Skip to content
COOEY

FAIL › dossier

redhat

VENDOR

· dossier confidence 20%

Red Hat is a major open-source software vendor with a significant security track record, evidenced by multiple critical and high-severity vulnerabilities in core components and cloud platforms over the last year.

PROFILE
CategorySoftware VendorWhat they doRed Hat is a global software company that provides open-source software solutions, primarily focused on enterprise Linux, cloud computing, and containerization technologies. Websitehttps://www.redhat.com ↗
SECURITY POSTURE

Red Hat has a history of releasing critical and high-severity vulnerabilities across multiple product lines, including RCE flaws in core components like Samba, GLib, and Undertow, indicating a need for rigorous patch management.

Notable failures
  • CVE-2026-1709: Critical Keylime registrar flaw
  • CVE-2026-12543: Critical Undertow HTTP server core flaw
  • CVE-2026-4408: Critical Samba RCE0day
  • CVE-2026-5483: High Red Hat Openshift AI odh-dashboard flaw
  • CVE-2026-28369: High Undertow HTTP request flaw
  • CVE-2026-17107: High RHACM cluster-proxy impersonation escalation
Patterns: Repeated unpatched edge-device RCEs; Core component vulnerabilities (GLib, Undertow, Samba); Cloud platform security flaws (OpenShift, Keylime)
FAILURE HISTORY · 17
DATEEVENTSEVSUMMARY
2026-05-28 CVE-2026-4408 critical A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed
2025-12-10 CVE-2025-14087 medium A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.
2026-06-30 CVE-2026-58016 high A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested within other elements like <method>, <signal>, <property> o
2026-05-07 CVE-2026-42010 high A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authe
2026-04-30 CVE-2026-33845 high A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of
2026-08-10 CVE-2026-59090 high CVE-2026-59090: A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsign
2026-08-05 CVE-2026-16442 high CVE-2026-16442: A flaw was found in the SAML broker component of Keycloak, which is used to mana
2026-08-05 CVE-2026-16443 high CVE-2026-16443: A flaw was found in the SAML metadata import functionality of the keycloak-servi
2026-04-10 CVE-2026-5483 high CVE-2026-5483: A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in
2026-03-27 CVE-2026-28369 high CVE-2026-28369: A flaw was found in Undertow. When Undertow receives an HTTP request where the f
2026-02-06 CVE-2026-1709 critical CVE-2026-1709: A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does n
2026-01-07 CVE-2025-12543 critical CVE-2025-12543: A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBo
2021-09-16 CVE-2021-40438 critical CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an orig
2017-10-04 CVE-2017-12149 critical CVE-2017-12149: In Jboss Application Server as shipped with Red Hat Enterprise Application Platf
2017-05-23 CVE-2016-9841 critical CVE-2016-9841: inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecif
2017-04-06 CVE-2016-8735 critical CVE-2016-8735: Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7
2012-08-28 CVE-2012-4681 critical CVE-2012-4681: Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Orac
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Red Hat shipped a vulnerable JBoss Application Server with arbitrary code execution via deserialization, a critical flaw that was publicly disclosed and required urgent patching.
cooey ↗severe-fallout-0.60
Red Hat shipped a vulnerable JBoss Application Server with arbitrary code execution via deserialization, a critical flaw that was publicly disclosed and required urgent patching.
"In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data."
Open questions: Red Hat's response time to critical vulnerabilities · Red Hat's patch management effectiveness across enterprise deployments
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-30 03:47:11.491678+00:00