Red Hat Security Advisory: Satellite 6.16.13 Async Update
🔗 CVE IDs covered (7)
📋 Description
CVE-2026-10051 — jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections CVE-2026-34993 — aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() CVE-2026-45363 — ruby-jwt: ruby-jwt: Authentication bypass due to empty key in HMAC verification CVE-2026-54512 — jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass CVE-2026-68494 — com.fasterxml.jackson.core/jackson-core: tools.jackson.core/jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser CVE-2026-69243 — aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade CVE-2026-69244 — aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses
🎯 Affected products60
- Red Hat Satellite 6.16 for RHEL 8
- Red Hat Satellite 6.16 for RHEL 9
- openvox-server-0:8.15.2-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- openvox-server-0:8.15.2-1.el8sat.src as a component of Red Hat Satellite 6.16 for RHEL 8
- openvox-server-0:8.15.2-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- openvox-server-0:8.15.2-1.el9sat.src as a component of Red Hat Satellite 6.16 for RHEL 9
- python-aiohappyeyeballs-0:2.7.1-1.el8pc.src as a component of Red Hat Satellite 6.16 for RHEL 8
- python-aiohappyeyeballs-0:2.7.1-1.el9pc.src as a component of Red Hat Satellite 6.16 for RHEL 9
- python-aiohttp-0:3.14.3-1.el8pc.src as a component of Red Hat Satellite 6.16 for RHEL 8
- python-aiohttp-0:3.14.3-1.el9pc.src as a component of Red Hat Satellite 6.16 for RHEL 9
- python-aiohttp-debugsource-0:3.14.3-1.el8pc.x86_64 as a component of Red Hat Satellite 6.16 for RHEL 8
- python-aiohttp-debugsource-0:3.14.3-1.el9pc.x86_64 as a component of Red Hat Satellite 6.16 for RHEL 9
- python-aiosignal-0:1.4.0-1.el8pc.src as a component of Red Hat Satellite 6.16 for RHEL 8
- python-aiosignal-0:1.4.0-1.el9pc.src as a component of Red Hat Satellite 6.16 for RHEL 9
- python-propcache-0:0.2.1-1.el8pc.src as a component of Red Hat Satellite 6.16 for RHEL 8
- python-propcache-0:0.2.1-1.el9pc.src as a component of Red Hat Satellite 6.16 for RHEL 9
- python-propcache-debugsource-0:0.2.1-1.el8pc.x86_64 as a component of Red Hat Satellite 6.16 for RHEL 8
- python-propcache-debugsource-0:0.2.1-1.el9pc.x86_64 as a component of Red Hat Satellite 6.16 for RHEL 9
- python-pulpcore-0:3.49.39-3.el8pc.src as a component of Red Hat Satellite 6.16 for RHEL 8
- python-pulpcore-0:3.49.39-3.el9pc.src as a component of Red Hat Satellite 6.16 for RHEL 9
- python-tablib-0:3.5.0-1.el8pc.src as a component of Red Hat Satellite 6.16 for RHEL 8
- python-tablib-0:3.5.0-1.el9pc.src as a component of Red Hat Satellite 6.16 for RHEL 9
- python-yarl-0:1.18.3-1.el8pc.src as a component of Red Hat Satellite 6.16 for RHEL 8
- python-yarl-0:1.18.3-1.el9pc.src as a component of Red Hat Satellite 6.16 for RHEL 9
- python3.11-aiohappyeyeballs-0:2.7.1-1.el8pc.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- python3.11-aiohappyeyeballs-0:2.7.1-1.el9pc.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- python3.11-aiohttp-0:3.14.3-1.el8pc.x86_64 as a component of Red Hat Satellite 6.16 for RHEL 8
- python3.11-aiohttp-0:3.14.3-1.el9pc.x86_64 as a component of Red Hat Satellite 6.16 for RHEL 9
- python3.11-aiohttp-debuginfo-0:3.14.3-1.el8pc.x86_64 as a component of Red Hat Satellite 6.16 for RHEL 8
- python3.11-aiohttp-debuginfo-0:3.14.3-1.el9pc.x86_64 as a component of Red Hat Satellite 6.16 for RHEL 9
- +30 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_satellite/6.16/html/updating_red_hat_satellite/index Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Applications using AIOHTTP that are configured to load untrusted files via the `CookieJar.load()` function should implement input sanitization prior to loading. This prevents the injection of malicious code. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2026:63327
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2484099
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492015
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2499928
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2500739
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510825
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510831
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2511026
- externalhttps://issues.redhat.com/browse/SAT-48474
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_63327.json