VulnSea

Red Hat has 1,289 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1042 in the last 90 days against 125 in the 90 before. The busiest recent month was September 2026 with 642. The median CVSS is 7.0 (high), with 57 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (97) and CWE-825 (89). Most affected products: Red Hat Enterprise Linux 9 (212), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
—(1)
Last 90 days
1042 prev 125

Products

  • Red Hat Enterprise Linux 9 212
  • Red Hat OpenShift Container Platform 4 95
  • Red Hat Enterprise Linux 10 62
  • Linux 57
  • Red Hat OpenShift AI (RHOAI) 45
  • Red Hat Enterprise Linux BaseOS (v. 10) 36
1289
Total CVEs
57
Critical
1
CISA KEV
1
Exploited

Red Hat vulnerabilities

CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.

1289 CVEsRSS

CVE-2025-4373Medium· 4.8
1y ago

A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function

A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite.

▾ SunlitRed Hat · glibEPSS 0.61%via NVD
CVE-2025-3501High· 8.2
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

▾ TwilightRed Hat · keycloakEPSS 0.46%via NVD
CVE-2025-32912Medium· 6.5
1y ago

A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference

A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.45%via NVD
CVE-2025-32910Medium· 6.5
1y ago

A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference

A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup client to crash.

▾ SunlitRed Hat · libsoupEPSS 0.45%via NVD
CVE-2025-32909Medium· 5.3
1y ago

A flaw was found in libsoup

A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause the libsoup client to crash.

▾ SunlitRed Hat · libsoupEPSS 0.52%via NVD
CVE-2025-2842Medium· 4.3
1y ago

A flaw was found in the Tempo Operator

A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to…

▾ SunlitRed Hat · tempo-operatorEPSS 0.38%via NVD
CVE-2025-2786Medium· 4.3
1y ago

A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance

A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extra…

▾ SunlitRed Hat · tempo-operatorEPSS 0.36%via NVD
CVE-2025-2559Medium· 4.9
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache…

▾ SunlitRed Hat · keycloakEPSS 0.69%via NVD
CVE-2024-40635Medium· 4.6PoC
1y ago

containerd: containerd has an integer overflow in User ID handling (CVE-2024-40635)

A flaw was found in containerd package. Containers launched with a User set as a UID:GID larger than the maximum 32-bit signed integer can cause an overflow condition where the container ultimately runs as root (UID 0). This issue could ca…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.29%via CSAF
CVE-2024-8176High· 7.5PoC
1y ago

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse ind…

▾ MidnightRed Hat · libexpatEPSS 1.3%via NVD
CVE-2025-1391Medium· 5.4
1y ago

A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern

A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leadin…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.41%via NVD
CVE-2024-11831Medium· 5.4
1y ago

A flaw was found in npm-serialize-javascript

A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject mali…

▾ SunlitRed Hat · serialize-javascriptEPSS 1.1%via NVD
CVE-2025-22866Medium· 5.3
1y ago

crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)

A flaw was found in the Golang crypto/internal/nistec package. Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le archi…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream E4S (v.8.8)EPSS 0.29%via CSAF
CVE-2025-0604Medium· 5.4
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate the new credentials against AD. This vulnerability allows users whose AD accounts are ex…

▾ SunlitRed Hat · keycloak-ldap-federationEPSS 0.59%via NVD
CVE-2025-5791High· 7.1
1y ago

users: `root` appended to group listings (CVE-2025-5791)

A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in th…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.20%via CSAF
CVE-2024-8447Medium· 5.9
1y ago

A security issue was discovered in the LRA Coordinator component of Narayana

A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the applicatio…

▾ SunlitRed Hat · Red Hat JBoss EAP 8.0 for RHEL 8EPSS 0.69%via NVD
CVE-2024-45497High· 7.6
1y ago

A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod

A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credenti…

▾ TwilightRed Hat · openshiftEPSS 0.55%via NVD
CVE-2024-12397High· 7.4
1y ago

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoo…

▾ TwilightRed Hat · Cryostat 4 on RHEL 9EPSS 0.82%via NVD
CVE-2024-9666Medium· 4.7
1y ago

A vulnerability was found in the Keycloak Server

A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accep…

▾ SunlitRed Hat · keycloakEPSS 0.40%via NVD
CVE-2024-10492Low· 2.7
1y ago

A vulnerability was found in Keycloak

A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order t…

▾ SunlitRed Hat · keycloakEPSS 0.71%via NVD
CVE-2024-10451Medium· 5.9
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during the Keycloak build process and embedded as default values in bytecode, leading to unintended information disclosu…

▾ SunlitRed Hat · rhbk/keycloak-operator-bundleEPSS 0.92%via NVD
CVE-2024-10270Medium· 6.5
1y ago

A vulnerability was found in the Keycloak-services package

A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.

▾ SunlitRed Hat · keycloakEPSS 1.3%via NVD
CVE-2024-51744Low· 3.1
1y ago

golang-jwt: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt (CVE-2024-517…

A flaw was found in the golang-jwt package. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are not checking errors in the way they should be. Especially, if a token is both expired and in…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4.16EPSS 0.51%via CSAF
CVE-2024-10006High· 8.3
1y ago

hashicorp/consul: consul: Consul L7 Intentions Vulnerable To Headers Bypass (CVE-2024-10006)

A flaw was found in HashiCorp Consul and Consul Enterprise. The server response does not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and can lead to reflected cross-site scripting (XSS).

▾ TwilightRed Hat · Red Hat OpenShift Dev Spaces (RHOSDS) 3.23EPSS 0.47%via CSAF
CVE-2024-8775Medium· 5.5
2y ago

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without se…

▾ SunlitRed Hat · ansible-coreEPSS 0.27%via NVD
CVE-2024-3653Medium· 5.3
2y ago

A vulnerability was found in Undertow

A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the…

▾ SunlitRed Hat · undertowEPSS 1.9%via NVD
CVE-2024-5042Medium· 6.6
2y ago

A flaw was found in the Submariner project

A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromis…

▾ SunlitRed Hat · submariner-operatorEPSS 0.51%via NVD
CVE-2024-4029Medium· 4.1
2y ago

A vulnerability was found in Wildfly’s management interface

A vulnerability was found in Wildfly’s management interface. Due to the lack of limitation of sockets for the management interface, it may be possible to cause a denial of service hitting the nofile limit as there is no possibility to co…

▾ SunlitRed Hat · wildflyEPSS 0.28%via NVD
CVE-2023-6717Medium· 6.0
2y ago

A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk

A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This is…

▾ SunlitRed Hat · keycloakEPSS 0.71%via NVD
CVE-2024-1249High· 7.4
2y ago

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly i…

▾ TwilightRed Hat · keycloakEPSS 0.44%via NVD
Red Hat vulnerabilities (CVEs) — page 42 · VulnSea