RHSA-2026:14835HighCVSS 8.5

Red Hat Security Advisory: Satellite 6.18.5 Async Update

Published
May 7, 2026
Last Modified
May 28, 2026

🔗 CVE IDs covered (8)

CVE-2025-69534 · pendingCVE-2026-1207CVE-2026-1285CVE-2026-1287CVE-2026-1312CVE-2026-27459 · pendingCVE-2026-33176 · pendingCVE-2025-14550

📋 Description

CVE-2025-14550 — Django: Django: Denial of Service via crafted request with duplicate headers CVE-2025-69534 — python-markdown: denial of service via malformed HTML-like sequences CVE-2026-1207 — Django: Django: SQL Injection via RasterField band index parameter CVE-2026-1285 — Django: Django: Denial of Service via crafted HTML inputs CVE-2026-1287 — Django: Django: SQL Injection via crafted column aliases CVE-2026-1312 — Django: Django: SQL injection via crafted column aliases in QuerySet.order_by() CVE-2026-27459 — pyOpenSSL: DTLS cookie callback buffer overflow CVE-2026-33176 — Rails: Active Support: Active Support: Denial of Service via large scientific notation strings

🔗 References (25)