redhat
353 known vulnerabilities affecting redhat products.
Products
enterprise_linux 215
openshift_container_platform 86
build_of_keycloak 64
hardened_images 48
enterprise_linux_eus 16
enterprise_linux_server 15
jboss_enterprise_application_platform 15
single_sign-on 15
quay 14
enterprise_linux_server_aus 14
enterprise_linux_for_power_little_endian 13
enterprise_linux_for_ibm_z_systems 13
enterprise_linux_workstation 13
enterprise_linux_server_tus 12
389_directory_server 12
directory_server 11
enterprise_linux_for_ibm_z_systems_eus 11
enterprise_linux_desktop 11
enterprise_linux_for_power_little_endian_eus 11
jboss_enterprise_application_platform_expansion_pack 11
enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 9
data_grid 9
openshift_update_service 8
jboss_core_services 7
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2024-1459 | Low | 1.7% | 5.3 | A path traversal vulnerability was found in Undertow. This issue may allow a rem… | |
| CVE-2025-5318 | Low | 1.7% | 5.4 | A flaw was found in the libssh library in versions less than 0.11.2. An out-of-b… | |
| CVE-2025-32988 | Low | 1.3% | 6.5 | A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to … | |
| CVE-2025-32989 | Low | 1.3% | 5.3 | A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the C… | |
| CVE-2026-2100 | Low | 1.2% | 5.3 | A flaw was found in p11-kit. A remote attacker could exploit this vulnerability … | |
| CVE-2024-9341 | Low | 1.0% | 5.4 | A flaw was found in Go. When FIPS mode is enabled on a system, container runtime… | |
| CVE-2026-2340 | Low | 0.9% | 6.5 | A flaw was found in Samba’s vfs_worm module. The module is intended to provide w… | |
| CVE-2026-0990 | Low | 0.9% | 5.9 | A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion… | |
| CVE-2025-4598 | Low | 0.8% | 4.7 | A vulnerability was found in systemd-coredump. This flaw allows an attacker to f… | |
| CVE-2025-14087 | Low | 0.8% | 5.6 | A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacke… | |
| CVE-2025-32990 | Low | 0.8% | 6.5 | A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the… | |
| CVE-2025-23367 | Low | 0.8% | 6.5 | A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider… | |
| CVE-2026-3832 | Low | 0.7% | 3.7 | A flaw was found in gnutls. A remote attacker could exploit this vulnerability b… | |
| CVE-2026-58015 | Low | 0.7% | 5.9 | A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKI… | |
| CVE-2024-10234 | Low | 0.6% | 6.1 | A vulnerability was found in Wildfly, where a user may perform Cross-site script… | |
| CVE-2026-6732 | Low | 0.6% | 6.5 | A flaw was found in libxml2. This vulnerability occurs when the library processe… | |
| CVE-2023-6393 | Low | 0.6% | 5.3 | A flaw was found in the Quarkus Cache Runtime. When request processing utilizes … | |
| CVE-2025-14512 | Low | 0.6% | 6.5 | A flaw was found in glib. This vulnerability allows a heap buffer overflow and d… | |
| CVE-2026-59843 | Low | 0.6% | 6.5 | A flaw was found in libssh. A remote authenticated peer can advertise a zero max… | |
| CVE-2026-59844 | Low | 0.6% | 6.5 | A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ… | |
| CVE-2026-3833 | Low | 0.6% | 6.5 | A flaw was found in gnutls. This vulnerability occurs because gnutls performs ca… | |
| CVE-2026-11788 | Low | 0.6% | 5.9 | A flaw was found in 389 Directory Server. The dereference control plugin does no… | |
| CVE-2024-50312 | Low | 0.6% | 5.3 | A vulnerability was found in GraphQL due to improper access controls on the Grap… | |
| CVE-2025-5351 | Low | 0.5% | 6.5 | A flaw was found in the key export functionality of libssh. The issue occurs in … | |
| CVE-2026-12725 | Low | 0.5% | 5.9 | A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and qu… | |
| CVE-2026-12993 | Low | 0.5% | 6.5 | A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blo… | |
| CVE-2026-58013 | Low | 0.5% | 6.5 | A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line… | |
| CVE-2026-0989 | Low | 0.5% | 3.7 | A flaw was identified in the RelaxNG parser of libxml2 related to how external s… | |
| CVE-2023-4693 | Low | 0.5% | 5.3 | An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This iss… | |
| CVE-2026-17059 | Low | 0.5% | 6.5 | A flaw was found in the role-users endpoint of the keycloak-services library, wh… | |
| CVE-2026-58010 | Low | 0.5% | 6.5 | A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_norm… | |
| CVE-2026-58012 | Low | 0.5% | 6.5 | A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace fu… | |
| CVE-2026-4629 | Low | 0.5% | 6.5 | A flaw was found in Keycloak. A highly privileged user with `manage-clients` per… | |
| CVE-2023-3384 | Low | 0.5% | 5.4 | A flaw was found in the Quay registry. While the image labels created through Qu… | |
| CVE-2026-58011 | Low | 0.5% | 6.5 | A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the… | |
| CVE-2026-71475 | Low | 0.5% | 6.8 | A flaw was found in insights-client. A compromised managed cluster, referred to … | |
| CVE-2026-0992 | Low | 0.5% | 2.9 | A flaw was found in the libxml2 library. This uncontrolled resource consumption … | |
| CVE-2026-15154 | Low | 0.5% | 6.5 | A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI.… | |
| CVE-2025-12801 | Low | 0.5% | 6.5 | A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-util… | |
| CVE-2025-23366 | Low | 0.5% | 6.5 | A flaw was found in the HAL Console in the Wildfly component, which does not neu… | |
| CVE-2026-0968 | Low | 0.4% | 3.1 | A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol… | |
| CVE-2026-3184 | Low | 0.4% | 3.7 | A flaw was found in util-linux. Improper hostname canonicalization in the `login… | |
| CVE-2025-5372 | Low | 0.4% | 5.0 | A flaw was found in libssh versions built with OpenSSL versions older than 3.0, … | |
| CVE-2026-16072 | Low | 0.4% | 4.9 | A flaw was found in the organization management component of Keycloak. A delegat… | |
| CVE-2026-55654 | Low | 0.4% | 3.7 | A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occu… | |
| CVE-2026-16106 | Low | 0.4% | 4.9 | A flaw was found in the admin REST API of Keycloak, a solution for identity and … | |
| CVE-2025-8419 | Low | 0.4% | 5.3 | A vulnerability was found in Keycloak-services. Special characters used during e… | |
| CVE-2026-9150 | Low | 0.4% | 6.5 | A flaw was found in libsolv. This stack-based buffer overflow vulnerability occu… | |
| CVE-2026-0964 | Low | 0.4% | 6.3 | A malicious SCP server can send unexpected paths that could make the client appl… | |
| CVE-2026-59842 | Low | 0.4% | 3.7 | A flaw was found in libssh. During server-side GSSAPI key exchange, a client-sup… |