RHSA-2026:51199HighCVSS 7.5
Red Hat Security Advisory: General availability of the satellite/iop-advisor-frontend-rhel9 container image
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
🎯 Affected products2
- Red Hat Satellite 6.19
- registry.redhat.io/satellite/iop-advisor-frontend-rhel9@sha256:e5055af2d8b1a0cdcf8a46e6db84495889bcfd104149828be3e815cb636fff20_amd64 as a component of Red Hat Satellite 6.19
✅ Remediation
For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:51199
- externalhttps://access.redhat.com/documentation/en-us/red_hat_satellite/6.19/html/updating_red_hat_satellite/index
- externalhttps://access.redhat.com/security/cve/CVE-2026-13149
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/software/containers/search
- externalhttps://docs.redhat.com/en/documentation/red_hat_satellite/6.19/html/installing_satellite_server_in_a_connected_network_environment/performing-additional-configuration-on-server_satellite#installing-and-configuring-red-hat-lightspeed-in-satellite
- externalhttps://docs.redhat.com/en/documentation/red_hat_satellite/6.19/html/installing_satellite_server_in_a_disconnected_network_environment/performing-additional-configuration#installing-and-configuring-red-hat-lightspeed-in-satellite
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_51199.json