RHSA-2026:0629HighCVSS 8.1

Red Hat Security Advisory: satellite/foreman-mcp-server-rhel9 container image available as a Technology Preview

Published
January 14, 2026
Last Modified
August 23, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2025-62706 — authlib: Authlib : JWE zip=DEF decompression bomb enables DoS CVE-2025-66416 — mcp: DNS Rebinding Protection Disabled by Default in Model Context Protocol Python SDK

🎯 Affected products2

  • Red Hat Satellite 6.18
  • registry.redhat.io/satellite/foreman-mcp-server-rhel9@sha256:1d79cdb237d1d245131c9daea04ddf1c056551ab18e422b4ea4f63cf438c1212_amd64 as a component of Red Hat Satellite 6.18

✅ Remediation

For Satellite MCP integration see the Red Hat Satellite documentation. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (8)