Where
AND
-Infinity
0

Vendor Risk Score

See how red hat compares to other vendors in security performance

View Risk Score →

Software

red hat red hat enterprise linux for x86_64 - update services for sap solutions
1857
red hat red hat enterprise linux server for power le - update services for sap solutions
1836
red hat red hat enterprise linux server - aus
1580
red hat red hat enterprise linux for arm 64 - 4 years of updates
1462
red hat red hat enterprise linux for ibm z systems - 4 years of updates
1431
red hat red hat enterprise linux for power, little endian - extended update support
1339
red hat red hat enterprise linux for x86_64 - extended update support
1330
red hat red hat enterprise linux for x86_64
1305
red hat red hat enterprise linux for arm 64 - extended update support
1300
red hat red hat enterprise linux for power, little endian
1283
red hat red hat enterprise linux for arm 64
1255
red hat red hat enterprise linux for ibm z systems - extended update support
1252
red hat red hat enterprise linux for ibm z systems
1202
red hat red hat enterprise linux for x86_64 - extended life cycle
965
red hat red hat enterprise linux for power, little endian - extended life cycle
943
red hat red hat enterprise linux for arm 64 - extended life cycle
902
red hat red hat enterprise linux for ibm z systems - extended life cycle
883
red hat enterprise linux for sap solutions
639
red hat enterprise linux server
636
red hat enterprise linux server for power le - update services for sap solutions
633
red hat red hat enterprise linux server - tus
536
red hat enterprise linux for power, little endian - extended update support
508
red hat enterprise linux server for ibm z systems
476
red hat red hat codeready linux builder for x86_64 - extended update support
450
red hat red hat codeready linux builder for arm 64 - extended update support
443
red hat red hat codeready linux builder for power, little endian - extended update support
443
red hat red hat codeready linux builder for ibm z systems - extended update support
431
red hat red hat codeready linux builder for x86_64
417
red hat red hat codeready linux builder for arm 64
409
red hat red hat codeready linux builder for power, little endian
405
red hat red hat enterprise linux for x86_64 - extended update support extension
397
red hat red hat enterprise linux for power, little endian - 4 years of support
387
red hat red hat enterprise linux for x86_64 - 4 years of updates
386
red hat enterprise linux for arm 64
372
red hat red hat codeready linux builder for ibm z systems
365
red hat red hat openshift container platform
357
red hat enterprise linux for arm64 eus
322
red hat enterprise linux for x86_64 - extended update support
311
red hat enterprise linux for ibm z systems
305
red hat openshift container platform
289
red hat enterprise linux 8
276
red hat red hat openshift container platform for power
190
red hat red hat openshift container platform for arm 64
189
red hat red hat openshift container platform for ibm z and linuxone
188
red hat red hat enterprise linux for x86_64 - extended life cycle long life
155
red hat codeready linux builder for x86_64 - extended update support
135
red hat codeready linux builder for ibm z systems
121
red hat red hat enterprise linux server - extended life cycle support
115
red hat red hat enterprise linux server for arm 64 - 4 years of updates
114
red hat red hat enterprise linux server - extended life cycle support (for ibm z systems)
113
Severity
7.5
XEE
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitive file contents in the HTTP response. This is due to the SourceProvider.writeTo() method creating a SAXParser without disabling external entity resolution, leading to an XML External Entity (XXE) vulnerability.

First published (updated )
Severity
7

Important: Red Hat AMQ Broker 7.13.6 release and security update

First published (updated )
Severity
7

Important: nginx security update

First published (updated )
Severity
7

Important: Red Hat AMQ Broker 7.14.1 release and security update

First published (updated )
Severity
7

Important: osbuild-composer security update

First published (updated )
Severity
7.5
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

A flaw was found in the OpenShift Router. When a Route has insecureEdgeTerminationPolicy set to Allow, the HTTP frontend does not remove X-SSL-Client- headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted X-SSL-Client- headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication can be bypassed, enabling the attacker to impersonate client certificate identities.

1 / 2
Source: MITRE
First published (updated )
Severity
7.7
SSRF
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allows the router to proxy requests to the cloud metadata endpoint, leading to the disclosure of instance credentials and other sensitive metadata. This bypasses previous security measures for validating IP addresses.

1 / 2
Source: MITRE
First published (updated )
Severity
7.4
AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow the attacker to read, modify, or cancel another user's in-progress image upload.

1 / 2
Source: NVD
First published (updated )
Severity
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.

1 / 2
Source: NVD
First published (updated )
Severity
7

Important: openssh security update

First published (updated )
Severity
7

Important: gstreamer1-plugins-bad-free security update

First published (updated )
Severity
7

Important: gstreamer1-plugins-bad-free security update

First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 17.1 security and bug fix advisory

First published (updated )
Severity
7

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

First published (updated )
Severity
7

Important: vim security update

First published (updated )
Severity
7

Important: OpenShift Container Platform 4.16.70 bug fix and security update

First published (updated )
Severity
7

Important: freerdp security update

First published (updated )
Severity
7

Important: vim security update

First published (updated )
Severity
7

Important: vim security update

First published (updated )
Severity
7

Important: osbuild-composer security, bug fix, and enhancement update

First published (updated )
Severity
7

Important: kernel security, bug fix, and enhancement update

First published (updated )
Severity
7

Important: kernel-rt security, bug fix, and enhancement update

First published (updated )
Severity
7

Important: freerdp security update

First published (updated )
Severity
8.8
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.

1 / 2
Source: NVD
First published (updated )
Severity
7.8
OS Command Injection, Command Injection
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow invokes rpmuncompress on the malicious file, leading to high impact on the confidentiality, integrity, and availability of data accessible to the invoking user.

1 / 3
Source: MITRE
First published (updated )
Severity
7
OS Command Injection
AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

A flaw was found in rpm. A local attacker could supply a specially crafted .gem filename containing RPM macro syntax. When a user or automated workflow invokes rpmuncompress -x on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability.

1 / 3
Source: NVD
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203