Red Hat Security Advisory: Satellite 6.19.4 Async Update
🔗 CVE IDs covered (22)
📋 Description
CVE-2026-10051 — jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections
CVE-2026-11332 — ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution
CVE-2026-16493 — ansible-core: argument injection in ansible-galaxy collection install via git clone (incomplete fix for CVE-2026-11332)
CVE-2026-34993 — aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load()
CVE-2026-42215 — GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks
CVE-2026-42284 — GitPython: GitPython: Arbitrary code execution via improper validation of clone options
CVE-2026-44244 — GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration
CVE-2026-45363 — ruby-jwt: ruby-jwt: Authentication bypass due to empty key in HMAC verification
CVE-2026-54512 — jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
CVE-2026-68494 — com.fasterxml.jackson.core/jackson-core: tools.jackson.core/jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser
CVE-2026-69243 — aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade
CVE-2026-69244 — aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses
CVE-2026-73620 — gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding
CVE-2026-73622 — gitpython: GitPython: Information disclosure via environment variable expansion in URL handling
CVE-2026-73623 — gitpython: GitPython: Remote Code Execution via malicious Git template
CVE-2026-73624 — gitpython: GitPython: Arbitrary File Overwrite via improper git option validation
CVE-2026-73625 — gitpython: GitPython: Remote Code Execution via kwarg value smuggling
CVE-2026-76218 — gitpython: GitPython: Remote Code Execution via malicious Git hooks
CVE-2026-76219 — gitpython: GitPython: Arbitrary File Overwrite via git read-tree option injection
CVE-2026-76220 — gitpython: GitPython: Arbitrary command execution via crafted kwargs
CVE-2026-76221 — gitpython: GitPython: Arbitrary code execution via config-name injection
CVE-2026-76222 — gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names
🎯 Affected products52
- Red Hat Satellite 6.19 for RHEL 9
- ansible-core-1:2.16.19-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- ansible-core-1:2.16.19-1.el9sat.src as a component of Red Hat Satellite 6.19 for RHEL 9
- ansible-test-1:2.16.19-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- foreman-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- foreman-0:3.18.0.10-1.el9sat.src as a component of Red Hat Satellite 6.19 for RHEL 9
- foreman-cli-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- foreman-debug-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- foreman-dynflow-sidekiq-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- foreman-ec2-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- foreman-installer-1:3.18.0.3-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- foreman-installer-1:3.18.0.3-1.el9sat.src as a component of Red Hat Satellite 6.19 for RHEL 9
- foreman-installer-katello-1:3.18.0.3-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- foreman-journald-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- foreman-libvirt-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- foreman-openstack-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- foreman-pcp-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- foreman-postgresql-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- foreman-redis-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- foreman-service-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- foreman-telemetry-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- foreman-vmware-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- openvox-agent-0:8.28.1-1.el9sat.src as a component of Red Hat Satellite 6.19 for RHEL 9
- openvox-agent-0:8.28.1-1.el9sat.x86_64 as a component of Red Hat Satellite 6.19 for RHEL 9
- openvox-server-0:8.15.2-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- openvox-server-0:8.15.2-1.el9sat.src as a component of Red Hat Satellite 6.19 for RHEL 9
- pulpcore-obsolete-packages-0:1.3.1-5.el9pc.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
- pulpcore-obsolete-packages-0:1.3.1-5.el9pc.src as a component of Red Hat Satellite 6.19 for RHEL 9
- python3.12-aiohttp-0:3.14.3-1.el9pc.src as a component of Red Hat Satellite 6.19 for RHEL 9
- python3.12-aiohttp-0:3.14.3-1.el9pc.x86_64 as a component of Red Hat Satellite 6.19 for RHEL 9
- +22 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_satellite/6.19/html/updating_red_hat_satellite/index Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: The following practices would help for avoiding exposure and mitigate this flaw: 1. Do not install Ansible collections from untrusted or unverified git sources. Only install collections from trusted sources such as Ansible Galaxy (https://galaxy.ansible.com), Red Hat Automation Hub (https://console.redhat.com/ansible/automation-hub), or verified internal repositories using HTTPS URLs. 2. Carefully inspect any requirements.yml files before running 'ansible-galaxy collection install -r requirements.yml'. Verify that all collection sources use legitimate HTTPS URLs and do not contain git+ prefixed URIs with suspicious characters (especially values starting with '-'). 3. Ensure your system's git version is 2.12 or later, which disables the ext:: transport by default. While this does not fully prevent exploitation (the -ccore.sshCommand technique bypasses transport restrictions), it eliminates one of the exploitation vectors. 4. Restrict the GIT_ALLOW_PROTOCOL environment variable to only necessary protocols (e.g. https, ssh) and never include 'ext' unless absolutely required. Workaround: Applications using AIOHTTP that are configured to load untrusted files via the `CookieJar.load()` function should implement input sanitization prior to loading. This prevents the injection of malicious code. Workaround: To mitigate this issue, applications that use GitPython and process untrusted input for Git configuration values must implement robust input validation and sanitization. This prevents the injection of newlines that could manipulate `core.hooksPath` and lead to arbitrary code execution. Additionally, ensure that applications interacting with Git repositories operate with the principle of least privilege to limit the potential impact of any successful exploitation. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Do not pass untrusted or attacker-influenced input as the template parameter (or other forwarded options) to GitPython's Repo.init. Upgrade to GitPython 3.1.58 or later, where the unsafe option forwarding is fixed. Workaround: Do not pass untrusted or attacker-influenced treeish arguments to GitPython's IndexFile.from_tree, IndexFile.reset, or IndexFile.merge_tree. Upgrade to GitPython 3.1.58 or later, where option injection into `git read-tree` is fixed. Workaround: Do not pass untrusted or attacker-influenced keyword arguments to GitPython's guarded methods such as clone_from, and do not set split_single_char_options=False on untrusted input. Upgrade to GitPython 3.1.58 or later, where the check_unsafe_options bypass is fixed. Workaround: Do not pass untrusted or attacker-influenced git option names to GitPython. Upgrade to GitPython 3.1.58 or later, where option-name (config) injection is fixed. Workaround: There is no mitigation beyond not cloning or initializing git submodules from untrusted repositories. Upgrade to GitPython 3.1.58 or later when it becomes available.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2026:63385
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://issues.redhat.com/browse/SAT-45592
- externalhttps://issues.redhat.com/browse/SAT-46105
- externalhttps://issues.redhat.com/browse/SAT-48574
- externalhttps://issues.redhat.com/browse/SAT-48584
- externalhttps://issues.redhat.com/browse/SAT-48585
- externalhttps://issues.redhat.com/browse/SAT-48586
- externalhttps://issues.redhat.com/browse/SAT-48587
- externalhttps://issues.redhat.com/browse/SAT-48588
- externalhttps://issues.redhat.com/browse/SAT-48589
- externalhttps://issues.redhat.com/browse/SAT-48628
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_63385.json