VulnSea

Red Hat has 1,289 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1042 in the last 90 days against 125 in the 90 before. The busiest recent month was September 2026 with 642. The median CVSS is 7.0 (high), with 57 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (97) and CWE-825 (89). Most affected products: Red Hat Enterprise Linux 9 (212), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
—(1)
Last 90 days
1042 prev 125

Products

  • Red Hat Enterprise Linux 9 212
  • Red Hat OpenShift Container Platform 4 95
  • Red Hat Enterprise Linux 10 62
  • Linux 57
  • Red Hat OpenShift AI (RHOAI) 45
  • Red Hat Enterprise Linux BaseOS (v. 10) 36
1289
Total CVEs
57
Critical
1
CISA KEV
1
Exploited

Red Hat vulnerabilities

CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.

1289 CVEsRSS

CVE-2025-40149Medium· 5.0⚖ disputed
10mo ago

kernel: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock() (CVE-2025-40149)

A flaw was found in the Linux kernel’s TLS implementation (net/tls/tls_device.c). The function get_netdev_for_sock() is invoked during setsockopt(), which is not executed under RCU (Read-Copy-Update) protection. It previously used sk_dst_g…

▾ SunlitRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.16%via CSAF
CVE-2025-2843High· 8.8
10mo ago

A flaw was found in the Observability Operator

A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with onl…

▾ TwilightRed Hat · Cluster Observability Operator 1.3.1EPSS 0.33%via NVD
CVE-2025-58188Medium
11mo ago

crypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509 (CVE-2025-58188)

A denial of service vector has been discovered in the golang crypto/x509 module. An attacker could craft an intermediate X.509 certificate containing a DSA public key and can crash a remote host with an unauthenticated call to any endpoint…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.36%via CSAF
CVE-2025-11374Medium· 6.5
11mo ago

github.com/hashicorp/consul: Consul's KV endpoint is vulnerable to denial of service (CVE-2025-11374)

A denial of service flaw has been discovered in Hashicorp Consul. The key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validation.

▾ SunlitRed Hat · Red Hat OpenShift Dev SpacesEPSS 0.40%via CSAF
CVE-2025-11579Medium· 5.3PoC
11mo ago

github.com/nwaples/rardecode: RarDecode Out Of Memory Crash (CVE-2025-11579)

A memory exhaustion flaw has been discovered in the golang Rar Decode library (github.com/nwaples/rardecode). Affected versions did not limit the size of an archive and so an attacker could provide a crafted archive to a tool or service bu…

▾ TwilightRed Hat · Red Hat Advanced Cluster Security 4EPSS 0.37%via CSAF
CVE-2025-59530Medium· 5.3⚖ disputed
11mo ago

github.com/quic-go/quic-go: quic-go Crash Due to Premature HANDSHAKE_DONE Frame (CVE-2025-59530)

A denial of service flaw has been discovered in the quic-go golang library. A misbehaving or malicious server can cause a denial-of-service (DoS) attack on the quic-go client by triggering an assertion failure, leading to a process crash. …

▾ SunlitRed Hat · Red Hat Ansible Automation Platform 2.5 for RHEL 8EPSS 0.46%via CSAF
CVE-2025-59425High· 7.5
11mo ago

vllm: Timing Attack in vLLM API Token Verification Leading to Authentication Bypass (CVE-2025-59425)

A flaw was found in vLLM’s API token authentication logic, where token comparisons were not performed in constant time. This weakness could allow an attacker to exploit timing differences to guess valid tokens and bypass authentication.

▾ TwilightRed Hat · Red Hat OpenShift AI 3.3EPSS 0.57%via CSAF
CVE-2025-11234High· 7.5
12mo ago

A flaw was found in QEMU

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel.…

▾ TwilightRed Hat · qemuEPSS 0.86%via NVD
CVE-2025-59682High· 8.8⚖ disputed
12mo ago

django: Potential partial directory-traversal via archive.extract() (CVE-2025-59682)

A flaw was found in Django. The django.utils.archive.extract() function, used by startapp --templateand startproject --template, allowed partial directory-traversal via an archive with file paths sharing a common prefix with the target dir…

▾ TwilightRed Hat · Red Hat Ansible Automation Platform 2.5 for RHEL 8EPSS 0.91%via CSAF
CVE-2025-55191Medium· 4.3⚖ disputed
12mo ago

github.com/argoproj/argo-cd/v2: github.com/argoproj/argo-cd/v3: Argo CD race condition leading to crash (CVE-2025-55191)

A race condition has been discovered in the Argo CD GitOps tool. This race condition is located in the repository credentials handler that can cause the Argo CD server to panic and crash when concurrent operations are performed on the same…

▾ SunlitRed Hat · Red Hat OpenShift GitOps 1.16EPSS 0.47%via CSAF
CVE-2025-59940Medium· 6.5
12mo ago

mkdocs-include-markdown-plugin: mkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholders (C…

There is an improper input validation flaw in the python `mkdocs-include-markdown-plugin` package. Under certain conditions placeholders are not properly validated and may collide with other data elements resulting in inconsistent output.

▾ SunlitRed Hat · Multicluster Engine for KubernetesEPSS 0.34%via CSAF
CVE-2025-59420High· 7.5
1y ago

authlib: Authlib RFC violation (CVE-2025-59420)

Authlib’s JWS verification accepts tokens that declare unknown critical header parameters (crit), violating RFC 7515 “must‑understand” semantics. An attacker can craft a signed token with a critical header (for example, bork or cnf) that s…

▾ TwilightRed Hat · Red Hat Quay 3.10EPSS 0.26%via CSAF
CVE-2025-39862Medium· 5.5⚖ disputed
1y ago

kernel: wifi: mt76: mt7915: fix list corruption after hardware restart (CVE-2025-39862)

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: fix list corruption after hardware restart Since stations are recreated from scratch, all lists that wcids are added to must be cleared before callin…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.19%via CSAF
CVE-2025-47906Medium· 6.5
1y ago

os/exec: Unexpected paths returned from LookPath in os/exec (CVE-2025-47906)

A path handling flaw has been discovered in the os/exec go package. If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result i…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.55%via CSAF
CVE-2025-4953High· 7.4
1y ago

A flaw was found in Podman

A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build c…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4.13EPSS 0.64%via NVD
CVE-2025-9566High· 8.1
1y ago

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In…

▾ TwilightRed Hat · podmanEPSS 1.1%via NVD
CVE-2025-55190High· 8.8PoC
1y ago

github.com/argoproj/argo-cd: Project API Token Exposes Repository Credentials (CVE-2025-55190)

An information leak was discovered in how Argo CD handles API tokens. The project details API endpoint could provide unintentional access to sensitive repository credentials.

▾ MidnightRed Hat · Red Hat OpenShift GitOps 1.17EPSS 5.5%via CSAF
CVE-2025-48956High· 7.5
1y ago

vllm: HTTP header size limit not enforced allows Denial of Service from Unauthenticated requests (CVE-2025-48956)

A flaw was found in vLLM. A denial of service (DoS) vulnerability can be triggered by sending a single HTTP GET request with an extremely large X-Forwarded-For header to an HTTP endpoint. This results in server memory exhaustion, potential…

▾ TwilightRed Hat · Red Hat Enterprise Linux AI (RHEL AI)EPSS 0.56%via CSAF
CVE-2025-57809High· 7.5
1y ago

xgrammar: XGrammar affected by Denial of Service by infinite recursion grammars (CVE-2025-57809)

A flaw was found in xgrammar. Recursive grammar definitions could trigger infinite recursion during parsing in GrammarMatcherBase::ExpandEquivalentStackElements, leading to unbounded stack growth and a segmentation fault. This vulnerabilit…

▾ TwilightRed Hat · Red Hat Enterprise Linux AI 1.5EPSS 0.47%via CSAF
CVE-2025-5187Medium· 6.7
1y ago

kubernetes: kube-apiserver: Nodes can delete themselves by adding an OwnerReference (CVE-2025-5187)

A vulnerability was found in the kube-apiserver's NodeRestriction admission controller, where node users can delete their corresponding node object by setting their own OwnerReference to a cluster-scoped resource. This flaw allows an attac…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.55%via CSAF
CVE-2025-54576High· 7.4
1y ago

github.com/oauth2-proxy/oauth2-proxy: OAuth2-Proxy authentication bypass (CVE-2025-54576)

An authentication bypass flaw was found in the OAuth2-Proxy project. This bypass affects systems that have configured their deployment to skip authentication on endpoints that match a deployment-defined regular expression. HTTP parameters …

▾ TwilightRed Hat · Red Hat Ceph Storage 8EPSS 1.2%via CSAF
CVE-2025-8194High· 7.5
1y ago

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and dea…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.64%via NVD
CVE-2025-53547High· 8.5PoC
1y ago

helm.sh/helm/v3: Helm Chart Code Execution (CVE-2025-53547)

A command injection vulnerability has been identified in Helm, a package manager for Kubernetes. An attacker can craft a malicious Chart.yaml file with specially linked dependencies in a Chart.lock file. If the Chart.lock file is a symboli…

▾ MidnightRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9EPSS 0.38%via CSAF
CVE-2025-50181Medium· 5.3
1y ago

urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation (CVE-2025-50181)

A flaw was found in urllib3. The `PoolManager` class allows redirects to be disabled by configuring retries in a specific manner, effectively bypassing intended HTTP redirection behavior. A network attacker can leverage this configuration …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.47%via CSAF
CVE-2025-50182Medium· 5.3
1y ago

urllib3: urllib3 does not control redirects in browsers and Node.js (CVE-2025-50182)

A flaw was found in urllib3. The library fails to properly validate redirect URLs, allowing an attacker to manipulate redirect chains when used in environments like Pyodide utilizing the JavaScript Fetch API. This lack of validation can en…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.39%via CSAF
CVE-2025-6020High· 7.8
1y ago

A flaw was found in linux-pam

A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.

▾ TwilightRed Hat · linux-pamEPSS 0.46%via NVD
CVE-2025-49796Critical· 9.1
1y ago

A vulnerability was found in libxml2

A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, res…

▾ MidnightRed Hat · libxml2EPSS 1.6%via NVD
CVE-2025-49794Critical· 9.1
1y ago

A use-after-free vulnerability was found in libxml2

A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to …

▾ MidnightRed Hat · libxml2EPSS 0.83%via NVD
CVE-2025-22874High· 7.5
1y ago

crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509 (CVE-2025-22874)

A flaw was found in Go's crypto/x509 package. This vulnerability allows improper certificate validation, bypassing policy constraints via using ExtKeyUsageAny in VerifyOptions.KeyUsages.

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4.20EPSS 0.37%via CSAF
CVE-2025-5278Medium· 4.4
1y ago

A flaw was found in GNU Coreutils

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key fo…

▾ SunlitRed Hat · coreutilsEPSS 0.29%via NVD
Red Hat vulnerabilities (CVEs) — page 41 · VulnSea