RHSA-2026:14877HighCVSS 7.5

Red Hat Security Advisory: General availability of the satellite/iop-puptoo-rhel9 container image

Published
May 7, 2026
Last Modified
September 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2025-66418 — urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion CVE-2025-66471 — urllib3: urllib3 Streaming API improperly handles highly compressed data CVE-2026-21441 — urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)

🎯 Affected products2

  • Red Hat Satellite 6.18
  • registry.redhat.io/satellite/iop-puptoo-rhel9@sha256:45a0ac91d832d0d67b50b8a5423e1156d824f87f1046cdadefe4f7f09ff3adb5_amd64 as a component of Red Hat Satellite 6.18

✅ Remediation

For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (10)