Redhat
17,638 known vulnerabilities
Top Products
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local a
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind cr
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confin
A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen
A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (
A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authoriza
Keycloak provides authorization services that allow administrators to restrict access to resources based on time policie
A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled.
A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This componen
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the Cle
A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attemp
A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution
Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization
Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Wor
A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is respo
A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flow
A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source
A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services.
A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a gr
A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoin
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom r
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able t
A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group m
Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discov
A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the pl
A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory alloca
A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memor
A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches t
A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes tha
A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes
A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloa
A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs w
A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch betw
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the
A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invok
A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clien
A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively re
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metachara
A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; durin
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large leng
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN
A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than
A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concaten
A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible
A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when
A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engi
A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, wher
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 5623 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 5623 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started