Technology · Red Hat
Red Hat Enterprise Linux AppStream vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 46 vulnerabilities in Red Hat Enterprise Linux AppStream: 0 in the last 7 days and 0 in the last 90 days, 10 of them critical and 0 exploited in the wild. The most recent, CVE-2026-44673, was published on 14 May 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 10
- Exploited in the wild
- 0
About Red Hat Enterprise Linux AppStream
Repository for Red Hat Enterprise Linux containing user-space applications, runtime languages, and databases.
Latest Red Hat Enterprise Linux AppStream vulnerabilities
- CVE-2026-44673: CESNET libyang heap buffer overflow in lyb_read_stringhighCVSS 7.5EPSS 0.3%
- CVE-2026-5172: dnsmasq heap out-of-bounds read in extract_addresseshighCVSS 7.3EPSS 0.7%
- CVE-2026-4891: dnsmasq heap out-of-bounds read in DNSSEC validationmediumCVSS 5.3EPSS 4.5%
- CVE-2026-4890: dnsmasq infinite loop in DNSSEC NSEC parsinghighCVSS 7.5EPSS 5.6%
- CVE-2026-7263: PHP DOMNode::C14N() denial of service via circular linked listhighCVSS 7.5EPSS 0.3%
- CVE-2026-6104: PHP mbstring out-of-bounds read in mb_convert_encodingcriticalCVSS 9.1EPSS 0.4%
- CVE-2026-7568: PHP signed integer overflow in metaphone functionhighCVSS 7.5EPSS 0.2%
- CVE-2026-7262: PHP SOAP extension NULL pointer dereference in apache:Map decoderhighCVSS 7.5EPSS 0.4%
- CVE-2026-25243: Redis RESTORE command invalid memory access leading to RCEhighCVSS 8.8EPSS 1.4%
- CVE-2026-23631: Redis use-after-free in Lua scripting synchronizationhighCVSS 8.1EPSS 1.2%
- CVE-2026-5656: Wireshark path traversal in Configuration Profile importhighCVSS 7EPSS 0.2%
- CVE-2026-42198: PostgreSQL pgjdbc denial of service via unbounded SCRAM iterationshighCVSS 7.5EPSS 0.5%
- CVE-2026-41316: Ruby ERB arbitrary code execution via deserialization guard bypasshighCVSS 8.1EPSS 0.5%
- CVE-2026-33116: Microsoft .NET infinite loop in XmlDecryptionTransformhighCVSS 7.5EPSS 1.1%
- CVE-2026-32203: Microsoft .NET and Visual Studio stack overflow denial of servicehighCVSS 7.5EPSS 1.6%
- CVE-2026-32178: Microsoft .NET SMTP command injection in MailAddress parsinghighCVSS 7.5EPSS 1.1%
- CVE-2026-26171: Microsoft .NET denial of service via XML entity expansionhighCVSS 7.5EPSS 0.9%
- CVE-2026-4151: GIMP ANI file parsing integer overflowhighCVSS 7.8EPSS 0.6%
- CVE-2026-34078: Flatpak sandbox escape via symlink following in sandbox-exposecriticalCVSS 10EPSS 1.6%
- CVE-2026-21413: LibRaw heap buffer overflow in lossless_jpeg_load_rawcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-34588: OpenEXR integer overflow in PIZ decoder leads to OOB read and writehighCVSS 7.8EPSS 0.6%
- CVE-2026-33983: FreeRDP denial of service in progressive_decompress_tile_upgrademediumCVSS 6.5EPSS 0.3%
- CVE-2026-21710: Node.js denial of service via __proto__ header in req.headersDistincthighCVSS 7.5EPSS 13.1%
- CVE-2026-32748: Squid heap use-after-free in ICP request handlinghighCVSS 7.5EPSS 2.7%
- CVE-2026-4371: Mozilla Thunderbird out of bounds read in IMAP parsinghighCVSS 7.4EPSS 0.3%
Most severe Red Hat Enterprise Linux AppStream vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-34078: Flatpak sandbox escape via symlink following in sandbox-exposecriticalCVSS 10EPSS 1.6%
- CVE-2026-2768: Mozilla Firefox and Thunderbird sandbox escape in IndexedDBcriticalCVSS 10EPSS 0.4%
- CVE-2026-21413: LibRaw heap buffer overflow in lossless_jpeg_load_rawcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-23884: FreeRDP use after free in GDI offscreen bitmap deletioncriticalCVSS 9.8EPSS 0.5%
- CVE-2025-67268: gpsd heap-based out-of-bounds write in NMEA2000 drivercriticalCVSS 9.8EPSS 0.5%
- CVE-2026-2762: Mozilla Firefox and Thunderbird integer overflow in JavaScript Standard LibrarycriticalCVSS 9.8EPSS 0.5%
- CVE-2026-22853: FreeRDP heap buffer overflow in RDPEAR NDR array readercriticalCVSS 9.8EPSS 0.5%
- CVE-2026-33210: Ruby JSON format string injection in JSON parsercriticalCVSS 9.1EPSS 0.5%
- CVE-2025-55130: Node.js permission model bypass via crafted symlinkscriticalCVSS 9.1EPSS 0.5%
- CVE-2026-6104: PHP mbstring out-of-bounds read in mb_convert_encodingcriticalCVSS 9.1EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/enterprise-linux-appstream.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Red Hat Enterprise Linux AppStream vulnerabilities", https://junglewise.ai/threats/technologies/enterprise-linux-appstream, 26 September 2026.