RHSA-2026:68044HighCVSS 8.2

Red Hat Security Advisory: Red Hat Edge Manager Version 1.1.4 Security Update

Published
September 16, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (36)

📋 Description

CVE-2026-6377 — CSM: Next4Biz CSM: Information disclosure via path traversal vulnerability CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42306 — github.com/docker/docker: github.com/moby/moby: Moby container framework: Host file overwrite via race condition in docker cp mount setup CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-45819 — baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-48050 — net/http/pprof: github.com/basekick-labs/arc: Arc: Information disclosure and Denial of Service via unauthenticated debug endpoints CVE-2026-50162 — oras-go: oras-go: File store write outside working directory via symlink traversal CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-71556 — github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution CVE-2026-73088 — browserslist: Browserslist: Prototype pollution leading to denial of service CVE-2026-73089 — browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results CVE-2026-73643 — js-yaml: js-yaml: Denial of Service via exponential parsing in flow collections CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects CVE-2026-81521 — go.mongodb.org/mongo-driver: MongoDB Go Driver: Write redirection via unvalidated database name in Client.BulkWrite CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies

🎯 Affected products29

  • Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-alert-exporter-rhel10@sha256:113a53ee67c1311ae8d6a5284b854e14230efda2a2a6c6b5552a4dcd92a126c2_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-alert-exporter-rhel10@sha256:656136d4c7b72d2c3239f84b22e8228a635372d85fdaf1ac5c764e365339a6fe_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-alertmanager-proxy-rhel10@sha256:91b3d6f34e7f2061d048302b5569da9a47fcfce85910341441d2d99e610fcf00_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-alertmanager-proxy-rhel10@sha256:e4f03dada46883472ee531eb44d41d092b010739377b385cb50136753b9da47c_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-api-rhel10@sha256:15dfe95f642c53a78955821fa81ae9ee87fce8a110d14bc3b1ffe8def4e1c0f4_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-api-rhel10@sha256:e1efba6747bbc718f39513f9583fcbd194456848dce4279363d80f5907786746_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-cli-artifacts-rhel10@sha256:8dee7d6a99673f300e1ec7a95d5d69ed4e5545d420e48de0e95f09dd017282f9_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-cli-artifacts-rhel10@sha256:9981379fe8cc0c2e266bc5f911ce81a1a97f94ab774ca9bad2ddaa2d3f030cb6_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-db-setup-rhel10@sha256:bf466b51aa1f15e0e84e46cc6b764b4d0d749a4ac2fddcbaea5821c5ba6228ae_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-db-setup-rhel10@sha256:df00f65b443a30d4c10867bf67832de6938cd1366803429b35531deba6c1d82d_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-imagebuilder-api-rhel10@sha256:55e8187000c001327f21f0591ef0c82fad4f5d97a8f0cdd233394207702f0c6f_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-imagebuilder-api-rhel10@sha256:c1f4abaaf64db27af7c31e8272bd97e0c50ee35734bee1de5fa1c3e7dee36722_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-imagebuilder-worker-rhel10@sha256:8e4f8befc4ef0ab57f2d54048db341bcfde05f1e4da11c37272153a2bf4894ac_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-imagebuilder-worker-rhel10@sha256:fbc0321779a2ee25d6b45b4c3812b87abb6fe5723730ba0954a8d239c593eca9_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-pam-issuer-rhel10@sha256:7ce7b208360c6c491f0864ec4fe32ae9cdeb2c9f047b3c044721590cb18b1510_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-pam-issuer-rhel10@sha256:e0831cf9f206e4a60b140ad2b4fdd0991557d70f59155e56d3f5eb21e4514bfe_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-periodic-rhel10@sha256:1dbaa4f464fea6256d911080384aa6b6cca0a146dc44592ecbb1c47e103d1595_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-periodic-rhel10@sha256:ff41c98221cce04e0937ddcdde2face8623b208ebfa81cb5fcc26b5c49ef0ca1_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-telemetry-gateway-rhel10@sha256:30e5e2a81aedbc24c3f90eab44be0cb6eeba7d289cf4acb9ee480a77ad4e19b4_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-telemetry-gateway-rhel10@sha256:d0791c0e0aad6f6b0a3c776d9954a3e9e8ddf270e3755b188866af413ea07313_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-ui-ocp-rhel10@sha256:a5fb17e530327f02e48e6841358127d9fb10a80b358ec826382a28cf2410fe01_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-ui-ocp-rhel10@sha256:ea81725d983f8981d5cf5da7a6a219be4b3b0c0436859e47e9d22331bbcbb945_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-ui-rhel10@sha256:7ce6544b3bae3cc7eb10fa205f6e2bf61c9aabc310daca4b8ff148e6814e8cd7_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-ui-rhel10@sha256:f69df76136f704f20f27e8d875e8b8912494fd5ccbcb2e0df72a3e21ef71f5cb_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-userinfo-proxy-rhel10@sha256:63ba68ee2c1ce3e5cd527a660f1b5b0b1aa88117188ff7bf9d21d81210ea9f99_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-userinfo-proxy-rhel10@sha256:9244877e26ecf46ba570c25799845f8fa625e2f85efc3ab707f5acdcde8c8923_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-worker-rhel10@sha256:14a88eafb9028ecf134d21ad5f22f925d6bb5b5f0eeded1ab465445dbb9025e7_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-worker-rhel10@sha256:a832e8d29cfd4595ecdeac4a4e5301f4586a9d20ac05ee6a2fa5c92b1243339c_amd64 as a component of Red Hat Edge Manager 1.1

✅ Remediation

See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: No mitigation is required. Red Hat products do not ship or include the affected Arc component (github.com/basekick-labs/arc), so they are not exposed to this vulnerability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later). Workaround: To reduce exposure, ensure that the `browserslist` tool processes only trusted `browserslist-stats.json`, `opts.stats`, and CLI `--stats` data. Avoid using the tool with untrusted input sources in development or build environments. If `browserslist` is integrated into automated pipelines, validate all input data originates from trusted sources. Workaround: To mitigate this issue, restrict applications from processing untrusted YAML input with affected versions of the `js-yaml` library. Implement strict input validation to ensure that only trusted and well-formed YAML data is processed. If the application is exposed to external, untrusted sources, consider isolating the application or implementing additional resource limits to prevent complete service disruption. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams.

🔗 References (41)