Red Hat Security Advisory: Migration Toolkit for Applications
🔗 CVE IDs covered (30)
📋 Description
CVE-2026-5422 — jupyter-server: jupyter-server: Sensitive data exposure via path traversal vulnerability CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-28684 — python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following CVE-2026-33079 — mistune: Mistune: Regular Expression Denial of Service (ReDoS) via crafted Markdown input CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-34993 — aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() CVE-2026-35397 — jupyter-server: Jupyter Server: Unauthorized File Access via Path Traversal Vulnerability CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-40110 — jupyter-server: Jupyter Server: Cross-Origin Resource Sharing (CORS) bypass via improper Origin header validation CVE-2026-40171 — Jupyter Notebook: JupyterLab: @jupyter-notebook/help-extension: @jupyterlab/help-extension: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting CVE-2026-42266 — jupyterlab: JupyterLab: Arbitrary code execution due to improper enforcement of extension allow-list CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-42557 — jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output CVE-2026-42561 — python-multipart: python-multipart: Denial of Service via excessive multipart part headers CVE-2026-44431 — urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression CVE-2026-44727 — jupyter-server: Jupyter Server: Remote Code Execution via stored Cross-Site Scripting in nbconvert handlers CVE-2026-44843 — langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization CVE-2026-45292 — opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens CVE-2026-48710 — starlette: Starlette: Security restriction bypass via malformed HTTP Host header CVE-2026-48746 — vllm: starlette: vLLM: Critical authentication bypass allows unauthorized API access CVE-2026-48990 — joserfc: joserfc: Resource exhaustion via oversized JSON Web Signature (JWS) payloads CVE-2026-54283 — starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS CVE-2026-59939 — httplib2: httplib2: Denial of Service via unbounded decompression of HTTP response bodies
🔗 References (35)
- selfhttps://access.redhat.com/errata/RHSA-2026:43038
- externalhttps://access.redhat.com/security/cve/CVE-2026-13676
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-28684
- externalhttps://access.redhat.com/security/cve/CVE-2026-33079
- externalhttps://access.redhat.com/security/cve/CVE-2026-33811
- externalhttps://access.redhat.com/security/cve/CVE-2026-34993
- externalhttps://access.redhat.com/security/cve/CVE-2026-35397
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-40110
- externalhttps://access.redhat.com/security/cve/CVE-2026-40171
- externalhttps://access.redhat.com/security/cve/CVE-2026-42266
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-42557
- externalhttps://access.redhat.com/security/cve/CVE-2026-42561
- externalhttps://access.redhat.com/security/cve/CVE-2026-44431
- externalhttps://access.redhat.com/security/cve/CVE-2026-44432
- externalhttps://access.redhat.com/security/cve/CVE-2026-44727
- externalhttps://access.redhat.com/security/cve/CVE-2026-44843
- externalhttps://access.redhat.com/security/cve/CVE-2026-45292
- externalhttps://access.redhat.com/security/cve/CVE-2026-48526
- externalhttps://access.redhat.com/security/cve/CVE-2026-48710
- externalhttps://access.redhat.com/security/cve/CVE-2026-48746
- externalhttps://access.redhat.com/security/cve/CVE-2026-48990
- externalhttps://access.redhat.com/security/cve/CVE-2026-5422
- externalhttps://access.redhat.com/security/cve/CVE-2026-54283
- externalhttps://access.redhat.com/security/cve/CVE-2026-59939
- externalhttps://access.redhat.com/security/cve/CVE-2026-6322
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://developers.redhat.com/products/mta/overview
- externalhttps://docs.redhat.com/en/documentation/migration_toolkit_for_applications/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_43038.json