VulnSea

redhat has 126 CVEs on record between 2010 and 2026. Cadence is steady at roughly 45 per quarter. The busiest recent month was July 2026 with 24. The median CVSS is 6.5 (medium), with 4 rated critical. 6% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 3915 days (7 cases). The dominant weakness classes are CWE-862 (9) and CWE-284 (6). Most affected products: build_of_keycloak (44), openshift_container_platform (15), advanced_cluster_management_for_kubernetes (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
6% vs 1% corpus
Median CVSS
6.5
Publish → KEV
3915 d median(7)
Last 90 days
45 prev 34

Products

  • build_of_keycloak 44
  • openshift_container_platform 15
  • advanced_cluster_management_for_kubernetes 5
  • automatic_bug_reporting_tool 5
  • hardened_images 5
  • jboss_enterprise_application_platform 5
126
Total CVEs
4
Critical
7
CISA KEV
8
Exploited

redhat vulnerabilities

CVEs affecting redhat, newest first. Open any entry for full detail, references, and exploit status.

126 CVEsRSS

CVE-2026-71846Medium· 6.5
1mo ago

A flaw was found in insights-client

A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive…

Sunlitredhat · advanced_cluster_management_for_kubernetesEPSS 0.12%via NVD
CVE-2026-71845Medium· 6.3
1mo ago

A flaw was found in insights-client

A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to le…

Sunlitredhat · advanced_cluster_management_for_kubernetesEPSS 0.28%via NVD
CVE-2026-71475Medium· 6.8
1mo ago

A flaw was found in insights-client

A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly…

Sunlitredhat · advanced_cluster_management_for_kubernetesEPSS 0.47%via NVD
CVE-2026-71474High· 7.1
1mo ago

A flaw was found in insights-client

A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read t…

Twilightredhat · advanced_cluster_management_for_kubernetesEPSS 0.11%via NVD
CVE-2026-16100Medium· 6.5
1mo ago

A flaw was found in the user-event metrics recording of Keycloak

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-s…

Sunlitredhat · build_of_keycloakEPSS 0.40%via NVD
CVE-2026-16071Medium· 5.4
1mo ago

A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories

A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished N…

Sunlitredhat · build_of_keycloakEPSS 0.23%via NVD
CVE-2026-15573High· 8.1
1mo ago

A flaw was found in Keycloak's Authorization Services

A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing…

Twilightredhat · build_of_keycloakEPSS 0.32%via NVD
CVE-2026-16102High· 8.1
1mo ago

A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution

A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to wri…

Twilightredhat · build_of_keycloakEPSS 0.32%via NVD
CVE-2026-71227Medium· 5.1
1mo ago

A flaw was found in libkcapi

A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can …

Sunlitredhat · hardened_imagesEPSS 0.17%via NVD
CVE-2026-71226High· 7.3
1mo ago

Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.

Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.

Twilightredhat · hardened_imagesEPSS 0.14%via NVD
CVE-2026-71225Medium· 6.5
1mo ago

A flaw was found in libkcapi

A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vec…

Sunlitredhat · hardened_imagesEPSS 0.33%via NVD
CVE-2026-18651Medium· 5.4
1mo ago

A flaw was found in 389 Directory Server

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is re…

Sunlitredhat · directory_serverEPSS 0.17%via NVD
CVE-2026-18573Medium· 6.5
1mo ago

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication…

Sunlitredhat · build_of_keycloakEPSS 0.27%via NVD
CVE-2026-18572Medium· 6.5
1mo ago

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours)

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake ti…

Sunlitredhat · build_of_keycloakEPSS 0.22%via NVD
CVE-2026-18571Medium· 6.6
1mo ago

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups t…

Sunlitredhat · build_of_keycloakEPSS 0.30%via NVD
CVE-2026-18570Medium· 5.4
1mo ago

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Key…

Sunlitredhat · build_of_keycloakEPSS 0.18%via NVD
CVE-2026-15722High· 7.5
1mo ago

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base)

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without b…

Twilightredhat · directory_serverEPSS 0.83%via NVD
CVE-2026-18218Medium· 4.2
1mo ago

A flaw was found in the TokenManager component of the Keycloak identity management service

A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently i…

Sunlitredhat · build_of_keycloakEPSS 0.17%via NVD
CVE-2026-18217Low· 3.4
1mo ago

A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution

A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect binding. If a client is…

Sunlitredhat · build_of_keycloakEPSS 0.19%via NVD
CVE-2026-18215Medium· 6.8
1mo ago

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant)

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means …

Sunlitredhat · build_of_keycloakEPSS 0.23%via NVD
CVE-2026-18211Medium· 4.2
1mo ago

A flaw was found in the secure-client-uris client policy executor within Keycloak core services

A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security requirements on client configurations, such as requiring encrypted connections for redi…

Sunlitredhat · build_of_keycloakEPSS 0.18%via NVD
CVE-2026-18209Low· 3.4
1mo ago

A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows

A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query p…

Sunlitredhat · build_of_keycloakEPSS 0.23%via NVD
CVE-2026-18208Medium· 6.5
1mo ago

A flaw was found in the OIDC token introspection endpoint of the keycloak-services component

A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a con…

Sunlitredhat · build_of_keycloakEPSS 0.20%via NVD
CVE-2026-18206Low· 3.7
1mo ago

A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services

A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a wildcard domain (like *.example.com) to restrict which hosts can …

Sunlitredhat · build_of_keycloakEPSS 0.20%via NVD
CVE-2026-16105Medium· 4.9
1mo ago

A flaw was found in the RoleContainerResource component of Keycloak

A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a de…

Sunlitredhat · build_of_keycloakEPSS 0.24%via NVD
CVE-2026-18214Medium· 6.8
1mo ago

Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains

Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloa…

Sunlitredhat · build_of_keycloakEPSS 0.22%via NVD
CVE-2026-18201Medium· 5.5
1mo ago

Keycloak provides a way to manage identity providers and organizations through its administrative API

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization…

Sunlitredhat · build_of_keycloakEPSS 0.27%via NVD
CVE-2026-17059Medium· 6.5
1mo ago

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has…

Sunlitredhat · build_of_keycloakEPSS 0.49%via NVD
CVE-2026-17048Medium· 5.5
1mo ago

A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients

A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper bound…

Sunlitredhat · build_of_keycloakEPSS 0.35%via NVD
CVE-2026-16103Medium· 4.3
2mo ago

A flaw was found in the keycloak-services component of Keycloak

A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handl…

Sunlitredhat · build_of_keycloakEPSS 0.34%via NVD
redhat vulnerabilities (CVEs) · VulnSea