VulnSea

Red Hat has 1,289 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1042 in the last 90 days against 125 in the 90 before. The busiest recent month was September 2026 with 642. The median CVSS is 7.0 (high), with 57 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (97) and CWE-825 (89). Most affected products: Red Hat Enterprise Linux 9 (212), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
—(1)
Last 90 days
1042 prev 125

Products

  • Red Hat Enterprise Linux 9 212
  • Red Hat OpenShift Container Platform 4 95
  • Red Hat Enterprise Linux 10 62
  • Linux 57
  • Red Hat OpenShift AI (RHOAI) 45
  • Red Hat Enterprise Linux BaseOS (v. 10) 36
1289
Total CVEs
57
Critical
1
CISA KEV
1
Exploited

Red Hat vulnerabilities

CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.

1289 CVEsRSS

CVE-2026-76218High· 7.5
1mo ago

gitpython: GitPython: Remote Code Execution via malicious Git hooks (CVE-2026-76218)

A flaw was found in GitPython. This vulnerability allows a remote attacker to achieve arbitrary code execution. By supplying a specially crafted template parameter to the `Repo.init` function, an attacker can point to a directory containin…

▾ TwilightRed Hat · Red Hat Satellite 6.19 for RHEL 9EPSS 0.83%via CSAF
CVE-2026-76219High· 8.1
1mo ago

gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection (CVE-2026-76219)

A flaw was found in GitPython. This vulnerability allows an attacker to overwrite arbitrary files on the system. By injecting specific options into the `git read-tree` command through methods like `IndexFile.from_tree`, `IndexFile.reset`, …

▾ TwilightRed Hat · Red Hat Satellite 6.19 for RHEL 9EPSS 0.54%via CSAF
CVE-2026-75838Medium· 6.1
1mo ago

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that ex…

▾ SunlitRed Hat · Red Hat Ceph Storage 9EPSS 0.30%via NVD
CVE-2026-66780Medium· 6.5
1mo ago

A flaw was found in the submariner-operator component

A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, sp…

▾ SunlitRed Hat · rhacm2/submariner-addon-rhel9EPSS 0.56%via NVD
CVE-2026-12564Critical· 9.6
1mo ago

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-c…

▾ MidnightRed Hat · automation-controllerEPSS 0.35%via NVD
CVE-2026-50161Critical· 9.8
1mo ago

libre is a generic library for real-time communications with asynchronous input and output support

libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4.8.1, the websock_decode() function in src/websock/websock.c contains an integer overflow when validating a masked WebSocket fr…

▾ MidnightRed HatEPSS 0.52%via NVD
CVE-2026-73073High· 7.3
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficiently escaped typeref: or typename: value from a tags file,…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.20%via NVD
CVE-2026-73426Medium· 4.6
1mo ago

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can …

▾ SunlitRed HatEPSS 0.32%via NVD
CVE-2026-50187High· 8.8
1mo ago

Oh My Zsh is a community-driven framework for managing Zsh configuration

Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to source after a directory change into a folder containing a .en…

▾ TwilightRed Hat · Red Hat Ansible Automation Platform 2EPSS 0.54%via NVD
CVE-2026-18963Critical· 9.1PoC
1mo ago

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the passwo…

▾ AbyssalRed Hat · rhbk/keycloak-operator-bundleEPSS 3.2%via NVD
CVE-2026-75485Medium· 5.5
1mo ago

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This e…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.11EPSS 0.19%via NVD
CVE-2026-73834Medium· 5.5
1mo ago

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, cre…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.11EPSS 0.11%via NVD
CVE-2026-16732Medium· 6.1
1mo ago

fastify: fastify: Request spoofing via numeric trustProxy configuration (CVE-2026-16732)

A flaw was found in fastify. When configured with a numeric `trustProxy` value, an attacker who can directly access the Fastify origin, bypassing the front-facing proxy, can spoof forwarded request fields. This vulnerability allows for hos…

▾ SunlitRed Hat · Red Hat OpenShift Dev SpacesEPSS 0.16%via CSAF
CVE-2026-70906High· 7.5
1mo ago

Vulnerability in Oracle Java SE (component: 2D)

Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 25.0.4 and 26.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to…

▾ TwilightRed Hat · Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)EPSS 0.46%via NVD
CVE-2026-74960High· 8.1⚖ disputed
1mo ago

Site isolation issue in the WebExtensions component

Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.22%via NVD
CVE-2026-74959Critical· 9.1⚖ disputed
1mo ago

Mitigation bypass in the Storage: Cache API component

Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

▾ MidnightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.48%via NVD
CVE-2026-74957High· 8.1⚖ disputed
1mo ago

Mitigation bypass in the Safe Browsing component

Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.43%via NVD
CVE-2026-74948Medium· 6.5
1mo ago

Information disclosure in the Graphics component

Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.44%via NVD
CVE-2026-74945Medium· 6.5PoC
1mo ago

Information disclosure in the Graphics: Text component

Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.44%via NVD
CVE-2026-74934High· 7.5
1mo ago

Site isolation issue in the Graphics: CanvasWebGL component

Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.21%via NVD
CVE-2026-17106High· 7.8PoC
1mo ago

github.com/moby/go-archive: moby/go-archive: Arbitrary file write via link following in tar extraction (CVE-2026-17106)

A flaw was found in moby/go-archive. The tar extraction routines in the component do not properly restrict filesystem operations to the intended destination directory. An attacker who controls the contents of an archive can exploit this by…

▾ MidnightRed Hat · Red Hat Edge Manager 1.2EPSS 0.44%via CSAF
CVE-2026-73502Medium· 5.3
1mo ago

kin-openapi is a Go project for handling OpenAPI files

kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.ValidateRequest can encounter a NULL-pointer-dereference denial of service when an operation declares a content parameter whose application/…

▾ SunlitRed Hat · Red Hat Edge Manager 1EPSS 0.51%via NVD
CVE-2026-66792Critical· 9.9
1mo ago

A flaw was found in the multicloud-operators-subscription component

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitatio…

▾ MidnightRed Hat · multicluster-globalhub/multicluster-globalhub-agent-rhel9EPSS 0.69%via NVD
CVE-2026-73646High· 7.5
1mo ago

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL values to joi…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.53%via NVD
CVE-2026-19693High· 8.1
1mo ago

extract-zip: extract-zip: Arbitrary file write via symlink in archive (CVE-2026-19693)

A flaw was found in extract-zip. This vulnerability allows a remote attacker to perform an arbitrary file write outside the intended destination directory. By crafting a malicious zip archive containing a symbolic link (symlink) and a regu…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.28%via CSAF
CVE-2026-66795Critical· 9.9
1mo ago

A flaw was found in the managedcluster-import-controller

A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. …

▾ MidnightRed Hat · multicluster-engine/managedcluster-import-controller-rhel9EPSS 0.49%via NVD
CVE-2026-64849High· 8.5CISA KEVPoC
1mo ago

mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS …

A flaw was found in MLflow. An unauthenticated remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability by sending a specially crafted request to the webhook test endpoint. This occurs because the system validates onl…

▾ AbyssalRed Hat · Red Hat OpenShift AI 3.4EPSS 9.8%via CSAF
CVE-2026-71491High· 7.5
1mo ago

sqlparse is a non-validating SQL parser module for Python

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only statements before the MAX_GROUPING_TOKENS guard, causing quadratic CPU consumption t…

▾ TwilightRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.26%via NVD
CVE-2026-72045High· 8.8
1mo ago

In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF rvu_mbox_handler_lmtst_tbl_setup() uses req->base_pcifunc as a direct index into the LMT map table to re…

In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF rvu_mbox_handler_lmtst_tbl_setup() uses req->base_pcifunc as a direct index into the LMT map table to re…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 9)EPSS 0.17%via NVD
CVE-2026-18165Medium· 4.2
1mo ago

@fastify/oauth2 is an OAuth 2.0 plugin for Fastify

@fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8.3.0, the plugin validates the OAuth state, and with PKCE the code verifier, by comparing the callback query parameter against an unprefi…

▾ SunlitRed Hat · Red Hat OpenShift Dev SpacesEPSS 0.10%via NVD
Red Hat vulnerabilities (CVEs) — page 26 · VulnSea