VulnSea

Red Hat has 1,289 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1042 in the last 90 days against 125 in the 90 before. The busiest recent month was September 2026 with 642. The median CVSS is 7.0 (high), with 57 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (97) and CWE-825 (89). Most affected products: Red Hat Enterprise Linux 9 (212), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
—(1)
Last 90 days
1042 prev 125

Products

  • Red Hat Enterprise Linux 9 212
  • Red Hat OpenShift Container Platform 4 95
  • Red Hat Enterprise Linux 10 62
  • Linux 57
  • Red Hat OpenShift AI (RHOAI) 45
  • Red Hat Enterprise Linux BaseOS (v. 10) 36
1289
Total CVEs
57
Critical
1
CISA KEV
1
Exploited

Red Hat vulnerabilities

CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.

1289 CVEsRSS

CVE-2026-71556High· 7.1
1mo ago

go-git is an extensible git implementation library written in pure Go

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resoluti…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.36%via NVD
CVE-2026-18649High· 7.5PoC
1mo ago

A flaw was found in the GStreamer gst-plugins-good package

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, u…

▾ MidnightRed Hat · gstreamer1-plugins-goodEPSS 0.96%via NVD
CVE-2026-7867High· 7.8PoC
1mo ago

A flaw was found in udisks2

A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker…

▾ MidnightRed Hat · udisksEPSS 0.17%via NVD
CVE-2026-18427High· 7.5
1mo ago

@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass

@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dot…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.66%via NVD
CVE-2026-64597Critical· 9.8⚖ disputed
1mo ago

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails b…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.67%via NVD
CVE-2026-67422High· 7.5
1mo ago

pymdown-extensions is a collection of extensions for the Python Markdown library

pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can parti…

▾ TwilightRed Hat · Red Hat Developer HubEPSS 0.61%via NVD
CVE-2026-71430Medium· 6.2
1mo ago

node-re2 provides RE2 regular expression bindings for Node.js

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty MaybeLocal that…

▾ SunlitRed Hat · re2EPSS 0.16%via NVD
CVE-2026-71498Medium· 5.1
1mo ago

node-re2 provides RE2 regular expression bindings for Node.js

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read past the end of the…

▾ SunlitRed Hat · re2EPSS 0.17%via NVD
CVE-2026-67434High· 7.8
1mo ago

PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards

PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgbl…

▾ TwilightRed Hat · squizlabs/php_codesnifferEPSS 1.1%via NVD
CVE-2026-44950High· 7.5
1mo ago

libxfonts2: libXfont2: Privilege Escalation via Heap Buffer Overflow in Font Server Client (CVE-2026-44950)

A flaw was found in the libXfont2 font-server client. This heap buffer overflow vulnerability allows a malicious font server to send specially crafted glyph data. The fs_read_glyphs() function fails to properly validate the total size of t…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.44%via CSAF
CVE-2026-10090Critical· 9.0
1mo ago

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM)

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can cre…

▾ MidnightRed Hat · rhacm2/multicluster-operators-subscription-rhel9EPSS 0.58%via NVD
CVE-2026-10059Critical· 9.1
1mo ago

A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller

A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertent…

▾ MidnightRed Hat · multicluster-engine/cluster-curator-controller-rhel9EPSS 0.64%via NVD
CVE-2026-54876High· 7.5
1mo ago

Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an attacker…

Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an attacker…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.52%via NVD
CVE-2026-71235High· 8.8
1mo ago

Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive

Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. The Lua script engine (re/lua.go) performs no input validation at all and preloads danger…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.52%via NVD
CVE-2026-64582High· 7.8
1mo ago

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list and releases pending_lock while the struct's k…

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list and releases pending_lock while the struct's k…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.13%via NVD
CVE-2026-68494High· 7.5
1mo ago

The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete

The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass. The earlier fix wired valida…

▾ TwilightRed Hat · Red Hat JBoss EAP 7.4 ELS for RHEL 7 ServerEPSS 0.62%via NVD
CVE-2026-64564Critical· 9.8PoC⚖ disputed
1mo ago

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport …

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport …

▾ AbyssalRed Hat · Red Hat Enterprise Linux 9EPSS 1.4%via NVD
CVE-2026-64563High· 7.8PoC
1mo ago

In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhashtable_walk_start_check() has two restart paths when resuming a walk. When iter->walker.tbl is valid, it re-valida…

In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhashtable_walk_start_check() has two restart paths when resuming a walk. When iter->walker.tbl is valid, it re-valida…

▾ MidnightRed Hat · Red Hat Enterprise Linux 9EPSS 0.12%via NVD
CVE-2026-69243High· 7.0PoC
1mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If using the server-side component, an attack…

▾ MidnightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.44%via NVD
CVE-2026-69244High· 7.5
1mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker contro…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.53%via NVD
CVE-2026-69247Medium· 5.9
1mo ago

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a Recipien…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.27%via NVD
CVE-2026-69249High· 7.5
1mo ago

python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed cert…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.33%via NVD
CVE-2026-69248High· 7.4
1mo ago

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 45.0.0 through 48.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate h…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.31%via NVD
CVE-2026-69192High· 8.6
1mo ago

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, an…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.66%via NVD
CVE-2026-69152High· 7.5
1mo ago

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation (CVE-2026-69152)

A flaw was found in the brace-expansion library. The `expand()` function does not apply `maxLength` when constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block …

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.65%via CSAF
CVE-2026-69153High· 7.5
1mo ago

postcss: PostCSS: Information disclosure via crafted sourceMappingURL (CVE-2026-69153)

A flaw was found in PostCSS. A remote attacker can exploit this vulnerability by providing a specially crafted sourceMappingURL when a specific configuration (the 'from' parameter) is not set. This can cause the application to read and exp…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.45%via CSAF
CVE-2026-68945High· 8.2
1mo ago

@angular/common: Angular: Cross-Request Response Reuse and State Poisoning in HttpTransferCache (CVE-2026-68945)

A flaw was found in Angular's HttpTransferCache component. This component, used for caching HTTP requests during server-side rendering, incorrectly generates cache keys when repeated request parameters are present, causing semantically dif…

▾ TwilightRed Hat · Red Hat Ceph Storage 4EPSS 0.18%via CSAF
CVE-2026-8763High· 7.4
1mo ago

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.…

▾ TwilightRed Hat · Red Hat Ceph Storage 9EPSS 0.45%via NVD
CVE-2026-59651High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key

In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.24%via NVD
CVE-2026-59650High· 7.4
1mo ago

In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value

In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.45%via NVD
Red Hat vulnerabilities (CVEs) — page 30 · VulnSea