RHSA-2026:38236HighCVSS 7.5

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

Published
July 11, 2026
Last Modified
July 21, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2026-5078 — morgan: morgan: Log forgery due to unneutralized control characters CVE-2026-6733 — undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. CVE-2026-6734 — undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing CVE-2026-9678 — undici: Undici: Information disclosure due to improper cache-control header parsing CVE-2026-9679 — undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding CVE-2026-9697 — undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy CVE-2026-11525 — undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header CVE-2026-12151 — undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames CVE-2026-53550 — js-yaml: js-yaml: Denial of Service via crafted YAML merge keys CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents

🔗 References (14)