Red Hat has 1,283 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1041 in the last 90 days against 120 in the 90 before. The busiest recent month was September 2026 with 636. The median CVSS is 7.0 (high), with 58 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (97) and CWE-825 (89). Most affected products: Red Hat Enterprise Linux 9 (212), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.0
- Publish → KEV
- —(1)
- Last 90 days
- 1041 prev 120
Weakness classes
Products
- Red Hat Enterprise Linux 9 212
- Red Hat OpenShift Container Platform 4 95
- Red Hat Enterprise Linux 10 62
- Linux 57
- Red Hat OpenShift AI (RHOAI) 45
- Red Hat Enterprise Linux BaseOS (v. 10) 36
Worst active — by depth score
CVE-2026-64849High· 8.5mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS …74CVE-2025-68664Critical· 9.3langchain-core: LangChain: Arbitrary code execution via serialization injection (CVE-2025-68664)72CVE-2026-40453Critical· 9.9The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'67CVE-2026-76578Critical· 9.8A flaw was found in FreeIPA66CVE-2026-64564Critical· 9.8In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport …66
Red Hat vulnerabilities
CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.
1283 CVEsRSS
CVE-2026-90994Medium· 4.0A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data()
A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the PAM responder's UNIX socket can exploit this by negotiating p…
CVE-2026-90947High· 7.8A flaw was found in GIMP
A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not properly validate the number of light sources. This can lead to an out-of-bounds write, corrupting memory. An attack…
CVE-2026-90463Medium· 4.0A flaw was found in the sssd NSS responder
A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to cause an out-of-bounds read. This out-of…
CVE-2026-90698Medium· 5.3PoCA security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43
A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds…
CVE-2024-23176Medium· 5.4PoCAn issue was discovered in the MassMessage extension in MediaWiki before 1.40.2
An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.
CVE-2026-88932Medium· 5.3multer is a Node.js middleware for handling multipart/form-data uploads
multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes that complete after multer has already run its abort cleanup a…
CVE-2026-90949High· 7.8A flaw was found in GIMP's PSP (Paint Shop Pro) file loader
A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size and the amount of data decompressed. …
CVE-2026-90948High· 7.8A flaw was found in GIMP's ICO file loader
A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This leads to an undersized buffer being allocate…
CVE-2026-90678High· 7.5An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5
An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic…
CVE-2026-90779High· 7.5SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters
SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to …
CVE-2026-90560High· 8.2PoCzstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds
zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply …
CVE-2026-80948Medium· 5.5kernel: wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() (CVE-2026-80948)
A flaw was found in the Linux kernel's iwlwifi driver. An error handling issue within the `iwl_op_mode_dvm_start()` function can cause a memory leak. This occurs when certain error paths bypass a memory deallocation step, leading to unrele…
CVE-2026-89773Medium· 5.5kernel: drm/amd/display: Skip Update HDCP Config In Transition State (CVE-2026-89773)
A flaw was found in the `drm/amd/display` component of the Linux kernel. This vulnerability occurs because the High-bandwidth Digital Content Protection (HDCP) configuration routine is skipped during a transition state when an invalid `dm_…
CVE-2026-89722Medium· 5.5kernel: PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io() (CVE-2026-89722)
A flaw was found in the Linux kernel's PCI/sysfs component. A local user with root privileges could trigger an out-of-bounds read in the `pci_write_legacy_io()` function by writing to the `legacy_io` sysfs file with a size less than four b…
CVE-2026-89642High· 7.0kernel: cifs: call pagecache_isize_extended() in cifs_setsize() when extending (CVE-2026-89642)
A flaw was found in the Linux kernel's Common Internet File System (CIFS) implementation. When a client extends a file, the `cifs_setsize()` function fails to properly zero out the newly extended portion of the page cache. This oversight c…
CVE-2026-89637High· 7.0⚖ disputedkernel: smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 (CVE-2026-89637)
A flaw was found in the Linux kernel's Server Message Block (SMB) client. When processing a malformed secondary TRANSACT2 response, a use-after-free (UAF) vulnerability and a buffer leak can occur in the `cifs_check_trans2()` function. Thi…
CVE-2026-89556Medium· 5.5kernel: module: validate string table section types (CVE-2026-89556)
A flaw was found in the Linux kernel. This vulnerability arises from insufficient validation of string table section types within ELF (Executable and Linkable Format) files. A local attacker could exploit this by providing a specially craf…
CVE-2026-81004Medium· 5.5⚖ disputedkernel: ipmi:msghandler: Cancel work cleanly on an error (CVE-2026-81004)
A flaw was found in the Linux kernel's Intelligent Platform Management Interface (IPMI) message handler. When an error occurs during the startup of an IPMI interface, scheduled work may not be properly canceled. This can prevent the interf…
CVE-2026-80998Medium· 5.5kernel: net: bnxt: ring the doorbell when SW USO exits early (CVE-2026-80998)
A flaw was found in the Linux kernel's `bnxt` network driver. When processing a burst of packets, the driver may fail to notify the network device (ring the doorbell) if the Software UDP Segmentation Offload (SW USO) path exits prematurely…
CVE-2026-80997Medium· 5.5⚖ disputedkernel: net: ipa: fix stalled modem TX queue after runtime resume (CVE-2026-80997)
A flaw was found in the Linux kernel's IP Accelerator (IPA) network driver. Specifically, the `ipa_start_xmit()` function incorrectly manages the transmit (TX) queue during a device's runtime resume process. This can lead to the TX queue s…
CVE-2026-80995Medium· 5.5⚖ disputedkernel: net: mctp: hold a reference to the route device in mctp_route_lookup() (CVE-2026-80995)
A flaw was found in the Linux kernel's MCTP (Message Control Transport Protocol) networking implementation. This vulnerability arises because the `mctp_route_lookup()` function accesses a route device without holding a persistent reference…
CVE-2026-80991Medium· 5.5⚖ disputedkernel: net: ravb: serialize PTP clock teardown (CVE-2026-80991)
A flaw was found in the Linux kernel's `net: ravb` module. A race condition exists during the Precision Time Protocol (PTP) clock teardown. This allows the `ravb_ptp_interrupt()` function to attempt to use a PTP clock after it has been fre…
CVE-2026-80986High· 7.0⚖ disputedkernel: net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages (CVE-2026-80986)
A flaw was found in the Linux kernel's SMC-Rv2 network component. A remote attacker could exploit this vulnerability by sending a specially crafted message during an SMC-Rv2 link addition. This can lead to a slab-out-of-bounds write, poten…
CVE-2026-80985High· 7.0⚖ disputedkernel: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry (CVE-2026-80985)
A flaw was found in the Linux kernel's Server Message Block over Remote Direct Memory Access (SMC-Rv2) protocol implementation. The `smc_llc_rmt_delete_rkey()` and `smc_llc_save_add_link_rkeys()` functions incorrectly handle oversized LLC …
CVE-2026-80981High· 7.0⚖ disputedkernel: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() (CVE-2026-80981)
A flaw was found in the Linux kernel's net/smc component. A local attacker could exploit a use-after-free vulnerability in the `smc_llc_srv_add_link()` function, where a freed memory region is improperly accessed. This can lead to memory c…
CVE-2026-80980Medium· 5.5⚖ disputedkernel: net/smc: stop killed, freed and out_of_sync sharing a byte (CVE-2026-80980)
A flaw was found in the Linux kernel's SMC (Server Message Block over Remote Direct Memory Access) protocol implementation. A concurrency issue exists where three connection state flags (killed, freed, and out_of_sync) share a single byte …
CVE-2026-80975Medium· 5.5⚖ disputedkernel: mfd: qnap-mcu: keep the reply buffer alive past a command timeout (CVE-2026-80975)
A flaw was found in the Linux kernel's `qnap-mcu` driver. This vulnerability occurs when the driver processes commands and a reply from the Microcontroller Unit (MCU) arrives after a command has timed out or failed. The driver may write th…
CVE-2026-80962Medium· 5.5kernel: dm-pcache: validate geometry fields from on-disk cache_info (CVE-2026-80962)
A flaw was found in the Linux kernel's dm-pcache component. A local attacker with administrative privileges (CAP_SYS_ADMIN) could manipulate on-disk cache metadata to provide invalid geometry fields. This manipulation could lead to an out-…
CVE-2026-80961Medium· 5.5⚖ disputedkernel: dm-pcache: validate kset key_num and intra-segment bounds (CVE-2026-80961)
A flaw was found in the `dm-pcache` component of the Linux kernel. A local attacker with `CAP_SYS_ADMIN` capabilities could exploit unbounded fields decoded from the cache device. This could lead to an out-of-bounds read, potentially discl…
CVE-2026-80959Medium· 5.5⚖ disputedkernel: dm-pcache: bound the persisted tail-position offset (CVE-2026-80959)
A flaw was found in the Linux kernel's device-mapper persistent cache (dm-pcache) component. A local attacker with administrative privileges (CAP_SYS_ADMIN) could provide a specially crafted cache device, leading to an out-of-bounds read. …