Red Hat Security Advisory: satellite/foreman-mcp-server-rhel9 container image available as a Technology Preview
🔗 CVE IDs covered (3)
📋 Description
CVE-2025-68158 — Authlib: Authlib: Cross-Site Request Forgery due to improper session management in state storage CVE-2026-9073 — foreman-mcp-server: MCP Server: Insecure Sensitive HTTP Header Sanitization CVE-2026-12112 — foreman-mcp-server: MCP Server: Active Session Hijacking via Insecure Session State Reuse
🎯 Affected products2
- Red Hat Satellite 6.18
- registry.redhat.io/satellite/foreman-mcp-server-rhel9@sha256:1b7b876fff71426558de0a3f790b8c62f9e34c61b9d6dd80a6c7c45154971428_amd64 as a component of Red Hat Satellite 6.18
✅ Remediation
For Satellite MCP integration see the Red Hat Satellite documentation. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:28405
- externalhttps://access.redhat.com/documentation/en-us/red_hat_satellite/6.18/html/updating_red_hat_satellite/index
- externalhttps://access.redhat.com/security/cve/CVE-2025-68158
- externalhttps://access.redhat.com/security/cve/CVE-2026-12112
- externalhttps://access.redhat.com/security/cve/CVE-2026-9073
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/software/containers/search
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_28405.json