MFSA 2026-57 Security Vulnerabilities fixed in Firefox 152
Official Mozilla security advisory for Mozilla products.
Release notes and known issues →VERIFIED PUBLISHER INTELLIGENCE
Source-attributed product updates, affected versions, fixes and operational context. Update publication dates are kept separate from lifecycle boundaries.
Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Official Mozilla security advisory for Mozilla products.
Release notes and known issues →Nightly releases are snapshots of the development activity on the Packer project that may include new features and bug fixes scheduled for upcoming releases . These releases are made available to make it easier for users to test their existing build configurations against the latest Packer code base for potential issues or to experiment with new features, with a chance to provide feedback on ways to improve the changes before being released. As these releases are snapshots of the latest code, you may encounter an issue compared to the latest stable release. Users are encouraged to run nightly releases in a non production environment. If you encounter an issue, please check our issue tracker to see if the issue has already been reported; if a report hasn't been made, please report it so we can review the issue and make any needed fixes. Note : Nightly releases are only available via GitHub Releases, and artifacts are not codesigned or notarized. Distribution via other Release Channels such as the Releases Site or Homebrew is not yet supported.
Release notes and known issues →Updated images are now available for RHODF-4.14-RHEL-9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift DataFoundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API. Security Fix(es): * golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (CVE-2024-45337) * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Release notes and known issues →Red Hat OpenShift Container Platform release 4.16.39 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.16. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.16.39. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2025:4008 Security Fix(es): * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli.
Release notes and known issues →Logging for Red Hat OpenShift - 5.8.20 Logging for Red Hat OpenShift - 5.8.20 logging-loki-container: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338)
Release notes and known issues →Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.17.7 on Red Hat Enterprise Linux 9 from Red Hat Container Registry. Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.
Release notes and known issues →Red Hat OpenShift Container Platform release 4.15.52 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.15. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.15.52. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2025:8299 Security Fix(es): * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli.
Release notes and known issues →Updated images are now available for RHODF-4.16-RHEL-9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift DataFoundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API. Security Fix(es): * express: cause malformed URLs to be evaluated (CVE-2024-29041) * nodejs-async: Regular expression denial of service while parsing function in autoinject (CVE-2024-39249) * body-parser: Denial of Service Vulnerability in body-parser (CVE-2024-45590) * npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript (CVE-2024-11831) * http-proxy-middleware: Denial of Service (CVE-2024-21536) * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) * golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Release notes and known issues →The Migration Toolkit for Containers (MTC) 1.8.7 is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. The Migration Toolkit for Containers (MTC) enables you to migrate Kubernetes resources, persistent volume data, and internal container images between OpenShift Container Platform clusters, using the MTC web console or the Kubernetes API. Security Fix(es) from Bugzilla: * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) * golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws (CVE-2025-22868) * golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204) * http-proxy-middleware: Denial of Service (CVE-2024-21536) * cross-spawn: regular expression denial of service (CVE-2024-21538) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Release notes and known issues →Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.15.14 on Red Hat Enterprise Linux 9 from Red Hat Container Registry. Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.
Release notes and known issues →Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.14.18 on Red Hat Enterprise Linux 9 from Red Hat Container Registry. Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.
Release notes and known issues →Red Hat OpenShift Container Platform release 4.16.42 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.16. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.16.42. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2025:8557 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ Security Fix(es): * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) * golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws (CVE-2025-22868) * golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204) * openshift-console: OpenShift Console: Server-Side Request Forgery (CVE-2024-6538) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli.
Release notes and known issues →The components for Red Hat OpenShift for Windows Containers 10.16.2 are now available Red Hat OpenShift for Windows Containers allows you to deploy Windows container workloads running on Windows Server containers.
Release notes and known issues →A new rhceph-7.1 container image is now available in the Red Hat Ecosystem Catalog. Red Hat Ceph Storage is a scalable, open, software-defined storage platform that combines the most stable version of the Ceph storage system with a Ceph management platform, deployment utilities, and support services. This new container image is based on Red Hat Ceph Storage 7.1 and Red Hat Enterprise Linux 8.10, 9.4, 9.5. Space precludes documenting all of these changes in this advisory. Users are directed to the Red Hat Ceph Storage Release Notes for information on the most significant of these changes: https://docs.redhat.com/en/documentation/red_hat_ceph_storage/7/html/7.1_release_notes All users of Red Hat Ceph Storage are advised to pull these new images from the Red Hat Ecosystem catalog, which provides numerous bug fixes.
Release notes and known issues →OpenShift API for Data Protection (OADP) 1.3.7 is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. OpenShift API for Data Protection (OADP) enables you to back up and restore application resources, persistent volume data, and internal container images to external backup storage. OADP enables both file system-based and snapshot-based backups for persistent volumes. Security Fix(es) from Bugzilla: * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) * golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws (CVE-2025-22868) * golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Release notes and known issues →Red Hat OpenShift Container Platform release 4.14.53 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.14. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.14.53. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2025:9759 Security Fix(es): * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli.
Release notes and known issues →Red Hat Quay 3.12.13 is now available with bug fixes. Quay 3.12.13
Release notes and known issues →Red Hat Quay 3.16.2 is now available with bug fixes. Quay 3.16.2
Release notes and known issues →Red Hat Quay 3.9.18 is now available with bug fixes. Quay 3.9.18
Release notes and known issues →Red Hat Quay 3.10.18 is now available with bug fixes. Quay 3.10.18
Release notes and known issues →The Cluster Observability Operator (COO) is a Red Hat OpenShift Container Platform Operator that you can deploy to manage observability component stacks by using custom resource descriptions (CRDs). The 1.5 release of COO.
Release notes and known issues →An update for Red Hat Hardened Images RPMs is now available. This update includes the following RPMs: ruby4.0: * ruby4.0-4.0.6-37.2.hum1 (aarch64, x86_64) * ruby4.0-bundled-gems-4.0.6-37.2.hum1 (aarch64, x86_64) * ruby4.0-default-gems-4.0.6-37.2.hum1 (noarch) * ruby4.0-devel-4.0.6-37.2.hum1 (aarch64, x86_64) * ruby4.0-doc-4.0.6-37.2.hum1 (noarch) * ruby4.0-libs-4.0.6-37.2.hum1 (aarch64, x86_64) * rubygem4.0-bigdecimal-4.0.1-37.2.hum1 (aarch64, x86_64) * rubygem4.0-bundler-4.0.16-37.2.hum1 (noarch) * rubygem4.0-devel-4.0.16-37.2.hum1 (noarch) * rubygem4.0-io-console-0.8.2-37.2.hum1 (aarch64, x86_64) * rubygem4.0-irb-1.16.0-37.2.hum1 (noarch) * rubygem4.0-json-2.18.0-37.2.hum1 (aarch64, x86_64) * rubygem4.0-minitest-6.0.0-37.2.hum1 (noarch) * rubygem4.0-power_assert-3.0.1-37.2.hum1 (noarch) * rubygem4.0-psych-5.3.1-37.2.hum1 (aarch64, x86_64) * rubygem4.0-racc-1.8.1-37.2.hum1 (aarch64, x86_64) * rubygem4.0-rake-13.3.1-37.2.hum1 (noarch) * rubygem4.0-rbs-3.10.0-37.2.hum1 (aarch64, x86_64) * rubygem4.0-rdoc-7.0.4-37.2.hum1 (noarch) * rubygem4.0-rexml-3.4.4-37.2.hum1 (noarch) * rubygem4.0-rss-0.3.2-37.2.hum1 (noarch) * rubygem4.0-rubygems-4.0.16-37.2.hum1 (noarch) * rubygem4.0-test-unit-3.7.5-37.2.hum1 (noarch) * rubygem4.0-typeprof-0.31.1-37.2.hum1 (noarch) * ruby4.0-4.0.6-37.2.hum1.src (src) Security Fix(es): ruby4.0: * CVE-2026-33210
Release notes and known issues →An update for Red Hat Hardened Images RPMs is now available. This update includes the following RPMs: ruby3.3: * ruby3.3-3.3.10-23.5.hum1 (aarch64, x86_64) * ruby3.3-bundled-gems-3.3.10-23.5.hum1 (aarch64, x86_64) * ruby3.3-default-gems-3.3.10-23.5.hum1 (noarch) * ruby3.3-devel-3.3.10-23.5.hum1 (aarch64, x86_64) * ruby3.3-doc-3.3.10-23.5.hum1 (noarch) * ruby3.3-libs-3.3.10-23.5.hum1 (aarch64, x86_64) * rubygem3.3-bigdecimal-3.1.5-23.5.hum1 (aarch64, x86_64) * rubygem3.3-bundler-2.5.22-23.5.hum1 (noarch) * rubygem3.3-devel-3.5.22-23.5.hum1 (noarch) * rubygem3.3-io-console-0.7.1-23.5.hum1 (aarch64, x86_64) * rubygem3.3-irb-1.13.1-23.5.hum1 (noarch) * rubygem3.3-json-2.7.2-23.5.hum1 (aarch64, x86_64) * rubygem3.3-minitest-5.20.0-23.5.hum1 (noarch) * rubygem3.3-power_assert-2.0.3-23.5.hum1 (noarch) * rubygem3.3-psych-5.1.2-23.5.hum1 (aarch64, x86_64) * rubygem3.3-racc-1.7.3-23.5.hum1 (aarch64, x86_64) * rubygem3.3-rake-13.1.0-23.5.hum1 (noarch) * rubygem3.3-rbs-3.4.0-23.5.hum1 (aarch64, x86_64) * rubygem3.3-rdoc-6.6.3.1-23.5.hum1 (noarch) * rubygem3.3-rexml-3.4.4-23.5.hum1 (noarch) * rubygem3.3-rss-0.3.1-23.5.hum1 (noarch) * rubygem3.3-rubygems-3.5.22-23.5.hum1 (noarch) * rubygem3.3-test-unit-3.6.1-23.5.hum1 (noarch) * rubygem3.3-typeprof-0.21.9-23.5.hum1 (noarch) * ruby3.3-3.3.10-23.5.hum1.src (src)
Release notes and known issues →An update for Red Hat Hardened Images RPMs is now available. This update includes the following RPMs: ruby3.4: * ruby3.4-3.4.10-31.6.hum1 (aarch64, x86_64) * ruby3.4-bundled-gems-3.4.10-31.6.hum1 (aarch64, x86_64) * ruby3.4-default-gems-3.4.10-31.6.hum1 (noarch) * ruby3.4-devel-3.4.10-31.6.hum1 (aarch64, x86_64) * ruby3.4-doc-3.4.10-31.6.hum1 (noarch) * ruby3.4-libs-3.4.10-31.6.hum1 (aarch64, x86_64) * rubygem3.4-bigdecimal-3.1.8-31.6.hum1 (aarch64, x86_64) * rubygem3.4-bundler-2.6.9-31.6.hum1 (noarch) * rubygem3.4-devel-3.6.9-31.6.hum1 (noarch) * rubygem3.4-io-console-0.8.1-31.6.hum1 (aarch64, x86_64) * rubygem3.4-irb-1.14.3-31.6.hum1 (noarch) * rubygem3.4-json-2.9.1-31.6.hum1 (aarch64, x86_64) * rubygem3.4-minitest-5.25.4-31.6.hum1 (noarch) * rubygem3.4-power_assert-2.0.5-31.6.hum1 (noarch) * rubygem3.4-psych-5.2.2-31.6.hum1 (aarch64, x86_64) * rubygem3.4-racc-1.8.1-31.6.hum1 (aarch64, x86_64) * rubygem3.4-rake-13.2.1-31.6.hum1 (noarch) * rubygem3.4-rbs-3.8.0-31.6.hum1 (aarch64, x86_64) * rubygem3.4-rdoc-6.14.0-31.6.hum1 (noarch) * rubygem3.4-rexml-3.4.4-31.6.hum1 (noarch) * rubygem3.4-rss-0.3.1-31.6.hum1 (noarch) * rubygem3.4-rubygems-3.6.9-31.6.hum1 (noarch) * rubygem3.4-test-unit-3.6.7-31.6.hum1 (noarch) * rubygem3.4-typeprof-0.30.1-31.6.hum1 (noarch) * ruby3.4-3.4.10-31.6.hum1.src (src)
Release notes and known issues →An update for Red Hat Hardened Images RPMs is now available. This update includes the following RPMs: ruby3.3: * ruby3.3-3.3.10-23.6.hum1 (aarch64, x86_64) * ruby3.3-bundled-gems-3.3.10-23.6.hum1 (aarch64, x86_64) * ruby3.3-default-gems-3.3.10-23.6.hum1 (noarch) * ruby3.3-devel-3.3.10-23.6.hum1 (aarch64, x86_64) * ruby3.3-doc-3.3.10-23.6.hum1 (noarch) * ruby3.3-libs-3.3.10-23.6.hum1 (aarch64, x86_64) * rubygem3.3-bigdecimal-3.1.5-23.6.hum1 (aarch64, x86_64) * rubygem3.3-bundler-2.5.22-23.6.hum1 (noarch) * rubygem3.3-devel-3.5.22-23.6.hum1 (noarch) * rubygem3.3-io-console-0.7.1-23.6.hum1 (aarch64, x86_64) * rubygem3.3-irb-1.13.1-23.6.hum1 (noarch) * rubygem3.3-json-2.7.2-23.6.hum1 (aarch64, x86_64) * rubygem3.3-minitest-5.20.0-23.6.hum1 (noarch) * rubygem3.3-power_assert-2.0.3-23.6.hum1 (noarch) * rubygem3.3-psych-5.1.2-23.6.hum1 (aarch64, x86_64) * rubygem3.3-racc-1.7.3-23.6.hum1 (aarch64, x86_64) * rubygem3.3-rake-13.1.0-23.6.hum1 (noarch) * rubygem3.3-rbs-3.4.0-23.6.hum1 (aarch64, x86_64) * rubygem3.3-rdoc-6.6.3.1-23.6.hum1 (noarch) * rubygem3.3-rexml-3.4.4-23.6.hum1 (noarch) * rubygem3.3-rss-0.3.1-23.6.hum1 (noarch) * rubygem3.3-rubygems-3.5.22-23.6.hum1 (noarch) * rubygem3.3-test-unit-3.6.1-23.6.hum1 (noarch) * rubygem3.3-typeprof-0.21.9-23.6.hum1 (noarch) * ruby3.3-3.3.10-23.6.hum1.src (src) Security Fix(es): ruby3.3: * CVE-2026-80212 * CVE-2026-80213
Release notes and known issues →An update for Red Hat Hardened Images RPMs is now available. This update includes the following RPMs: ruby4.0: * ruby4.0-4.0.6-37.3.hum1 (aarch64, x86_64) * ruby4.0-bundled-gems-4.0.6-37.3.hum1 (aarch64, x86_64) * ruby4.0-default-gems-4.0.6-37.3.hum1 (noarch) * ruby4.0-devel-4.0.6-37.3.hum1 (aarch64, x86_64) * ruby4.0-doc-4.0.6-37.3.hum1 (noarch) * ruby4.0-libs-4.0.6-37.3.hum1 (aarch64, x86_64) * rubygem4.0-bigdecimal-4.0.1-37.3.hum1 (aarch64, x86_64) * rubygem4.0-bundler-4.0.16-37.3.hum1 (noarch) * rubygem4.0-devel-4.0.16-37.3.hum1 (noarch) * rubygem4.0-io-console-0.8.2-37.3.hum1 (aarch64, x86_64) * rubygem4.0-irb-1.16.0-37.3.hum1 (noarch) * rubygem4.0-json-2.18.0-37.3.hum1 (aarch64, x86_64) * rubygem4.0-minitest-6.0.0-37.3.hum1 (noarch) * rubygem4.0-power_assert-3.0.1-37.3.hum1 (noarch) * rubygem4.0-psych-5.3.1-37.3.hum1 (aarch64, x86_64) * rubygem4.0-racc-1.8.1-37.3.hum1 (aarch64, x86_64) * rubygem4.0-rake-13.3.1-37.3.hum1 (noarch) * rubygem4.0-rbs-3.10.0-37.3.hum1 (aarch64, x86_64) * rubygem4.0-rdoc-7.0.4-37.3.hum1 (noarch) * rubygem4.0-rexml-3.4.4-37.3.hum1 (noarch) * rubygem4.0-rss-0.3.2-37.3.hum1 (noarch) * rubygem4.0-rubygems-4.0.16-37.3.hum1 (noarch) * rubygem4.0-test-unit-3.7.5-37.3.hum1 (noarch) * rubygem4.0-typeprof-0.31.1-37.3.hum1 (noarch) * ruby4.0-4.0.6-37.3.hum1.src (src) Security Fix(es): ruby4.0: * CVE-2026-80212 * CVE-2026-80213
Release notes and known issues →Red Hat Quay 3.15.4 is now available with bug fixes. Quay 3.15.4
Release notes and known issues →Red Hat OpenShift Container Platform release 4.14.74 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.14. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.14.74. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:67836 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/
Release notes and known issues →Red Hat OpenShift Container Platform release 4.14.74 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.14. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.14.74. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:67838 Security Fix(es): * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli.
Release notes and known issues →Red Hat OpenShift Container Platform release 4.15.69 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.15. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.15.69. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:67856 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html/release_notes/
Release notes and known issues →Red Hat OpenShift Container Platform release 4.15.69 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.15. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.15.69. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:67858 Security Fix(es): * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli.
Release notes and known issues →Red Hat OpenShift Container Platform release 4.16.71 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.16. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.16.71. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:67934 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/
Release notes and known issues →Red Hat OpenShift Container Platform release 4.16.71 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.16. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.16.71. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:67936 Security Fix(es): * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli.
Release notes and known issues →Red Hat OpenShift Container Platform release 4.19.48 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.19. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.19.48. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:68534 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/
Release notes and known issues →Red Hat OpenShift Container Platform release 4.20.39 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.20. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.20.39. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:68535 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/
Release notes and known issues →Red Hat OpenShift Container Platform release 4.19.48 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.19. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.19.48. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:68540 Security Fix(es): * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli.
Release notes and known issues →Red Hat OpenShift Container Platform release 4.21.34 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.21. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.21.34. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:68538 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/
Release notes and known issues →Red Hat OpenShift Container Platform release 4.21.34 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.21. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.21.34. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:68546 Security Fix(es): * fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization (CVE-2026-84292) * fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency (CVE-2026-16221) * fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects (CVE-2026-76172) * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) * baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling (CVE-2026-45819) * fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority (CVE-2026-18446) * fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies (CVE-2026-84394) * fast-uri: fast-uri: Host confusion via skipped IDN canonicalization (CVE-2026-75931) * fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899) * fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli.
Release notes and known issues →Red Hat OpenShift Container Platform release 4.22.15 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.22. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.22.15. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:68550 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/
Release notes and known issues →Red Hat OpenShift Container Platform release 4.22.15 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.22. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.22.15. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:68552 Security Fix(es): * fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization (CVE-2026-84292) * fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency (CVE-2026-16221) * fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects (CVE-2026-76172) * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) * baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling (CVE-2026-45819) * fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority (CVE-2026-18446) * fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies (CVE-2026-84394) * fast-uri: fast-uri: Host confusion via skipped IDN canonicalization (CVE-2026-75931) * fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899) * fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.22 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli.
Release notes and known issues →An update for ibu components is available for Red Hat OpenShift Container Platform 4.22. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the extra ibu container images for Red Hat OpenShift Container Platform 4.22. All OpenShift Container Platform users are advised to upgrade to these updated packages and images.
Release notes and known issues →An update for the ruby:3.3 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. Security Fix(es): * resolv: resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses (CVE-2026-80212) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Release notes and known issues →Multiple security issues were found in Rack, an interface for developing web applications in Ruby, which could result in denial of service, information disclosure, spoofing or bypass of access restrictions. https://security-tracker.debian.org/tracker/DSA-6492-1
Release notes and known issues →Several vulnerabilities were discovered in libevent, an asynchronous event notification library. The HTTP implementation (evhttp) handled Transfer-Encoding and Content-Length headers, chunked-encoding line terminators, header line folding and chunked trailers too permissively, which could allow HTTP request smuggling, header injection or access control bypass when a libevent-based server or client is combined with an HTTP proxy. Out-of-bounds memory accesses in the DNS (evdns), tagged RPC (evtag/evrpc) and buffered socket (bufferevent) code, and a use-after-free in evbuffer, could result in denial of service or potentially the execution of arbitrary code when processing untrusted input. https://security-tracker.debian.org/tracker/DSA-6493-1
Release notes and known issues →Multiple security vulnerabilities were discovered in the Kamailio SIP server, which could result in denial of service. https://security-tracker.debian.org/tracker/DSA-6494-1
Release notes and known issues →The Internet is changing more today than at any point since Cloudflare launched back on September 27, 2010. As automated traffic surpasses human activity, we reflect on the rise of AI agents, new creators, and how we can help build a fair, sustainable future for the web.
Release notes and known issues →update api,sdk,envoyextensions in troubleshoot
Release notes and known issues →update api and sdk in envoyextensions
Release notes and known issues →update sdk version in api
Release notes and known issues →Turn off Tuya fans when the speed is set to 0% ( @frenck - #181972 ) ( tuya docs ) Fix Todoist timed calendar event duration ( @andremmfaria - #182121 ) ( todoist docs ) Fix ISEO Argo BLE offering unrelated devices for discovery ( @FezVrasta - #182315 ) ( iseo_argo_ble docs ) Bump pyenphase to 4.0.5 ( @catsmanac - #182473 ) ( enphase_envoy docs ) (dependency) Make HTTP security filter scan cost track request target length ( @frenck - #182570 ) ( http docs ) Fix HomematicIP Cloud config flow advancing on a rejected PIN ( @frenck - #182601 ) ( homematicip_cloud docs ) Fix friends' achievement stats in Xbox integration ( @scardus - #182686 ) ( xbox docs ) Fix typo in the Z-Wave controller statistics key ( @balloob - #182827 ) ( zwave_js docs ) Log the entity ID in the MQTT group member update message ( @David-Wu1119 - #182928 ) ( mqtt docs ) Bump pyenphase to 4.0.6 ( @catsmanac - #183094 ) ( enphase_envoy docs ) (dependency) Handle MissingSerial during OpenEVSE entry setup ( @firstof9 - #183105 ) ( openevse docs ) Bump imgw_pib to 2.5.2 ( @bieniu - #183111 ) ( imgw_pib docs ) (dependency) Bump python-xbox to 0.2.2 ( @tr4nt0r - #182072 ) ( xbox docs ) (dependency) Bump python-xbox to 0.3.0 ( @tr4nt0r - #182643 ) ( xbox docs ) (dependency)
Release notes and known issues →Official IBM security bulletin for IBM InfoSphere Information Server.
Release notes and known issues →Admin v2: Mask client secrets for view-only users ( #52731 ) * Admin v2: Mask client secrets for view-only users When a user lacks manage permission on a client, strip client secrets from GET /clients/{client} and GET /clients responses to match v1 behavior. Closes #52197 Signed-off-by: Shatrughan Rai <polyglot.dev@outlook.com> # Conflicts: # rest/admin-v2/services/src/main/java/org/keycloak/services/client/DefaultClientService.java * Refactor getClientListSecretMaskedForViewOnly test Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Signed-off-by: Shatrughan Rai <polyglot.dev@outlook.com> * Fix: test scope fixes an unclosed Stream in the authorization test by wrapping it in try-with-resources, matching the pattern used in tests. Fixes : #52197 Signed-off-by: Shatrughan Rai <polyglot.dev@outlook.com> * moving the fix to the new client resource type Signed-off-by: Steve Hawkins <shawkins@redhat.com> --------- Signed-off-by: Shatrughan Rai <polyglot.dev@outlook.com> Signed-off-by: Steve Hawkins <shawkins@redhat.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Steve Hawkins <shawkins@redhat.com>
Release notes and known issues →Version: 7.3-rc5 (mainline) Released: 2026-09-27 Source: linux-7.3-rc5.tar.gz Patch: full ( incremental )
Release notes and known issues →Microsoft Security Response Center release information for 2026-Sep.
Release notes and known issues →This is an updated version of the Node Maintenance Operator. This Operator is delivered by Red Hat Workload Availability (RHWA). The Node Maintenance Operator works in conjunction with the machine health check or the node health check to provide automatic remediation of unhealthy nodes by rebooting them. This minimizes downtime for stateful applications and ReadWriteOnce (RWO) Volumes as well as restoring compute capacity in the event of transient failures.
Release notes and known issues →This is an updated version of the Self Node Remediation Operator. This Operator is delivered by Red Hat Workload Availability (RHWA). The Self Node Remediation Operator works in conjunction with the machine health check or the node health check to provide automatic remediation of unhealthy nodes by rebooting them. This minimizes downtime for stateful applications and ReadWriteOnce (RWO) Volumes as well as restoring compute capacity in the event of transient failures.
Release notes and known issues →This is an updated version of the Machine Deletion Remediation Operator. This Operator is delivered by Red Hat Workload Availability (RHWA). The Machine Deletion Remediation (MDR) Operator works with the Node Health Check (NHC) Operator to reprovision unhealthy nodes using the Machine API. The MDR Operator looks for the associated machine of an unhealthy node, and deletes it. After the machine custom resource (CR) has been deleted, the owning controller creates a replacement machine CR.
Release notes and known issues →This is an updated version of the Storage-Based Remediation Operator. This Operator is delivered by Red Hat Workload Availability (RHWA). The Storage-Based Remediation Operator is an OLM Operator for managing STONITH Block Device (SBD) configurations and remediations for high-availability clustering. The operator provides automated node remediation when nodes become unresponsive by leveraging shared block storage for fencing operations.
Release notes and known issues →This is an updated version of the Node Health Check Operator. This Operator is delivered by Red Hat Workload Availability (RHWA). The Node Health Check Operator deploys the Node Health Check controller. The controller identifies unhealthy nodes and uses a remediation provider to remediate the unhealthy nodes. You can install either the Self Node Remediation Operator, the Fence Agents Remediation Operator, or the Machine Deletion Remedation Operator as a remediation provider.
Release notes and known issues →Red Hat Advanced Cluster Management for Kubernetes v2.15 general availability release images, which provide security fixes, bug fixes, and updated container images. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE links in the References section. Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console—with security policy built in. This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which add new features and enhancements, bug fixes, and updated container images. See the following Release Notes documentation, which will be updated shortly for this release, for additional details about this release: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.15/html-single/release_notes/index#acm-release-notes
Release notes and known issues →An update is now available for Red Hat Lightspeed (formerly Insights) for Runtimes on RHEL 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. An update is now available for Red Hat Lightspeed (formerly Insights) for Runtimes on RHEL 9. Security fix(es): * golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering (CVE-2026-42502) * golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136) * golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681) * golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) * Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) * golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Release notes and known issues →