Red Hat Security Advisory: Red Hat Ceph Storage
🔗 CVE IDs covered (9)
📋 Description
CVE-2019-10790 — taffy: taffydb: Internal Property Tampering CVE-2023-25153 — containerd: OCI image importer memory exhaustion CVE-2023-28155 — request: bypass of SSRF mitigations when following a cross-protocol redirect CVE-2024-11831 — npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript CVE-2025-50181 — urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation CVE-2025-50182 — urllib3: urllib3 does not control redirects in browsers and Node.js CVE-2025-59436 — ip: Node ip SSRF CVE-2025-66418 — urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion CVE-2026-24049 — wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking
🎯 Affected products29
- Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/grafana-rhel9@sha256:044d55095e592d054a5ec69603c1fd8886ea3efcedfd95945dbef3596c9835d5_arm64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/grafana-rhel9@sha256:9b426d409203a3366689db14f15b0d8639d231945678184c3b43869d56705dbd_ppc64le as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/grafana-rhel9@sha256:a1642617a4fc8ff1b79299b160b0f644eeafeb4809981a9d00a3e621ec8bb096_amd64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/grafana-rhel9@sha256:bbb4f2499a816032af66bb8b022d8a51198a5db01ee39714800340cbd4a45d40_s390x as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/keepalived-rhel9@sha256:39cf934468566964e44ddac65928d837528d126d16d5ad6d71298c0570b0066d_ppc64le as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/keepalived-rhel9@sha256:3d2d10adc4f85192a3729477777b068366b5178512724d3ffd6c498ba577d847_amd64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/keepalived-rhel9@sha256:8aac763313e46322e3d0fbb3fbed767228906f75865d54eb753f03f027408926_arm64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/keepalived-rhel9@sha256:cbd32c0b082f368583eeff3657a97a79a11ccb5d3bcf5663dd8738d09a0d53e8_s390x as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/oauth2-proxy-rhel9@sha256:3a7dedb1b1fee0c80dcfe0f3ebce6e20aa6a364fe66808458f5416ae09890c56_s390x as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/oauth2-proxy-rhel9@sha256:3d4665881548c0808fea1612a972c732c5f2b928ad49fbb8025ceb7f410faabb_amd64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/oauth2-proxy-rhel9@sha256:765efce53826bcdd18c41186fb1fa291e9b1450c43706747d2be1dd5addda19a_ppc64le as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/oauth2-proxy-rhel9@sha256:79bd982b6824100b974103347eaaa7f34c60f4b1118c93d7e628bafb11945a17_arm64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:070f43995aae0152eac7d228ae7d4d005eb57e06e14aef1b50d4db64341b826a_arm64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:6c084d7b7609111b8c28d22a7e69d2093607e9a648b7fb7259bcf5693ca35875_amd64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:b36874b30b49a770f223a34034ae128a1a02fe0dfdb16cea5432ed67a24728af_ppc64le as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:decb2f66e30c9500882c35f898e7da4e4d2ee31a7421b9dcab736350c7a5a771_s390x as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-haproxy-rhel9@sha256:3c1bbf300b5bd123493c57ffe84ca24bf14fcf32b648cc8c279ad3a3101c19c8_ppc64le as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-haproxy-rhel9@sha256:7256c524d36f6128bffc8fdeec7e9ec435d43ceb57afd1512e496f85a09376f9_s390x as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-haproxy-rhel9@sha256:7e7b6ea0214c616e7ef462152854207afe84732c54150914fa6180d8cc29a4ad_amd64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-haproxy-rhel9@sha256:ed001e7318e45d7c0372b966a8c447eddf75d1079b1b937872c2c12893389849_arm64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-promtail-rhel9@sha256:4493b44fc1a487413d554826a92f82a44aca453e8c5d9c476ed47ef3efc1123a_ppc64le as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-promtail-rhel9@sha256:63eed84d24f949baf09d2294dcc9849e72a6cbe6213844872efb9843898a132f_s390x as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-promtail-rhel9@sha256:b0ba95a2611c37db8f149d5fe44f424f3ff696535f7e5ac5cbadd45837f864cb_amd64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/rhceph-promtail-rhel9@sha256:db068d24b3055fe96d2fa8703405eca07634238306159e3803ff4ae23f1024fd_arm64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/snmp-notifier-rhel9@sha256:65f82ec0df5d07b18d73620b7823bf7a51f33c3f3c4c44b290d9cd5f79c8e64a_ppc64le as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/snmp-notifier-rhel9@sha256:86d8a15cc12eaf34d01d077924301ee0276bc2b9539987b1133dc9b65609d660_s390x as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/snmp-notifier-rhel9@sha256:b48486f663889cd57eead6f097d6cc26e6c2ff9bdfbb6f24b8d1f8d2e42a2b4c_arm64 as a component of Red Hat Ceph Storage 8.1
- registry.redhat.io/rhceph/snmp-notifier-rhel9@sha256:de99e5235ccf7714e7df2ef04b8c5c60c3efe04cacee13acfbaddaa60c5f88bf_amd64 as a component of Red Hat Ceph Storage 8.1
✅ Remediation
The container images provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io using the "podman pull" command. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2026:62115
- externalhttps://access.redhat.com/security/cve/CVE-2019-10790
- externalhttps://access.redhat.com/security/cve/CVE-2023-25153
- externalhttps://access.redhat.com/security/cve/CVE-2023-28155
- externalhttps://access.redhat.com/security/cve/CVE-2024-11831
- externalhttps://access.redhat.com/security/cve/CVE-2025-50181
- externalhttps://access.redhat.com/security/cve/CVE-2025-50182
- externalhttps://access.redhat.com/security/cve/CVE-2025-59436
- externalhttps://access.redhat.com/security/cve/CVE-2025-66418
- externalhttps://access.redhat.com/security/cve/CVE-2026-24049
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_ceph_storage/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_62115.json