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table. When a stream reaches the CLOSED state, stream_state returns the concurrency slot…

▾ TwilightRed Hat · Protocol-HTTP2EPSS 0.36%via NVD
CVE-2026-86469Medium· 5.3PoC
2w ago

A flaw was found in GLib2

A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation …

▾ TwilightRed Hat · glib2EPSS 0.14%via NVD
CVE-2026-76560High· 7.5
2w ago

A flaw was found in 389 Directory Server

A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access contr…

▾ TwilightRed Hat · redhat-ds:11EPSS 0.64%via NVD
CVE-2026-19843High· 8.4PoC
2w ago

A flaw was found in 389-ds-base

A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated…

▾ MidnightRed Hat · redhat-ds:11EPSS 0.48%via NVD
CVE-2026-18922Critical· 9.8
2w ago

A flaw was found in 389 Directory Server

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated s…

▾ MidnightRed Hat · redhat-ds:11EPSS 0.56%via NVD
CVE-2026-18453High· 7.5
2w ago

A flaw was found in 389 Directory Server

A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests …

▾ TwilightRed Hat · redhat-ds:11EPSS 0.85%via NVD
CVE-2026-79678High· 8.1
2w ago

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated…

▾ TwilightRed Hat · ipaEPSS 0.66%via NVD
CVE-2026-76578Critical· 9.8PoC
2w ago

A flaw was found in FreeIPA

A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a r…

▾ AbyssalRed Hat · ipaEPSS 0.96%via NVD
CVE-2026-86289Medium· 4.3PoC
2w ago

A vulnerability was found in Ollama up to 0.31.1

A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing a manipulation results in integer overflow. The attack is possible t…

▾ TwilightRed Hat · OllamaEPSS 0.69%via NVD
CVE-2026-86250High· 7.5
3w ago

h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions

h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted cookie header with an extremely large chunk…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.49%via NVD
CVE-2026-85769Medium· 6.5PoC
3w ago

A flaw was found in libtpms, a library that provides software TPM 2.0 emulation

A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migration restore), a malformed state blob can supply an oversized sk…

▾ TwilightRed Hat · libtpmsEPSS 0.42%via NVD
CVE-2026-85197High· 7.6PoC
3w ago

A flaw was found in libsoup

A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using …

▾ MidnightRed Hat · libsoup3EPSS 0.27%via NVD
CVE-2026-81665High· 7.5
3w ago

A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly

A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds.…

▾ TwilightRed Hat · corosyncEPSS 0.35%via NVD
CVE-2026-76925Medium· 5.8
3w ago

A flaw was found in Flatpak

A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occurs because a privileged `chmod` operation executes before the OSTr…

▾ SunlitRed Hat · flatpakEPSS 0.10%via NVD
CVE-2026-85781High· 8.7
3w ago

Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion…

Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.44%via NVD
CVE-2026-81666Medium· 6.5
3w ago

An integer overflow was found in Corosync's handling of membership commit token messages

An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems due to an integer overflow in the calculation of the expected mess…

▾ SunlitRed Hat · corosyncEPSS 0.19%via NVD
CVE-2026-85150High· 7.5
3w ago

A NULL pointer dereference flaw was found in GStreamer's RTSP support library

A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement aro…

▾ TwilightRed Hat · gstreamer1-plugins-baseEPSS 0.53%via NVD
CVE-2026-85180High· 7.5
3w ago

Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts

Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An attacker can control a registry, serve a malicious tensor-layer manifes…

▾ TwilightRed Hat · ollamaEPSS 0.50%via NVD
CVE-2026-85458Medium· 4.7
3w ago

Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height.

Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height.

▾ SunlitRed HatEPSS 0.14%via NVD
CVE-2026-63376High· 8.2⚖ disputed
3w ago

toml-node is a TOML parser for Node.js and the browser

toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Ob…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.68%via NVD
Red Hat vulnerabilities (CVEs) — page 21 · VulnSea