RHSA-2026:51200HighCVSS 8.1

Red Hat Security Advisory: General availability of the satellite/iop-remediations-rhel9 container image

Published
August 6, 2026
Last Modified
August 19, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-42338 — ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input CVE-2026-59873 — tar: node-tar: Denial of Service via crafted gzip bomb CVE-2026-59874 — tar: Node-tar: Denial of Service via malformed tar archive header

🎯 Affected products2

  • Red Hat Satellite 6.19
  • registry.redhat.io/satellite/iop-remediations-rhel9@sha256:6d3ace96df28bfd4de714fa7345cfac8da2431a56eb18f99c4a9b7388902c5e1_amd64 as a component of Red Hat Satellite 6.19

✅ Remediation

For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (10)