VulnSea

Red Hat has 1,283 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1041 in the last 90 days against 120 in the 90 before. The busiest recent month was September 2026 with 636. The median CVSS is 7.0 (high), with 58 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (97) and CWE-825 (89). Most affected products: Red Hat Enterprise Linux 9 (212), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
—(1)
Last 90 days
1041 prev 120

Products

  • Red Hat Enterprise Linux 9 212
  • Red Hat OpenShift Container Platform 4 95
  • Red Hat Enterprise Linux 10 62
  • Linux 57
  • Red Hat OpenShift AI (RHOAI) 45
  • Red Hat Enterprise Linux BaseOS (v. 10) 36
1283
Total CVEs
58
Critical
1
CISA KEV
1
Exploited

Red Hat vulnerabilities

CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.

1283 CVEsRSS

CVE-2026-88837Medium· 6.5
4d ago

BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.

BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.

▾ SunlitRed Hat · busybox-mainEPSS 0.27%via NVD
CVE-2026-88835Medium· 6.1
4d ago

BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.

BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.

▾ SunlitRed Hat · busybox-mainEPSS 0.12%via NVD
CVE-2026-88831Medium· 5.3
4d ago

BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.

BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.

▾ SunlitRed Hat · busybox-mainEPSS 0.24%via NVD
CVE-2026-88832High· 7.3
4d ago

BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.

BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.

▾ TwilightRed Hat · busybox-mainEPSS 0.13%via NVD
CVE-2026-88830High· 7.5
4d ago

A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.

A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.

▾ TwilightRed Hat · busyboxEPSS 0.35%via NVD
CVE-2026-6668High· 7.5
4d ago

Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service

Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service. Sufficiently large input makes the buffer size computation overflow, leaving the growt…

▾ TwilightRed Hat · PgBouncerEPSS 0.40%via NVD
CVE-2026-19888High· 7.5
4d ago

Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to crash the process

Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to crash the process. A malformed message can make the parser report success while…

▾ TwilightRed Hat · PgBouncerEPSS 0.39%via NVD
CVE-2026-6669Medium· 5.9
4d ago

Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in PgBouncer through 1.25.2 allows a malicious or compromised PostgreSQL backend to cause uncontrolled CPU consumption in …

Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in PgBouncer through 1.25.2 allows a malicious or compromised PostgreSQL backend to cause uncontrolled CPU consumption in …

▾ SunlitRed Hat · PgBouncerEPSS 0.31%via NVD
CVE-2026-79310High· 8.5
4d ago

webpy web.py 0.76 is vulnerable to server-side template injection (SSTI)

webpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be tricked into executing attacker-controlled template code that built-in security checks are designed to reject. When an application preco…

▾ TwilightRed HatEPSS 0.72%via NVD
CVE-2026-96276Critical· 9.8
4d ago

If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working …

If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working …

▾ MidnightRed Hat · flatpakEPSS 0.46%via NVD
CVE-2026-96275High· 8.8
4d ago

A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data()

A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` …

▾ TwilightRed Hat · flatpakEPSS 0.36%via NVD
CVE-2026-96512High· 7.8PoC
4d ago

A flaw was found in sudo

A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, the time evaluation relies on the TZ environment variable inherited from…

▾ MidnightRed Hat · sudoEPSS 0.13%via NVD
CVE-2026-96446Medium· 4.2
4d ago

A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak

A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent authentication path prompt=none is used, which allows the authorization process to skip certain steps if a user is alre…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.18%via NVD
CVE-2026-96445Medium· 6.8
4d ago

A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution

A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates specific HTTP headers to determine if a one-time password (OTP) should be skipped, …

▾ SunlitRed Hat · keycloak-servicesEPSS 0.24%via NVD
CVE-2026-95897Medium· 5.5PoC
4d ago

A security vulnerability has been detected in Dask up to 2026.8.0

A security vulnerability has been detected in Dask up to 2026.8.0. This affects the function from_npy_stack of the file dask/array/core.py of the component Loader. Such manipulation leads to deserialization. The attack can be launched re…

▾ TwilightRed Hat · DaskEPSS 0.19%via NVD
CVE-2026-75432Medium· 6.5
5d ago

An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive information via the src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components

An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive information via the src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components

▾ SunlitRed HatEPSS 0.22%via NVD
CVE-2026-88341Medium· 5.5PoC
5d ago

A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files

A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid arena configuration (num_buffers=0) that triggers an assertion failure in yr…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.17%via NVD
CVE-2026-13087High· 8.8PoC
5d ago

A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c

A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c. When a crafted RPC-over-RDMA client sends a large NFS READ request with an empty Write lis…

▾ MidnightRed Hat · kernelEPSS 0.47%via NVD
CVE-2026-79311Medium· 6.1
5d ago

webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via render_jinja.__init__().

webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via render_jinja.__init__().

▾ SunlitRed HatEPSS 0.15%via NVD
CVE-2026-94640High· 7.5
5d ago

A flaw was found in rpcbind

A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number of unique requests. The rpcbind service records previously unseen RPC (Remote Procedur…

▾ TwilightRed Hat · rpcbindEPSS 0.61%via NVD
CVE-2026-90462Medium· 5.4PoC
5d ago

A flaw was found in SSSD

A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. Thi…

▾ TwilightRed Hat · sssdEPSS 0.21%via NVD
CVE-2026-79312Medium· 6.8
5d ago

webpy web.py 0.76 is vulnerable to Session Fixation

webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads session_id directly from the request cookie and loads that session from the store, and _save() writes back under the same session_id; no rotation af…

▾ SunlitRed HatEPSS 0.29%via NVD
CVE-2026-79313Critical· 9.8⚖ disputed
5d ago

webpy web.py 0.76 is vulnerable to Insufficient Session Expiration

webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access time when a session is loaded. As a result, an exp…

▾ MidnightRed HatEPSS 0.38%via NVD
CVE-2026-95619High· 7.7
5d ago

A flaw was found in libstdc++

A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corrup…

▾ TwilightRed Hat · gcc-mainEPSS 0.36%via NVD
CVE-2026-95508High· 7.4
5d ago

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply bu…

▾ TwilightRed Hat · libslirpEPSS 0.57%via NVD
CVE-2026-95511High· 8.2PoC
5d ago

Rejected reason: Not a vulnerability

Rejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in cupsd admin role granted by a superuser. No privilege boundary is crossed.

▾ MidnightRed Hat · cups-filtersEPSS 0.12%via NVD
CVE-2016-15059Critical· 9.8
5d ago

Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns, sized …

Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns, sized …

▾ MidnightRed Hat · Net-IDN-EncodeEPSS 0.42%via NVD
CVE-2026-95503Medium· 6.8
5d ago

A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution

A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication is used without SPNEGO, the system fails to verify the identity of the Key Di…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.19%via NVD
CVE-2026-79079High· 7.8PoC
6d ago

An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components

An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components

▾ MidnightRed HatEPSS 0.19%via NVD
CVE-2026-93433Medium· 5.5
6d ago

A flaw was found in libstoragemgmt

A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specially crafted SCSI (Small Computer System Interface) Vital Product Data (VPD) page 0x80 data. This malformed data, spec…

▾ SunlitRed Hat · libstoragemgmtEPSS 0.15%via NVD
Red Hat vulnerabilities (CVEs) — page 3 · VulnSea