RHSA-2026:63385HighCVSS 8.8

Red Hat Security Advisory: Satellite 6.19.4 Async Update

Published
September 3, 2026
Last Modified
September 4, 2026

🔗 CVE IDs covered (22)

📋 Description

CVE-2026-10051 — jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections CVE-2026-11332 — ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution CVE-2026-16493 — ansible-core: argument injection in ansible-galaxy collection install via git clone (incomplete fix for CVE-2026-11332) CVE-2026-34993 — aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() CVE-2026-42215 — GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks CVE-2026-42284 — GitPython: GitPython: Arbitrary code execution via improper validation of clone options CVE-2026-44244 — GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration CVE-2026-45363 — ruby-jwt: ruby-jwt: Authentication bypass due to empty key in HMAC verification CVE-2026-54512 — jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass CVE-2026-68494 — com.fasterxml.jackson.core/jackson-core: tools.jackson.core/jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser CVE-2026-69243 — aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade CVE-2026-69244 — aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses CVE-2026-73620 — gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding CVE-2026-73622 — gitpython: GitPython: Information disclosure via environment variable expansion in URL handling CVE-2026-73623 — gitpython: GitPython: Remote Code Execution via malicious Git template CVE-2026-73624 — gitpython: GitPython: Arbitrary File Overwrite via improper git option validation CVE-2026-73625 — gitpython: GitPython: Remote Code Execution via kwarg value smuggling CVE-2026-76218 — gitpython: GitPython: Remote Code Execution via malicious Git hooks CVE-2026-76219 — gitpython: GitPython: Arbitrary File Overwrite via git read-tree option injection CVE-2026-76220 — gitpython: GitPython: Arbitrary command execution via crafted kwargs CVE-2026-76221 — gitpython: GitPython: Arbitrary code execution via config-name injection CVE-2026-76222 — gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names

🎯 Affected products52

  • Red Hat Satellite 6.19 for RHEL 9
  • ansible-core-1:2.16.19-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • ansible-core-1:2.16.19-1.el9sat.src as a component of Red Hat Satellite 6.19 for RHEL 9
  • ansible-test-1:2.16.19-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-0:3.18.0.10-1.el9sat.src as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-cli-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-debug-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-dynflow-sidekiq-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-ec2-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-installer-1:3.18.0.3-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-installer-1:3.18.0.3-1.el9sat.src as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-installer-katello-1:3.18.0.3-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-journald-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-libvirt-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-openstack-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-pcp-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-postgresql-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-redis-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-service-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-telemetry-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-vmware-0:3.18.0.10-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • openvox-agent-0:8.28.1-1.el9sat.src as a component of Red Hat Satellite 6.19 for RHEL 9
  • openvox-agent-0:8.28.1-1.el9sat.x86_64 as a component of Red Hat Satellite 6.19 for RHEL 9
  • openvox-server-0:8.15.2-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • openvox-server-0:8.15.2-1.el9sat.src as a component of Red Hat Satellite 6.19 for RHEL 9
  • pulpcore-obsolete-packages-0:1.3.1-5.el9pc.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • pulpcore-obsolete-packages-0:1.3.1-5.el9pc.src as a component of Red Hat Satellite 6.19 for RHEL 9
  • python3.12-aiohttp-0:3.14.3-1.el9pc.src as a component of Red Hat Satellite 6.19 for RHEL 9
  • python3.12-aiohttp-0:3.14.3-1.el9pc.x86_64 as a component of Red Hat Satellite 6.19 for RHEL 9
  • +22 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_satellite/6.19/html/updating_red_hat_satellite/index Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: The following practices would help for avoiding exposure and mitigate this flaw: 1. Do not install Ansible collections from untrusted or unverified git sources. Only install collections from trusted sources such as Ansible Galaxy (https://galaxy.ansible.com), Red Hat Automation Hub (https://console.redhat.com/ansible/automation-hub), or verified internal repositories using HTTPS URLs. 2. Carefully inspect any requirements.yml files before running 'ansible-galaxy collection install -r requirements.yml'. Verify that all collection sources use legitimate HTTPS URLs and do not contain git+ prefixed URIs with suspicious characters (especially values starting with '-'). 3. Ensure your system's git version is 2.12 or later, which disables the ext:: transport by default. While this does not fully prevent exploitation (the -ccore.sshCommand technique bypasses transport restrictions), it eliminates one of the exploitation vectors. 4. Restrict the GIT_ALLOW_PROTOCOL environment variable to only necessary protocols (e.g. https, ssh) and never include 'ext' unless absolutely required. Workaround: Applications using AIOHTTP that are configured to load untrusted files via the `CookieJar.load()` function should implement input sanitization prior to loading. This prevents the injection of malicious code. Workaround: To mitigate this issue, applications that use GitPython and process untrusted input for Git configuration values must implement robust input validation and sanitization. This prevents the injection of newlines that could manipulate `core.hooksPath` and lead to arbitrary code execution. Additionally, ensure that applications interacting with Git repositories operate with the principle of least privilege to limit the potential impact of any successful exploitation. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Do not pass untrusted or attacker-influenced input as the template parameter (or other forwarded options) to GitPython's Repo.init. Upgrade to GitPython 3.1.58 or later, where the unsafe option forwarding is fixed. Workaround: Do not pass untrusted or attacker-influenced treeish arguments to GitPython's IndexFile.from_tree, IndexFile.reset, or IndexFile.merge_tree. Upgrade to GitPython 3.1.58 or later, where option injection into `git read-tree` is fixed. Workaround: Do not pass untrusted or attacker-influenced keyword arguments to GitPython's guarded methods such as clone_from, and do not set split_single_char_options=False on untrusted input. Upgrade to GitPython 3.1.58 or later, where the check_unsafe_options bypass is fixed. Workaround: Do not pass untrusted or attacker-influenced git option names to GitPython. Upgrade to GitPython 3.1.58 or later, where option-name (config) injection is fixed. Workaround: There is no mitigation beyond not cloning or initializing git submodules from untrusted repositories. Upgrade to GitPython 3.1.58 or later when it becomes available.

🔗 References (13)