redhat
353 known vulnerabilities affecting redhat products.
Products
enterprise_linux 215
openshift_container_platform 86
build_of_keycloak 64
hardened_images 48
enterprise_linux_eus 16
enterprise_linux_server 15
jboss_enterprise_application_platform 15
single_sign-on 15
quay 14
enterprise_linux_server_aus 14
enterprise_linux_for_power_little_endian 13
enterprise_linux_for_ibm_z_systems 13
enterprise_linux_workstation 13
enterprise_linux_server_tus 12
389_directory_server 12
directory_server 11
enterprise_linux_for_ibm_z_systems_eus 11
enterprise_linux_desktop 11
enterprise_linux_for_power_little_endian_eus 11
jboss_enterprise_application_platform_expansion_pack 11
enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 9
data_grid 9
openshift_update_service 8
jboss_core_services 7
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-11787 | Low | 0.2% | 5.0 | A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads byt… | |
| CVE-2026-54231 | Low | 0.2% | 5.5 | A content injection vulnerability was found in the ABRT post-create event handle… | |
| CVE-2024-0639 | Low | 0.2% | 5.5 | A denial of service vulnerability due to a deadlock was found in sctp_auto_ascon… | |
| CVE-2026-74240 | Low | 0.2% | 5.4 | A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated… | |
| CVE-2026-13595 | Low | 0.2% | 6.8 | A flaw was found in the libblkid library of util-linux. During nested partition … | |
| CVE-2026-18218 | Low | 0.2% | 4.2 | A flaw was found in the TokenManager component of the Keycloak identity manageme… | |
| CVE-2026-4647 | Low | 0.2% | 6.1 | A flaw was found in the GNU Binutils BFD library, a widely used component for ha… | |
| CVE-2026-18651 | Low | 0.2% | 5.4 | A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the … | |
| CVE-2026-71227 | Low | 0.2% | 5.1 | A flaw was found in libkcapi. A local attacker can influence an application that… | |
| CVE-2026-5745 | Low | 0.2% | 5.5 | A flaw was found in libarchive. A NULL pointer dereference vulnerability exists … | |
| CVE-2026-9793 | Low | 0.2% | 5.9 | A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request… | |
| CVE-2026-11819 | Low | 0.2% | 5.5 | Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/… | |
| CVE-2026-11786 | Low | 0.2% | 1.9 | A flaw was found in 389 Directory Server. The LDIF parser reads past the end of … | |
| CVE-2026-18569 | Low | 0.2% | 3.7 | A flaw was found in the backchannel logout endpoint of the keycloak-services com… | |
| CVE-2025-57847 | Low | 0.2% | 6.4 | A container privilege escalation flaw was found in certain Ansible Automation Pl… | |
| CVE-2025-57853 | Low | 0.2% | 6.4 | A container privilege escalation flaw was found in certain Web Terminal images. … | |
| CVE-2026-0965 | Low | 0.2% | 3.3 | A flaw was found in libssh where it can attempt to open arbitrary files during c… | |
| CVE-2026-15370 | Low | 0.2% | 6.7 | A flaw was found in libssh. During SFTP server directory listing, the longname f… | |
| CVE-2026-4897 | Low | 0.2% | 5.5 | A flaw was found in polkit. A local user can exploit this by providing a special… | |
| CVE-2026-13757 | Low | 0.1% | 6.2 | A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc… | |
| CVE-2026-6845 | Low | 0.1% | 5.0 | A flaw was found in binutils, specifically within the `readelf` utility. This vu… | |
| CVE-2025-57854 | Low | 0.1% | 6.4 | A container privilege escalation flaw was found in certain OpenShift Update Serv… | |
| CVE-2025-58713 | Low | 0.1% | 6.4 | A container privilege escalation flaw was found in certain Red Hat Process Autom… | |
| CVE-2026-74247 | Low | 0.1% | 4.2 | A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and … | |
| CVE-2026-18967 | Low | 0.1% | 6.4 | A flaw was found in the SAML broker component of Keycloak, an identity and acces… | |
| CVE-2026-6694 | Low | 0.1% | 5.5 | A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this b… | |
| CVE-2026-73433 | Low | 0.1% | 6.6 | A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM… | |
| CVE-2026-73434 | Low | 0.1% | 6.1 | A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff… | |
| CVE-2026-18508 | Low | 0.1% | 4.4 | A flaw was found in GNU tar. When extracting an archive with the --one-top-level… | |
| CVE-2026-50263 | Low | 0.1% | 5.5 | A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSave… | |
| CVE-2026-74244 | Low | 0.1% | 5.9 | A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerab… | |
| CVE-2026-6245 | Low | 0.1% | 5.5 | A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_… | |
| CVE-2026-50262 | Low | 0.1% | 5.5 | An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glX… | |
| CVE-2026-4948 | Low | 0.1% | 5.5 | A flaw was found in firewalld. A local unprivileged user can exploit this vulner… | |
| CVE-2026-12610 | Low | 0.1% | 6.4 | A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM respo… | |
| CVE-2026-71846 | Low | 0.1% | 6.5 | A flaw was found in insights-client. The component's ServiceAccount is bound to … | |
| CVE-2026-59846 | Low | 0.1% | 3.9 | A flaw was found in libssh. A malicious username expanded through %r in ProxyCom… | |
| CVE-2026-19548 | Low | 0.1% | 5.5 | Multiple Use-After-Free vulnerabilities were found in the add_archive_element fu… | |
| CVE-2025-57851 | Low | 0.1% | 6.4 | A container privilege escalation flaw was found in certain Multicluster Engine f… | |
| CVE-2026-6843 | Low | 0.1% | 5.5 | A flaw was found in nano. A local user could exploit a format string vulnerabili… | |
| CVE-2026-19617 | Low | 0.1% | 5.5 | A flaw was found in libdm. A local attacker could craft a malicious Logical Volu… | |
| CVE-2026-59845 | Low | 0.1% | 5.3 | A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failu… | |
| CVE-2026-6844 | Low | 0.1% | 5.5 | A flaw was found in the `readelf` utility of the binutils package. A local attac… | |
| CVE-2026-13002 | Low | 0.1% | 4.4 | A flow has been identified into dnssec.c library, causing an infinite loop to dn… | |
| CVE-2026-73585 | Low | 0.1% | 6.3 | A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the pro… | |
| CVE-2026-68743 | Low | 0.1% | 5.5 | A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder… | |
| CVE-2026-68744 | Low | 0.1% | 3.3 | A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS… | |
| CVE-2026-73583 | Low | 0.1% | 6.6 | A flaw was found in sblim-sfcb. A local attacker with access to the system can e… | |
| CVE-2026-68742 | Low | 0.1% | 5.5 | A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS … | |
| CVE-2026-73584 | Low | 0.1% | 6.3 | A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a r… |