redhat
353 known vulnerabilities affecting redhat products.
Products
enterprise_linux 215
openshift_container_platform 86
build_of_keycloak 64
hardened_images 48
enterprise_linux_eus 16
enterprise_linux_server 15
jboss_enterprise_application_platform 15
single_sign-on 15
quay 14
enterprise_linux_server_aus 14
enterprise_linux_for_power_little_endian 13
enterprise_linux_for_ibm_z_systems 13
enterprise_linux_workstation 13
enterprise_linux_server_tus 12
389_directory_server 12
directory_server 11
enterprise_linux_for_ibm_z_systems_eus 11
enterprise_linux_desktop 11
enterprise_linux_for_power_little_endian_eus 11
jboss_enterprise_application_platform_expansion_pack 11
enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 9
data_grid 9
openshift_update_service 8
jboss_core_services 7
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2025-13601 | Medium | 0.3% | 7.7 | A heap-based buffer overflow problem was found in glib through an incorrect calc… | |
| CVE-2024-1488 | Medium | 0.3% | 8.0 | A vulnerability was found in Unbound due to incorrect default permissions, allow… | |
| CVE-2026-15573 | Medium | 0.3% | 8.1 | A flaw was found in Keycloak's Authorization Services. The component responsible… | |
| CVE-2024-0646 | Medium | 0.3% | 7.0 | An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Lay… | |
| CVE-2026-2092 | Medium | 0.3% | 7.7 | A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAM… | |
| CVE-2026-54100 | Medium | 0.3% | 8.3 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenS… | |
| CVE-2026-66758 | Medium | 0.3% | 7.8 | A flaw was found in the file-fits plugin in GIMP. When processing a FITS image f… | |
| CVE-2026-59851 | Medium | 0.3% | 8.8 | A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssap… | |
| CVE-2026-13097 | Medium | 0.3% | 8.7 | A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enfo… | |
| CVE-2026-42965 | Medium | 0.3% | 7.7 | A flaw was found in the OpenShift Router. A user with EndpointSlice write access… | |
| CVE-2026-3012 | Medium | 0.3% | 8.0 | A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. W… | |
| CVE-2026-58380 | Medium | 0.3% | 7.3 | A flaw was found in GIMP's PNM file format parser. When parsing a specially craf… | |
| CVE-2026-66759 | Medium | 0.3% | 7.1 | A flaw was found in the file-icns plugin in GIMP. When applying a decompressed m… | |
| CVE-2025-7365 | Medium | 0.2% | 7.1 | A flaw was found in Keycloak. When an authenticated attacker attempts to merge a… | |
| CVE-2026-32589 | Medium | 0.2% | 7.4 | A flaw was found in Red Hat Quay's container image upload process. An authentica… | |
| CVE-2024-50074 | Medium | 0.2% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: parport: Pr… | |
| CVE-2026-19550 | Medium | 0.2% | 8.2 | A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-… | |
| CVE-2026-18378 | Medium | 0.2% | 7.6 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsC… | |
| CVE-2026-48864 | Medium | 0.2% | 7.8 | A flaw was found in libsolv. This heap buffer overflow occurs during the decompr… | |
| CVE-2023-6531 | Medium | 0.2% | 7.0 | A use-after-free flaw was found in the Linux Kernel due to a race problem in the… | |
| CVE-2026-13201 | Medium | 0.2% | 7.3 | A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAt… | |
| CVE-2026-16442 | Medium | 0.2% | 7.4 | A flaw was found in the SAML broker component of Keycloak, which is used to mana… | |
| CVE-2026-1784 | Medium | 0.2% | 8.8 | The Route OpenShift resource allows to define routes to make pods reachable at a… | |
| CVE-2026-18381 | Medium | 0.2% | 7.6 | A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operato… | |
| CVE-2026-11861 | Medium | 0.2% | 9.6 | A flaw was found in FreeIPA. When a trust relationship is configured between Fre… | |
| CVE-2026-54230 | Medium | 0.2% | 7.0 | A symlink following vulnerability was found in the ABRT post-create event handle… | |
| CVE-2026-16443 | Medium | 0.2% | 7.4 | A flaw was found in the SAML metadata import functionality of the keycloak-servi… | |
| CVE-2026-13601 | Medium | 0.2% | 7.1 | A flaw was found in Yelp due to an overly permissive Content Security Policy (CS… | |
| CVE-2026-6846 | Medium | 0.2% | 7.8 | A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when p… | |
| CVE-2026-50259 | Medium | 0.2% | 7.8 | A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland.… | |
| CVE-2026-42170 | Medium | 0.2% | 7.8 | A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Su… | |
| CVE-2026-50258 | Medium | 0.2% | 7.8 | A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland.… | |
| CVE-2026-50256 | Medium | 0.2% | 7.8 | A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland.… | |
| CVE-2026-50260 | Medium | 0.2% | 7.8 | A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounte… | |
| CVE-2026-50261 | Medium | 0.2% | 7.8 | A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChange… | |
| CVE-2026-4740 | Medium | 0.1% | 8.2 | A flaw was found in Open Cluster Management (OCM), the technology underlying Red… | |
| CVE-2026-50264 | Medium | 0.1% | 7.8 | An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIG… | |
| CVE-2026-50257 | Medium | 0.1% | 7.8 | A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDest… | |
| CVE-2026-53000 | Medium | 0.1% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: netfilter: … | |
| CVE-2026-53009 | Medium | 0.1% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: ice: fix do… | |
| CVE-2026-71226 | Medium | 0.1% | 7.3 | Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO … | |
| CVE-2025-14821 | Medium | 0.1% | 7.8 | A flaw was found in libssh. This vulnerability allows local man-in-the-middle at… | |
| CVE-2026-54099 | Medium | 0.1% | 8.8 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenS… | |
| CVE-2026-71474 | Medium | 0.1% | 7.1 | A flaw was found in insights-client. When the application receives a non-200 res… | |
| CVE-2026-13367 | Medium | 0.1% | 7.8 | IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation… | |
| CVE-2026-53153 | Medium | 0.1% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: mm/list_lru… | |
| CVE-2025-26465 | Low | 7.7% | 6.8 | A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled… | |
| CVE-2019-10219 | Low | 2.2% | 6.1 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotat… | |
| CVE-2024-8883 | Low | 2.1% | 6.1 | A misconfiguration flaw was found in Keycloak. This issue can allow an attacker … | |
| CVE-2024-12086 | Low | 1.8% | 6.1 | A flaw was found in rsync. It could allow a server to enumerate the contents of … |