RHSA-2026:43038CriticalCVSS 9.1

Red Hat Security Advisory: Migration Toolkit for Applications

Published
July 21, 2026
Last Modified
September 6, 2026

🔗 CVE IDs covered (30)

📋 Description

CVE-2026-5422 — jupyter-server: jupyter-server: Sensitive data exposure via path traversal vulnerability CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-28684 — python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following CVE-2026-33079 — mistune: Mistune: Regular Expression Denial of Service (ReDoS) via crafted Markdown input CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-34993 — aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() CVE-2026-35397 — jupyter-server: Jupyter Server: Unauthorized File Access via Path Traversal Vulnerability CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-40110 — jupyter-server: Jupyter Server: Cross-Origin Resource Sharing (CORS) bypass via improper Origin header validation CVE-2026-40171 — Jupyter Notebook: JupyterLab: @jupyter-notebook/help-extension: @jupyterlab/help-extension: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting CVE-2026-42266 — jupyterlab: JupyterLab: Arbitrary code execution due to improper enforcement of extension allow-list CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-42557 — jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output CVE-2026-42561 — python-multipart: python-multipart: Denial of Service via excessive multipart part headers CVE-2026-44431 — urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression CVE-2026-44727 — jupyter-server: Jupyter Server: Remote Code Execution via stored Cross-Site Scripting in nbconvert handlers CVE-2026-44843 — langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization CVE-2026-45292 — opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens CVE-2026-48710 — starlette: Starlette: Security restriction bypass via malformed HTTP Host header CVE-2026-48746 — vllm: starlette: vLLM: Critical authentication bypass allows unauthorized API access CVE-2026-48990 — joserfc: joserfc: Resource exhaustion via oversized JSON Web Signature (JWS) payloads CVE-2026-54283 — starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS CVE-2026-59939 — httplib2: httplib2: Denial of Service via unbounded decompression of HTTP response bodies

🎯 Affected products28

  • Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-analyzer-addon-rhel9@sha256:1e20ac649ee7fdcdad9930b1f0384e10c8794db9a2f211d4e3d1679c0c10cc53_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-analyzer-addon-rhel9@sha256:907c0c8c40c1fb494caa5feac439b90754160bf3f79d8e76cf2dded63f549db6_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-cli-rhel9@sha256:d466bf042711b13fc53cbc561b70e4f58cd77f8a05d1d4ee10c10a6e1c201fe7_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-cli-rhel9@sha256:ecae0c1053637d609a19773757c0ea8b336b645950a42473015daabfe9677fab_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-discovery-addon-rhel9@sha256:7377a2c2f16ca436819cbbf106fc27d3a8c44c7fca0a44108ccc826bf8678ace_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-discovery-addon-rhel9@sha256:a72cbf7b2ba6420e31ecca15f7d3628a671dd642a6ccf4610c5a26462a5d4b36_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-dotnet-external-provider-rhel9@sha256:794180378ddb9a88001d76b849df305034924683a79ef145f744fe03bee9c32b_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-dotnet-external-provider-rhel9@sha256:b5d66f8d4c6d6680886e631296c927c9502817fbb823a680f1dabf1cc92e0465_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-go-external-provider-rhel9@sha256:8e5ba3659ef5f88b81c1c9d795b6af6048fd7d870493ce5f013efcb9fce90b9d_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-go-external-provider-rhel9@sha256:8f91d460985e1a97ac6892d26c0517f39871d94d1b3bfad005d58d424bed2b0b_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-hub-rhel9@sha256:0223927b9e584f302aabafdbf015a779b14c9b5816cf0baa0cb1bfe0b1cc3415_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-hub-rhel9@sha256:2e251b0343327f2ac6e60d2888da526be6a82a355310f1aea93011426cddc485_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-java-external-provider-rhel9@sha256:60c4a45085db3517f6a9bae32a4b93fd2dfa799c3e957776ad2d8ab0777507c2_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-java-external-provider-rhel9@sha256:e8bd699e851fbab4466d1d25e3a08e2bcf8997978cb7f19f509c627be42d03dd_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-nodejs-external-provider-rhel9@sha256:12883516af95bf0f6abad1556d22896f16a087c1e4191fedc1f5d689cf6d67f6_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-nodejs-external-provider-rhel9@sha256:a89c4d19ff39a406f3279b4ffd6f8d2a2a82a78ab3e9aa1dc0f2c385a24fa844_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-operator-bundle@sha256:94f88bf557a036c54b348c2689c699a720d5d347b1bba141feec273e624ccdbf_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-platform-addon-rhel9@sha256:647ca556be4338749fbe7cb18580466ce6155bfce17c96deda7b7c037fd16240_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-platform-addon-rhel9@sha256:f421044ff3d6911097aebcbabfac87ddad74987e0e5f18a96dd89454f46a4cdf_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-python-external-provider-rhel9@sha256:25618ee8a690f336e1604a1b1ca9dd5197bbdea5cd02cfaf588fbd950a8fd228_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-python-external-provider-rhel9@sha256:4f46867f5ff78e9e970bc572a1a625080ae8faea29dc098d3d7d4355e8350ca1_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-rhel9-operator@sha256:3926f791376886972749cae0f8eb635af67a088811214066c6deb010c6b762f0_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-rhel9-operator@sha256:957a553608cbf9ed108c22f851ef809ed348cf592610851c3a554f3342ba511a_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-solution-server-rhel9@sha256:21fab4b77580795980fd60b24ab1d6a3cc159a9246beccd1c19938bca94edd23_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-solution-server-rhel9@sha256:f8c8651cc5fa016003ef4105f28775e0b225472d2c3135e5f37d1e1f748c515e_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-ui-rhel9@sha256:a77f5a731c20943958b5f654bf3147b690d5dd608b794bff261a23dd89f785f1_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-ui-rhel9@sha256:f59dcacb1eed9bcd539bc6c26a630115cf35378d77075247fb42219836e2adb7_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Applications using AIOHTTP that are configured to load untrusted files via the `CookieJar.load()` function should implement input sanitization prior to loading. This prevents the injection of malicious code. Workaround: To mitigate this issue, ensure that directory names within Jupyter Server deployments do not share common prefixes with sibling directories. This operational control prevents authenticated users from exploiting the path traversal vulnerability to access unauthorized content. For example, avoid naming directories 'user1' and 'user10' if 'user' is a common prefix. This mitigation does not require service restarts or reloads. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: Administrators should review and update the `allow_origin_pat` configuration in Jupyter Server to use a more precise regular expression. Ensure the pattern explicitly anchors to the end of the string (e.g., by adding `$` to the end of the regex) to prevent partial domain matches. After modifying the configuration, the Jupyter Server service must be restarted for the changes to take effect. Workaround: To reduce the risk of exploitation, disable the affected help extensions in Jupyter Notebook and JupyterLab, or set the `allowCommandLinker` option to `false` within the sanitizer configuration. Consult the Jupyter documentation for specific instructions on modifying these settings. Disabling these features may affect the availability of certain help functionalities. Workaround: Upgrade JupyterLab to version 4.5.7 or later. Set the JupyterLab extension manager to read-only mode to prevent users from installing unauthorized extensions. Note: configuring a PyPI proxy with an allow list of packages is not sufficient to protect against this vulnerability. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: Users should avoid opening or interacting with JupyterLab notebooks from untrusted sources. Exercise caution and verify the origin of any notebook before clicking buttons within its output, as this action could lead to the execution of arbitrary commands. Workaround: To mitigate this issue, applications using LangChain should avoid passing untrusted structured input directly to load() or loads() functions. Instead, ensure all incoming untrusted data is validated and canonicalized into an inert schema before being processed by LangChain. Additionally, migrate away from deprecated LangChain APIs, including RunnableWithMessageHistory, astream_log(), and astream_events(version="v1"), as these older code paths are more susceptible to insecure deserialization. Workaround: Deploying an RFC-compliant reverse proxy (such as nginx, Apache, HAProxy, or Caddy) in front of the ASGI server will reject malformed Host headers before they reach the application. This is the most straightforward mitigation that does not require code changes. If custom middleware is present, it should be updated to use `request.scope["path"]` instead of `request.url.path` for any security decisions. The ASGI scope path is derived from the HTTP request line and is not influenced by the Host header, so it reflects the actual request target. Workaround: Restrict network access to the vLLM API endpoint to only trusted clients and internal networks. Implement firewall rules or network policies to limit inbound connections to the vLLM service, thereby reducing the attack surface. This operational control helps prevent unauthorized external access to the vulnerable API. Workaround: The risk can be mitigated by rejecting oversized serialized JWS inputs before they reach joserfc and enforcing strict request/body size limits at the application or reverse-proxy layer.

🔗 References (35)