RED HATRHSA-2026-62563
An update for Red Hat Hardened Images RPMs is now available. This update includes the following RPMs: ruby4.0: * ruby4.0-4.0.6-37.3.hum1 (aarch64, x86_64) * ruby4.0-bundled-gems-4.0.6-37.3.hum1 (aarch64, x86_64) * ruby4.0-default-gems-4.0.6-37.3.hum1 (noarch) * ruby4.0-devel-4.0.6-37.3.hum1 (aarch64, x86_64) * ruby4.0-doc-4.0.6-37.3.hum1 (noarch) * ruby4.0-libs-4.0.6-37.3.hum1 (aarch64, x86_64) * rubygem4.0-bigdecimal-4.0.1-37.3.hum1 (aarch64, x86_64) * rubygem4.0-bundler-4.0.16-37.3.hum1 (noarch) * rubygem4.0-devel-4.0.16-37.3.hum1 (noarch) * rubygem4.0-io-console-0.8.2-37.3.hum1 (aarch64, x86_64) * rubygem4.0-irb-1.16.0-37.3.hum1 (noarch) * rubygem4.0-json-2.18.0-37.3.hum1 (aarch64, x86_64) * rubygem4.0-minitest-6.0.0-37.3.hum1 (noarch) * rubygem4.0-power_assert-3.0.1-37.3.hum1 (noarch) * rubygem4.0-psych-5.3.1-37.3.hum1 (aarch64, x86_64) * rubygem4.0-racc-1.8.1-37.3.hum1 (aarch64, x86_64) * rubygem4.0-rake-13.3.1-37.3.hum1 (noarch) * rubygem4.0-rbs-3.10.0-37.3.hum1 (aarch64, x86_64) * rubygem4.0-rdoc-7.0.4-37.3.hum1 (noarch) * rubygem4.0-rexml-3.4.4-37.3.hum1 (noarch) * rubygem4.0-rss-0.3.2-37.3.hum1 (noarch) * rubygem4.0-rubygems-4.0.16-37.3.hum1 (noarch) * rubygem4.0-test-unit-3.7.5-37.3.hum1 (noarch) * rubygem4.0-typeprof-0.31.1-37.3.hum1 (noarch) * ruby4.0-4.0.6-37.3.hum1.src (src) Security Fix(es): ruby4.0: * CVE-2026-80212 * CVE-2026-80213
Published 2 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-6568
Red Hat Quay 3.15.4 is now available with bug fixes. Quay 3.15.4
Published 3 Apr 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-67838
Red Hat OpenShift Container Platform release 4.14.74 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.14. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.14.74. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:67836 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/
Published 24 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-67839
Red Hat OpenShift Container Platform release 4.14.74 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.14. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.14.74. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:67838 Security Fix(es): * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli.
Published 24 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-67858
Red Hat OpenShift Container Platform release 4.15.69 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.15. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.15.69. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:67856 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html/release_notes/
Published 24 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-67859
Red Hat OpenShift Container Platform release 4.15.69 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.15. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.15.69. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:67858 Security Fix(es): * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli.
Published 24 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-67936
Red Hat OpenShift Container Platform release 4.16.71 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.16. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.16.71. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:67934 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/
Published 24 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-67938
Red Hat OpenShift Container Platform release 4.16.71 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.16. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.16.71. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:67936 Security Fix(es): * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli.
Published 24 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-68527
An update for opentelemetry-collector is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Collector with the supported components for a Red Hat build of OpenTelemetry Security Fix(es): * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499) * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820) * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Published 17 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-68540
Red Hat OpenShift Container Platform release 4.19.48 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.19. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.19.48. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:68534 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/
Published 23 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-68541
Red Hat OpenShift Container Platform release 4.20.39 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.20. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.20.39. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:68535 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/
Published 22 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-68542
Red Hat OpenShift Container Platform release 4.19.48 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.19. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.19.48. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:68540 Security Fix(es): * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli.
Published 23 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-68546
Red Hat OpenShift Container Platform release 4.21.34 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.21. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.21.34. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:68538 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/
Published 22 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-68547
Red Hat OpenShift Container Platform release 4.21.34 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.21. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.21.34. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:68546 Security Fix(es): * fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization (CVE-2026-84292) * fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency (CVE-2026-16221) * fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects (CVE-2026-76172) * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) * baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling (CVE-2026-45819) * fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority (CVE-2026-18446) * fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies (CVE-2026-84394) * fast-uri: fast-uri: Host confusion via skipped IDN canonicalization (CVE-2026-75931) * fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899) * fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli.
Published 22 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-68550
Red Hat OpenShift Container Platform release 4.22.15 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.22. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.22.15. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:68552 Security Fix(es): * github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.22 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli.
Published 22 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-68552
Red Hat OpenShift Container Platform release 4.22.15 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.22. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.22.15. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:68550 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/
Published 22 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-68553
Red Hat OpenShift Container Platform release 4.22.15 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.22. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.22.15. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:68552 Security Fix(es): * fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization (CVE-2026-84292) * fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency (CVE-2026-16221) * fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects (CVE-2026-76172) * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) * baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling (CVE-2026-45819) * fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority (CVE-2026-18446) * fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies (CVE-2026-84394) * fast-uri: fast-uri: Host confusion via skipped IDN canonicalization (CVE-2026-75931) * fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899) * fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.22 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli.
Published 22 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-69293
An update for osbuild-composer is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients. Security Fix(es): * golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136) * golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681) * golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering (CVE-2026-42502) * github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178) * github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Published 21 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-69917
OpenShift Source To Image 1.6.4 Release Release of OpenShift Source To Image 1.6.4
Published 22 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-69922
An update for ibu components is available for Red Hat OpenShift Container Platform 4.22. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the extra ibu container images for Red Hat OpenShift Container Platform 4.22. All OpenShift Container Platform users are advised to upgrade to these updated packages and images.
Published 22 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-69928
Red Hat OpenShift Builds 1.8.2 Release of Red Hat OpenShift Builds 1.8.2
Published 22 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-69945
Red Hat OpenShift Builds 1.8.2 Release of Red Hat OpenShift Builds 1.8.2
Published 22 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-70824
The 1.3.8 release of Red Hat Trusted Artifact Signer OpenShift Operator. For more details please visit the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3 The RHTAS Operator can be used with OpenShift Container Platform 4.16, 4.17, 4.18, 4.19, 4.20 and 4.21
Published 23 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-70826
The 1.3.8 release of Red Hat Trusted Artifact Signer OpenShift Operator. For more details please visit the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3 The RHTAS Operator can be used with OpenShift Container Platform 4.16, 4.17, 4.18, 4.19, 4.20 and 4.21
Published 23 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-70828
The 1.3.8 release of Red Hat Trusted Artifact Signer OpenShift Operator. For more details please visit the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3 The RHTAS Operator can be used with OpenShift Container Platform 4.16, 4.17, 4.18, 4.19, 4.20 and 4.21
Published 23 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-70829
The 1.3.8 release of Red Hat Trusted Artifact Signer OpenShift Operator. For more details please visit the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3 The RHTAS Operator can be used with OpenShift Container Platform 4.16, 4.17, 4.18, 4.19, 4.20 and 4.21
Published 23 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-70870
Logging for Red Hat OpenShift - 6.5.3 Red Hat OpenShift Logging 6.5.3 is a cluster-wide logging solution for OpenShift that collects and manages applications, infrastructure, and audit logs.
Published 23 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-71597
Multicluster Global Hub v1.5.8 general availability release images, which provide security fixes, bug fixes, and updated container images. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE links in the References section. Red Hat multicluster global hub is a set of components that enable you to import one or more hub clusters and manage them from a single hub cluster.
Published 24 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-72285
An update for the ruby:3.3 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. Security Fix(es): * resolv: resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses (CVE-2026-80212) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Published 28 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →CANONICALUSN-8825-1
It was discovered that Requests did not correctly handle generating random temporary file paths. An attacker could possibly use this issue to execute arbitrary code.
Published 28 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →CANONICALUSN-8826-1
Maher Azzouzi discovered that LXC did not correctly handle logging certain failure messages. An attacker could possibly use this issue to leak sensitive information. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2022-47952) Sam Sanoop discovered that LXC did not correctly handle certain forms of user authorization. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-39402)
Published 28 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →DEBIANDSA-6492-1
Multiple security issues were found in Rack, an interface for developing web applications in Ruby, which could result in denial of service, information disclosure, spoofing or bypass of access restrictions. https://security-tracker.debian.org/tracker/DSA-6492-1
Published Never · Source checked 27 Sep 2026
Release notes and known issues →DEBIANDSA-6493-1
Several vulnerabilities were discovered in libevent, an asynchronous event notification library. The HTTP implementation (evhttp) handled Transfer-Encoding and Content-Length headers, chunked-encoding line terminators, header line folding and chunked trailers too permissively, which could allow HTTP request smuggling, header injection or access control bypass when a libevent-based server or client is combined with an HTTP proxy. Out-of-bounds memory accesses in the DNS (evdns), tagged RPC (evtag/evrpc) and buffered socket (bufferevent) code, and a use-after-free in evbuffer, could result in denial of service or potentially the execution of arbitrary code when processing untrusted input. https://security-tracker.debian.org/tracker/DSA-6493-1
Published Never · Source checked 27 Sep 2026
Release notes and known issues →DEBIANDSA-6494-1
Multiple security vulnerabilities were discovered in the Kamailio SIP server, which could result in denial of service. https://security-tracker.debian.org/tracker/DSA-6494-1
Published Never · Source checked 27 Sep 2026
Release notes and known issues →CLOUDFLARECLOUDFLARE-8B7BC895ED07B08D
The Internet is changing more today than at any point since Cloudflare launched back on September 27, 2010. As automated traffic surpasses human activity, we reflect on the rise of AI agents, new creators, and how we can help build a fair, sustainable future for the web.
Published 27 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →HASHICORPCONSUL-0.10.0-RC1
update api,sdk,envoyextensions in troubleshoot
Published Never · Source checked 28 Sep 2026
Release notes and known issues →HASHICORPCONSUL-0.11.0-RC1
update api and sdk in envoyextensions
Published Never · Source checked 28 Sep 2026
Release notes and known issues →HASHICORPCONSUL-1.35.0-RC1
update sdk version in api
Published Never · Source checked 28 Sep 2026
Release notes and known issues →OPEN HOME FOUNDATIONHOME-ASSISTANT-2026.9.4
Turn off Tuya fans when the speed is set to 0% ( @frenck - #181972 ) ( tuya docs ) Fix Todoist timed calendar event duration ( @andremmfaria - #182121 ) ( todoist docs ) Fix ISEO Argo BLE offering unrelated devices for discovery ( @FezVrasta - #182315 ) ( iseo_argo_ble docs ) Bump pyenphase to 4.0.5 ( @catsmanac - #182473 ) ( enphase_envoy docs ) (dependency) Make HTTP security filter scan cost track request target length ( @frenck - #182570 ) ( http docs ) Fix HomematicIP Cloud config flow advancing on a rejected PIN ( @frenck - #182601 ) ( homematicip_cloud docs ) Fix friends' achievement stats in Xbox integration ( @scardus - #182686 ) ( xbox docs ) Fix typo in the Z-Wave controller statistics key ( @balloob - #182827 ) ( zwave_js docs ) Log the entity ID in the MQTT group member update message ( @David-Wu1119 - #182928 ) ( mqtt docs ) Bump pyenphase to 4.0.6 ( @catsmanac - #183094 ) ( enphase_envoy docs ) (dependency) Handle MissingSerial during OpenEVSE entry setup ( @firstof9 - #183105 ) ( openevse docs ) Bump imgw_pib to 2.5.2 ( @bieniu - #183111 ) ( imgw_pib docs ) (dependency) Bump python-xbox to 0.2.2 ( @tr4nt0r - #182072 ) ( xbox docs ) (dependency) Bump python-xbox to 0.3.0 ( @tr4nt0r - #182643 ) ( xbox docs ) (dependency)
Published Never · Source checked 28 Sep 2026
Release notes and known issues →IBMIBM-PRODUCTS-IBM-7289434
Official IBM security bulletin for IBM InfoSphere Information Server.
Published 27 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →LINUX KERNEL ORGANIZATIONLINUX-1B828F4144D4620A
Version: 7.3-rc5 (mainline) Released: 2026-09-27 Source: linux-7.3-rc5.tar.gz Patch: full ( incremental )
Published 27 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →MICROSOFTMSRC-2024-FEB
Microsoft Security Response Center release information for 2024-Feb.
Published 13 Feb 2024 · Source checked 28 Sep 2026
Release notes and known issues →RED HATRHSA-2026-54283
This is an updated version of the Node Maintenance Operator. This Operator is delivered by Red Hat Workload Availability (RHWA). The Node Maintenance Operator works in conjunction with the machine health check or the node health check to provide automatic remediation of unhealthy nodes by rebooting them. This minimizes downtime for stateful applications and ReadWriteOnce (RWO) Volumes as well as restoring compute capacity in the event of transient failures.
Published 12 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-54284
This is an updated version of the Self Node Remediation Operator. This Operator is delivered by Red Hat Workload Availability (RHWA). The Self Node Remediation Operator works in conjunction with the machine health check or the node health check to provide automatic remediation of unhealthy nodes by rebooting them. This minimizes downtime for stateful applications and ReadWriteOnce (RWO) Volumes as well as restoring compute capacity in the event of transient failures.
Published 12 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-54285
This is an updated version of the Machine Deletion Remediation Operator. This Operator is delivered by Red Hat Workload Availability (RHWA). The Machine Deletion Remediation (MDR) Operator works with the Node Health Check (NHC) Operator to reprovision unhealthy nodes using the Machine API. The MDR Operator looks for the associated machine of an unhealthy node, and deletes it. After the machine custom resource (CR) has been deleted, the owning controller creates a replacement machine CR.
Published 12 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-54286
This is an updated version of the Storage-Based Remediation Operator. This Operator is delivered by Red Hat Workload Availability (RHWA). The Storage-Based Remediation Operator is an OLM Operator for managing STONITH Block Device (SBD) configurations and remediations for high-availability clustering. The operator provides automated node remediation when nodes become unresponsive by leveraging shared block storage for fencing operations.
Published 12 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-54287
This is an updated version of the Node Health Check Operator. This Operator is delivered by Red Hat Workload Availability (RHWA). The Node Health Check Operator deploys the Node Health Check controller. The controller identifies unhealthy nodes and uses a remediation provider to remediate the unhealthy nodes. You can install either the Self Node Remediation Operator, the Fence Agents Remediation Operator, or the Machine Deletion Remedation Operator as a remediation provider.
Published 12 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-54427
Red Hat Advanced Cluster Management for Kubernetes v2.15 general availability release images, which provide security fixes, bug fixes, and updated container images. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE links in the References section. Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console—with security policy built in. This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which add new features and enhancements, bug fixes, and updated container images. See the following Release Notes documentation, which will be updated shortly for this release, for additional details about this release: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.15/html-single/release_notes/index#acm-release-notes
Published 12 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-54441
An update is now available for Red Hat Lightspeed (formerly Insights) for Runtimes on RHEL 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. An update is now available for Red Hat Lightspeed (formerly Insights) for Runtimes on RHEL 9. Security fix(es): * golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering (CVE-2026-42502) * golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136) * golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681) * golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) * Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) * golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Published 12 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-54527
cert-manager Operator for Red Hat OpenShift 1.19.1 The cert-manager Operator for Red Hat OpenShift builds on top of Kubernetes, introducing certificate authorities and certificates as first-class resource types in the Kubernetes API. This makes it possible to provide certificates-as-a-service to developers working within your Kubernetes cluster.
Published 13 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-54531
cert-manager Operator for Red Hat OpenShift 1.19.1 The cert-manager Operator for Red Hat OpenShift builds on top of Kubernetes, introducing certificate authorities and certificates as first-class resource types in the Kubernetes API. This makes it possible to provide certificates-as-a-service to developers working within your Kubernetes cluster.
Published 13 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-54583
Red Hat OpenShift Container Platform release 4.20.34 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.20. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.20.34. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:54580 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/
Published 18 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-56340
Logging for Red Hat OpenShift - 6.5.2 Red Hat OpenShift Logging 6.5.2 is a cluster-wide logging solution for OpenShift that collects and manages applications, infrastructure, and audit logs.
Published 18 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-56347
A new version of Migration Toolkit for Applications (MTA) is now available. Migration Toolkit for Applications (MTA) accelerates large-scale application modernization efforts across hybrid cloud environments on Red Hat OpenShift. This solution provides insight throughout the adoption process, at both the portfolio and application levels: inventory, assess, analyze, and manage applications for faster migration to OpenShift via the user interface.
Published 18 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-56366
Red Hat OpenShift Data Foundation 4.19.22 security, enhancement & bug fix update Red Hat OpenShift Data Foundation 4.19.22 security, enhancement & bug fix update FIXED BUGS: ========== DFBUGS-7382: [Backport to odf-4.19.z] [GSS] PDB is created for rgw even though the gateway instance count is 1 DFBUGS-7005: [Backport to odf-4.19.z] [GSS][Disconnected env] ODF is upgraded itself from ODF v4.20.2 to ODF v4.20.7 without Manual Approval when upgrdaing OCP v4.20.5 to OCP v4.20.16 DFBUGS-6996: [Backport to odf-4.19.z] [GSS][ODF] Noobaa DB_CLEANER not honoring set value DFBUGS-6815: release-4.19 ODF must-gather missing CR storageclusterpeer.yaml DFBUGS-6704: Backport to odf-4.19.z [GSS] Unnecessary OSD redeployments on 4.19.z upgrade for already-encrypted OSDs DFBUGS-5636: [4.19]Topology awareness issue DFBUGS-3947: 4.19 [RDR] cephblockpool radosnamespaces contains "failed to retrieve mirroring pool ocs-storagecluster-cephblockpool" message after the uninstallation of DR
Published 18 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-57013
Red Hat OpenShift Data Foundation 4.20.17 security, enhancement & bug fix update Red Hat OpenShift Data Foundation 4.20.17 security, enhancement & bug fix update FIXED BUGS: ========== DFBUGS-8962: RHODF 4.20.17 release DFBUGS-8003: [GSS] Rook Ceph metrics are not being scraped, and the rook-ceph-mgr-external service is inaccessible from within the cluster. DFBUGS-7951: [upgrade from 4.19 to 4.20] Clusters with Convergence changes always have nfs driver deployed DFBUGS-7393: [Backport to odf-4.20.z] [MCG] noobaa-core pod restart overwrites admin account default_resource to arbitrary backingstore DFBUGS-7380: [Backport to odf-4.20.z] [GSS] PDB is created for rgw even though the gateway instance count is 1 DFBUGS-7318: [Backport to 4.20] - noobaa-core-0 intermittent CrashLoopBackOff due to OOMKilled during object delete workload - map_deleter unbounded memory consumption DFBUGS-7004: [Backport to odf-4.20.z] [GSS][Disconnected env] ODF is upgraded itself from ODF v4.20.2 to ODF v4.20.7 without Manual Approval when upgrdaing OCP v4.20.5 to OCP v4.20.16 DFBUGS-6997: [Backport to odf-4.20.z] [GSS][ODF] Noobaa DB_CLEANER not honoring set value DFBUGS-6814: release-4.20 ODF must-gather missing CR storageclusterpeer.yaml DFBUGS-5767: [4.20.z] Landing page after installation of operator is not correct
Published 19 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-57191
Red Hat Advanced Cluster Management for Kubernetes v2.16 general availability release images, which provide security fixes, bug fixes, and updated container images. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE links in the References section. Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console—with security policy built in. This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which add new features and enhancements, bug fixes, and updated container images. See the following Release Notes documentation, which will be updated shortly for this release, for additional details about this release: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.16/html-single/release_notes/index#acm-release-notes
Published 19 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-57194
Red Hat multicluster engine for Kubernetes v2.11 general availability release images, which provide security fixes, bug fixes, and updated container images. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE links in the References section. The multicluster engine for Kubernetes provides the foundational components that are necessary for the centralized management of multiple Kubernetes-based clusters across data centers, public clouds, and private clouds. You can use the engine to create new Red Hat OpenShift Container Platform clusters or to bring existing Kubernetes-based clusters under management by importing them. After the clusters are managed, you can use the APIs that are provided by the engine to distribute configuration based on placement policy.
Published 19 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-59467
A new version of OpenShift API for Data Protection (OADP) is now available. OpenShift API for Data Protection (OADP) enables you to back up and restore application resources, persistent volume data, and internal container images to external backup storage. OADP enables both file system-based and snapshot-based backups for persistent volumes.
Published 25 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-59558
Red Hat multicluster engine for Kubernetes v2.8 general availability release images, which provide security fixes, bug fixes, and updated container images. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE links in the References section. The multicluster engine for Kubernetes provides the foundational components that are necessary for the centralized management of multiple Kubernetes-based clusters across data centers, public clouds, and private clouds. You can use the engine to create new Red Hat OpenShift Container Platform clusters or to bring existing Kubernetes-based clusters under management by importing them. After the clusters are managed, you can use the APIs that are provided by the engine to distribute configuration based on placement policy.
Published 25 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-59560
An update for osbuild-composer is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients. Security Fix(es): * golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136) * golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681) * golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering (CVE-2026-42502) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Published 25 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-59562
An update for osbuild-composer is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients. Security Fix(es): * golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) * golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136) * golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681) * golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering (CVE-2026-42502) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Published 25 Aug 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-63636
Red Hat build of MicroShift release 4.19.46 is now available with updates to packages and images that include a security update. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat build of MicroShift is Red Hat's light-weight Kubernetes orchestration solution designed for edge device deployments and is built from the edge capabilities of Red Hat OpenShift Container Platform. MicroShift is an application that is deployed on top of Red Hat Enterprise Linux devices at the edge, providing an efficient way to operate single-node clusters in these low-resource environments. This advisory contains the RPM packages for Red Hat build of MicroShift 4.19.46. Read the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:63047 Security Fix(es): * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499) All Red Hat build of MicroShift 4.19 users are advised to use these updated packages and images when they are available in the RPM repository.
Published 9 Sep 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-63639
Red Hat build of MicroShift release 4.22.13 is now available with updates to packages and images that include a security update. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat build of MicroShift is Red Hat's light-weight Kubernetes orchestration solution designed for edge device deployments and is built from the edge capabilities of Red Hat OpenShift Container Platform. MicroShift is an application that is deployed on top of Red Hat Enterprise Linux devices at the edge, providing an efficient way to operate single-node clusters in these low-resource environments. This advisory contains the RPM packages for Red Hat build of MicroShift 4.22.13. Read the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:63096 Security Fix(es): * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) All Red Hat build of MicroShift 4.22 users are advised to use these updated packages and images when they are available in the RPM repository.
Published 8 Sep 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-65853
Red Hat OpenShift Container Platform release 4.18.55 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.18. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.18.55. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:65852 Security Fix(es): * brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257) * brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation (CVE-2026-69152) * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli.
Published 17 Sep 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-65908
Red Hat OpenShift Container Platform release 4.12.98 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.12. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.12.98. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:65906 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html/release_notes
Published 17 Sep 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-66350
Red Hat OpenShift Container Platform release 4.21.33 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.21. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.21.33. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:66352 Security Fix(es): * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) * golang: Go os.Root: Symlink following vulnerability allows directory traversal (CVE-2026-39822) * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli.
Published 15 Sep 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-66353
Red Hat OpenShift Container Platform release 4.21.33 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.21. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.21.33. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:66352 Security Fix(es): * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli.
Published 15 Sep 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-66358
Red Hat OpenShift Container Platform release 4.22.14 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.22. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.22.14. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:66356 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/
Published 15 Sep 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-66359
Red Hat OpenShift Container Platform release 4.22.14 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.22. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.22.14. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:66358 Security Fix(es): * golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs (CVE-2026-46597) * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.22 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli.
Published 15 Sep 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-66371
Red Hat OpenShift Container Platform release 4.19.47 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.19. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.19.47. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:66369 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/
Published 16 Sep 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-66372
Red Hat OpenShift Container Platform release 4.19.47 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.19. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.19.47. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:66371 Security Fix(es): * brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257) * brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation (CVE-2026-69152) * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli.
Published 16 Sep 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-66377
Red Hat OpenShift Container Platform release 4.20.38 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.20. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.20.38. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:66375 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/
Published 15 Sep 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-66378
Red Hat OpenShift Container Platform release 4.20.38 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.20. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.20.38. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:66377 Security Fix(es): * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli.
Published 15 Sep 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-8218
The multicluster engine for Kubernetes 2.8 General Availability release images, which add new features and enhancements, bug fixes, and updated container images. The multicluster engine for Kubernetes v2.8 images The multicluster engine for Kubernetes provides the foundational components that are necessary for the centralized management of multiple Kubernetes-based clusters across data centers, public clouds, and private clouds. You can use the engine to create new Red Hat OpenShift Container Platform clusters or to bring existing Kubernetes-based clusters under management by importing them. After the clusters are managed, you can use the APIs that are provided by the engine to distribute configuration based on placement policy.
Published 15 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-8448
Red Hat OpenShift Container Platform release 4.18.38 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.18. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.18.38. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:8422 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/
Published 22 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-8449
Red Hat OpenShift Container Platform release 4.18.38 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.18. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.18.38. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:8448 Security Fix(es): * google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli.
Published 22 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-8483
Kiali 1.73.29 for Red Hat OpenShift Service Mesh 2.6 is now available. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Kiali 1.73.29, for Red Hat OpenShift Service Mesh 2.6, provides observability for the service mesh by offering a visual representation of the mesh topology and metrics, helping users monitor, trace, and manage efficiently. Security Fix(es): * CVE-2025-61726 Memory exhaustion in query parameter parsing in net/url (OSSM-12470) * CVE-2025-62718 Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization (OSSM-13225, OSSM-13226) * CVE-2025-68121 Unexpected session resumption in crypto/tls (OSSM-12553) * CVE-2026-25679 Incorrect parsing of IPv6 host literals in net/url (OSSM-12952) * CVE-2026-27606 Rollup: Remote Code Execution via Path Traversal Vulnerability (OSSM-12689) * CVE-2026-29074 SVGO: Denial of Service via XML entity expansion (OSSM-12891) * CVE-2026-29063 Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (OSSM-12970, OSSM-12971) * CVE-2026-33186 gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (OSSM-12996) * CVE-2026-4800 lodash: Arbitrary code execution via untrusted input in template imports (OSSM-13112, OSSM-13113) * CVE-2026-40175 Axios: Remote Code Execution via Prototype Pollution escalation (OSSM-13249, OSSM-13250) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Published 16 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-8484
Kiali 2.4.15 for Red Hat OpenShift Service Mesh 3.0 is now available. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Kiali 2.4.15, for Red Hat OpenShift Service Mesh 3.0, provides observability for the service mesh by offering a visual representation of the mesh topology and metrics, helping users monitor, trace, and manage efficiently. Security Fix(es): * CVE-2025-62718 Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization (OSSM-13227, OSSM-13230) * CVE-2026-25679 Incorrect parsing of IPv6 host literals in net/url (OSSM-12919) * CVE-2026-29074 SVGO: Denial of Service via XML entity expansion (OSSM-12893, OSSM-12894) * CVE-2026-29063 Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (OSSM-12973, OSSM-12974) * CVE-2026-33186 gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (OSSM-13005) * CVE-2026-4800 lodash: Arbitrary code execution via untrusted input in template imports (OSSM-13115, OSSM-13116) * CVE-2026-40175 Axios: Remote Code Execution via Prototype Pollution escalation (OSSM-13252, OSSM-13253) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Published 16 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-8490
Kiali 2.11.9 for Red Hat OpenShift Service Mesh 3.1 is now available. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Kiali 2.11.9, for Red Hat OpenShift Service Mesh 3.1, provides observability for the service mesh by offering a visual representation of the mesh topology and metrics, helping users monitor, trace, and manage efficiently. Security Fix(es): * CVE-2025-62718 Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization (OSSM-13231, OSSM-13234) * CVE-2026-25679 Incorrect parsing of IPv6 host literals in net/url (OSSM-12921) * CVE-2026-29074 SVGO: Denial of Service via XML entity expansion (OSSM-12897, OSSM-12898) * CVE-2026-29063 Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (OSSM-12977, OSSM-12978) * CVE-2026-33186 gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (OSSM-13012) * CVE-2026-4800 lodash: Arbitrary code execution via untrusted input in template imports (OSSM-13119, OSSM-13120) * CVE-2026-34986 Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (OSSM-13147) * CVE-2026-40175 Axios: Remote Code Execution via Prototype Pollution escalation (OSSM-13256, OSSM-13257) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Published 16 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-8491
Kiali 2.17.6 for Red Hat OpenShift Service Mesh 3.2 is now available. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Kiali 2.17.6, for Red Hat OpenShift Service Mesh 3.2, provides observability for the service mesh by offering a visual representation of the mesh topology and metrics, helping users monitor, trace, and manage efficiently. Security Fix(es): * CVE-2025-62718 Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization (OSSM-13235, OSSM-13236) * CVE-2026-25679 Incorrect parsing of IPv6 host literals in net/url (OSSM-12922) * CVE-2026-29074 SVGO: Denial of Service via XML entity expansion (OSSM-12900, OSSM-12901) * CVE-2026-29063 Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (OSSM-12980, OSSM-12981) * CVE-2026-33186 gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (OSSM-13018) * CVE-2026-4800 lodash: Arbitrary code execution via untrusted input in template imports (OSSM-13122, OSSM-13123) * CVE-2026-34986 Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (OSSM-13162) * CVE-2026-40175 Axios: Remote Code Execution via Prototype Pollution escalation (OSSM-13259, OSSM-13260) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Published 16 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-8493
Kiali 2.22.2 for Red Hat OpenShift Service Mesh 3.3 is now available. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Kiali 2.22.2, for Red Hat OpenShift Service Mesh 3.3, provides observability for the service mesh by offering a visual representation of the mesh topology and metrics, helping users monitor, trace, and manage efficiently. Security Fix(es): * CVE-2025-62718 Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization (OSSM-13237, OSSM-13238) * CVE-2026-25679 Incorrect parsing of IPv6 host literals in net/url (OSSM-13272) * CVE-2026-29074 SVGO: Denial of Service via XML entity expansion (OSSM-13274, OSSM-13275) * CVE-2026-29063 Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (OSSM-13276, OSSM-13277, OSSM-13278) * CVE-2026-33186 gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (OSSM-13279, OSSM-13280) * CVE-2026-4800 lodash: Arbitrary code execution via untrusted input in template imports (OSSM-13281, OSSM-13282) * CVE-2026-34986 Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (OSSM-13283) * CVE-2026-40175 Axios: Remote Code Execution via Prototype Pollution escalation (OSSM-13284, OSSM-13285) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Published 16 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-9031
An update for python-urllib3 is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * urllib3: urllib3 Streaming API improperly handles highly compressed data (CVE-2025-66471) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Published 20 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-9097
An update for runc is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime. Security Fix(es): * crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729) * golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726) * crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121) * net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Published 20 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-9098
An update for skopeo is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. The skopeo command lets you inspect images from container image registries, get images and image layers, and use signatures to create and verify files. Security Fix(es): * crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729) * golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726) * crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121) * net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Published 20 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-9108
An update for gvisor-tap-vsock is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. A replacement for libslirp and VPNKit, written in pure Go. It is based on the network stack of gVisor. Compared to libslirp, gvisor-tap-vsock brings a configurable DNS server and dynamic port forwarding. Security Fix(es): * crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729) * golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726) * crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121) * net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Published 20 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-9109
An update for containernetworking-plugins is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. The Container Network Interface (CNI) project consists of a specification and libraries for writing plug-ins for configuring network interfaces in Linux containers, along with a number of supported plug-ins. CNI concerns itself only with network connectivity of containers and removing allocated resources when the container is deleted. Security Fix(es): * crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729) * golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726) * crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121) * net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Published 20 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-9385
Red Hat OpenShift distributed tracing platform (Tempo) 3.9.2 has been released This release of the Red Hat OpenShift distributed tracing platform (Tempo) provides security improvements and bug fixes. Breaking changes: * None. Deprecations: * None. Technology Preview features: * None. Enhancements: * None. Bug fixes: * gRPC-Go authorization bypass vulnerability fix: Previously, gRPC-Go was vulnerable to an authorization bypass attack. This issue occurred because the HTTP/2 :path pseudo-header was not properly validated. Remote attackers could send raw HTTP/2 frames with a malformed :path that omitted the mandatory leading slash to bypass defined security policies. With this update, gRPC-Go properly validates the :path pseudo-header and rejects malformed requests. As a result, attackers can no longer bypass security policies to gain unauthorized access to services or disclose information. For more information, see https://access.redhat.com/security/cve/cve-2026-33186. * XPath component fix: Previously, the github.com/antchfx/xpath component did not properly handle certain Boolean XPath expressions. A remote attacker could submit a crafted expression that caused an infinite loop, resulting in 100% CPU utilization and a denial-of-service condition. With this update, the XPath component correctly processes Boolean expressions that evaluate to true. The system no longer enters an infinite loop when handling these expressions. For more information, see https://access.redhat.com/security/cve/cve-2026-4645. * Go JOSE denial-of-service vulnerability fix: Previously, the Go JOSE library for handling JSON Web Encryption (JWE) objects was vulnerable to a denial-of-service (DoS) attack. This issue occurred because the application failed when decrypting a specially crafted JWE object that specified a key wrapping algorithm but contained an empty encrypted key field. With this update, Go JOSE properly validates the encrypted key field before decryption. As a result, the application no longer crashes when processing malformed JWE objects, and the service remains available to legitimate users. For more information, see https://access.redhat.com/security/cve/cve-2026-34986. * Lodash _.template function fix: Previously, the lodash _.template function validated the variable option but did not validate options.imports key names. Both options passed values to the same code execution path. An attacker with the ability to control options.imports key names or pollute Object.prototype could exploit this gap to execute arbitrary code. With this update, lodash validates options.imports key names by using the same rules applied to the variable option. The _.template function rejects invalid key names and prevents code injection through this path. For more information, see https://access.redhat.com/security/cve/cve-2026-4800. * Go crypto/x509 and crypto/tls packages fix: Previously, the Go standard library crypto/x509 and crypto/tls packages did not limit the number of intermediate certificates processed during certificate chain building. An attacker could provide an excessive number of intermediate certificates, causing the system to perform an uncontrolled amount of work and resulting in a denial-of-service condition. With this update, the packages limit the number of intermediate certificates accepted during certificate chain validation. The system rejects certificate chains that exceed this limit. For more information, see https://access.redhat.com/security/cve/cve-2026-32280. * Go Root.Chmod function fix: Previously, the Root.Chmod function in the Go standard library internal/syscall/unix package had a race condition between checking and modifying a target file. An attacker could replace the target with a symbolic link after the check but before the operation completed, causing the permission change to apply to the linked file instead. This allowed an attacker to bypass directory restrictions and change permissions on unintended files. With this update
Published 21 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-9388
Red Hat build of OpenTelemetry 3.9.2 has been released This release of the Red Hat build of OpenTelemetry provides security improvements. Breaking changes: * None Deprecations: * None Technology Preview features: * None Enhancements: * None Bug fixes: * XPath library vulnerability is fixed: Previously, the 'github.com/antchfx/xpath' library was vulnerable to a denial of service (DoS) attack. This issue occurred because specially crafted boolean XPath expressions that evaluated to true caused an infinite loop in the 'logicalQuery.Select' function, leading to 100% CPU utilization. With this update, the XPath library properly handles these expressions and prevents infinite loops. As a result, the system is no longer vulnerable to this DoS condition. For more information, see https://access.redhat.com/security/cve/cve-2026-32287. * gRPC-Go authorization bypass vulnerability is fixed: Previously, gRPC-Go was vulnerable to an authorization bypass attack. This issue occurred because the HTTP/2 ':path' pseudo-header was not properly validated. Remote attackers could send raw HTTP/2 frames with a malformed ':path' that omitted the mandatory leading slash to bypass defined security policies. With this update, gRPC-Go properly validates the ':path' pseudo-header and rejects malformed requests. As a result, attackers can no longer bypass security policies to gain unauthorized access to services or disclose information. For more information, see https://access.redhat.com/security/cve/cve-2026-33186. * Go JOSE denial of service vulnerability is fixed: Previously, the Go JOSE library for handling JSON Web Encryption (JWE) objects was vulnerable to a denial of service (DoS) attack. This issue occurred because the application failed when decrypting a specially crafted JWE object that specified a key wrapping algorithm but contained an empty encrypted key field. With this update, Go JOSE properly validates the encrypted key field before decryption. As a result, the application no longer crashes when processing malformed JWE objects, and the service remains available to legitimate users. For more information, see https://access.redhat.com/security/cve/cve-2026-34986. Known issues: * The filesystem scraper does not produce the `system.filesystem.inodes.usage` and `system.filesystem.usage` metrics in the Host Metrics Receiver after upgrading from Collector version 0.142.0 to 0.143.0 or later. No known workaround exists. For more information, see https://issues.redhat.com/browse/TRACING-5963.
Published 21 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-9440
Red Hat OpenShift Service Mesh 3.0.10 This update has a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Service Mesh 3.0.10, which is based on the open source Istio project, addresses a variety of problems in a microservice architecture by creating a centralized point of control in an application. Fixes/Improvements: Security Fix(es): * istio-rhel9-operator: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * istio-cni-rhel9: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * istio-pilot-rhel9: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * istio-proxyv2-rhel9: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * istio-proxyv2-rhel9: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186) * istio-proxyv2-rhel9: BuildKit: Arbitrary file write and code execution via untrusted frontend (CVE-2026-33747) * istio-proxyv2-rhel9: BuildKit: Unauthorized file access via Git URL fragment subdir components (CVE-2026-33748)
Published 21 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-9448
Red Hat OpenShift Service Mesh 3.1.7 This update has a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Service Mesh 3.1.7, which is based on the open source Istio project, addresses a variety of problems in a microservice architecture by creating a centralized point of control in an application. Fixes/Improvements: Security Fix(es): * istio-rhel9-operator: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * istio-cni-rhel9: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * istio-pilot-rhel9: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * istio-proxyv2-rhel9: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * istio-proxyv2-rhel9: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186) * istio-proxyv2-rhel9: BuildKit: Arbitrary file write and code execution via untrusted frontend (CVE-2026-33747) * istio-proxyv2-rhel9: BuildKit: Unauthorized file access via Git URL fragment subdir components (CVE-2026-33748) * istio-cni-rhel9: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) * istio-pilot-rhel9: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) Bug Fix(es): * OSSM operator metrics reader ClusterRole conflicts with other operators (OSSM-13106)
Published 21 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-9453
Red Hat OpenShift Service Mesh 3.2.4 This update has a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat OpenShift Service Mesh 3.2.4, which is based on the open source Istio project, addresses a variety of problems in a microservice architecture by creating a centralized point of control in an application. Fixes/Improvements: Security Fix(es): * istio-rhel9-operator: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * istio-cni-rhel9: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * istio-pilot-rhel9: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * istio-proxyv2-rhel9: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * istio-proxyv2-rhel9: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186) * istio-proxyv2-rhel9: BuildKit: Arbitrary file write and code execution via untrusted frontend (CVE-2026-33747) * istio-proxyv2-rhel9: BuildKit: Unauthorized file access via Git URL fragment subdir components (CVE-2026-33748) * istio-cni-rhel9: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) * istio-pilot-rhel9: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) Bug Fix(es): * Ztunnel default value in operator contains older istio version (OSSM-13103) * OSSM operator metrics reader ClusterRole conflicts with other operators (OSSM-13106)
Published 21 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-9848
The multicluster engine for Kubernetes 2.6 General Availability release images, which add new features and enhancements, bug fixes, and updated container images. The multicluster engine for Kubernetes v2.6 images The multicluster engine for Kubernetes provides the foundational components that are necessary for the centralized management of multiple Kubernetes-based clusters across data centers, public clouds, and private clouds. You can use the engine to create new Red Hat OpenShift Container Platform clusters or to bring existing Kubernetes-based clusters under management by importing them. After the clusters are managed, you can use the APIs that are provided by the engine to distribute configuration based on placement policy.
Published 22 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →RED HATRHSA-2026-9872
DevWorkspace Operator 0.40.1 has been released. The DevWorkspace Operator extends OpenShift to provide DevWorkspace support.
Published 22 Apr 2026 · Source checked 27 Sep 2026
Release notes and known issues →DEBIANDSA-6491-1
Several vulnerabilities were discovered in the Slurm Workload Manager, a cluster resource management and job scheduling system, which may result in privilege escalation, SQL injection in the accounting database, deletion of files outside the container spool directory, bypass of credential verification for shared objects transferred with sbcast, or denial of service. https://security-tracker.debian.org/tracker/DSA-6491-1
Published Never · Source checked 26 Sep 2026
Release notes and known issues →DRUPALDRUPAL-10.6.18
Drupal 10.6.18
Published Never · Source checked 28 Sep 2026
Release notes and known issues →DRUPALDRUPAL-11.4.8
Drupal 11.4.8
Published Never · Source checked 28 Sep 2026
Release notes and known issues →IBMIBM-PRODUCTS-IBM-7289649
Official IBM security bulletin for IBM Engineering Lifecycle Management Base.
Published 26 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →IBMIBM-PRODUCTS-IBM-7289650
Official IBM security bulletin for IBM Engineering Lifecycle Management Base.
Published 26 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →IBMIBM-PRODUCTS-IBM-7289655
Official IBM security bulletin for IBM SevOne Network Performance Management.
Published 26 Sep 2026 · Source checked 28 Sep 2026
Release notes and known issues →