RHSA-2026:10140HighCVSS 8.8

Red Hat Security Advisory: Red Hat Enterprise Linux AI 3.3.1

Published
April 23, 2026
Last Modified
September 12, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2026-4519 — python: Python: Command-line option injection in webbrowser.open() via crafted URLs CVE-2026-4786 — python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API CVE-2026-6100 — python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-27893 — vllm: vLLM: Remote code execution due to hardcoded trust_remote_code setting CVE-2026-32597 — pyjwt: PyJWT accepts unknown crit header extensions (RFC 7515 §4.1.11 MUST violation)

🎯 Affected products8

  • Red Hat Enterprise Linux AI 3.3
  • registry.redhat.io/rhelai3/bootc-aws-cuda-rhel9@sha256:c4e99fdf145fa920e4d91f291010fe0826306112c55f8470c67b060b6235e58f_amd64 as a component of Red Hat Enterprise Linux AI 3.3
  • registry.redhat.io/rhelai3/bootc-azure-cuda-rhel9@sha256:bffbcba6080e3e3034581301575ce3211a8351ff560029426c6723ea06229430_amd64 as a component of Red Hat Enterprise Linux AI 3.3
  • registry.redhat.io/rhelai3/bootc-azure-rocm-rhel9@sha256:e288f64fd5bfeb9f94ae40c346cf6a77ae09cb639440494d36db9be9962035d6_amd64 as a component of Red Hat Enterprise Linux AI 3.3
  • registry.redhat.io/rhelai3/bootc-cuda-rhel9@sha256:080632b93a8171a88c7a17ddb8dc5f1cc7801da604aae599eac28861b5b38821_amd64 as a component of Red Hat Enterprise Linux AI 3.3
  • registry.redhat.io/rhelai3/bootc-cuda-rhel9@sha256:a6e60bde307c0d6fb5fa8c115d13169287ec851ef2f3c440da3df7a9089a8f63_arm64 as a component of Red Hat Enterprise Linux AI 3.3
  • registry.redhat.io/rhelai3/bootc-gcp-cuda-rhel9@sha256:b0f5035af6217c92086ae77c07f36742f31b2b36f5a24a70f801cd9ff181a264_amd64 as a component of Red Hat Enterprise Linux AI 3.3
  • registry.redhat.io/rhelai3/bootc-rocm-rhel9@sha256:59b3ca83b219cadb030d5b4805e505ad6bfa19e1a0f2130f646b2ba7e0b8394c_amd64 as a component of Red Hat Enterprise Linux AI 3.3

✅ Remediation

Before applying this update, ensure all previously released errata relevant to your system have been applied. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (10)