VulnSea

Red Hat has 1,289 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1042 in the last 90 days against 125 in the 90 before. The busiest recent month was September 2026 with 642. The median CVSS is 7.0 (high), with 57 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (97) and CWE-825 (89). Most affected products: Red Hat Enterprise Linux 9 (212), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
—(1)
Last 90 days
1042 prev 125

Products

  • Red Hat Enterprise Linux 9 212
  • Red Hat OpenShift Container Platform 4 95
  • Red Hat Enterprise Linux 10 62
  • Linux 57
  • Red Hat OpenShift AI (RHOAI) 45
  • Red Hat Enterprise Linux BaseOS (v. 10) 36
1289
Total CVEs
57
Critical
1
CISA KEV
1
Exploited

Red Hat vulnerabilities

CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.

1289 CVEsRSS

CVE-2026-9697High· 7.4
3mo ago

undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)

A flaw was found in undici. When undici's ProxyAgent is configured with a SOCKS5 proxy Uniform Resource Identifier (URI), it silently ignores Transport Layer Security (TLS) options, such as custom Certificate Authorities (CAs). This allows…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.55%via CSAF
CVE-2026-12003High· 7.8
3mo ago

To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local

To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark i…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.15%via NVD
CVE-2026-53704High· 7.1
3mo ago

A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package

A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using…

▾ TwilightRed Hat · gstreamer1-plugins-ugly-freeEPSS 0.46%via NVD
CVE-2026-5038High· 7.5⚖ disputed
3mo ago

multer: Multer: Denial of Service via aborted or malformed multipart uploads (CVE-2026-5038)

A flaw was found in multer. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by initiating and then aborting or sending malformed multipart uploads. This action leaves orphaned partial files on the disk, whi…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.49%via CSAF
CVE-2026-5079High· 7.5
3mo ago

multer: Multer: Denial of Service via deeply nested field names in multipart form data (CVE-2026-5079)

A flaw was found in Multer. A remote attacker can exploit this vulnerability by sending a single HTTP request with crafted multipart form data containing deeply nested field names. This can force the allocation of deeply nested object stru…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.49%via CSAF
CVE-2026-54411Medium· 5.9
3mo ago

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeate…

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeate…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.50%via NVD
CVE-2026-54133Critical· 9.8
3mo ago

jmespath.php: jmespath.php has CompilerRuntime code injection via unescaped function names (CVE-2026-54133)

A flaw was found in jmespath.php, a library for processing JSON documents in PHP applications. This vulnerability allows a remote attacker to execute arbitrary code by crafting a malicious JMESPath expression. The `JmesPath\CompilerRuntime…

▾ MidnightRed Hat · mtdowling/jmespath.phpEPSS 0.56%via CSAF
CVE-2026-42306High· 7.2
3mo ago

github.com/docker/docker: github.com/moby/moby: Moby container framework: Host file overwrite via race condition in docker cp mount setup (…

A flaw was found in the Moby container framework. A race condition occurs during the `docker cp` mount setup, which a malicious container can exploit. This vulnerability allows the container to redirect a bind mount target to an arbitrary …

▾ TwilightRed Hat · Red Hat Edge Manager 1.1EPSS 0.10%via CSAF
CVE-2026-45536Medium· 4.0
3mo ago

netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message han…

A flaw was found in Netty, a network application framework. A local attacker could exploit a vulnerability in the `netty_unix_socket_recvFd` function when handling `SCM_RIGHTS` messages in `Epoll` or `KQueue DomainSocketChannel` with `Doma…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.19%via CSAF
CVE-2026-45673Medium· 6.8
3mo ago

netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs (CVE-2026-45673)

A flaw was found in Netty's DNS resolver component. This vulnerability arises from the use of a predictable pseudo-random number generator (PRNG) for DNS transaction IDs and a static User Datagram Protocol (UDP) source port. This combinati…

▾ SunlitRed Hat · OpenShift ServerlessEPSS 0.40%via CSAF
CVE-2026-47244Medium· 5.3
3mo ago

netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams (CVE-2026-47244)

A flaw was found in Netty, a network application framework. A remote attacker can exploit this vulnerability by sending a large number of HTTP/2 stream requests to a Netty HTTP/2 server. If the server does not explicitly limit concurrent s…

▾ SunlitRed Hat · OpenShift ServerlessEPSS 0.51%via CSAF
CVE-2026-50020Medium· 5.3
3mo ago

netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder (CVE-2026-50020)

A flaw was found in Netty. The HttpObjectDecoder component, which processes incoming HTTP requests, incorrectly skips certain control characters and whitespace before reading the first request line. This behavior, which goes beyond standar…

▾ SunlitRed Hat · OpenShift ServerlessEPSS 0.40%via CSAF
CVE-2026-50560Medium· 5.3
3mo ago

netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling (CVE-2026-50560)

A flaw was found in Netty, a network application framework. A remote attacker can exploit a vulnerability in the HTTP/2 (Hypertext Transfer Protocol version 2) maximum header size handling. By sending a specific SETTINGS_MAX_HEADER_LIST_SI…

▾ SunlitRed Hat · OpenShift ServerlessEPSS 0.52%via CSAF
CVE-2026-11837High· 7.3PoC
3mo ago

A local privilege escalation vulnerability was found in the ansible.posix authorized_key module

A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys.…

▾ MidnightRed Hat · rhc-worker-playbookEPSS 0.16%via NVD
CVE-2026-6893High· 7.5
3mo ago

A flaw was found in dracut

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracu…

▾ TwilightRed Hat · dracutEPSS 3.1%via NVD
CVE-2026-10143High· 7.5
3mo ago

kafka-python: kafka-python: Denial of Service via excessive SCRAM authentication iteration count (CVE-2026-10143)

A flaw was found in kafka-python. A malicious or machine-in-the-middle broker could exploit a denial-of-service vulnerability during SCRAM authentication. By providing an excessively large iteration count, the broker can cause the client's…

▾ TwilightRed Hat · Red Hat Quay 3.12EPSS 0.52%via CSAF
CVE-2026-42563High· 8.0
3mo ago

dulwich: Dulwich: Arbitrary code execution via malicious Git file paths during merge (CVE-2026-42563)

A flaw was found in Dulwich, a pure-Python implementation of Git file formats and protocols. An attacker can exploit this vulnerability by crafting malicious file paths within an untrusted Git branch. When a victim merges this branch, the …

▾ TwilightRed Hat · Red Hat Ansible Automation Platform 2EPSS 0.80%via CSAF
CVE-2026-42305High· 8.8
3mo ago

dulwich: Dulwich: Remote Code Execution via Malicious Git Repository (CVE-2026-42305)

A flaw was found in Dulwich, a pure-Python implementation of the Git file formats and protocols. A remote attacker could exploit this vulnerability by enticing a user on a Windows system to clone or check out a specially crafted malicious …

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.85%via CSAF
CVE-2026-52726Medium· 5.4⚖ disputed
3mo ago

dulwich: Dulwich: Arbitrary code execution via crafted Git submodules (CVE-2026-52726)

A flaw was found in Dulwich, a pure-Python implementation of Git file formats and protocols. This vulnerability allows a remote attacker to achieve arbitrary code execution by crafting a malicious Git submodule. When a user clones or updat…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.68%via CSAF
CVE-2026-9669Medium· 5.9
3mo ago

bz2.BZ2Decompressor objects could be reused after a decompression error

bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.60%via NVD
CVE-2026-46311High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/userq: fix access to stale wptr mapping Use drm_exec to take both locks i.e vm root bo and wptr_obj bo to access the mapping data properly. This fixes the …

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/userq: fix access to stale wptr mapping Use drm_exec to take both locks i.e vm root bo and wptr_obj bo to access the mapping data properly. This fixes the …

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.17%via NVD
CVE-2026-11332High· 7.8
3mo ago

A flaw was found in ansible-core

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can in…

▾ TwilightRed Hat · ansible-coreEPSS 0.22%via NVD
CVE-2026-45409Medium· 5.3
3mo ago

python-idna: idna: Denial of Service via specially crafted long inputs (CVE-2026-45409)

A flaw was found in the idna library, which handles Internationalized Domain Names in Python applications. A remote attacker could exploit this vulnerability by sending specially crafted, excessively long inputs to the library's encoding f…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.46%via CSAF
CVE-2026-10805Medium· 6.7
3mo ago

A flaw was found in NetworkManager

A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to esca…

▾ SunlitRed Hat · NetworkManagerEPSS 0.17%via NVD
CVE-2026-41178High· 7.5
3mo ago

github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denia…

A flaw was found in OpenTelemetry-Go. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by sending oversized or invalid baggage headers. The `Parse` function, in affected versions, failed to reject raw-length i…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.34%via CSAF
CVE-2026-5241High· 7.7
3mo ago

python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting (CVE-2026-5241)

A flaw was found in python-transformers. An attacker can exploit this vulnerability by providing a malicious model repository. During model initialization, the `trust_remote_code` parameter, intended to prevent remote code execution, is ov…

▾ TwilightRed Hat · Red Hat AI Inference Server 3.4EPSS 0.94%via CSAF
CVE-2026-42507Medium· 5.3
3mo ago

net/textproto: golang: Golang net/textproto: Misleading error messages via input injection (CVE-2026-42507)

A flaw was found in the net/textproto package in Golang. When functions in this package return errors, they include their input as part of the error message. An attacker could exploit this by injecting misleading content into these error m…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.41%via CSAF
CVE-2026-34993High· 7.2
3mo ago

aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() (CVE-2026-34993)

A flaw was found in AIOHTTP, an asynchronous HTTP client/server framework for asyncio and Python. An attacker could exploit this vulnerability by providing untrusted input to the `CookieJar.load()` function. This could potentially lead to …

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.50%via CSAF
CVE-2026-44740High· 7.5
3mo ago

github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740)

A flaw was found in Billy, an interface filesystem abstraction for Go. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by providing crafted or malformed input. The issue arises from insufficient validation an…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.53%via CSAF
CVE-2026-43958High· 7.8
3mo ago

A flaw was found in rrdcached, a component of rrdtool

A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow by sending an oversized CREATE request. This vulnerability can lead to a denial of servic…

▾ TwilightRed Hat · rrdtoolEPSS 0.19%via NVD
Red Hat vulnerabilities (CVEs) — page 37 · VulnSea