RHSA-2026:68006HighCVSS 8.2

Red Hat Security Advisory: Red Hat Edge Manager Version 1.2.1 Security Update

Published
September 16, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (29)

📋 Description

CVE-2026-6377 — CSM: Next4Biz CSM: Information disclosure via path traversal vulnerability CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization CVE-2026-17106 — github.com/moby/go-archive: moby/go-archive: Arbitrary file write via link following in tar extraction CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-45819 — baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling CVE-2026-48050 — net/http/pprof: github.com/basekick-labs/arc: Arc: Information disclosure and Denial of Service via unauthenticated debug endpoints CVE-2026-50162 — oras-go: oras-go: File store write outside working directory via symlink traversal CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-71556 — github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution CVE-2026-73089 — browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results CVE-2026-73643 — js-yaml: js-yaml: Denial of Service via exponential parsing in flow collections CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects CVE-2026-81521 — go.mongodb.org/mongo-driver: MongoDB Go Driver: Write redirection via unvalidated database name in Client.BulkWrite CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies

🎯 Affected products29

  • Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-alert-exporter-rhel10@sha256:c07fc974387182b0901c4207b6322c8cbdc0c450248ead8114cd460c187844a5_arm64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-alert-exporter-rhel10@sha256:ce8cc823b039dfde3ed0f12d929a781318dca8081e0b3ad1dfc395ce4b283073_amd64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-alertmanager-proxy-rhel10@sha256:43abd7656958af997716f39af28fb87e034a6af795bd24f29c137d5512c4b262_amd64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-alertmanager-proxy-rhel10@sha256:524e9f0637943ff6bdf3b1115cfbdd7d5c4c9d26237b961376d252766e95f48d_arm64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-api-rhel10@sha256:d1c7da08eb272be975b97b674d43e7852d3bd8787e19377ae322b02478232eb9_amd64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-api-rhel10@sha256:dcc7300f1826d65c8200fe7ba5434600c0a7520e050fbae7f9a394d4eb662a8c_arm64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-cli-artifacts-rhel10@sha256:06c6652809bf74d48049d453aba530f9532cb59fcead4ad0a07089822ea51bb4_amd64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-cli-artifacts-rhel10@sha256:23c2f14159fa23781bcf9c1fa8b993481f0f099800a852c3eb009f709503c2eb_arm64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-db-setup-rhel10@sha256:75c7d5351ce497436e2f24fb66a49611ef1a15cfc5c49adde92bd609faff06fa_arm64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-db-setup-rhel10@sha256:f82dce35684695affa52e1155b2be8e865870cc92317cbe74b3c0fff8842aaf8_amd64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-imagebuilder-api-rhel10@sha256:415bed99e587889c5fc774957a1bbccc6fe5cd6cfaac60342a98a2159a68adb6_arm64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-imagebuilder-api-rhel10@sha256:8f82cda5b12f52c2d298a55f63f4a562bab7687d705ea30aaf0f2ac91074a06a_amd64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-imagebuilder-worker-rhel10@sha256:3468b781f5e9c49ea1445de85d911e2f0bb0e8a5cd439394e4abedb5396552c7_amd64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-imagebuilder-worker-rhel10@sha256:a77066d1b73a698daf9f9e0fea6bee25e31ad0076ba97aa39c7acb2bf5383e70_arm64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-pam-issuer-rhel10@sha256:0368ec1b33bb8fb3084c939329aa3a7ffaa422262fffa2091adbea1bb5ec4fa2_arm64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-pam-issuer-rhel10@sha256:bb44ab97b0070dde80ae6f591dc4b2070ce121403eae9145a3075ca14d6220a6_amd64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-periodic-rhel10@sha256:14aee2f06947935d5f00159ea45f80ad4f9a0b6a13e502024bf7152a5a8f9e5c_amd64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-periodic-rhel10@sha256:6debd45b617dffa5a1c4a0fbb28373e44e08bc775f692a3529cd70a5614bfb38_arm64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-telemetry-gateway-rhel10@sha256:6d3528b80e2963d736c32c83ff514324cff48a48851e801da3ac8d45e72a6247_amd64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-telemetry-gateway-rhel10@sha256:6dab8de581e257661046180f2e88bc576217b19b75d5d65f83e96eb635fd99e5_arm64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-ui-ocp-rhel10@sha256:238db2122047cf44d3645711f8b62077ba0da832a196b1b6c7740e660f672130_amd64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-ui-ocp-rhel10@sha256:60d221c9c8badef74ade9d8a7173267c3b8bc1bde43aa13fd626b03ff8002393_arm64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-ui-rhel10@sha256:8fc038cea92e459b6fcee4d9afef0120e2447ab99749741e6f9b81e5434876c9_amd64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-ui-rhel10@sha256:eb910fabee98ba81cf606000b6fdadd2c18d9cbdc22d3ef0aff399f53534f43e_arm64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-userinfo-proxy-rhel10@sha256:31d9a619e50f6a2d4310df31791f9288e339ccb0770bcf178d9499860e167426_amd64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-userinfo-proxy-rhel10@sha256:f83dab17987b97fd282ed813d211aa84efc13c9ce06ee4c902a2aa334b059815_arm64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-worker-rhel10@sha256:c768b190e580ad40eba090cbefb1b51de693429001c749042f3cee00c5f55a3e_arm64 as a component of Red Hat Edge Manager 1.2
  • registry.redhat.io/rhem/flightctl-worker-rhel10@sha256:e0b83499d6271f7edece85e7ebf0ce6a210de7e1ec652461525832d40ecd3729_amd64 as a component of Red Hat Edge Manager 1.2

✅ Remediation

See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.2 Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, avoid processing tar archives from untrusted sources. When handling archives from potentially untrusted origins, ensure that the extraction process is executed with the least privileges necessary to limit the impact of any arbitrary file write attempts. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: No mitigation is required. Red Hat products do not ship or include the affected Arc component (github.com/basekick-labs/arc), so they are not exposed to this vulnerability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later). Workaround: To mitigate this issue, restrict applications from processing untrusted YAML input with affected versions of the `js-yaml` library. Implement strict input validation to ensure that only trusted and well-formed YAML data is processed. If the application is exposed to external, untrusted sources, consider isolating the application or implementing additional resource limits to prevent complete service disruption. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams.

🔗 References (34)