Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT

VERIFIED PUBLISHER INTELLIGENCE

Release notes and known issues

Source-attributed product updates, affected versions, fixes and operational context. Update publication dates are kept separate from lifecycle boundaries.

85 official publisher sources registered · 83 collected automatically · 0 monitored for availability · 2 requires publisher access

1653 verified publisher records · Page 5 of 17

HASHICORPPACKER-C05A0F4CBC9F9CC5

nightly

Nightly releases are snapshots of the development activity on the Packer project that may include new features and bug fixes scheduled for upcoming releases . These releases are made available to make it easier for users to test their existing build configurations against the latest Packer code base for potential issues or to experiment with new features, with a chance to provide feedback on ways to improve the changes before being released. As these releases are snapshots of the latest code, you may encounter an issue compared to the latest stable release. Users are encouraged to run nightly releases in a non production environment. If you encounter an issue, please check our issue tracker to see if the issue has already been reported; if a report hasn't been made, please report it so we can review the issue and make any needed fixes. Note : Nightly releases are only available via GitHub Releases, and artifacts are not codesigned or notarized. Distribution via other Release Channels such as the Releases Site or Homebrew is not yet supported.

Published Never · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2025-3560

Red Hat Security Advisory: RHODF-4.14-RHEL-9 security update

Updated images are now available for RHODF-4.14-RHEL-9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift DataFoundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API. Security Fix(es): * golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (CVE-2024-45337) * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Published 3 Apr 2025 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2025-4007

Red Hat Security Advisory: OpenShift Container Platform 4.16.39 security and extras update

Red Hat OpenShift Container Platform release 4.16.39 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.16. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.16.39. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2025:4008 Security Fix(es): * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli.

Published 23 Apr 2025 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2025-8059

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.17.7 Bug Fix Update

Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.17.7 on Red Hat Enterprise Linux 9 from Red Hat Container Registry. Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.

Published 21 May 2025 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2025-8301

Red Hat Security Advisory: OpenShift Container Platform 4.15.52 security and extras update

Red Hat OpenShift Container Platform release 4.15.52 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.15. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.15.52. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2025:8299 Security Fix(es): * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli.

Published 4 Jun 2025 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2025-8479

Red Hat Security Advisory: RHODF-4.16-RHEL-9 security update

Updated images are now available for RHODF-4.16-RHEL-9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift DataFoundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API. Security Fix(es): * express: cause malformed URLs to be evaluated (CVE-2024-29041) * nodejs-async: Regular expression denial of service while parsing function in autoinject (CVE-2024-39249) * body-parser: Denial of Service Vulnerability in body-parser (CVE-2024-45590) * npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript (CVE-2024-11831) * http-proxy-middleware: Denial of Service (CVE-2024-21536) * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) * golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Published 4 Jun 2025 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2025-8510

Red Hat Security Advisory: Migration Toolkit for Containers (MTC) 1.8.7 security and bug fix update

The Migration Toolkit for Containers (MTC) 1.8.7 is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. The Migration Toolkit for Containers (MTC) enables you to migrate Kubernetes resources, persistent volume data, and internal container images between OpenShift Container Platform clusters, using the MTC web console or the Kubernetes API. Security Fix(es) from Bugzilla: * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) * golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws (CVE-2025-22868) * golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204) * http-proxy-middleware: Denial of Service (CVE-2024-21536) * cross-spawn: regular expression denial of service (CVE-2024-21538) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Published 4 Jun 2025 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2025-8544

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.15.14 Bug Fix Update

Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.15.14 on Red Hat Enterprise Linux 9 from Red Hat Container Registry. Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.

Published 4 Jun 2025 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2025-8551

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.14.18 Bug Fix Update

Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.14.18 on Red Hat Enterprise Linux 9 from Red Hat Container Registry. Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.

Published 4 Jun 2025 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2025-8556

Red Hat Security Advisory: OpenShift Container Platform 4.16.42 bug fix and security update

Red Hat OpenShift Container Platform release 4.16.42 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.16. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.16.42. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2025:8557 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ Security Fix(es): * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) * golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws (CVE-2025-22868) * golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204) * openshift-console: OpenShift Console: Server-Side Request Forgery (CVE-2024-6538) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli.

Published 13 Jun 2025 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2025-9340

Red Hat Security Advisory: Updated 7.1 container image is now available in the Red Hat Ecosystem Catalog.

A new rhceph-7.1 container image is now available in the Red Hat Ecosystem Catalog. Red Hat Ceph Storage is a scalable, open, software-defined storage platform that combines the most stable version of the Ceph storage system with a Ceph management platform, deployment utilities, and support services. This new container image is based on Red Hat Ceph Storage 7.1 and Red Hat Enterprise Linux 8.10, 9.4, 9.5. Space precludes documenting all of these changes in this advisory. Users are directed to the Red Hat Ceph Storage Release Notes for information on the most significant of these changes: https://docs.redhat.com/en/documentation/red_hat_ceph_storage/7/html/7.1_release_notes All users of Red Hat Ceph Storage are advised to pull these new images from the Red Hat Ecosystem catalog, which provides numerous bug fixes.

Published 23 Jun 2025 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2025-9646

Red Hat Security Advisory: OpenShift API for Data Protection (OADP) 1.3.7 security and bug fix update

OpenShift API for Data Protection (OADP) 1.3.7 is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. OpenShift API for Data Protection (OADP) enables you to back up and restore application resources, persistent volume data, and internal container images to external backup storage. OADP enables both file system-based and snapshot-based backups for persistent volumes. Security Fix(es) from Bugzilla: * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) * golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws (CVE-2025-22868) * golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Published 25 Jun 2025 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2025-9761

Red Hat Security Advisory: OpenShift Container Platform 4.14.53 security and extras update

Red Hat OpenShift Container Platform release 4.14.53 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.14. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.14.53. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2025:9759 Security Fix(es): * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli.

Published 2 Jul 2025 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-57565

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

An update for Red Hat Hardened Images RPMs is now available. This update includes the following RPMs: ruby4.0: * ruby4.0-4.0.6-37.2.hum1 (aarch64, x86_64) * ruby4.0-bundled-gems-4.0.6-37.2.hum1 (aarch64, x86_64) * ruby4.0-default-gems-4.0.6-37.2.hum1 (noarch) * ruby4.0-devel-4.0.6-37.2.hum1 (aarch64, x86_64) * ruby4.0-doc-4.0.6-37.2.hum1 (noarch) * ruby4.0-libs-4.0.6-37.2.hum1 (aarch64, x86_64) * rubygem4.0-bigdecimal-4.0.1-37.2.hum1 (aarch64, x86_64) * rubygem4.0-bundler-4.0.16-37.2.hum1 (noarch) * rubygem4.0-devel-4.0.16-37.2.hum1 (noarch) * rubygem4.0-io-console-0.8.2-37.2.hum1 (aarch64, x86_64) * rubygem4.0-irb-1.16.0-37.2.hum1 (noarch) * rubygem4.0-json-2.18.0-37.2.hum1 (aarch64, x86_64) * rubygem4.0-minitest-6.0.0-37.2.hum1 (noarch) * rubygem4.0-power_assert-3.0.1-37.2.hum1 (noarch) * rubygem4.0-psych-5.3.1-37.2.hum1 (aarch64, x86_64) * rubygem4.0-racc-1.8.1-37.2.hum1 (aarch64, x86_64) * rubygem4.0-rake-13.3.1-37.2.hum1 (noarch) * rubygem4.0-rbs-3.10.0-37.2.hum1 (aarch64, x86_64) * rubygem4.0-rdoc-7.0.4-37.2.hum1 (noarch) * rubygem4.0-rexml-3.4.4-37.2.hum1 (noarch) * rubygem4.0-rss-0.3.2-37.2.hum1 (noarch) * rubygem4.0-rubygems-4.0.16-37.2.hum1 (noarch) * rubygem4.0-test-unit-3.7.5-37.2.hum1 (noarch) * rubygem4.0-typeprof-0.31.1-37.2.hum1 (noarch) * ruby4.0-4.0.6-37.2.hum1.src (src) Security Fix(es): ruby4.0: * CVE-2026-33210

Published 20 Aug 2026 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-57986

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

An update for Red Hat Hardened Images RPMs is now available. This update includes the following RPMs: ruby3.3: * ruby3.3-3.3.10-23.5.hum1 (aarch64, x86_64) * ruby3.3-bundled-gems-3.3.10-23.5.hum1 (aarch64, x86_64) * ruby3.3-default-gems-3.3.10-23.5.hum1 (noarch) * ruby3.3-devel-3.3.10-23.5.hum1 (aarch64, x86_64) * ruby3.3-doc-3.3.10-23.5.hum1 (noarch) * ruby3.3-libs-3.3.10-23.5.hum1 (aarch64, x86_64) * rubygem3.3-bigdecimal-3.1.5-23.5.hum1 (aarch64, x86_64) * rubygem3.3-bundler-2.5.22-23.5.hum1 (noarch) * rubygem3.3-devel-3.5.22-23.5.hum1 (noarch) * rubygem3.3-io-console-0.7.1-23.5.hum1 (aarch64, x86_64) * rubygem3.3-irb-1.13.1-23.5.hum1 (noarch) * rubygem3.3-json-2.7.2-23.5.hum1 (aarch64, x86_64) * rubygem3.3-minitest-5.20.0-23.5.hum1 (noarch) * rubygem3.3-power_assert-2.0.3-23.5.hum1 (noarch) * rubygem3.3-psych-5.1.2-23.5.hum1 (aarch64, x86_64) * rubygem3.3-racc-1.7.3-23.5.hum1 (aarch64, x86_64) * rubygem3.3-rake-13.1.0-23.5.hum1 (noarch) * rubygem3.3-rbs-3.4.0-23.5.hum1 (aarch64, x86_64) * rubygem3.3-rdoc-6.6.3.1-23.5.hum1 (noarch) * rubygem3.3-rexml-3.4.4-23.5.hum1 (noarch) * rubygem3.3-rss-0.3.1-23.5.hum1 (noarch) * rubygem3.3-rubygems-3.5.22-23.5.hum1 (noarch) * rubygem3.3-test-unit-3.6.1-23.5.hum1 (noarch) * rubygem3.3-typeprof-0.21.9-23.5.hum1 (noarch) * ruby3.3-3.3.10-23.5.hum1.src (src)

Published 21 Aug 2026 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-57994

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

An update for Red Hat Hardened Images RPMs is now available. This update includes the following RPMs: ruby3.4: * ruby3.4-3.4.10-31.6.hum1 (aarch64, x86_64) * ruby3.4-bundled-gems-3.4.10-31.6.hum1 (aarch64, x86_64) * ruby3.4-default-gems-3.4.10-31.6.hum1 (noarch) * ruby3.4-devel-3.4.10-31.6.hum1 (aarch64, x86_64) * ruby3.4-doc-3.4.10-31.6.hum1 (noarch) * ruby3.4-libs-3.4.10-31.6.hum1 (aarch64, x86_64) * rubygem3.4-bigdecimal-3.1.8-31.6.hum1 (aarch64, x86_64) * rubygem3.4-bundler-2.6.9-31.6.hum1 (noarch) * rubygem3.4-devel-3.6.9-31.6.hum1 (noarch) * rubygem3.4-io-console-0.8.1-31.6.hum1 (aarch64, x86_64) * rubygem3.4-irb-1.14.3-31.6.hum1 (noarch) * rubygem3.4-json-2.9.1-31.6.hum1 (aarch64, x86_64) * rubygem3.4-minitest-5.25.4-31.6.hum1 (noarch) * rubygem3.4-power_assert-2.0.5-31.6.hum1 (noarch) * rubygem3.4-psych-5.2.2-31.6.hum1 (aarch64, x86_64) * rubygem3.4-racc-1.8.1-31.6.hum1 (aarch64, x86_64) * rubygem3.4-rake-13.2.1-31.6.hum1 (noarch) * rubygem3.4-rbs-3.8.0-31.6.hum1 (aarch64, x86_64) * rubygem3.4-rdoc-6.14.0-31.6.hum1 (noarch) * rubygem3.4-rexml-3.4.4-31.6.hum1 (noarch) * rubygem3.4-rss-0.3.1-31.6.hum1 (noarch) * rubygem3.4-rubygems-3.6.9-31.6.hum1 (noarch) * rubygem3.4-test-unit-3.6.7-31.6.hum1 (noarch) * rubygem3.4-typeprof-0.30.1-31.6.hum1 (noarch) * ruby3.4-3.4.10-31.6.hum1.src (src)

Published 21 Aug 2026 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-62562

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

An update for Red Hat Hardened Images RPMs is now available. This update includes the following RPMs: ruby3.3: * ruby3.3-3.3.10-23.6.hum1 (aarch64, x86_64) * ruby3.3-bundled-gems-3.3.10-23.6.hum1 (aarch64, x86_64) * ruby3.3-default-gems-3.3.10-23.6.hum1 (noarch) * ruby3.3-devel-3.3.10-23.6.hum1 (aarch64, x86_64) * ruby3.3-doc-3.3.10-23.6.hum1 (noarch) * ruby3.3-libs-3.3.10-23.6.hum1 (aarch64, x86_64) * rubygem3.3-bigdecimal-3.1.5-23.6.hum1 (aarch64, x86_64) * rubygem3.3-bundler-2.5.22-23.6.hum1 (noarch) * rubygem3.3-devel-3.5.22-23.6.hum1 (noarch) * rubygem3.3-io-console-0.7.1-23.6.hum1 (aarch64, x86_64) * rubygem3.3-irb-1.13.1-23.6.hum1 (noarch) * rubygem3.3-json-2.7.2-23.6.hum1 (aarch64, x86_64) * rubygem3.3-minitest-5.20.0-23.6.hum1 (noarch) * rubygem3.3-power_assert-2.0.3-23.6.hum1 (noarch) * rubygem3.3-psych-5.1.2-23.6.hum1 (aarch64, x86_64) * rubygem3.3-racc-1.7.3-23.6.hum1 (aarch64, x86_64) * rubygem3.3-rake-13.1.0-23.6.hum1 (noarch) * rubygem3.3-rbs-3.4.0-23.6.hum1 (aarch64, x86_64) * rubygem3.3-rdoc-6.6.3.1-23.6.hum1 (noarch) * rubygem3.3-rexml-3.4.4-23.6.hum1 (noarch) * rubygem3.3-rss-0.3.1-23.6.hum1 (noarch) * rubygem3.3-rubygems-3.5.22-23.6.hum1 (noarch) * rubygem3.3-test-unit-3.6.1-23.6.hum1 (noarch) * rubygem3.3-typeprof-0.21.9-23.6.hum1 (noarch) * ruby3.3-3.3.10-23.6.hum1.src (src) Security Fix(es): ruby3.3: * CVE-2026-80212 * CVE-2026-80213

Published 2 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-62563

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

An update for Red Hat Hardened Images RPMs is now available. This update includes the following RPMs: ruby4.0: * ruby4.0-4.0.6-37.3.hum1 (aarch64, x86_64) * ruby4.0-bundled-gems-4.0.6-37.3.hum1 (aarch64, x86_64) * ruby4.0-default-gems-4.0.6-37.3.hum1 (noarch) * ruby4.0-devel-4.0.6-37.3.hum1 (aarch64, x86_64) * ruby4.0-doc-4.0.6-37.3.hum1 (noarch) * ruby4.0-libs-4.0.6-37.3.hum1 (aarch64, x86_64) * rubygem4.0-bigdecimal-4.0.1-37.3.hum1 (aarch64, x86_64) * rubygem4.0-bundler-4.0.16-37.3.hum1 (noarch) * rubygem4.0-devel-4.0.16-37.3.hum1 (noarch) * rubygem4.0-io-console-0.8.2-37.3.hum1 (aarch64, x86_64) * rubygem4.0-irb-1.16.0-37.3.hum1 (noarch) * rubygem4.0-json-2.18.0-37.3.hum1 (aarch64, x86_64) * rubygem4.0-minitest-6.0.0-37.3.hum1 (noarch) * rubygem4.0-power_assert-3.0.1-37.3.hum1 (noarch) * rubygem4.0-psych-5.3.1-37.3.hum1 (aarch64, x86_64) * rubygem4.0-racc-1.8.1-37.3.hum1 (aarch64, x86_64) * rubygem4.0-rake-13.3.1-37.3.hum1 (noarch) * rubygem4.0-rbs-3.10.0-37.3.hum1 (aarch64, x86_64) * rubygem4.0-rdoc-7.0.4-37.3.hum1 (noarch) * rubygem4.0-rexml-3.4.4-37.3.hum1 (noarch) * rubygem4.0-rss-0.3.2-37.3.hum1 (noarch) * rubygem4.0-rubygems-4.0.16-37.3.hum1 (noarch) * rubygem4.0-test-unit-3.7.5-37.3.hum1 (noarch) * rubygem4.0-typeprof-0.31.1-37.3.hum1 (noarch) * ruby4.0-4.0.6-37.3.hum1.src (src) Security Fix(es): ruby4.0: * CVE-2026-80212 * CVE-2026-80213

Published 2 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-67838

Red Hat Security Advisory: OpenShift Container Platform 4.14.74 bug fix and security update

Red Hat OpenShift Container Platform release 4.14.74 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.14. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.14.74. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:67836 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/

Published 24 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-67839

Red Hat Security Advisory: OpenShift Container Platform 4.14.74 security and extras update

Red Hat OpenShift Container Platform release 4.14.74 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.14. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.14.74. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:67838 Security Fix(es): * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli.

Published 24 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-67858

Red Hat Security Advisory: OpenShift Container Platform 4.15.69 bug fix and security update

Red Hat OpenShift Container Platform release 4.15.69 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.15. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.15.69. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:67856 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html/release_notes/

Published 24 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-67859

Red Hat Security Advisory: OpenShift Container Platform 4.15.69 security and extras update

Red Hat OpenShift Container Platform release 4.15.69 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.15. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.15.69. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:67858 Security Fix(es): * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli.

Published 24 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-67936

Red Hat Security Advisory: OpenShift Container Platform 4.16.71 bug fix and security update

Red Hat OpenShift Container Platform release 4.16.71 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.16. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.16.71. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:67934 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/

Published 24 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-67938

Red Hat Security Advisory: OpenShift Container Platform 4.16.71 security and extras update

Red Hat OpenShift Container Platform release 4.16.71 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.16. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.16.71. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:67936 Security Fix(es): * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli.

Published 24 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-68540

Red Hat Security Advisory: OpenShift Container Platform 4.19.48 bug fix and security update

Red Hat OpenShift Container Platform release 4.19.48 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.19. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.19.48. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:68534 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/

Published 23 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-68541

Red Hat Security Advisory: OpenShift Container Platform 4.20.39 bug fix and security update

Red Hat OpenShift Container Platform release 4.20.39 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.20. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.20.39. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:68535 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/

Published 22 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-68542

Red Hat Security Advisory: OpenShift Container Platform 4.19.48 security and extras update

Red Hat OpenShift Container Platform release 4.19.48 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.19. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.19.48. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:68540 Security Fix(es): * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli.

Published 23 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-68546

Red Hat Security Advisory: OpenShift Container Platform 4.21.34 bug fix and security update

Red Hat OpenShift Container Platform release 4.21.34 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.21. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.21.34. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:68538 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/

Published 22 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-68547

Red Hat Security Advisory: OpenShift Container Platform 4.21.34 security and extras update

Red Hat OpenShift Container Platform release 4.21.34 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.21. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.21.34. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:68546 Security Fix(es): * fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization (CVE-2026-84292) * fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency (CVE-2026-16221) * fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects (CVE-2026-76172) * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) * baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling (CVE-2026-45819) * fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority (CVE-2026-18446) * fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies (CVE-2026-84394) * fast-uri: fast-uri: Host confusion via skipped IDN canonicalization (CVE-2026-75931) * fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899) * fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli.

Published 22 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-68552

Red Hat Security Advisory: OpenShift Container Platform 4.22.15 bug fix and security update

Red Hat OpenShift Container Platform release 4.22.15 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.22. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.22.15. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:68550 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/

Published 22 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-68553

Red Hat Security Advisory: OpenShift Container Platform 4.22.15 security and extras update

Red Hat OpenShift Container Platform release 4.22.15 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.22. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.22.15. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:68552 Security Fix(es): * fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization (CVE-2026-84292) * fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency (CVE-2026-16221) * fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects (CVE-2026-76172) * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) * baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling (CVE-2026-45819) * fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority (CVE-2026-18446) * fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies (CVE-2026-84394) * fast-uri: fast-uri: Host confusion via skipped IDN canonicalization (CVE-2026-75931) * fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899) * fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.22 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli.

Published 22 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-69922

Red Hat Security Advisory: OpenShift Container Platform 4.22 CNF IBU extras update

An update for ibu components is available for Red Hat OpenShift Container Platform 4.22. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the extra ibu container images for Red Hat OpenShift Container Platform 4.22. All OpenShift Container Platform users are advised to upgrade to these updated packages and images.

Published 22 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-72285

Red Hat Security Advisory: ruby:3.3 security update

An update for the ruby:3.3 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. Security Fix(es): * resolv: resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses (CVE-2026-80212) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Published 28 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
DEBIANDSA-6492-1

DSA-6492-1 ruby-rack - security update

Multiple security issues were found in Rack, an interface for developing web applications in Ruby, which could result in denial of service, information disclosure, spoofing or bypass of access restrictions. https://security-tracker.debian.org/tracker/DSA-6492-1

Published Never · Source checked 27 Sep 2026

Release notes and known issues →
DEBIANDSA-6493-1

DSA-6493-1 libevent - security update

Several vulnerabilities were discovered in libevent, an asynchronous event notification library. The HTTP implementation (evhttp) handled Transfer-Encoding and Content-Length headers, chunked-encoding line terminators, header line folding and chunked trailers too permissively, which could allow HTTP request smuggling, header injection or access control bypass when a libevent-based server or client is combined with an HTTP proxy. Out-of-bounds memory accesses in the DNS (evdns), tagged RPC (evtag/evrpc) and buffered socket (bufferevent) code, and a use-after-free in evbuffer, could result in denial of service or potentially the execution of arbitrary code when processing untrusted input. https://security-tracker.debian.org/tracker/DSA-6493-1

Published Never · Source checked 27 Sep 2026

Release notes and known issues →
CLOUDFLARECLOUDFLARE-8B7BC895ED07B08D

Cloudflare’s 2026 Annual Founders’ Letter

The Internet is changing more today than at any point since Cloudflare launched back on September 27, 2010. As automated traffic surpasses human activity, we reflect on the rise of AI agents, new creators, and how we can help build a fair, sustainable future for the web.

Published 27 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
OPEN HOME FOUNDATIONHOME-ASSISTANT-2026.9.4

2026.9.4

Turn off Tuya fans when the speed is set to 0% ( @frenck - #181972 ) ( tuya docs ) Fix Todoist timed calendar event duration ( @andremmfaria - #182121 ) ( todoist docs ) Fix ISEO Argo BLE offering unrelated devices for discovery ( @FezVrasta - #182315 ) ( iseo_argo_ble docs ) Bump pyenphase to 4.0.5 ( @catsmanac - #182473 ) ( enphase_envoy docs ) (dependency) Make HTTP security filter scan cost track request target length ( @frenck - #182570 ) ( http docs ) Fix HomematicIP Cloud config flow advancing on a rejected PIN ( @frenck - #182601 ) ( homematicip_cloud docs ) Fix friends' achievement stats in Xbox integration ( @scardus - #182686 ) ( xbox docs ) Fix typo in the Z-Wave controller statistics key ( @balloob - #182827 ) ( zwave_js docs ) Log the entity ID in the MQTT group member update message ( @David-Wu1119 - #182928 ) ( mqtt docs ) Bump pyenphase to 4.0.6 ( @catsmanac - #183094 ) ( enphase_envoy docs ) (dependency) Handle MissingSerial during OpenEVSE entry setup ( @firstof9 - #183105 ) ( openevse docs ) Bump imgw_pib to 2.5.2 ( @bieniu - #183111 ) ( imgw_pib docs ) (dependency) Bump python-xbox to 0.2.2 ( @tr4nt0r - #182072 ) ( xbox docs ) (dependency) Bump python-xbox to 0.3.0 ( @tr4nt0r - #182643 ) ( xbox docs ) (dependency)

Published Never · Source checked 28 Sep 2026

Release notes and known issues →
KEYCLOAKKEYCLOAK-A7CA5549D862CEC1

nightly

Admin v2: Mask client secrets for view-only users ( #52731 ) * Admin v2: Mask client secrets for view-only users When a user lacks manage permission on a client, strip client secrets from GET /clients/{client} and GET /clients responses to match v1 behavior. Closes #52197 Signed-off-by: Shatrughan Rai <polyglot.dev@outlook.com> # Conflicts: # rest/admin-v2/services/src/main/java/org/keycloak/services/client/DefaultClientService.java * Refactor getClientListSecretMaskedForViewOnly test Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Signed-off-by: Shatrughan Rai <polyglot.dev@outlook.com> * Fix: test scope fixes an unclosed Stream in the authorization test by wrapping it in try-with-resources, matching the pattern used in tests. Fixes : #52197 Signed-off-by: Shatrughan Rai <polyglot.dev@outlook.com> * moving the fix to the new client resource type Signed-off-by: Steve Hawkins <shawkins@redhat.com> --------- Signed-off-by: Shatrughan Rai <polyglot.dev@outlook.com> Signed-off-by: Steve Hawkins <shawkins@redhat.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Steve Hawkins <shawkins@redhat.com>

Published Never · Source checked 28 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-54283

Red Hat Security Advisory: Red Hat OpenShift Workload Availability v5.7.1 security update

This is an updated version of the Node Maintenance Operator. This Operator is delivered by Red Hat Workload Availability (RHWA). The Node Maintenance Operator works in conjunction with the machine health check or the node health check to provide automatic remediation of unhealthy nodes by rebooting them. This minimizes downtime for stateful applications and ReadWriteOnce (RWO) Volumes as well as restoring compute capacity in the event of transient failures.

Published 12 Aug 2026 · Source checked 27 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-54284

Red Hat Security Advisory: Red Hat OpenShift Workload Availability Operator v0.13.1 security update

This is an updated version of the Self Node Remediation Operator. This Operator is delivered by Red Hat Workload Availability (RHWA). The Self Node Remediation Operator works in conjunction with the machine health check or the node health check to provide automatic remediation of unhealthy nodes by rebooting them. This minimizes downtime for stateful applications and ReadWriteOnce (RWO) Volumes as well as restoring compute capacity in the event of transient failures.

Published 12 Aug 2026 · Source checked 27 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-54285

Red Hat Security Advisory: Red Hat OpenShift Workload Availability Operator v0.7.1 security update

This is an updated version of the Machine Deletion Remediation Operator. This Operator is delivered by Red Hat Workload Availability (RHWA). The Machine Deletion Remediation (MDR) Operator works with the Node Health Check (NHC) Operator to reprovision unhealthy nodes using the Machine API. The MDR Operator looks for the associated machine of an unhealthy node, and deletes it. After the machine custom resource (CR) has been deleted, the owning controller creates a replacement machine CR.

Published 12 Aug 2026 · Source checked 27 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-54286

Red Hat Security Advisory: Red Hat OpenShift Workload Availability Operator v0.3.1 security update

This is an updated version of the Storage-Based Remediation Operator. This Operator is delivered by Red Hat Workload Availability (RHWA). The Storage-Based Remediation Operator is an OLM Operator for managing STONITH Block Device (SBD) configurations and remediations for high-availability clustering. The operator provides automated node remediation when nodes become unresponsive by leveraging shared block storage for fencing operations.

Published 12 Aug 2026 · Source checked 27 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-54287

Red Hat Security Advisory: Red Hat OpenShift Workload Availability Operator v0.12.1 security update

This is an updated version of the Node Health Check Operator. This Operator is delivered by Red Hat Workload Availability (RHWA). The Node Health Check Operator deploys the Node Health Check controller. The controller identifies unhealthy nodes and uses a remediation provider to remediate the unhealthy nodes. You can install either the Self Node Remediation Operator, the Fence Agents Remediation Operator, or the Machine Deletion Remedation Operator as a remediation provider.

Published 12 Aug 2026 · Source checked 27 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-54427

Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.15.5 security update

Red Hat Advanced Cluster Management for Kubernetes v2.15 general availability release images, which provide security fixes, bug fixes, and updated container images. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE links in the References section. Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console—with security policy built in. This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which add new features and enhancements, bug fixes, and updated container images. See the following Release Notes documentation, which will be updated shortly for this release, for additional details about this release: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.15/html-single/release_notes/index#acm-release-notes

Published 12 Aug 2026 · Source checked 27 Sep 2026

Release notes and known issues →
RED HATRHSA-2026-54441

Red Hat Security Advisory: Red Hat Lightspeed (formerly Insights) for Runtimes security update

An update is now available for Red Hat Lightspeed (formerly Insights) for Runtimes on RHEL 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. An update is now available for Red Hat Lightspeed (formerly Insights) for Runtimes on RHEL 9. Security fix(es): * golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering (CVE-2026-42502) * golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136) * golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681) * golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) * Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) * golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Published 12 Aug 2026 · Source checked 27 Sep 2026

Release notes and known issues →