Where
AND
-Infinity
0

Vendor Risk Score

See how red hat compares to other vendors in security performance

View Risk Score →

Software

red hat red hat enterprise linux for x86_64 - update services for sap solutions
661
red hat red hat enterprise linux server for power le - update services for sap solutions
651
red hat red hat enterprise linux for arm 64
630
red hat red hat enterprise linux for x86_64
627
red hat red hat enterprise linux for power, little endian
625
red hat red hat enterprise linux for ibm z systems
607
red hat red hat enterprise linux server - aus
574
red hat red hat enterprise linux for arm 64 - 4 years of updates
531
red hat red hat enterprise linux for arm 64 - extended update support
531
red hat red hat enterprise linux for power, little endian - extended update support
519
red hat red hat enterprise linux for ibm z systems - 4 years of updates
515
red hat red hat enterprise linux for x86_64 - extended update support
505
red hat red hat enterprise linux for ibm z systems - extended update support
503
red hat red hat codeready linux builder for arm 64
265
red hat red hat codeready linux builder for power, little endian
264
red hat red hat codeready linux builder for x86_64
260
red hat enterprise linux for power, little endian - extended update support
240
red hat red hat codeready linux builder for arm 64 - extended update support
238
red hat red hat codeready linux builder for power, little endian - extended update support
236
red hat red hat codeready linux builder for x86_64 - extended update support
234
red hat red hat codeready linux builder for ibm z systems
232
red hat red hat codeready linux builder for ibm z systems - extended update support
219
red hat enterprise linux server for ibm z systems
204
red hat red hat enterprise linux server - tus
187
red hat enterprise linux 8
185
red hat red hat enterprise linux for x86_64 - extended life cycle
172
red hat enterprise linux for arm 64
170
red hat red hat enterprise linux for arm 64 - extended life cycle
168
red hat red hat enterprise linux for power, little endian - extended life cycle
168
red hat red hat enterprise linux for ibm z systems - extended life cycle
164
red hat enterprise linux server
150
red hat enterprise linux server for power le - update services for sap solutions
140
red hat enterprise linux for sap solutions
133
red hat red hat enterprise linux for power, little endian - 4 years of support
128
red hat red hat enterprise linux for x86_64 - extended update support extension
128
red hat red hat enterprise linux for x86_64 - 4 years of updates
127
red hat enterprise linux for arm64 eus
125
red hat openshift container platform
123
red hat enterprise linux for ibm z systems
100
red hat enterprise linux for x86_64 - extended update support
100
red hat red hat openshift container platform
87
red hat codeready linux builder for x86_64 - extended update support
85
red hat codeready linux builder for ibm z systems
68
red hat red hat enterprise linux server for arm 64 - 4 years of updates
58
red hat codeready linux builder for arm 64
55
red hat codeready linux builder for arm 64 - extended update support
53
red hat red hat openshift container platform for arm 64
52
red hat red hat enterprise linux server for ibm z systems - 4 years of updates
51
red hat red hat openshift container platform for ibm z and linuxone
51
red hat red hat openshift container platform for power
51
Severity
4

Moderate: Red Hat Certificate System 10.4.4 security and bug fix update for RHEL 8

First published (updated )
Severity
4

Moderate: gstreamer1-plugins-base security update

First published (updated )
Severity
4

Moderate: apr-util security update

First published (updated )
Severity
4

Moderate: apr-util security update

First published (updated )
Severity
5.9
EPSS
0.25%
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

A denial-of-service vulnerability was discovered in skupper-router within the AMQP field parser. The flaw is caused by unbounded recursion when processing deeply nested or specially crafted AMQP messages, leading to a stack overflow. An attacker who can send messages to the router can trigger this crash. Exploitation requires the attacker to possess a valid x.509 certificate signed by the Red Hat Service Interconnect network's certificate authority. Successful exploitation results in the skupper-router process crashing, terminating all active connections and preventing new traffic from being routed through the affected node.

1 / 2
Source: Red Hat
First published (updated )
Severity
4

A denial-of-service vulnerability was discovered in skupper-router within the AMQP field parser. The flaw is caused by unbounded recursion when processing deeply nested or specially crafted AMQP messages, leading to a stack overflow. An attacker who can send messages to the router can trigger this crash. Exploitation requires the attacker to possess a valid x.509 certificate signed by the Red Hat Service Interconnect network's certificate authority. Successful exploitation results in the skupper-router process crashing, terminating all active connections and preventing new traffic from being routed through the affected node.

First published (updated )
Severity
4

Moderate: gstreamer1-plugins-good security update

First published (updated )
Severity
4

Moderate: gzip security update

First published (updated )
Severity
4

Moderate: gstreamer1-plugins-good security update

First published (updated )
Severity
4.9
Path Traversal
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm administrator to still submit arbitrary filesystem paths as keystore parameters. This can be used to determine the existence and readability of files on the server, potentially exposing sensitive system information.

First published (updated )
Severity
4

Moderate: glib2 security update

First published (updated )
Severity
4

Moderate: glib2 security update

First published (updated )
Severity
4

Moderate: glib2 security update

First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the cluster NVIDIA NGC API key Secret (apiKeySecret) and the NIM image pull secret (nimPullSecret). Create and delete of the same NIM credential are admin-gated; the read path is not. This is missing authorization (CWE-862) and insufficiently protected credentials (CWE-522). It is distinct from CVE-2026-5483 (service-account token leak in the Kubernetes client response wrapper on the same route) and CVE-2026-16456 (odh-model-controller cross-namespace confused deputy).

1 / 2
Source: MITRE
First published (updated )
Severity
4

A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the cluster NVIDIA NGC API key Secret (apiKeySecret) and the NIM image pull secret (nimPullSecret). Create and delete of the same NIM credential are admin-gated; the read path is not. This is missing authorization (CWE-862) and insufficiently protected credentials (CWE-522). It is distinct from CVE-2026-5483 (service-account token leak in the Kubernetes client response wrapper on the same route) and CVE-2026-16456 (odh-model-controller cross-namespace confused deputy).

Reported privately by Dmitry Maranik (Sectum AI) via PSIRTSUPT-22896. Confirmed by source review of opendatahub-io/odh-dashboard at HEAD (backend/src/routes/api/nim-serving/index.ts). Not reproduced against a live RHOAI + NGC deployment. Preconditions: authenticated dashboard access and a NIM Account CR with the referenced Secrets present.

First published (updated )
Severity
4

PCS (Pacemaker Configuration System) has an arbitrary file read vulnerability in the pcs host auth --token <path> command path. When a non-root user in the 'haclient' group runs this command, the nonrootrun() function in pcs/app.py forwards it to the locally running pcsd daemon via HTTP POST to /runpcs. The pcsd daemon (running as root) matches the command against its allowedcommands list in pcsd/pcsd.rb (['host', 'auth', '...']) with no restriction on --token, and re-executes PCS as root. This causes utils.gettokenfromfile() in pcs/utils.py to open and read the attacker-specified file path with root privileges, reading up to 256 bytes. The file contents are base64-encoded and stored as a token in the known-hosts configuration file. The attacker can exfiltrate the file contents by triggering node communication (e.g., pcs pcsd status) and intercepting the HTTP Cookie header containing the base64-encoded token.

Affected: PCS versions from 0.10.8 onwards (introduced in commit 9178b78d11baa70e700a5c0d9fc1c17f27d452fa). RHEL 8.4+, RHEL 9.0+, and RHEL 10.0+ ship affected PCS versions.

Fix: Upstream patch attached to PSIRTSUPT-22935 (commit b41eaf3c6e2ecfc575c42442fb02b8ef05b4dd6a, not yet on public GitHub main). Blocks pcs host auth --token for non-root users in both pcs/app.py and pcsd/pcsd.rb.

Reporter: Peter Romancik (PCS upstream developer, Red Hat). PSIRT ticket: PSIRTSUPT-22935

First published (updated )
Severity
4

Moderate: gstreamer1-plugins-good security update

First published (updated )
Severity
4
Buffer Overflow

Moderate: wget security, bug fix, and enhancement update

1 / 2
Source: Red Hat
First published (updated )
Severity
4
Buffer Overflow

Moderate: wget security, bug fix, and enhancement update

1 / 2
Source: Red Hat
First published (updated )
Severity
4
Use After Free

libssh is a library which implements the SSH protocol. It can be used to implement client and server applications.Security Fix(es): libssh: libssh: denial of service via zero advertised channel packet size (CVE-2026-59843) libssh: libssh: denial of service via oversized SFTP read length (CVE-2026-59844) libssh: libssh: denial of service via unchecked ProxyCommand fork() failure (CVE-2026-59845) libssh: libssh: information disclosure via ProxyCommand %r username expansion (CVE-2026-59846) libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification (CVE-2026-59847) libssh: libssh: denial of service via SFTP responses with unknown request IDs (CVE-2026-59848) libssh: libssh: use-after-free via data callbacks on closed channels (CVE-2026-59850) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

1 / 2
Source: Red Hat
First published (updated )
Severity
4

Moderate: pam security update

1 / 2
Source: Red Hat
First published (updated )
Severity
4

Moderate: pam security update

1 / 2
Source: Red Hat
First published (updated )
Severity
4

Moderate: pam security update

1 / 2
Source: Red Hat
First published (updated )
Severity
4

Moderate: pam security update

1 / 2
Source: Red Hat
First published (updated )
Severity
4

Moderate: pam security update

1 / 2
Source: Red Hat
First published (updated )
Severity
4

Moderate: pam security update

1 / 2
Source: Red Hat
First published (updated )
Severity
4

Moderate: pam security update

1 / 2
Source: Red Hat
First published (updated )
Severity
4
Buffer Overflow, Use After Free

Moderate: libxml2 security update

1 / 2
Source: Red Hat
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203