Fedora
This hub aggregates every CVE we track for Fedora, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
6,147
CVEs tracked
517
Critical
2,688
High
88
In CISA KEV
Severity distribution
HIGH2,688MEDIUM2,676CRITICAL517LOW266
Monthly trend
14
21
57
11
16
1
11
15
7
20
11
8
6
1
18
22
10
9
18
2
1
2
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Fedora.
- CVE-2026-54231Abrt: unsanitized systemd journal content written to dump directory files enables content injection5.5
- CVE-2026-54230Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites7.0
- CVE-2026-43284xfrm: esp: avoid in-place decrypt on shared skb frags8.8
- CVE-2026-35093Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins8.8
- CVE-2026-35094Libinput: libinput: information disclosure via dangling pointer in lua plugin handling3.3
- CVE-2026-25645Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function4.4
- CVE-2026-2369Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources6.5
- CVE-2026-3941Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity:...4.3
- CVE-2026-3942Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)4.3
- CVE-2026-3940Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity:...5.3
- CVE-2026-3939Insufficient policy enforcement in PDF in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted PDF file. (Chromium security severity: Low)5.3
- CVE-2026-3938Insufficient policy enforcement in Clipboard in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML ...4.3
- CVE-2026-3936Use after free in WebView in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: M...8.8
- CVE-2026-3937Incorrect security UI in Downloads in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)6.5
- CVE-2026-3935Incorrect security UI in WebAppInstalls in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)6.5
Product normalization is registry-driven with AI assist and human review. How it works