RHSA-2026:6288HighCVSS 8.2

Red Hat Security Advisory: General availability of the satellite/iop-remediations-rhel9 container image

Published
March 31, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions

🎯 Affected products2

  • Red Hat Satellite 6.18
  • registry.redhat.io/satellite/iop-remediations-rhel9@sha256:9e1aa62d0019dc33a52584e614a93edbc6111605ef0ed3cae0b9f900dbb9097e_amd64 as a component of Red Hat Satellite 6.18

✅ Remediation

For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example.

🔗 References (8)