VulnSea

Red Hat has 1,289 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1042 in the last 90 days against 125 in the 90 before. The busiest recent month was September 2026 with 642. The median CVSS is 7.0 (high), with 57 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (97) and CWE-825 (89). Most affected products: Red Hat Enterprise Linux 9 (212), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
—(1)
Last 90 days
1042 prev 125

Products

  • Red Hat Enterprise Linux 9 212
  • Red Hat OpenShift Container Platform 4 95
  • Red Hat Enterprise Linux 10 62
  • Linux 57
  • Red Hat OpenShift AI (RHOAI) 45
  • Red Hat Enterprise Linux BaseOS (v. 10) 36
1289
Total CVEs
57
Critical
1
CISA KEV
1
Exploited

Red Hat vulnerabilities

CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.

1289 CVEsRSS

CVE-2026-59649High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory

In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1…

▾ TwilightRed Hat · Red Hat JBoss Enterprise Application Platform 7EPSS 0.49%via NVD
CVE-2026-59647High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count

In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.42%via NVD
CVE-2026-59645High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema

In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcu…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.49%via NVD
CVE-2026-59642High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present

In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips …

▾ TwilightRed Hat · Red Hat Ceph Storage 9EPSS 0.19%via NVD
CVE-2026-59639High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0…

▾ TwilightRed Hat · Red Hat Ceph Storage 9EPSS 0.24%via NVD
CVE-2026-59638High· 7.4
1mo ago

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc…

▾ TwilightRed HatEPSS 0.34%via NVD
CVE-2026-15055High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input

In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 …

▾ TwilightRed Hat · Red Hat Ceph Storage 9EPSS 0.34%via NVD
CVE-2026-67325High· 8.8
1mo ago

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like uplo…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 2.2%via NVD
CVE-2026-67324Critical· 9.8
1mo ago

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Re…

▾ MidnightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.64%via NVD
CVE-2026-67322High· 7.5
1mo ago

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from()

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL befor…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.33%via NVD
CVE-2026-67320High· 7.4
1mo ago

axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy

axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but request interceptors run after the merge; a…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.52%via NVD
CVE-2026-67317Medium· 5.3
1mo ago

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload siz…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.60%via NVD
CVE-2026-67314High· 7.4
1mo ago

axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js)

axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js). When an application is already affected by a separate prototype-po…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.41%via NVD
CVE-2026-67313High· 7.5
1mo ago

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brac…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.52%via NVD
CVE-2026-67312High· 7.5
1mo ago

axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData with Content-Type: application/json)

axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData with Content-Type: application/json). Whe…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.52%via NVD
CVE-2026-67298High· 7.5
1mo ago

FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c)

FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PD…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.67%via NVD
CVE-2026-67291High· 7.5
1mo ago

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads …

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.65%via NVD
CVE-2026-67290High· 7.5
1mo ago

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to t…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.61%via NVD
CVE-2026-67288High· 7.5⚖ disputed
1mo ago

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emu…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.64%via NVD
CVE-2026-18446High· 7.5
1mo ago

fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority (CVE-2026-18446)

A flaw was found in fast-uri. This vulnerability arises because fast-uri incorrectly parses Uniform Resource Identifiers (URIs) when a backslash is used in place of a forward slash to introduce the authority component. This discrepancy wit…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.22%via CSAF
CVE-2026-18369Medium· 5.8
2mo ago

Dogtag-pki: pki-core: redhat-pki: pki: acme http-01 validation ssrf via ip literal identifiers and unvalidated redirects

A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated AC…

▾ SunlitRed Hat · redhat-pki:10EPSS 0.22%via CVEORG
CVE-2026-59881Medium· 5.3
2mo ago

aiohttp: AIOHTTP: Denial of Service via unnegotiated WebSocket compression (CVE-2026-59881)

A flaw was found in AIOHTTP. The WebSocket client in AIOHTTP processes compressed data frames even when the compression mechanism, known as permessage-deflate, has not been properly negotiated. A malicious server can exploit this by sendin…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.52%via CSAF
CVE-2026-18255High· 7.2
2mo ago

A flaw was found in Quay

A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot …

▾ TwilightRed Hat · quay/quay-rhel8EPSS 0.65%via NVD
CVE-2026-16313High· 7.6
2mo ago

A flaw was found in sg3_utils

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-suppl…

▾ TwilightRed Hat · sg3_utilsEPSS 0.35%via NVD
CVE-2026-49332High· 8.5
2mo ago

A flaw was found in openshift/oauth-proxy

A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP f…

▾ TwilightRed Hat · openshift4/ose-oauth-proxyEPSS 0.53%via NVD
CVE-2026-47219High· 7.5
2mo ago

find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server (CVE-2026-47219)

A flaw was found in find-my-way, a routing module for Node.js. A remote attacker could exploit this vulnerability when find-my-way is used with Node's HTTP/2 server. By sending specially crafted HTTP/2 method values, an attacker can cause …

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.46%via CSAF
CVE-2026-17527High· 7.7
2mo ago

In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource

In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone a…

▾ TwilightRed Hat · container-native-virtualization/virt-cdi-operator-rhel9EPSS 0.57%via NVD
CVE-2026-43871High· 7.5
2mo ago

thrift: Apache Thrift: Denial of Service via infinite loop (CVE-2026-43871)

A flaw was found in Apache Thrift, affecting its Python, Go, PHP, and Java components. This vulnerability, known as an 'Infinite Loop', could allow a remote attacker to disrupt service availability. By exploiting this flaw, an attacker can…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 1.0%via CSAF
CVE-2026-54272High· 7.2
2mo ago

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifie…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream EUS (v.9.6)EPSS 0.43%via NVD
CVE-2026-15928High· 7.4
2mo ago

XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.

XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.

▾ TwilightRed Hat · Red Hat Enterprise Linux CRB (v. 8)EPSS 0.28%via NVD
Red Hat vulnerabilities (CVEs) — page 31 · VulnSea