RHSA-2026:3087HighCVSS 8.2

Red Hat Security Advisory: RHTAS 1.3.2 - Red Hat Trusted Artifact Signer Release

Published
February 23, 2026
Last Modified
May 31, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-66564 — github.com/sigstore/timestamp-authority: Sigstore Timestamp Authority: Denial of Service via excessive OID or Content-Type header parsing CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig

🔗 References (10)