RHSA-2026:26214HighCVSS 8.2

Red Hat Security Advisory: General availability of the satellite/iop-advisor-frontend-rhel9 container image

Published
June 16, 2026
Last Modified
August 25, 2026

🔗 CVE IDs covered (11)

📋 Description

CVE-2025-69873 — ajv: ReDoS via $data reference CVE-2026-6321 — fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies CVE-2026-26996 — minimatch: minimatch: Denial of Service via specially crafted glob patterns CVE-2026-27904 — minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions CVE-2026-41680 — marked: Marked: Denial of Service via specific input sequence CVE-2026-42033 — axios: Axios: HTTP Transport Hijacking via Prototype Pollution CVE-2026-42035 — axios: Axios: Arbitrary HTTP header injection via prototype pollution CVE-2026-42039 — axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data CVE-2026-42041 — axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling CVE-2026-42043 — axios: Axios: NO_PROXY bypass via crafted URL CVE-2026-42044 — axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget

🎯 Affected products2

  • Red Hat Satellite 6.18
  • registry.redhat.io/satellite/iop-advisor-frontend-rhel9@sha256:2fa7abb9dbae17fc3b6c7b6a5edbbff617e9a1a86256a61f714a1b8dbaf14105_amd64 as a component of Red Hat Satellite 6.18

✅ Remediation

For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. Workaround: To mitigate this issue, disable the $data feature if your application does not require it. If $data must be used, implement strict validation of the input fields that are referenced by the pattern keyword to ensure they contain only expected and safe characters. Workaround: To mitigate this vulnerability, Red Hat products that utilize the 'marked' library should be configured to process markdown content only from trusted sources. If markdown rendering is not a critical function, consider disabling or restricting its use within the application's configuration to reduce exposure. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (18)