redhat has 126 CVEs on record between 2010 and 2026. Cadence is steady at roughly 45 per quarter. The busiest recent month was July 2026 with 24. The median CVSS is 6.5 (medium), with 4 rated critical. 6% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 3915 days (7 cases). The dominant weakness classes are CWE-862 (9) and CWE-284 (6). Most affected products: build_of_keycloak (44), openshift_container_platform (15), advanced_cluster_management_for_kubernetes (5).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 6% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- 3915 d median(7)
- Last 90 days
- 45 prev 34
Products
- build_of_keycloak 44
- openshift_container_platform 15
- advanced_cluster_management_for_kubernetes 5
- automatic_bug_reporting_tool 5
- hardened_images 5
- jboss_enterprise_application_platform 5
Worst active — by depth score
CVE-2017-12149Critical· 9.8In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserializatio…100CVE-2021-40438Critical· 9.0A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user99CVE-2026-31431High· 7.8In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in op…88CVE-2010-1428High· 7.5The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allow…84CVE-2010-0738Medium· 5.3The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows …75
redhat vulnerabilities
CVEs affecting redhat, newest first. Open any entry for full detail, references, and exploit status.
126 CVEsRSS
CVE-2026-16108Medium· 4.3A flaw was found in the default-groups REST endpoint and realm representation of Keycloak
A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated admini…
CVE-2026-16106Medium· 4.9A flaw was found in the admin REST API of Keycloak, a solution for identity and access management
A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks…
CVE-2026-16104Medium· 4.3A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management
A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask se…
CVE-2026-16093Medium· 5.4Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication
Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker wit…
CVE-2026-16089Medium· 5.4A flaw was found in the keycloak-services component of Red Hat Build of Keycloak
A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept a…
CVE-2026-16072Medium· 4.9A flaw was found in the organization management component of Keycloak
A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration …
CVE-2026-15943Medium· 5.5A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers
A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel val…
CVE-2026-15945Medium· 4.3A flaw was found in the group search functionality of the Keycloak server's administrative API
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they…
CVE-2026-1609High· 8.1A flaw was found in Keycloak
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A…
CVE-2026-15154Medium· 6.5A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI
A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the …
CVE-2026-13757Medium· 6.2A flaw was found in p11-kit
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing n…
CVE-2026-12993Medium· 6.5A flaw was found in Apicurio Registry
A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. An attacker with artifact-write permission …
CVE-2026-12992High· 7.4A flaw was found in Apicurio Registry
A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. When the VALIDITY rule is set to FULL, an attacker with Developer-role access can upload …
CVE-2026-12975High· 8.5A flaw was found in Apicurio Registry
A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure processing features or disabling external entity resolution. An attacker with artifact-write permission …
CVE-2026-9800High· 8.1A flaw was found in Keycloak Policy Enforcer
A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured acce…
CVE-2026-11819Medium· 5.5Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from the OS native keyring (GNOME Keyring, macOS Keychain, Windows Credential Manager) and pl…
Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from the OS native keyring (GNOME Keyring, macOS Keychain, Windows Credential Manager) and pl…
CVE-2026-12112High· 7.8A flaw was found in the foreman-mcp-server
A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of authenticated client connections, by t…
CVE-2026-9073Medium· 6.2A flaw was found in foreman-mcp-server
A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session identifiers, which are treated as authentication creden…
CVE-2026-12725Medium· 5.9A heap-based buffer overflow was found in dnsmasq
A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an …
CVE-2026-54100High· 8.3A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker …
CVE-2026-54099High· 8.8A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not rej…
CVE-2026-54231Medium· 5.5A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport
A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump…
CVE-2026-54230High· 7.0A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink,…
CVE-2026-11788Medium· 5.9A flaw was found in 389 Directory Server
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under me…
CVE-2026-11793Medium· 4.9A stack buffer overflow flaw was found in 389 Directory Server
A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribut…
CVE-2026-1784High· 8.8The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a contro…
CVE-2026-42965High· 7.7A flaw was found in the OpenShift Router
A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoin…
CVE-2026-46579High· 7.4A flaw was found in the OpenShift Router
A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send p…
CVE-2026-9796Medium· 6.5A flaw was found in Keycloak
A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their…
CVE-2026-9798Medium· 4.3A flaw was found in Keycloak, an open-source identity and access management solution
A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initi…