RHSA-2026:61236HighCVSS 7.4
Red Hat Security Advisory: xmlrpc-c security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-15928 — xmlrpc-c: XMLRPC-C Library: Cross-Site Scripting in error page component
🎯 Affected products36
- Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- xmlrpc-c-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- xmlrpc-c-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- xmlrpc-c-0:1.51.0-5.el8_4.3.src as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- xmlrpc-c-0:1.51.0-5.el8_4.3.src as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- xmlrpc-c-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- xmlrpc-c-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- xmlrpc-c-apps-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- xmlrpc-c-apps-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- xmlrpc-c-apps-debuginfo-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- xmlrpc-c-apps-debuginfo-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- xmlrpc-c-c++-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- xmlrpc-c-c++-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- xmlrpc-c-c++-debuginfo-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- xmlrpc-c-c++-debuginfo-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- xmlrpc-c-client++-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- xmlrpc-c-client++-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- xmlrpc-c-client++-debuginfo-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- xmlrpc-c-client++-debuginfo-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- xmlrpc-c-client-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- xmlrpc-c-client-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- xmlrpc-c-client-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- xmlrpc-c-client-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- xmlrpc-c-client-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- xmlrpc-c-client-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- xmlrpc-c-client-debuginfo-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- xmlrpc-c-client-debuginfo-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- xmlrpc-c-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- xmlrpc-c-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- +6 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, ensure that applications utilizing the XMLRPC-C library do not directly expose its error pages to end-users via a web browser. Configure web servers or application frontends to intercept and sanitize or replace error responses originating from XMLRPC-C before they are rendered client-side. Alternatively, restrict XMLRPC-C deployments to backend services that do not present error output in a user-facing web interface.