redhat
353 known vulnerabilities affecting redhat products.
Products
enterprise_linux 215
openshift_container_platform 86
build_of_keycloak 64
hardened_images 48
enterprise_linux_eus 16
enterprise_linux_server 15
jboss_enterprise_application_platform 15
single_sign-on 15
quay 14
enterprise_linux_server_aus 14
enterprise_linux_for_power_little_endian 13
enterprise_linux_for_ibm_z_systems 13
enterprise_linux_workstation 13
enterprise_linux_server_tus 12
389_directory_server 12
directory_server 11
enterprise_linux_for_ibm_z_systems_eus 11
enterprise_linux_desktop 11
enterprise_linux_for_power_little_endian_eus 11
jboss_enterprise_application_platform_expansion_pack 11
enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 9
data_grid 9
openshift_update_service 8
jboss_core_services 7
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-2377 | Low | 0.4% | 6.5 | A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The … | |
| CVE-2026-16100 | Low | 0.4% | 6.5 | A flaw was found in the user-event metrics recording of Keycloak. When metrics a… | |
| CVE-2026-5704 | Low | 0.4% | 5.0 | A flaw was found in tar. A remote attacker could exploit this vulnerability by c… | |
| CVE-2026-12969 | Low | 0.4% | 5.3 | An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in s… | |
| CVE-2026-16093 | Low | 0.4% | 5.4 | Keycloak provides a mechanism called Client Policies to enforce security require… | |
| CVE-2026-8830 | Low | 0.4% | 4.3 | A flaw was found in Keycloak. An authenticated user can bypass configured WebAut… | |
| CVE-2026-14209 | Low | 0.4% | 4.3 | A vulnerability was discovered in Keycloak's Admin UI extension that allows cert… | |
| CVE-2025-5918 | Low | 0.4% | 3.9 | A vulnerability has been identified in the libarchive library. This flaw can be … | |
| CVE-2026-17048 | Low | 0.4% | 5.5 | A flaw was found in the Keycloak Admin REST API, which is used to manage securit… | |
| CVE-2026-9798 | Low | 0.3% | 4.3 | A flaw was found in Keycloak, an open-source identity and access management solu… | |
| CVE-2026-59850 | Low | 0.3% | 4.3 | A flaw was found in libssh. If data packets are processed after a channel is clo… | |
| CVE-2026-16103 | Low | 0.3% | 4.3 | A flaw was found in the keycloak-services component of Keycloak. This issue is a… | |
| CVE-2026-59848 | Low | 0.3% | 5.3 | A flaw was found in libssh. A malicious SFTP server can send responses for unkno… | |
| CVE-2026-15943 | Low | 0.3% | 5.5 | A flaw was found in the Keycloak keycloak-services component, which handles the … | |
| CVE-2026-59088 | Low | 0.3% | 5.5 | A flaw was found in GIMP. A signed integer overflow vulnerability exists in the … | |
| CVE-2026-59847 | Low | 0.3% | 5.9 | A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds usin… | |
| CVE-2026-14613 | Low | 0.3% | 4.3 | A vulnerability was discovered in Keycloak's administrative interface that allow… | |
| CVE-2026-71225 | Low | 0.3% | 6.5 | A flaw was found in libkcapi. When performing one-shot symmetric cipher operatio… | |
| CVE-2026-32591 | Low | 0.3% | 5.2 | A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an or… | |
| CVE-2025-4374 | Low | 0.3% | 6.5 | A flaw was found in Quay. When an organization acts as a proxy cache, and a user… | |
| CVE-2026-9689 | Low | 0.3% | 4.2 | A flaw was found in Keycloak, an open-source identity and access management solu… | |
| CVE-2025-6170 | Low | 0.3% | 2.5 | A flaw was found in the interactive shell of the xmllint command-line tool, used… | |
| CVE-2026-14615 | Low | 0.3% | 4.3 | A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation … | |
| CVE-2026-14614 | Low | 0.3% | 5.4 | A flaw was found in the ClientResource component of Keycloak's admin services wh… | |
| CVE-2026-15945 | Low | 0.3% | 4.3 | A flaw was found in the group search functionality of the Keycloak server's admi… | |
| CVE-2026-9087 | Low | 0.3% | 6.4 | A flaw was found in Keycloak. The cross-session verification proof is keyed only… | |
| CVE-2026-9149 | Low | 0.3% | 6.5 | A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when… | |
| CVE-2025-8283 | Low | 0.3% | 3.7 | A vulnerability was found in the netavark package, a network stack for container… | |
| CVE-2026-4426 | Low | 0.3% | 6.5 | A flaw was found in libarchive. An Undefined Behavior vulnerability exists in th… | |
| CVE-2026-74245 | Low | 0.3% | 5.9 | A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated att… | |
| CVE-2026-11986 | Low | 0.3% | 4.9 | A flaw was found in the admin-ui-ext component of Keycloak, which provides exten… | |
| CVE-2026-18571 | Low | 0.3% | 6.6 | A flaw was found in the user creation component of Keycloak when Fine-Grained Ad… | |
| CVE-2026-55653 | Low | 0.3% | 4.3 | A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vu… | |
| CVE-2026-59089 | Low | 0.3% | 5.5 | A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling P… | |
| CVE-2026-11790 | Low | 0.3% | 4.9 | A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plu… | |
| CVE-2026-58224 | Low | 0.3% | 6.5 | A flaw was found in Samba's CTDB, the clustered database service used by Samba. … | |
| CVE-2025-14243 | Low | 0.3% | 5.3 | A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an … | |
| CVE-2026-71845 | Low | 0.3% | 6.3 | A flaw was found in insights-client. The setDefault() function logs the value of… | |
| CVE-2026-11789 | Low | 0.3% | 4.9 | A flaw was found in 389 Directory Server. The SMD5 password storage plugin perfo… | |
| CVE-2026-11793 | Low | 0.3% | 4.9 | A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix(… | |
| CVE-2026-8922 | Low | 0.3% | 5.4 | A flaw was found in Keycloak. When both realm-level and client-level `notBefore`… | |
| CVE-2026-14781 | Low | 0.3% | 4.8 | A flaw exists in the org.keycloak.broker.oidc package where the OIDC broker inco… | |
| CVE-2026-18201 | Low | 0.3% | 5.5 | Keycloak provides a way to manage identity providers and organizations through i… | |
| CVE-2026-18573 | Low | 0.3% | 6.5 | A flaw was found in the keycloak-services component of Keycloak, which is used f… | |
| CVE-2026-18382 | Low | 0.3% | 6.8 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsC… | |
| CVE-2026-2366 | Low | 0.3% | 3.1 | A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycl… | |
| CVE-2026-74243 | Low | 0.3% | 6.5 | A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared k… | |
| CVE-2026-74242 | Low | 0.3% | 5.3 | A flaw was found in Red Hat Quay. An administrator of any repository, by knowing… | |
| CVE-2026-16104 | Low | 0.3% | 4.3 | A flaw was found in the authentication configuration endpoint of the keycloak-se… | |
| CVE-2026-3442 | Low | 0.3% | 6.1 | A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overfl… |