VulnSea

Red Hat has 1,289 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1042 in the last 90 days against 125 in the 90 before. The busiest recent month was September 2026 with 642. The median CVSS is 7.0 (high), with 57 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (97) and CWE-825 (89). Most affected products: Red Hat Enterprise Linux 9 (212), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
—(1)
Last 90 days
1042 prev 125

Products

  • Red Hat Enterprise Linux 9 212
  • Red Hat OpenShift Container Platform 4 95
  • Red Hat Enterprise Linux 10 62
  • Linux 57
  • Red Hat OpenShift AI (RHOAI) 45
  • Red Hat Enterprise Linux BaseOS (v. 10) 36
1289
Total CVEs
57
Critical
1
CISA KEV
1
Exploited

Red Hat vulnerabilities

CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.

1289 CVEsRSS

CVE-2026-26209Medium· 5.5⚖ disputed
6mo ago

cbor2: cbor2: Denial of Service due to uncontrolled recursion via crafted CBOR payloads (CVE-2026-26209)

A flaw was found in cbor2, a library for encoding and decoding Concise Binary Object Representation (CBOR) data. A remote attacker can exploit this vulnerability by sending a specially crafted CBOR payload containing deeply nested structur…

▾ SunlitRed Hat · Red Hat Enterprise Linux AI (RHEL AI) 3EPSS 0.65%via CSAF
CVE-2026-33022Medium· 6.5
6mo ago

github.com/tektoncd/pipeline: Tekton Pipelines: Denial of Service via long resolver names (CVE-2026-33022)

A denial of service flaw was found in Tekton Pipelines. Any user who can create a TaskRun or PipelineRun to crash the controller cluster-wide by setting .spec.taskRef.resolver (or .spec.pipelineRef.resolver) to a string of 31+ characters. …

▾ SunlitRed Hat · OpenShift PipelinesEPSS 0.45%via CSAF
CVE-2026-33154High· 7.5PoC
6mo ago

dynaconf: jinja2: Dynaconf: Arbitrary code execution via Server-Side Template Injection (CVE-2026-33154)

A flaw was found in dynaconf, a Python configuration management tool. This Server-Side Template Injection (SSTI) vulnerability occurs due to unsafe template evaluation in the @Jinja resolver when the jinja2 package is installed. A remote a…

▾ MidnightRed Hat · Red Hat Ansible Automation Platform 2EPSS 0.57%via CSAF
CVE-2026-27135High· 7.5
6mo ago

nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination (CVE-2026-27135)

A flaw was found in nghttp2. Due to missing internal state validation, the library continues to process incoming data even after a session has been terminated. A remote attacker could exploit this by sending a specially crafted HTTP/2 fram…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.89%via CSAF
CVE-2026-30922High· 7.5PoC
6mo ago

pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)

An unbounded recursion flaw has been discovered in the pypi pyasn1 library. This uncontrolled recursion occurs when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing nested SEQUENCE (0x3…

▾ MidnightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.93%via CSAF
CVE-2026-31892High· 8.5
6mo ago

github.com/argoproj/argo-workflows: Argo Workflows: Security bypass allows privilege escalation via podSpecPatch field (CVE-2026-31892)

A flaw was found in Argo Workflows. A user with privileges to submit workflows can bypass security settings defined in a WorkflowTemplate by including a `podSpecPatch` field in their workflow submission. This allows them to circumvent rest…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.65%via CSAF
CVE-2026-27628High· 7.5
7mo ago

pypdf: possible infinite loop when loading circular /Prev entries in cross-reference streams (CVE-2026-27628)

A flaw was found in pypdf. Processing a specially crafted PDF document, specifically with circular /Prev references in the cross-reference (xref) chain, can cause an infinite loop and a high consumption of CPU, resulting in a denial of ser…

▾ TwilightRed Hat · Red Hat Quay 3.16EPSS 0.61%via CSAF
CVE-2026-25934Medium· 4.3
7mo ago

go-git/go-git: go-git: Data integrity issue due to improper verification of pack and index files (CVE-2026-25934)

A flaw was found in go-git, a library for Git implementation in Go. This vulnerability allows a remote attacker to provide specially crafted Git pack or index files that are not properly verified for data integrity. Successful exploitation…

▾ SunlitRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.15%via CSAF
CVE-2026-23103Medium· 4.7⚖ disputed
7mo ago

kernel: ipvlan: Make the addrs_lock be per port (CVE-2026-23103)

A race condition vulnerability was found in the Linux kernel's ipvlan driver. The per-device addrs_lock was incorrectly used instead of a per-port lock, and some code paths (ipvlan_open/ipvlan_close) failed to acquire the lock entirely. Fo…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.11%via CSAF
CVE-2025-61730Medium· 5.3
8mo ago

crypto/tls: Handshake messages may be processed at the incorrect encryption level in crypto/tls (CVE-2025-61730)

A TLS connection handling flaw has been discovered in the golang crypto/tls library. During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted E…

▾ SunlitRed Hat · Red Hat Ceph Storage 6EPSS 0.33%via CSAF
CVE-2025-14525Medium· 6.4
8mo ago

A flaw was found in kubevirt

A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by causing the agent to report an excessive number of network interfaces. This action can overwhelm the system's ability t…

▾ SunlitRed Hat · kubevirtEPSS 0.29%via NVD
CVE-2026-0603High· 8.3PoC
8mo ago

A flaw was found in Hibernate

A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrCl…

▾ MidnightRed Hat · Red Hat JBoss EAP 7.4 ELS for RHEL 8EPSS 0.87%via NVD
CVE-2026-24117Medium· 5.3
8mo ago

github.com/sigstore/rekor: Rekor Server-Side Request Forgery (SSRF) (CVE-2026-24117)

A Server-Side Request Forgery (SSRF) flaw has been discovered in the Rekor transparency log tool. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /api/v1/index/retrieve supports retrieving a p…

▾ SunlitRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.37%via CSAF
CVE-2026-23831Medium· 5.3
8mo ago

github.com/sigstore/rekor: Rekor denial of service (CVE-2026-23831)

Rekor’s cose v0.0.1 entry implementation can panic on attacker-controlled input when canonicalizing a proposed entry with an empty spec.message. validate() returns nil (success) when message is empty, leaving sign1Msg uninitialized, and Ca…

▾ SunlitRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.44%via CSAF
CVE-2026-23991Medium· 5.9
8mo ago

github.com/theupdateframework/go-tuf/v2: go-tuf client DoS via malformed server response (CVE-2026-23991)

A denial of service flaw has been discovered in go-tuf. If the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial o…

▾ SunlitRed Hat · OpenShift PipelinesEPSS 0.59%via CSAF
CVE-2026-0532High· 8.6
8mo ago

External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connect…

External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connect…

▾ TwilightRed Hat · Red Hat OpenShift distributed tracing 3EPSS 0.48%via NVD
CVE-2025-12548Critical· 9.0PoC
8mo ago

A flaw was found in Eclipse Che che-machine-exec

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unau…

▾ AbyssalRed Hat · devspaces/code-rhel9EPSS 1.3%via NVD
CVE-2026-0716Medium· 4.8PoC
8mo ago

A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages

A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. T…

▾ TwilightRed Hat · libsoup3EPSS 0.39%via NVD
CVE-2026-22703Medium· 5.5
8mo ago

github.com/sigstore/cosign: Cosign verification accepts any valid Rekor entry under certain conditions (CVE-2026-22703)

A data verification flaw has been discovered in the golang cosign library. A Cosign bundle can be crafted to successfully verify an artifact even if the embedded Rekor entry does not reference the artifact's digest, signature or public key…

▾ SunlitRed Hat · OpenShift PipelinesEPSS 0.11%via CSAF
CVE-2026-22701Medium· 5.3
8mo ago

filelock: filelock Time-of-Check-Time-of-Use (TOCTOU) in SoftFileLock (CVE-2026-22701)

A Time-of-Check-Time-of-Use (TOCTOU) flaw has been discovered in the pypi filelock package. The TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access…

▾ SunlitRed Hat · Red Hat Ansible Automation Platform 2EPSS 0.13%via CSAF
CVE-2025-69262High· 7.5
8mo ago

pnpm is a package manager

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environme…

▾ TwilightRed HatEPSS 1.1%via NVD
CVE-2025-69263High· 7.5PoC
8mo ago

pnpm is a package manager

pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve different content on each install, even when…

▾ MidnightRed Hat · pnpmEPSS 0.48%via NVD
CVE-2025-69227High· 7.5
8mo ago

aiohttp: aiohttp: Denial of Service via specially crafted POST request (CVE-2025-69227)

A flaw was found in aiohttp, an asynchronous HTTP client/server framework for Python. A remote attacker could exploit this vulnerability by sending a specially crafted POST request to an application using the Request.post() method, provide…

▾ TwilightRed Hat · Red Hat Ansible Automation Platform 2EPSS 0.39%via CSAF
CVE-2025-69228Medium· 6.8
8mo ago

aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request (CVE-2025-69228)

A flaw was found in aiohttp. A remote attacker can craft a malicious request that, when processed by an aiohttp server using the `Request.post()` method, causes the server's memory to fill uncontrollably. This can lead to a Denial of Servi…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.40%via CSAF
CVE-2025-68742Medium· 4.7
9mo ago

kernel: bpf: Fix invalid prog->stats access when update_effective_progs fails (CVE-2025-68742)

An invalid memory access vulnerability was found in the Linux kernel's BPF cgroup subsystem. When update_effective_progs fails due to allocation failure (such as from fault injection), the code replaces the program with dummy_bpf_prog. If …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2025-68664Critical· 9.3PoC
9mo ago

langchain-core: LangChain: Arbitrary code execution via serialization injection (CVE-2025-68664)

A flaw was found in LangChain, a framework for building agents and LLM-powered applications. A remote attacker can exploit a serialization injection vulnerability in LangChain's `dumps()` and `dumpd()` functions. This occurs because the fu…

▾ AbyssalRed Hat · Red Hat Ansible Automation Platform 2.5EPSS 43%via CSAF
CVE-2025-67724Medium· 5.4
9mo ago

tornado: Tornado Header Injection and XSS via reason argument (CVE-2025-67724)

An unescaped input flaw has been discovered in the Tornado networking library. In Tornado, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (whe…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.24%via CSAF
CVE-2025-66448High· 7.5
10mo ago

vllm: vLLM: Remote Code Execution via malicious model configuration (CVE-2025-66448)

A remote code execution vulnerability has been identified in vLLM. An attacker can exploit a weakness in the model loading process to silently fetch and run unauthorized, malicious Python code on the host system. This happens because the e…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.3EPSS 0.66%via CSAF
CVE-2025-62426Medium· 6.5
10mo ago

vllm: vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs` (CVE-2025-624…

A vulnerability in vLLM allows an authenticated user to trigger unintended tokenization during chat template processing by supplying crafted chat_template_kwargs to the /v1/chat/completions or /tokenize endpoints. By forcing the server to …

▾ SunlitRed Hat · Red Hat Enterprise Linux AI (RHEL AI)EPSS 0.37%via CSAF
CVE-2025-47913High· 7.5
10mo ago

golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS (CVE-2025-47913)

A flaw in golang.org/x/crypto/ssh/agent causes the SSH agent client to panic when a peer responds with the generic SSH_AGENT_SUCCESS (0x06) message to requests expecting typed replies (e.g., List, Sign). The unmarshal layer produces an une…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream E4S (v.8.6)EPSS 0.62%via CSAF
Red Hat vulnerabilities (CVEs) — page 40 · VulnSea