VulnSea

Red Hat has 1,331 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1068 in the last 90 days against 140 in the 90 before. The busiest recent month was September 2026 with 657. The median CVSS is 7.0 (high), with 59 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (98) and CWE-825 (93). Most affected products: Red Hat Enterprise Linux 9 (216), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
—(1)
Last 90 days
1068 prev 140

Products

  • Red Hat Enterprise Linux 9 216
  • Red Hat OpenShift Container Platform 4 95
  • Red Hat Enterprise Linux 10 62
  • Linux 57
  • Red Hat OpenShift AI (RHOAI) 47
  • Red Hat Enterprise Linux BaseOS (v. 10) 38
1331
Total CVEs
59
Critical
1
CISA KEV
1
Exploited

Red Hat vulnerabilities

CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.

1331 CVEsRSS

CVE-2024-9666Medium· 4.7
1y ago

A vulnerability was found in the Keycloak Server

A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accep…

▾ SunlitRed Hat · keycloakEPSS 0.40%via NVD
CVE-2024-10492Low· 2.7
1y ago

A vulnerability was found in Keycloak

A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order t…

▾ SunlitRed Hat · keycloakEPSS 0.71%via NVD
CVE-2024-10451Medium· 5.9
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during the Keycloak build process and embedded as default values in bytecode, leading to unintended information disclosu…

▾ SunlitRed Hat · rhbk/keycloak-operator-bundleEPSS 0.92%via NVD
CVE-2024-10270Medium· 6.5
1y ago

A vulnerability was found in the Keycloak-services package

A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.

▾ SunlitRed Hat · keycloakEPSS 1.3%via NVD
CVE-2024-51744Low· 3.1
1y ago

golang-jwt: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt (CVE-2024-517…

A flaw was found in the golang-jwt package. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are not checking errors in the way they should be. Especially, if a token is both expired and in…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4.16EPSS 0.51%via CSAF
CVE-2024-10006High· 8.3
1y ago

hashicorp/consul: consul: Consul L7 Intentions Vulnerable To Headers Bypass (CVE-2024-10006)

A flaw was found in HashiCorp Consul and Consul Enterprise. The server response does not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and can lead to reflected cross-site scripting (XSS).

▾ TwilightRed Hat · Red Hat OpenShift Dev Spaces (RHOSDS) 3.23EPSS 0.47%via CSAF
CVE-2024-8775Medium· 5.5
2y ago

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without se…

▾ SunlitRed Hat · ansible-coreEPSS 0.27%via NVD
CVE-2024-3653Medium· 5.3
2y ago

A vulnerability was found in Undertow

A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the…

▾ SunlitRed Hat · undertowEPSS 1.9%via NVD
CVE-2024-5042Medium· 6.6
2y ago

A flaw was found in the Submariner project

A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromis…

▾ SunlitRed Hat · submariner-operatorEPSS 0.51%via NVD
CVE-2024-4029Medium· 4.1
2y ago

A vulnerability was found in Wildfly’s management interface

A vulnerability was found in Wildfly’s management interface. Due to the lack of limitation of sockets for the management interface, it may be possible to cause a denial of service hitting the nofile limit as there is no possibility to co…

▾ SunlitRed Hat · wildflyEPSS 0.28%via NVD
CVE-2023-6717Medium· 6.0
2y ago

A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk

A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This is…

▾ SunlitRed Hat · keycloakEPSS 0.70%via NVD
CVE-2024-1249High· 7.4
2y ago

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly i…

▾ TwilightRed Hat · keycloakEPSS 0.44%via NVD
CVE-2024-28869High· 7.5
2y ago

traefik: denial of service (CVE-2024-28869)

An improper handling of exceptional conditions vulnerability was found in Traefik. In affected versions, sending a GET request to any Traefik endpoint with the "Content-length" request header results in an indefinite hang with the default …

▾ TwilightRed Hat · Red Hat OpenShift Dev Spaces (RHOSDS) 3.23EPSS 1.0%via CSAF
CVE-2024-1300Medium· 5.4
2y ago

A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support

A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped certificate, the SSL c…

▾ SunlitRed Hat · io.vertx:vertx-coreEPSS 1.1%via NVD
CVE-2024-1023Medium· 6.5PoC
2y ago

A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures

A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. …

▾ TwilightRed Hat · vertx-coreEPSS 1.7%via NVD
CVE-2024-1313Medium· 6.5
2y ago

grafana: vulnerable to authorization bypass (CVE-2024-1313)

A vulnerability was found in Grafana. Due to an error in authorization logic, it is possible for an unprivileged user in a different organization other than the snapshot owner to perform unauthorized actions such as deleting it using a vie…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.65%via CSAF
CVE-2023-5685High· 7.5
2y ago

A flaw was found in XNIO

A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large can lead to uncontrolled resource management and a possible denial of service (DoS).

▾ TwilightRed Hat · xnioEPSS 3.5%via NVD
CVE-2024-1753High· 8.6PoC
2y ago

A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers

A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the ro…

▾ MidnightRed Hat · buildahEPSS 0.49%via NVD
CVE-2024-1442Medium· 6.0
2y ago

grafana: Improper priviledge managent for users with data source permissions (CVE-2024-1442)

A flaw was found in Grafana, where setting the Grafana API Data Source UID to '*' Grants Unrestricted Access, grants a user the ability to set the UID to '*' via the Grafana API poses a severe security risk. This issue enables unauthorized…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9EPSS 0.80%via CSAF
CVE-2024-27304High· 8.1PoC
2y ago

pgx: SQL Injection via Protocol Message Size Overflow (CVE-2024-27304)

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be…

▾ MidnightRed Hat · RHACS 4.3 for RHEL 8EPSS 1.1%via CSAF
CVE-2023-4822Medium· 6.7
2y ago

grafana: incorrect assessment of permissions across organizations (CVE-2023-4822)

A flaw was found in the Grafana enterprise package. Grafana is incorrectly assessing permissions to update global roles and role assignments, therefore, users with administrator permissions in one organization can change global role permis…

▾ SunlitRed Hat · Red Hat Ceph Storage 7.1 ToolsEPSS 1.1%via CSAF
CVE-2023-28842Medium· 6.8
3y ago

moby: Encrypted overlay network with a single endpoint is unauthenticated (CVE-2023-28842)

A vulnerability was found in Moby due to an unprotected alternate channel within encrypted overlay networks, which could allow a remote attacker to bypass security restrictions. By sending a specially crafted request, an attacker could inj…

▾ SunlitRed Hat · multicluster engine for Kubernetes 2.4 for RHEL 8EPSS 1.4%via CSAF
CVE-2023-27534Low· 3.7PoC⚖ disputed
3y ago

curl: SFTP path ~ resolving discrepancy (CVE-2023-27534)

A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicat…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 9)EPSS 2.2%via CSAF
CVE-2023-27522High· 7.5
3y ago

httpd: mod_proxy_uwsgi HTTP response splitting (CVE-2023-27522)

An HTTP Response Smuggling vulnerability was found in the Apache HTTP Server via mod_proxy_uwsgi. This security issue occurs when special characters in the origin response header can truncate or split the response forwarded to the client.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream EUS (v.8.6)EPSS 2.1%via CSAF
CVE-2023-0594High· 7.3
3y ago

grafana: cross site scripting (CVE-2023-0594)

A flaw was found in the grafana package. This flaw allows a malicious user with the ability to introduce trace data to provide a JavaScript that changes the password for the user viewing the trace view (this could be an admin) to a known p…

▾ TwilightRed Hat · Red Hat Ceph Storage 5.3 ToolsEPSS 9.2%via CSAF
CVE-2023-25153Medium· 5.5
3y ago

containerd: OCI image importer memory exhaustion (CVE-2023-25153)

A flaw was found in containerd. When importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file, where a limit was not applied could cause a denial of service.

▾ SunlitRed Hat · Red Hat Ceph Storage 9.0 ToolsEPSS 0.36%via CSAF
CVE-2023-0286High· 7.4
3y ago

openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286)

A type confusion vulnerability was found in OpenSSL when OpenSSL X.400 addresses processing inside an X.509 GeneralName. When CRL checking is enabled (for example, the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability ma…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 60%via CSAF
CVE-2022-39324Medium· 6.7
3y ago

grafana: Spoofing of the originalUrl parameter of snapshots (CVE-2022-39324)

A flaw was found in the grafana package. While creating a snapshot, an attacker may manipulate a hidden HTTP parameter to inject a malicious URL in the "Open original dashboard" button.

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.83%via CSAF
CVE-2022-41721High· 7.5
3y ago

x/net/http2/h2c: request smuggling (CVE-2022-41721)

A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead read the b…

▾ TwilightRed Hat · OpenShift Service Mesh 2.1EPSS 1.8%via CSAF
CVE-2022-23524High· 7.5⚖ disputed
3y ago

helm: Denial of service through string value parsing (CVE-2022-23524)

A flaw was found in Helm, a tool for managing Charts, a pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption. Input to functions in the _strvals_ package could cause a stack overflo…

▾ TwilightRed Hat · RHACS 4.0 for RHEL 8EPSS 0.78%via CSAF
Red Hat vulnerabilities (CVEs) — page 44 · VulnSea