VulnSea

Red Hat has 1,289 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1047 in the last 90 days against 120 in the 90 before. The busiest recent month was September 2026 with 642. The median CVSS is 7.0 (high), with 57 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (97) and CWE-825 (89). Most affected products: Red Hat Enterprise Linux 9 (212), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
—(1)
Last 90 days
1047 prev 120

Products

  • Red Hat Enterprise Linux 9 212
  • Red Hat OpenShift Container Platform 4 95
  • Red Hat Enterprise Linux 10 62
  • Linux 57
  • Red Hat OpenShift AI (RHOAI) 45
  • Red Hat Enterprise Linux BaseOS (v. 10) 36
1289
Total CVEs
57
Critical
1
CISA KEV
1
Exploited

Red Hat vulnerabilities

CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.

1289 CVEsRSS

CVE-2026-77465High· 7.5⚖ disputed
3w ago

toml-node is a TOML parser for Node.js and the browser

toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() uses a Peggy 5.1.0 generated recursive-descent parser in lib/parser.js whose peg$parsevalue, peg$parsearray, and peg$parseinline_table_entry functions r…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.61%via NVD
CVE-2026-53683Medium· 4.3
3w ago

Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html

reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed o…

▾ SunlitRed Hat · ipaEPSS 0.27%via CVEORG
CVE-2026-84377Medium· 6.5
3w ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination the user controls a…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.54%via NVD
CVE-2026-78662Medium· 5.3
3w ago

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding (CVE-2026-78662)

A flaw was found in golang.org/x/crypto/ssh. A malicious remote attacker could flood a channel's incoming requests before it is established, leading to a deadlock of the entire connection. This could result in a denial of service (DoS) for…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.43%via CSAF
CVE-2026-84470Medium· 6.4
3w ago

A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard…

A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard…

▾ SunlitRed Hat · automation-controllerEPSS 0.30%via NVD
CVE-2026-53682Medium· 5.3
3w ago

An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsy…

An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsy…

▾ SunlitRed Hat · pki-coreEPSS 0.21%via NVD
CVE-2026-49329High· 7.5
3w ago

Openshift/oauth-server: openshift/oauth-server: quadratic-time dos via accept-language header underscore bypass on unauthenticated login endpoints

A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcceptLanguage() without input validation. A bypass of the CVE-2022-3…

▾ TwilightRed Hat · openshift4/ose-oauth-server-rhel8EPSS 0.63%via CVEORG
CVE-2026-84639High· 7.5
3w ago

thunderbird: Uninitialized memory in MIME parsing (CVE-2026-84639)

A flaw was found in Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.32%via CSAF
CVE-2026-84332Medium· 5.4
3w ago

chromium-browser: Google Chrome: System access restriction bypass via crafted HTML page (CVE-2026-84332)

A flaw was found in Google Chrome. This incorrect authorization vulnerability in SiteSettings allows a remote attacker to bypass system access restrictions by enticing a user to visit a specially crafted HTML page. This could lead to unaut…

▾ SunlitRed Hat · ChromeEPSS 0.29%via CSAF
CVE-2026-84232Medium· 5.4
3w ago

Pulpcore: python-pulpcore: stored cross-site scripting via inline rendering of uploaded html/svg content

A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for .html files, image/svg+xml for .svg files) and without a Content-D…

▾ SunlitRed Hat · ansible-automation-platform-24/hub-rhel8EPSS 0.24%via CVEORG
CVE-2026-83557Medium· 5.6
3w ago

DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator

DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of "unsafe bas…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.71%via NVD
CVE-2026-84371Medium· 5.4
3w ago

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value…

▾ SunlitRed Hat · Red Hat Satellite 6EPSS 0.30%via NVD
CVE-2026-17615High· 7.5
3w ago

A flaw was found in RESTEasy's SourceProvider

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external …

▾ TwilightRed Hat · keycloak-rhel9-containerEPSS 0.35%via NVD
CVE-2026-82853Medium· 4.9
3w ago

Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands

Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return a…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 1.0%via NVD
CVE-2026-82660Medium· 5.4
3w ago

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content field…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.26%via NVD
CVE-2026-82659High· 7.1
3w ago

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href pr…

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href pr…

▾ TwilightRed Hat · Red Hat Developer HubEPSS 0.35%via NVD
CVE-2024-58379Medium· 5.3
3w ago

nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments

nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicio…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.30%via NVD
CVE-2026-81624High· 7.5
3w ago

Undertow is a flexible performant web server used in JBoss EAP and WildFly

Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot …

▾ TwilightRed Hat · undertow-coreEPSS 0.58%via NVD
CVE-2026-82556Medium· 6.3
4w ago

A vulnerability was found in Forgejo up to 15.0.4

A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration Handler. Performing a manipulation resu…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.37%via NVD
CVE-2026-82562Low· 3.7
4w ago

### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the …

### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.54%via NVD
CVE-2026-82417Medium· 5.3⚖ disputed
4w ago

### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member

### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)`…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.42%via NVD
CVE-2026-82474High· 7.8
4w ago

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.13%via NVD
CVE-2026-37237High· 7.5
1mo ago

vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion

vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.fetch_audio and AsyncMediaIO.fetch_image functions in multimodal/inputs.py fetch user-supplied media URLs using …

▾ TwilightRed Hat · Red Hat AI Inference ServerEPSS 0.75%via NVD
CVE-2025-30156High· 8.9
1mo ago

Ceph is an open-source distributed storage platform providing object, block, and file storage

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol encrypts tickets with AES-128-CBC in an unauthenticated mode that us…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.09%via NVD
CVE-2026-37236Critical· 9.8⚖ disputed
1mo ago

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-ww…

▾ MidnightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.43%via NVD
CVE-2026-56854Medium· 6.8
1mo ago

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions (CVE-2026-56854)

A flaw was found in golang.org/x/crypto/ssh. The component failed to properly enforce source-address restrictions for several authentication methods, including password and keyboard-interactive callbacks. In applications that misuse the Se…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.44%via CSAF
CVE-2026-80179Medium· 5.9PoC
1mo ago

Jwcrypto: jwcrypto: denial of service via malformed jwe tokens

A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memor…

▾ TwilightRed Hat · ansible-automation-platform-24/controller-rhel8EPSS 0.41%via CVEORG
CVE-2026-80212High· 7.5
1mo ago

An issue was discovered in the resolv gem before 0.7.2 for Ruby

An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::Resource.get_class, Resolv::DNS::Resource::Generic.create, and Resolv::DNS::SvcParam::Generic.create generate a new class for each unknown DNS resource record …

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.57%via NVD
CVE-2026-5680High· 7.5
1mo ago

A flaw was found in Undertow

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDef…

▾ TwilightRed Hat · undertow-coreEPSS 1.1%via NVD
CVE-2026-81725Medium· 5.9
1mo ago

nltk: NLTK: Regular Expression Denial of Service via malformed TEI blocks (CVE-2026-81725)

A flaw was found in NLTK, specifically within the Pl196xCorpusReader component. A remote attacker can exploit this by supplying malformed Text Encoding Initiative (TEI) blocks containing numerous unmatched opening tags. This triggers a reg…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.37%via CSAF
Red Hat vulnerabilities (CVEs) — page 22 · VulnSea