Fedora
6,154 CVEs tracked. 89 of them are in CISA KEV.
This hub aggregates every CVE we track for Fedora, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Fedora CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 21 |
| 2024-11 | 57 |
| 2024-12 | 11 |
| 2025-01 | 16 |
| 2025-02 | 1 |
| 2025-03 | 11 |
| 2025-04 | 15 |
| 2025-05 | 7 |
| 2025-06 | 20 |
| 2025-07 | 11 |
| 2025-08 | 8 |
| 2025-09 | 6 |
| 2025-10 | 1 |
| 2025-11 | 18 |
| 2025-12 | 22 |
| 2026-01 | 10 |
| 2026-02 | 9 |
| 2026-03 | 18 |
| 2026-04 | 2 |
| 2026-05 | 1 |
| 2026-06 | 2 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 2 |
Severity
How the 6,154 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical517
- High2,692
- Medium2,678
- Low267
Latest CVEs
The 15 most recently published vulnerabilities affecting Fedora.
- CVE-2026-19816PackageKit: dnf5 backend ignores SIMULATE on RepoRemove7.1
- CVE-2026-19624NetworkManager-l2tp: local privilege escalation via ipsec.conf injection7.8
- CVE-2026-54231Abrt: unsanitized systemd journal content written to dump directory files enables content injection5.5
- CVE-2026-54230Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites7.0
- CVE-2026-43284xfrm: esp: avoid in-place decrypt on shared skb frags8.8
- CVE-2026-35094Libinput: libinput: information disclosure via dangling pointer in lua plugin handling3.3
- CVE-2026-35093Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins8.8
- CVE-2026-25645Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function4.4
- CVE-2026-2369Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources6.5
- CVE-2026-3941Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity:...4.3
- CVE-2026-3942Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)4.3
- CVE-2026-3939Insufficient policy enforcement in PDF in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted PDF file. (Chromium security severity: Low)5.3
- CVE-2026-3940Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity:...5.3
- CVE-2026-3938Insufficient policy enforcement in Clipboard in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML ...4.3
- CVE-2026-3937Incorrect security UI in Downloads in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)6.5
Product grouping is registry-driven, with AI assist and human review. How it works