RHSA-2026:68253HighCVSS 8.2

Red Hat Security Advisory: Red Hat Edge Manager Version 1.1.4 Security Update

Published
September 16, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (30)

📋 Description

CVE-2026-6377 — CSM: Next4Biz CSM: Information disclosure via path traversal vulnerability CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42306 — github.com/docker/docker: github.com/moby/moby: Moby container framework: Host file overwrite via race condition in docker cp mount setup CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-45819 — baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-48050 — net/http/pprof: github.com/basekick-labs/arc: Arc: Information disclosure and Denial of Service via unauthenticated debug endpoints CVE-2026-50162 — oras-go: oras-go: File store write outside working directory via symlink traversal CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-71556 — github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution CVE-2026-73088 — browserslist: Browserslist: Prototype pollution leading to denial of service CVE-2026-73089 — browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results CVE-2026-73643 — js-yaml: js-yaml: Denial of Service via exponential parsing in flow collections CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects CVE-2026-81521 — go.mongodb.org/mongo-driver: MongoDB Go Driver: Write redirection via unvalidated database name in Client.BulkWrite CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies

🎯 Affected products27

  • Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-alert-exporter-rhel9@sha256:8eeea362be347d270710e86ef5dee31b8b9cd5e3b15a51b1258aeca65f26a3b7_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-alert-exporter-rhel9@sha256:e53c0e3dd8f5a1143f68a8de71b482f4d8d7d3ef396600386f85245b01f0edb6_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-alertmanager-proxy-rhel9@sha256:70048407630a264c09823ddbf8af4dd60c8b2c47b8c7f23afa90e7a5640033ee_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-alertmanager-proxy-rhel9@sha256:72afdd84d055d32c001a229aca8205fc31473f2725484591777cd8bbb1827078_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-api-rhel9@sha256:37a4d17111ff87b669602992a1a03bf3ccc06bc3d35205ff3b5546a7be334b1f_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-api-rhel9@sha256:612957b7d51455605d78e8c3aee8e85bedd72e2f6226d0b36fed49249a5faaee_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-cli-artifacts-rhel9@sha256:ac3703c0bd8c3656abc4ee6f42e6319f50bc3307b3a59719fbabbbe53b931da5_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-cli-artifacts-rhel9@sha256:af270ba4a70e320b903796bbee4287b1c9bf63a651222375d01c7267c580f802_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-db-setup-rhel9@sha256:131a1ef7f4827997e88c21ec6cdcc335938309c27bb3494be75df7a48da54e3c_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-db-setup-rhel9@sha256:5eef392ec5e02ce9c0dac063fc10939e5372a67c1e4ce07c53a0b10a540b92fe_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-imagebuilder-api-rhel9@sha256:71f79cd1d7c052b559c88757461de172e270ad09868b8dd93ea49f4bfe190ac6_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-imagebuilder-api-rhel9@sha256:fc99de2ea21deb0de1dda7ce4b1859b7fde1a2215db6e37d1832612f2f4fd6ac_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-imagebuilder-worker-rhel9@sha256:709386165bae873dd1fdab6a02b2b2e0565799244f9776ede6d163419e591be7_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-imagebuilder-worker-rhel9@sha256:e0c41a3fd0535a76b2ab9f2807ff52019ca24866e984409fd13e17fc1ccdafc3_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-pam-issuer-rhel9@sha256:04f7f30f70d42d112149432339b5f937e19d5e23162e423bd807a7d873f0bdf2_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-pam-issuer-rhel9@sha256:7be1622f2bc5b9e716b7383f21e599ef75b60ae51b0d204fd2a5867b16bea794_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-periodic-rhel9@sha256:2bf9f0ee955940c9bcf004ad4bcdbd456c9611f047660c5fcda910f262180aa4_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-periodic-rhel9@sha256:c3ef52a4fe319130fb8e53c8def77a8c6b4075fa9e06d6df728db66743bf5137_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-telemetry-gateway-rhel9@sha256:0fe6bd2d1e06ceb24c7046e3c2b097e38106770355a54d122aa933c3d2856048_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-telemetry-gateway-rhel9@sha256:d36b9e9db3fbfd430974680bd378fcd0464c1daef109d987374d3a9e95647bd2_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-ui-ocp-rhel9@sha256:662ade5cd4939cfa4d84988829f35e208cc130923d6ded14dec84fd2cb9c0fcc_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-ui-ocp-rhel9@sha256:cabc41da9e58595c2e983e3e85fd0ea0f6f47ce3492d3c8c6794994601b5d0e1_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-userinfo-proxy-rhel9@sha256:a07805d660a53ca7e440e86bc029cb9071cff7fd5f95e6cccb5232279fb10e22_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-userinfo-proxy-rhel9@sha256:c871ea8df5f1d2aa64c8b41402e64360f3f6d5bf7280bcb139c5916e85e858b0_arm64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-worker-rhel9@sha256:3bc593de4c4041cff17548c3f1c7d09c0fbd7996787c7c70505b9a0e982a356a_amd64 as a component of Red Hat Edge Manager 1.1
  • registry.redhat.io/rhem/flightctl-worker-rhel9@sha256:8262517a827566c40552a7ee633fcb41c531d8947be975e8864e13ecd718e7c7_arm64 as a component of Red Hat Edge Manager 1.1

✅ Remediation

See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: No mitigation is required. Red Hat products do not ship or include the affected Arc component (github.com/basekick-labs/arc), so they are not exposed to this vulnerability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later). Workaround: To reduce exposure, ensure that the `browserslist` tool processes only trusted `browserslist-stats.json`, `opts.stats`, and CLI `--stats` data. Avoid using the tool with untrusted input sources in development or build environments. If `browserslist` is integrated into automated pipelines, validate all input data originates from trusted sources. Workaround: To mitigate this issue, restrict applications from processing untrusted YAML input with affected versions of the `js-yaml` library. Implement strict input validation to ensure that only trusted and well-formed YAML data is processed. If the application is exposed to external, untrusted sources, consider isolating the application or implementing additional resource limits to prevent complete service disruption. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams.

🔗 References (35)