Fedora ↗
Summary iPlain-English security verdict for Fedora, generated from its current health score, actively-exploited vulnerabilities, and latest supported version.
Fedora currently scores 81/100 — good. 1 actively-exploited vulnerability (CISA KEV) affects older releases (e.g. CVE-2021-40438) — staying on the latest supported version keeps you clear of it. The latest supported release is 44. It's largely safe; apply minor updates as they appear.
Disclosure trend iNew CVEs published for Fedora each year (NVD). A higher bar means more disclosures that year — more scrutiny, not necessarily less safe.
1 of its known vulnerability is linked to ransomware campaigns (CISA KEV).
Patch priority — what to act on iThe issues to fix first — actively exploited (CISA KEV) first, then by exploitation probability (EPSS), then severity. Each row's "→ fixed in" is the earliest version that patches it; "see advisory" means no fixed version is published.
Most urgent first — actively exploited, then likeliest to be exploited.
CVE-2021-40438 CRITICAL exploited ransomware Server-side request forgery (SSRF) EPSS 100% → see advisory CVE-2018-25032 HIGH Out-of-bounds write EPSS 52% → see advisory CVE-2022-37434 CRITICAL Out-of-bounds write EPSS 16% → see advisory CVE-2022-23303 CRITICAL CWE-203 EPSS 3% → see advisory CVE-2023-46850 CRITICAL Use-after-free EPSS 2% → see advisory CVE-2022-23304 CRITICAL CWE-203 EPSS 2% → see advisory CVE-2021-33643 CRITICAL Out-of-bounds read EPSS 1% → see advisory CVE-2023-6879 CRITICAL Improper input validation EPSS 1% → see advisoryGet alerted about Fedora
Be emailed the moment Fedora gets a newly exploited vulnerability (CISA KEV) or a release reaches end of life. Free · double opt-in · unsubscribe anytime.
We email only on real events for Fedora — no marketing, no sharing, and we never know what you run. Track your whole stack →
Versions & lifecycle iWhen each release line stops receiving security patches (end-of-life). After EOL there are no more fixes — plan upgrades before these dates.
How long each Fedora release line is supported — and when it sunsets. Select a line for its full report.
Full Fedora end-of-life dates & support timeline →
44 latest 44 Supported until 2027-06-0244 → 43 latest 43 Supported until 2026-12-0943 → 42 latest 42 End of life ended 2026-05-2742 → 41 latest 41 End of life ended 2025-12-1541 → 40 latest 40 End of life ended 2025-05-1340 → 39 latest 39 End of life ended 2024-11-2639 → 38 latest 38 End of life ended 2024-05-2138 → 37 latest 37 End of life ended 2023-12-0537 → 36 latest 36 End of life ended 2023-05-1636 → 35 latest 35 End of life ended 2022-12-1335 → See all upcoming end-of-life dates →Frequently asked
Is Fedora safe and patched?
Fedora currently scores 81/100 — good. 1 actively-exploited vulnerability (CISA KEV) affects older releases (e.g. CVE-2021-40438) — staying on the latest supported version keeps you clear of it. The latest supported release is 44. It's largely safe; apply minor updates as they appear.
What should I do about Fedora now?
Upgrade Fedora to the latest supported release (44) or later, which clears the actively-exploited issues affecting older versions, then confirm against Fedora Project's official advisory.
When does Fedora reach end-of-life?
The latest supported Fedora release is 44. After end-of-life a release no longer receives security patches.
Which versions of Fedora are still receiving security updates?
Supported Fedora release lines (latest 44): 44, 43. End-of-life releases no longer receive security patches.
Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Fedora Project's official advisory before you patch or upgrade — Fedora official site ↗