VulnSea

Red Hat has 1,289 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1042 in the last 90 days against 125 in the 90 before. The busiest recent month was September 2026 with 642. The median CVSS is 7.0 (high), with 57 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (97) and CWE-825 (89). Most affected products: Red Hat Enterprise Linux 9 (212), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
—(1)
Last 90 days
1042 prev 125

Products

  • Red Hat Enterprise Linux 9 212
  • Red Hat OpenShift Container Platform 4 95
  • Red Hat Enterprise Linux 10 62
  • Linux 57
  • Red Hat OpenShift AI (RHOAI) 45
  • Red Hat Enterprise Linux BaseOS (v. 10) 36
1289
Total CVEs
57
Critical
1
CISA KEV
1
Exploited

Red Hat vulnerabilities

CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.

1289 CVEsRSS

CVE-2026-63343Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file o…

▾ MidnightRed HatEPSS 0.48%via NVD
CVE-2026-54789High· 7.5
1mo ago

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream E4S (v.8.8)EPSS 0.72%via NVD
CVE-2026-73267High· 7.7
1mo ago

A flaw was found in the clusterclaims-controller component of multicluster engine (MCE)

A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This all…

▾ TwilightRed Hat · multicluster-engine/clusterclaims-controller-rhel9EPSS 0.63%via NVD
CVE-2026-76905High· 7.5⚖ disputed
1mo ago

kin-openapi is a Go project for handling OpenAPI files

kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_error_encoder.go dereferences e.Parameter.In without checking whether e.Parameter is nil. A …

▾ TwilightRed Hat · Red Hat Edge Manager 1EPSS 0.61%via NVD
CVE-2026-48050High· 8.2
1mo ago

Arc is an open, SQL-native time-series database for telemetry

Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof` handlers at `/debug/pprof/*` via `app.Use(pprof.New())` in `internal/api/server.go`, and `/debug/pprof` is added to `…

▾ TwilightRed Hat · Red Hat Edge Manager 1EPSS 0.64%via NVD
CVE-2026-76641High· 7.5
1mo ago

Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate

Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.61%via NVD
CVE-2026-75140High· 7.5
1mo ago

jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-…

jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.53%via NVD
CVE-2026-19611High· 7.4
1mo ago

A flaw was found in WildFly Elytron

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using a…

▾ TwilightRed Hat · wildfly-elytron-password-implEPSS 0.56%via NVD
CVE-2026-55765High· 8.5
1mo ago

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by Set…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4EPSS 0.50%via NVD
CVE-2026-64846Low· 2.8
1mo ago

Nix is a package manager for Linux and other Unix systems

Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit a time-of-check/time-of-use race involving final symlink handling in the …

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.11%via NVD
CVE-2026-18917High· 7.8
1mo ago

A flaw was found in libvirt

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. …

▾ TwilightRed Hat · libvirtEPSS 0.18%via NVD
CVE-2026-73253Critical· 9.1
1mo ago

Mongoose is an embedded web server and network library

Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in TLS stack. The mg…

▾ MidnightRed HatEPSS 0.35%via NVD
CVE-2026-63385High· 7.7
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into literal NUL characters, which can cause dow…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 8)EPSS 0.55%via NVD
CVE-2026-63384High· 7.5
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode an attacker-controlled uint32 payload…

▾ TwilightRed Hat · Red Hat Enterprise Linux 6EPSS 0.52%via NVD
CVE-2026-63381Medium· 6.6
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains fre…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.16%via NVD
CVE-2026-63380Medium· 4.7
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters its error path after evhttp_start_ws_ succeeds but bufferevent_enable_locking_ fails. ev…

▾ SunlitRed Hat · Red Hat Enterprise Linux 6EPSS 0.14%via NVD
CVE-2026-54770Medium· 6.1
1mo ago

WebOb provides objects for HTTP requests and responses

WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips le…

▾ SunlitRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.38%via NVD
CVE-2026-49825High· 8.2
1mo ago

lxml is a library for processing XML and HTML in the Python language

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. cont…

▾ TwilightRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.43%via NVD
CVE-2026-55193High· 8.8
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c without bounding it to the 4088-byte …

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.47%via NVD
CVE-2026-76232Medium· 6.7
1mo ago

Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the repository parameter is appended to helm registry login commands without proper sanitization

Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the repository parameter is appended to helm registry login commands without proper sanitization. Attackers with reposito…

▾ SunlitRed HatEPSS 1.0%via NVD
CVE-2026-76230Medium· 6.7
1mo ago

Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-provided packageName values are appended to npm install commands without proper sanitization

Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-provided packageName values are appended to npm install commands without proper sanitization. Attackers with repository…

▾ SunlitRed HatEPSS 1.0%via NVD
CVE-2026-76227Medium· 5.5
1mo ago

Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict enviro…

Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict enviro…

▾ SunlitRed HatEPSS 0.15%via NVD
CVE-2026-75569High· 7.7
1mo ago

A flaw was found in mce-operator-bundle

A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with wr…

▾ TwilightRed Hat · multicluster-engine/mce-operator-bundleEPSS 0.60%via NVD
CVE-2026-76827Medium· 6.8
1mo ago

A flaw was found in search-indexer

A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-in…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.11EPSS 0.53%via NVD
CVE-2026-76139High· 8.0
1mo ago

A flaw was found in acm-operator-bundle

A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as Gi…

▾ TwilightRed Hat · rhacm2/acm-operator-bundleEPSS 0.72%via NVD
CVE-2026-66794Critical· 9.3
1mo ago

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks…

▾ MidnightRed Hat · multicluster-engine/cluster-proxy-addon-rhel9EPSS 0.62%via NVD
CVE-2026-18874Medium· 6.2
1mo ago

A flaw was found in volsync-addon-controller

A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This is due to improper esc…

▾ SunlitRed Hat · rhacm2/acm-volsync-addon-controller-rhel9EPSS 0.54%via NVD
CVE-2026-76220High· 8.8
1mo ago

gitpython: GitPython: Arbitrary command execution via crafted kwargs (CVE-2026-76220)

A flaw was found in GitPython. A remote attacker can bypass the `check_unsafe_options` guard by combining a single-character keyword argument with `split_single_char_options=False`. This allows the attacker to supply a crafted dictionary o…

▾ TwilightRed Hat · Red Hat Satellite 6.19 for RHEL 9EPSS 0.91%via CSAF
CVE-2026-76221High· 8.8
1mo ago

gitpython: GitPython: Arbitrary code execution via config-name injection (CVE-2026-76221)

A flaw was found in GitPython. This vulnerability allows attackers to inject malicious configuration options by manipulating option names within the option-name validator. By injecting special characters, an attacker can forge arbitrary gi…

▾ TwilightRed Hat · Red Hat Satellite 6.19 for RHEL 9EPSS 0.77%via CSAF
CVE-2026-76222High· 8.2
1mo ago

gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names (CVE-2026-76222)

A flaw was found in GitPython where it fails to properly validate submodule names within .gitmodules files. A remote attacker could craft a malicious Git repository containing specially formed submodule names with directory traversal seque…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.42%via CSAF
Red Hat vulnerabilities (CVEs) — page 25 · VulnSea