VulnSea

redhat has 126 CVEs on record between 2010 and 2026. Cadence is steady at roughly 45 per quarter. The busiest recent month was July 2026 with 24. The median CVSS is 6.5 (medium), with 4 rated critical. 6% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 3915 days (7 cases). The dominant weakness classes are CWE-862 (9) and CWE-284 (6). Most affected products: build_of_keycloak (44), openshift_container_platform (15), advanced_cluster_management_for_kubernetes (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
6% vs 1% corpus
Median CVSS
6.5
Publish → KEV
3915 d median(7)
Last 90 days
45 prev 34

Products

  • build_of_keycloak 44
  • openshift_container_platform 15
  • advanced_cluster_management_for_kubernetes 5
  • automatic_bug_reporting_tool 5
  • hardened_images 5
  • jboss_enterprise_application_platform 5
126
Total CVEs
4
Critical
7
CISA KEV
8
Exploited

redhat vulnerabilities

CVEs affecting redhat, newest first. Open any entry for full detail, references, and exploit status.

126 CVEsRSS

CVE-2026-9793Medium· 5.9
3mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This …

Sunlitredhat · build_of_keycloakEPSS 0.16%via NVD
CVE-2026-4408Critical· 9.0PoC
3mo ago

A flaw was found in Samba

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution characte…

Abyssalredhat · openshift_container_platformEPSS 2.5%via NVD
CVE-2026-9689Medium· 4.2
3mo ago

A flaw was found in Keycloak, an open-source identity and access management solution

A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authenticati…

Sunlitredhat · build_of_keycloakEPSS 0.32%via NVD
CVE-2026-2340Medium· 6.5
3mo ago

A flaw was found in Samba’s vfs_worm module

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename o…

Sunlitredhat · openshift_container_platformEPSS 0.94%via NVD
CVE-2026-1933High· 7.1
3mo ago

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete re…

Twilightredhat · openshift_container_platformEPSS 0.86%via NVD
CVE-2026-3012High· 8.0
3mo ago

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store…

Twilightredhat · openshift_container_platformEPSS 0.26%via NVD
CVE-2026-7163Medium· 6.1
4mo ago

A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrativ…

A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrativ…

Sunlitredhat · multicluster_engine_for_kubernetesEPSS 0.19%via NVD
CVE-2026-31431High· 7.8CISA KEVPoC
5mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in op…

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in op…

Abyssalredhat · openshift_container_platformEPSS 100%via NVD
CVE-2025-57847Medium· 6.4
5mo ago

A container privilege escalation flaw was found in certain Ansible Automation Platform images

A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an …

Sunlitredhat · ansible_automation_platformEPSS 0.16%via NVD
CVE-2025-14243Medium· 5.3
5mo ago

A flaw was found in the OpenShift Mirror Registry

A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account cre…

Sunlitredhat · mirror_registry_for_red_hat_openshiftEPSS 0.29%via NVD
CVE-2026-32591Medium· 5.2
5mo ago

A flaw was found in Red Hat Quay's Proxy Cache configuration feature

A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verify…

Sunlitredhat · mirror_registry_for_red_hat_openshiftEPSS 0.33%via NVD
CVE-2026-32590High· 7.1
5mo ago

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code …

Twilightredhat · mirror_registry_for_red_hat_openshiftEPSS 0.41%via NVD
CVE-2026-32589High· 7.4
5mo ago

A flaw was found in Red Hat Quay's container image upload process

A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they…

Twilightredhat · mirror_registry_for_red_hat_openshiftEPSS 0.24%via NVD
CVE-2026-2377Medium· 6.5
5mo ago

A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift

A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to specify an arbitrary callback URL. A backend process then makes server-side HTTP request…

Sunlitredhat · mirror_registry_for_red_hat_openshiftEPSS 0.40%via NVD
CVE-2026-4740High· 8.2
5mo ago

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM)

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client…

Twilightredhat · advanced_cluster_management_for_kubernetesEPSS 0.15%via NVD
CVE-2026-2625Medium· 4.0
5mo ago

A flaw was found in rust-rpm-sequoia

A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error i…

Sunlitredhat · hardened_imagesEPSS 0.08%via NVD
CVE-2026-28369High· 8.7
5mo ago

A flaw was found in Undertow

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP s…

Twilightredhat · build_of_apache_camel_-_hawtioEPSS 0.68%via NVD
CVE-2026-28368High· 8.7
5mo ago

A flaw was found in Undertow

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretati…

Twilightredhat · build_of_apache_camel_-_hawtioEPSS 0.70%via NVD
CVE-2026-28367High· 8.7
5mo ago

A flaw was found in Undertow

A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic …

Twilightredhat · build_of_apache_camel_-_hawtioEPSS 0.71%via NVD
CVE-2026-2603High· 8.1
6mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attac…

Twilightredhat · build_of_keycloakEPSS 0.43%via NVD
CVE-2025-8766Medium· 6.4
6mo ago

A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images

A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an atta…

Sunlitredhat · openshift_data_foundationEPSS 0.17%via NVD
CVE-2026-2366Low· 3.1
6mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This inf…

Sunlitredhat · build_of_keycloakEPSS 0.27%via NVD
CVE-2026-3429Medium· 4.2
6mo ago

A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions

A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obta…

Sunlitredhat · build_of_keycloakEPSS 0.25%via NVD
CVE-2026-3009High· 8.1
6mo ago

A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator

A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can…

Twilightredhat · build_of_keycloakEPSS 0.33%via NVD
CVE-2025-12150Low· 3.1
6mo ago

A flaw was found in Keycloak’s WebAuthn registration component

A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object wit…

Sunlitredhat · build_of_keycloakEPSS 0.20%via NVD
CVE-2025-12543Critical· 9.6PoC
8mo ago

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containi…

Abyssalredhat · build_of_apache_camelEPSS 1.4%via NVD
CVE-2025-13601High· 7.7
9mo ago

A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function

A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would ne…

Twilightredhat · codeready_linux_builderEPSS 0.32%via NVD
CVE-2025-9784High· 7.5PoC
1y ago

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive serv…

Midnightredhat · build_of_apache_camel_for_spring_bootEPSS 2.3%via NVD
CVE-2025-8419Medium· 5.3
1y ago

A vulnerability was found in Keycloak-services

A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Injection and unexpectedly send short unwanted e-mails. The email is limited to 64 characters (limited local part of the …

Sunlitredhat · keycloakEPSS 0.41%via NVD
CVE-2025-8283Low· 3.7
1y ago

A vulnerability was found in the netavark package, a network stack for containers used with Podman

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When …

Sunlitredhat · openshift_container_platformEPSS 0.31%via NVD
redhat vulnerabilities (CVEs) — page 3 · VulnSea