Red Hat Runtimes
Red Hat Runtimes is part of the Red Hat Application Services portfolio. Red Hat Runtimes is a set of products, tools, and components for developing and maintaining cloud-native applications. Customers of the Red Hat Ansible Automation Platform can take advantage of the Red Hat Ansible Certified Content Collections for Runtimes to automate the deployment of various runtimes products and components.
Included with Red Hat Runtimes
Red Hat JBoss Enterprise Application Platform (JBoss EAP) delivers enterprise-grade security, performance, and scalability in any environment. Red Hat supports deploying JBoss EAP on-premise, on hyperscalers, and on OpenShift. Whether on-premise, virtual, or in private, public, or hybrid clouds, JBoss EAP can help you deliver apps faster, everywhere. Customers of the Red Hat Ansible Automation Platform can take advantage of the Red Hat Ansible Certified Content Collections for Runtimes to automate the deployment of various runtimes products and components, including JBoss EAP 7.4.
Resources
Red Hat JBoss Web Server combines the world's most deployed web server (Apache) with the top servlet engine and the best support in middleware. Customers of the Red Hat Ansible Automation Platform can take advantage of the Red Hat Ansible Certified Content Collections for Runtimes to automate the deployment of various runtimes products and components.
Resources
Red Hat AMQ—based on open source communities like Apache ActiveMQ and Apache Kafka—is a flexible messaging platform that delivers information reliably, enabling real-time integration and connecting the Internet of Things (IoT).
Resources
Spring Boot lets you create stand-alone Spring-based applications and (Micro)services. Spring Boot provides ways to implement common (Micro)service patterns, such as externalized configuration, health check, circuit breaker, failover.
Resources
Eclipse Vert.x contains several different components designed to make it easier for you to write reactive applications. Vert.x is highly modular and you just use the bits that you need and nothing more.
Resources
Red Hat build of Keycloak is a cloud-native Identity Access Management solution based on the popular open source Keycloak project. Red Hat build of Keycloak replaces any planned future releases of Red Hat Single Sign-On. You can migrate Red Hat Single Sign-On to Red Hat build of Keycloak now.
Resources
Red Hat's single sign-on provides Web single sign-on and identity federation based on SAML 2.0, OpenID Connect and OAuth 2.0 specifications.
Resources
Red Hat Data Grid is an in-memory, distributed, elastic NoSQL key-value datastore. Built from the Infinispan open-source software project, it's available to deploy as an embedded library, as a standalone server, or as a containerized application on Red Hat OpenShift Container Platform.
Resources
The Red Hat build of Quarkus is based on the popular Quarkus community project. It's Kubernetes-native Java with low memory footprint and fast boot times for microservices and serverless applications.
Resources
The Red Hat build of OpenJDK is based on the upstream OpenJDK 8u and 11u projects. Red Hat maintains these projects upstream and adds additional future features into our builds that are available for download here.
Resources
Red Hat build of Node.js makes it possible to run JavaScript outside of a browser. Its small size, fast startup, and high developer productivity makes it versatile in almost any use case. From Microservices to embedded software, it provides an I/O model based on events and non-blocking operations that enables you to write efficient applications.
Resources
Select and deploy the core services that satisfy your use cases including load balancing, identification and authorization, high availability, or configuration management and monitoring. Entitlement to the collection and support for the components comes with most JBoss Middleware subscriptions. The components are tested with JBoss Middleware product releases and each component has a defined support lifecycle to enable effective long term planning and alignment across your middleware deployments.
Resources
Latest security advisories
| Severity | Advisory/CVE | Synopsis | Date |
|---|---|---|---|
| Severity Important | Advisory/CVECVE-2025-11393 | Synopsis A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to handle. This allows a standard user within the cluster to send unauthorized commands to the management platform, effectively acting with the full permissions of the cluster administrator. This could lead to unauthorized changes to the cluster's configuration or status on the Red Hat platform. | Date |
| Severity Moderate | Advisory/CVECVE-2025-61724 | Synopsis The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption. | Date |
| Severity Low | Advisory/CVECVE-2025-58186 | Synopsis A flaw was found in golang.org/net/http. A remote attacker could exploit this vulnerability by sending a large number of small cookies to an HTTP server. Despite a default 1MB limit on HTTP headers, the number of cookies parsed is unrestricted, leading to excessive memory allocation. This can cause the server to consume significant memory resources, resulting in a denial of service (DoS) for legitimate users. | Date |
| Severity Low | Advisory/CVECVE-2020-1698 | Synopsis A flaw was found in keycloak. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality. | Date |
| Severity Moderate | Advisory/CVECVE-2020-10693 | Synopsis A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages. | Date |
Top resources
Get support
Support cases
Get answers quickly by opening a support case with us.
Live chat
Directly access our support engineers during weekday business hours.
Call or email
Speak directly with a Red Hat Support expert by phone or through email.