RHSA-2026:61236HighCVSS 7.4

Red Hat Security Advisory: xmlrpc-c security update

Published
August 31, 2026
Last Modified
August 31, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-15928 — xmlrpc-c: XMLRPC-C Library: Cross-Site Scripting in error page component

🎯 Affected products36

  • Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • xmlrpc-c-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • xmlrpc-c-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • xmlrpc-c-0:1.51.0-5.el8_4.3.src as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • xmlrpc-c-0:1.51.0-5.el8_4.3.src as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • xmlrpc-c-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • xmlrpc-c-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • xmlrpc-c-apps-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • xmlrpc-c-apps-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • xmlrpc-c-apps-debuginfo-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • xmlrpc-c-apps-debuginfo-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • xmlrpc-c-c++-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • xmlrpc-c-c++-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • xmlrpc-c-c++-debuginfo-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • xmlrpc-c-c++-debuginfo-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • xmlrpc-c-client++-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • xmlrpc-c-client++-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • xmlrpc-c-client++-debuginfo-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • xmlrpc-c-client++-debuginfo-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • xmlrpc-c-client-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • xmlrpc-c-client-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • xmlrpc-c-client-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • xmlrpc-c-client-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • xmlrpc-c-client-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • xmlrpc-c-client-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • xmlrpc-c-client-debuginfo-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • xmlrpc-c-client-debuginfo-0:1.51.0-5.el8_4.3.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • xmlrpc-c-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • xmlrpc-c-debuginfo-0:1.51.0-5.el8_4.3.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • +6 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, ensure that applications utilizing the XMLRPC-C library do not directly expose its error pages to end-users via a web browser. Configure web servers or application frontends to intercept and sanitize or replace error responses originating from XMLRPC-C before they are rendered client-side. Alternatively, restrict XMLRPC-C deployments to backend services that do not present error output in a user-facing web interface.

🔗 References (4)