RHSA-2026:67593HighCVSS 7.5

Red Hat Security Advisory: goose bug fix and enhancement update

Published
September 15, 2026
Last Modified
September 21, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-18140 — aws-smithy-json: aws-smithy-json: Denial of Service via uncontrolled recursion with deeply nested JSON

🎯 Affected products14

  • Red Hat Enterprise Linux Extensions Channel (v. 10)
  • goose-0:1.38.0-1.el10_2.aarch64 as a component of Red Hat Enterprise Linux Extensions Channel (v. 10)
  • goose-0:1.38.0-1.el10_2.ppc64le as a component of Red Hat Enterprise Linux Extensions Channel (v. 10)
  • goose-0:1.38.0-1.el10_2.s390x as a component of Red Hat Enterprise Linux Extensions Channel (v. 10)
  • goose-0:1.38.0-1.el10_2.src as a component of Red Hat Enterprise Linux Extensions Channel (v. 10)
  • goose-0:1.38.0-1.el10_2.x86_64 as a component of Red Hat Enterprise Linux Extensions Channel (v. 10)
  • goose-debuginfo-0:1.38.0-1.el10_2.aarch64 as a component of Red Hat Enterprise Linux Extensions Channel (v. 10)
  • goose-debuginfo-0:1.38.0-1.el10_2.ppc64le as a component of Red Hat Enterprise Linux Extensions Channel (v. 10)
  • goose-debuginfo-0:1.38.0-1.el10_2.s390x as a component of Red Hat Enterprise Linux Extensions Channel (v. 10)
  • goose-debuginfo-0:1.38.0-1.el10_2.x86_64 as a component of Red Hat Enterprise Linux Extensions Channel (v. 10)
  • goose-debugsource-0:1.38.0-1.el10_2.aarch64 as a component of Red Hat Enterprise Linux Extensions Channel (v. 10)
  • goose-debugsource-0:1.38.0-1.el10_2.ppc64le as a component of Red Hat Enterprise Linux Extensions Channel (v. 10)
  • goose-debugsource-0:1.38.0-1.el10_2.s390x as a component of Red Hat Enterprise Linux Extensions Channel (v. 10)
  • goose-debugsource-0:1.38.0-1.el10_2.x86_64 as a component of Red Hat Enterprise Linux Extensions Channel (v. 10)

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Restrict network access to services that process JSON input using the `aws-smithy-json` runtime. Configure firewalls to limit incoming connections to trusted sources, thereby reducing the exposure to remote unauthenticated denial of service attacks. If the service is reloaded or restarted, ensure firewall rules persist.

🔗 References (3)