FAIL › dossier
redhat
VENDOR· dossier confidence 20%
Red Hat is a major open-source software vendor with a significant security track record, evidenced by multiple critical and high-severity vulnerabilities in core components and cloud platforms over the last year.
PROFILE
CategorySoftware VendorWhat they doRed Hat is a global software company that provides open-source software solutions, primarily focused on enterprise Linux, cloud computing, and containerization technologies.
Websitehttps://www.redhat.com ↗
SECURITY POSTURE
Red Hat has a history of releasing critical and high-severity vulnerabilities across multiple product lines, including RCE flaws in core components like Samba, GLib, and Undertow, indicating a need for rigorous patch management.
Notable failures
- CVE-2026-1709: Critical Keylime registrar flaw
- CVE-2026-12543: Critical Undertow HTTP server core flaw
- CVE-2026-4408: Critical Samba RCE0day
- CVE-2026-5483: High Red Hat Openshift AI odh-dashboard flaw
- CVE-2026-28369: High Undertow HTTP request flaw
- CVE-2026-17107: High RHACM cluster-proxy impersonation escalation
Patterns: Repeated unpatched edge-device RCEs; Core component vulnerabilities (GLib, Undertow, Samba); Cloud platform security flaws (OpenShift, Keylime)
FAILURE HISTORY · 17
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-05-28 | CVE-2026-4408 | critical | A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed |
| 2025-12-10 | CVE-2025-14087 | medium | A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings. |
| 2026-06-30 | CVE-2026-58016 | high | A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested within other elements like <method>, <signal>, <property> o |
| 2026-05-07 | CVE-2026-42010 | high | A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authe |
| 2026-04-30 | CVE-2026-33845 | high | A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of |
| 2026-08-10 | CVE-2026-59090 | high | CVE-2026-59090: A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsign |
| 2026-08-05 | CVE-2026-16442 | high | CVE-2026-16442: A flaw was found in the SAML broker component of Keycloak, which is used to mana |
| 2026-08-05 | CVE-2026-16443 | high | CVE-2026-16443: A flaw was found in the SAML metadata import functionality of the keycloak-servi |
| 2026-04-10 | CVE-2026-5483 | high | CVE-2026-5483: A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in |
| 2026-03-27 | CVE-2026-28369 | high | CVE-2026-28369: A flaw was found in Undertow. When Undertow receives an HTTP request where the f |
| 2026-02-06 | CVE-2026-1709 | critical | CVE-2026-1709: A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does n |
| 2026-01-07 | CVE-2025-12543 | critical | CVE-2025-12543: A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBo |
| 2021-09-16 | CVE-2021-40438 | critical | CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an orig |
| 2017-10-04 | CVE-2017-12149 | critical | CVE-2017-12149: In Jboss Application Server as shipped with Red Hat Enterprise Application Platf |
| 2017-05-23 | CVE-2016-9841 | critical | CVE-2016-9841: inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecif |
| 2017-04-06 | CVE-2016-8735 | critical | CVE-2016-8735: Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7 |
| 2012-08-28 | CVE-2012-4681 | critical | CVE-2012-4681: Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Orac |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Red Hat shipped a vulnerable JBoss Application Server with arbitrary code execution via deserialization, a critical flaw that was publicly disclosed and required urgent patching.
Red Hat shipped a vulnerable JBoss Application Server with arbitrary code execution via deserialization, a critical flaw that was publicly disclosed and required urgent patching.
"In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data."
DOSSIER SOURCES
- RedHat Is Hiring | Work From Office Internship | Software Engineering ... · amirsohel.com
- Compaq - Wikipedia · en.wikipedia.org
- Redhat CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- RHSA-2026:47248 - Security Advisory - Red Hat Customer Portal · access.redhat.com
- Real-Time Threat Response with ACS - Red Hat Developer · developers.redhat.com
Open questions: Red Hat's response time to critical vulnerabilities · Red Hat's patch management effectiveness across enterprise deployments
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-30 03:47:11.491678+00:00