Red Hat has 1,289 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1047 in the last 90 days against 120 in the 90 before. The busiest recent month was September 2026 with 642. The median CVSS is 7.0 (high), with 57 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (97) and CWE-825 (89). Most affected products: Red Hat Enterprise Linux 9 (212), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.0
- Publish → KEV
- —(1)
- Last 90 days
- 1047 prev 120
Weakness classes
Products
- Red Hat Enterprise Linux 9 212
- Red Hat OpenShift Container Platform 4 95
- Red Hat Enterprise Linux 10 62
- Linux 57
- Red Hat OpenShift AI (RHOAI) 45
- Red Hat Enterprise Linux BaseOS (v. 10) 36
Worst active — by depth score
CVE-2026-64849High· 8.5mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS …74CVE-2025-68664Critical· 9.3langchain-core: LangChain: Arbitrary code execution via serialization injection (CVE-2025-68664)72CVE-2026-40453Critical· 9.9The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'67CVE-2026-76578Critical· 9.8A flaw was found in FreeIPA66CVE-2026-64564Critical· 9.8In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport …66
Red Hat vulnerabilities
CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.
1289 CVEsRSS
CVE-2026-81724High· 7.5⚖ disputednltk: NLTK: Denial of Service via Uncontrolled Recursion (CVE-2026-81724)
A flaw was found in NLTK. This uncontrolled recursion vulnerability in `nltk.featstruct.FeatStructReader` allows unauthenticated attackers to cause a denial of service. Attackers can achieve this by supplying deeply nested feature-structur…
CVE-2026-81726High· 8.7nltk: NLTK: Unauthorized file access via path traversal in model-artifact APIs (CVE-2026-81726)
A flaw was found in NLTK. This vulnerability, known as path traversal, allows an attacker to bypass security restrictions in the model-artifact APIs. By exploiting this, an attacker can perform unauthorized read or write operations on file…
CVE-2026-81727High· 7.1nltk: NLTK: Filesystem containment bypass allows local file overwrite (CVE-2026-81727)
A flaw was found in NLTK. This vulnerability, a filesystem containment bypass, allows a local attacker with write access to a shared downloader directory to create special links (hardlinks) that point to files outside the intended installa…
CVE-2026-81722High· 7.5nltk: nltk PorterStemmer: Denial of Service due to inefficient token processing (CVE-2026-81722)
A flaw was found in the nltk PorterStemmer component. A remote attacker could exploit this vulnerability by providing a specially crafted, untrusted token. The inefficient algorithmic complexity in the stemming process, specifically within…
CVE-2026-78002High· 7.5A flaw was found in rsyslog
A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer …
CVE-2026-59317Medium· 6.5DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passes its raw bytes directly to new BigInteger(header.value()) with no length or format validation. Spring for Apach…
DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passes its raw bytes directly to new BigInteger(header.value()) with no length or format validation. Spring for Apach…
CVE-2026-59313Critical· 9.8⚖ disputedSpring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Fra…
Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Fra…
CVE-2026-59303Low· 3.1Dynamic destination cache size is not properly bound in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6
Dynamic destination cache size is not properly bound in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6
CVE-2026-80205High· 7.5nltk: NLTK: Denial of Service via unvalidated regular expressions (CVE-2026-80205)
A flaw was found in NLTK. A remote attacker can exploit a regular expression denial of service (ReDoS) vulnerability in the `Text.findall()` and `TokenSearcher.findall()` methods. These methods accept user-supplied regular expressions with…
CVE-2026-79654Medium· 4.3A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user
A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization m…
CVE-2026-79992High· 7.8Emacs: emacs: command injection via crafted filenames in tramp
A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to …
CVE-2026-79049High· 7.1⚖ disputedchromium-browser: chromium-browser: Incorrect reference resolution in Passwords (CVE-2026-79049)
An incorrect reference resolution flaw was found in the Passwords component of the Chromium browser. Upstream bug(s): https://code.google.com/p/chromium/issues/detail?id=513786555
CVE-2026-79050Medium· 5.4chromium-browser: Google Chrome: System access restriction bypass via crafted HTML page (CVE-2026-79050)
A flaw was found in Google Chrome's Network component. This incorrect authorization vulnerability allows a remote attacker to bypass system access restrictions. The attacker can achieve this by enticing a user to open a specially crafted H…
CVE-2026-79006Medium· 4.3chromium-browser: Google Chrome: Web origin policy bypass via crafted network traffic (CVE-2026-79006)
A flaw was found in Google Chrome. This vulnerability, located in the HttpsUpgrades component, allows a remote attacker to bypass the web origin policy. By sending specially crafted network traffic, an attacker could circumvent security re…
CVE-2026-79136Medium· 5.4chromium-browser: Chromium: Web origin policy bypass via incorrect ServiceWorker authorization (CVE-2026-79136)
A flaw was found in Chromium. This incorrect authorization vulnerability in the ServiceWorker component allows a remote attacker to bypass the web origin policy. By crafting a malicious HTML page, an attacker can circumvent security restri…
CVE-2026-79143Medium· 4.3chromium-browser: Google Chrome FileSystem: System access bypass through crafted HTML and social engineering (CVE-2026-79143)
A flaw was found in Google Chrome's FileSystem component. This incorrect authorization vulnerability allows a remote attacker to bypass system access restrictions. By leveraging social engineering techniques with a specially crafted HTML p…
CVE-2026-79199Medium· 4.3chromium-browser: Chromium-browser: System access restriction bypass via crafted HTML page (CVE-2026-79199)
A flaw was found in chromium-browser. This incorrect authorization vulnerability allows a remote attacker to bypass system access restrictions. By crafting a malicious HTML page, an attacker can gain unauthorized access within the network …
CVE-2026-79151Medium· 6.5⚖ disputedchromium-browser: Chromium-browser Safebrowsing: Bypass system access restrictions via improper input validation. (CVE-2026-79151)
A flaw was found in Chromium-browser's Safebrowsing component. A remote attacker could exploit this vulnerability by providing a specially crafted file. This could allow the attacker to bypass system access restrictions.
CVE-2026-79251Medium· 6.5⚖ disputedchromium-browser: Google Chrome: Web origin policy bypass via improper input validation (CVE-2026-79251)
A flaw was found in Google Chrome. Improper input validation in the Network component allows a remote attacker to potentially bypass the web origin policy. This can be achieved by enticing a user to visit a specially crafted HTML page. The…
CVE-2026-79020Medium· 4.3⚖ disputedchromium-browser: skia: chromium-browser: skia: Out of bounds read in Skia (CVE-2026-79020)
An out of bounds read flaw was found in the Skia component of the Chromium browser. Upstream bug(s): https://code.google.com/p/chromium/issues/detail?id=514017820
CVE-2026-79099Medium· 6.5chromium-browser: Google Chrome: System access restriction bypass via crafted HTML page (CVE-2026-79099)
A flaw was found in Google Chrome's Network component. A remote attacker could exploit this vulnerability by enticing a user to visit a specially crafted HTML page. This could allow the attacker to bypass system access restrictions, leadin…
CVE-2026-79173Medium· 4.3chromium-browser: Chromium-browser: UI spoofing via crafted HTML page (CVE-2026-79173)
A flaw was found in chromium-browser. A remote attacker could exploit this vulnerability by crafting a malicious HTML page, leading to user interface (UI) misrepresentation. This misrepresentation allows the attacker to spoof UI elements, …
CVE-2026-79191High· 7.6⚖ disputedchromium-browser: chromium-browser: Incorrect authorization in SiteIsolation (CVE-2026-79191)
An incorrect authorization flaw was found in the SiteIsolation component of the Chromium browser. Upstream bug(s): https://code.google.com/p/chromium/issues/detail?id=517606780
CVE-2026-79229Medium· 6.8chromium-browser: angle: Chromium: Information disclosure via uninitialized resource in ANGLE (CVE-2026-79229)
A flaw was found in ANGLE, a component within Chromium. This uninitialized resource vulnerability could allow a remote attacker, who has already compromised the renderer process, to read sensitive memory outside of the security sandbox. Th…
CVE-2026-79221Medium· 6.5chromium-browser: chromium-browser: Uninitialized resource in Dawn (CVE-2026-79221)
An uninitialized resource flaw was found in the Dawn component of the Chromium browser. Upstream bug(s): https://code.google.com/p/chromium/issues/detail?id=532923954
CVE-2026-79270High· 7.4chromium-browser: angle: Chromium-browser: Memory disclosure via uninitialized resource in ANGLE (CVE-2026-79270)
A flaw was found in chromium-browser. A remote attacker could exploit an uninitialized resource vulnerability in ANGLE by crafting a malicious HTML page. This could allow the attacker to read sensitive memory outside of the browser's secur…
CVE-2026-79042Medium· 5.4chromium-browser: Google Chrome: Missing authorization in Payments allows system access restriction bypass (CVE-2026-79042)
A flaw was found in Google Chrome on Android. Missing authorization in the Payments functionality allows a remote attacker, leveraging social engineering, to potentially bypass system access restrictions. This can be achieved by enticing a…
CVE-2026-79652Medium· 5.9A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak
A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access token…
CVE-2026-68515High· 7.1OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, exrmultiview can write past a heap…
CVE-2026-65979Medium· 5.5OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.12, the HTJ2K decoder parses a header-length field (PLEN) from a chunk's compr…