Red Hat Security Advisory: Red Hat Edge Manager Version 1.2.1 Security Update
🔗 CVE IDs covered (29)
📋 Description
CVE-2026-6377 — CSM: Next4Biz CSM: Information disclosure via path traversal vulnerability CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization CVE-2026-17106 — github.com/moby/go-archive: moby/go-archive: Arbitrary file write via link following in tar extraction CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-45819 — baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling CVE-2026-48050 — net/http/pprof: github.com/basekick-labs/arc: Arc: Information disclosure and Denial of Service via unauthenticated debug endpoints CVE-2026-50162 — oras-go: oras-go: File store write outside working directory via symlink traversal CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-71556 — github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution CVE-2026-73089 — browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results CVE-2026-73643 — js-yaml: js-yaml: Denial of Service via exponential parsing in flow collections CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects CVE-2026-81521 — go.mongodb.org/mongo-driver: MongoDB Go Driver: Write redirection via unvalidated database name in Client.BulkWrite CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies
🎯 Affected products29
- Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-alert-exporter-rhel9@sha256:4eee7c5423a9dfd66432a7618d99df255fc4b0b8c257af7efc216ce566531960_amd64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-alert-exporter-rhel9@sha256:5a823051eb98a63483f3b140d764647c0f93274d33a45f286dc6e65906293644_arm64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-alertmanager-proxy-rhel9@sha256:176b6708fba92be3544eab2e86336451ba4fdbaf5eca964facf3f14257f964b4_arm64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-alertmanager-proxy-rhel9@sha256:aa099c07c08ccf8848da309dc91f54d56239072dafe7ff5d31073281bc5e9c30_amd64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-api-rhel9@sha256:4e960becaa1c88b310cbbbd938c0f74b8132f346f0d13d20ca358c3d66c00f02_arm64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-api-rhel9@sha256:d0a9a8a051198f56c1285d9624f867b4e3f393258d6d3a63ba2fb1377f95f60a_amd64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-cli-artifacts-rhel9@sha256:62d802b7c909a4dee07b320a50724f65dedbaf066d6d88ae313c2da9d0d09d0f_amd64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-cli-artifacts-rhel9@sha256:f2c5583a6a135c331a10f65cb990790d23a6c6a730410c531cbeb093100cffcd_arm64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-db-setup-rhel9@sha256:262a91dc1b299a7e0868d9cfa330544d6d38b0555bab954ac26029379ed597a7_arm64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-db-setup-rhel9@sha256:97a66dbe4ab5cabd10df505822cab9f827d2790941b5212a2ed4dd3a100154f1_amd64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-imagebuilder-api-rhel9@sha256:66912f2b6e7661af75ef15f60cb71eca56721ceb38137f32a87e5b773ac7cccb_amd64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-imagebuilder-api-rhel9@sha256:67a8a2963f82ebf982619ff3a6f4a19d046370b272cf252ba45dd1b0ce25814e_arm64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-imagebuilder-worker-rhel9@sha256:1d7001e728a9d4e92037067b28957f0e1bc7836f99d1aabeda3a22a2c59077e4_arm64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-imagebuilder-worker-rhel9@sha256:ad3e3eb6f2f6f328edd57ffa898ca25a7ece9787a59a709fe62629ca6985b6fa_amd64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-pam-issuer-rhel9@sha256:261d19c54310cb51efb51672791851732b27e58eb2e27c474303123ab10f365e_amd64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-pam-issuer-rhel9@sha256:ce0f12689a86f9f6f440af2f295ee32ecdb699b2390b52a1defac91b53f68860_arm64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-periodic-rhel9@sha256:3db90b8256dce53c2f09de64609d629903ec26a3fced7b4c02da1930e91dd2b9_amd64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-periodic-rhel9@sha256:c16c2d10431bdd4bc32cf366bba3cdde56c633ef72535ee58e166098ef8e7b29_arm64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-telemetry-gateway-rhel9@sha256:54efc72fce34e01a658bbaae72b3573cc9a1c7024aecdf667b1f102b66f9cec0_amd64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-telemetry-gateway-rhel9@sha256:ee8786030a03934d623d1427e326ee3062180a558a4ceb91487dd28cf98bda58_arm64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-ui-ocp-rhel9@sha256:6b0cb88e5b03e97090e58055f3eaf5eaa7a873f574bb75ef55acdfedfb252b09_arm64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-ui-ocp-rhel9@sha256:8f4c57db20fcfc63497faaa0dbb7301459a898f5a89e09f45463dbfb33b1028e_amd64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-ui-rhel9@sha256:0ca6fb86b1875060a133476a0fd5f21f0926eecb4c89a1a5f4414d35c9f15601_amd64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-ui-rhel9@sha256:f73229a0e8e83367b22c633393d04b749ae6ffe30711f6cb40f6b21543dc5f13_arm64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-userinfo-proxy-rhel9@sha256:99ac72460e0f7a45867280cc66fdae8f39555c8ea8d29264b2add60dd54e2974_amd64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-userinfo-proxy-rhel9@sha256:b6d6ac7954ffa8ae3f3dd0b2072d0fdefe0c1e032131dc405c4f9a840b1e38ef_arm64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-worker-rhel9@sha256:1d0567cfeba5f1141500d4b6d9d22509c6d64fb589ab5fa79d1bcc23eaee421b_amd64 as a component of Red Hat Edge Manager 1.2
- registry.redhat.io/rhem/flightctl-worker-rhel9@sha256:a1be3f121884a8ef1c94e64bffbc2832a640bd87d175a72ae90f9e298322453b_arm64 as a component of Red Hat Edge Manager 1.2
✅ Remediation
See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.2 Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, avoid processing tar archives from untrusted sources. When handling archives from potentially untrusted origins, ensure that the extraction process is executed with the least privileges necessary to limit the impact of any arbitrary file write attempts. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: No mitigation is required. Red Hat products do not ship or include the affected Arc component (github.com/basekick-labs/arc), so they are not exposed to this vulnerability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later). Workaround: To mitigate this issue, restrict applications from processing untrusted YAML input with affected versions of the `js-yaml` library. Implement strict input validation to ensure that only trusted and well-formed YAML data is processed. If the application is exposed to external, untrusted sources, consider isolating the application or implementing additional resource limits to prevent complete service disruption. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams.
🔗 References (34)
- selfhttps://access.redhat.com/errata/RHSA-2026:68254
- externalhttps://access.redhat.com/security/cve/CVE-2026-13149
- externalhttps://access.redhat.com/security/cve/CVE-2026-13676
- externalhttps://access.redhat.com/security/cve/CVE-2026-17106
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-44740
- externalhttps://access.redhat.com/security/cve/CVE-2026-45819
- externalhttps://access.redhat.com/security/cve/CVE-2026-48050
- externalhttps://access.redhat.com/security/cve/CVE-2026-50162
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/cve/CVE-2026-6377
- externalhttps://access.redhat.com/security/cve/CVE-2026-69152
- externalhttps://access.redhat.com/security/cve/CVE-2026-71556
- externalhttps://access.redhat.com/security/cve/CVE-2026-73089
- externalhttps://access.redhat.com/security/cve/CVE-2026-73643
- externalhttps://access.redhat.com/security/cve/CVE-2026-75899
- externalhttps://access.redhat.com/security/cve/CVE-2026-75931
- externalhttps://access.redhat.com/security/cve/CVE-2026-75975
- externalhttps://access.redhat.com/security/cve/CVE-2026-76172
- externalhttps://access.redhat.com/security/cve/CVE-2026-81521
- externalhttps://access.redhat.com/security/cve/CVE-2026-84292
- externalhttps://access.redhat.com/security/cve/CVE-2026-84375
- externalhttps://access.redhat.com/security/cve/CVE-2026-84394
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.15/html-single/edge_manager/index#edge-mgr-intro
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/managing_device_fleets_with_the_red_hat_edge_manager/assembly-edge-manager-intro
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_68254.json