Red Hat Security Advisory: General availability of the satellite/iop-advisor-frontend-rhel9 container image
🔗 CVE IDs covered (17)
📋 Description
CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-67313 — axios: axios: Denial of Service via uncontrolled recursion in formDataToJSON CVE-2026-67314 — axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth CVE-2026-67320 — axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter CVE-2026-67321 — axios: axios: Denial of Service via object serialization bypass CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow CVE-2026-73088 — browserslist: Browserslist: Prototype pollution leading to denial of service CVE-2026-73089 — browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results CVE-2026-73646 — postcss: PostCSS: Information disclosure via path traversal in source map auto-loading CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies
🎯 Affected products2
- Red Hat Satellite 6.19
- registry.redhat.io/satellite/iop-advisor-frontend-rhel9@sha256:842b088286ed98d34c8e4081564e9c7f173773b3261776bcc3603a8f0fbcb9c3_amd64 as a component of Red Hat Satellite 6.19
✅ Remediation
For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce exposure, ensure that the `browserslist` tool processes only trusted `browserslist-stats.json`, `opts.stats`, and CLI `--stats` data. Avoid using the tool with untrusted input sources in development or build environments. If `browserslist` is integrated into automated pipelines, validate all input data originates from trusted sources. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams.
🔗 References (24)
- selfhttps://access.redhat.com/errata/RHSA-2026:68748
- externalhttps://access.redhat.com/documentation/en-us/red_hat_satellite/6.19/html/updating_red_hat_satellite/index
- externalhttps://access.redhat.com/security/cve/CVE-2026-12143
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/cve/CVE-2026-67313
- externalhttps://access.redhat.com/security/cve/CVE-2026-67314
- externalhttps://access.redhat.com/security/cve/CVE-2026-67320
- externalhttps://access.redhat.com/security/cve/CVE-2026-67321
- externalhttps://access.redhat.com/security/cve/CVE-2026-73086
- externalhttps://access.redhat.com/security/cve/CVE-2026-73088
- externalhttps://access.redhat.com/security/cve/CVE-2026-73089
- externalhttps://access.redhat.com/security/cve/CVE-2026-73646
- externalhttps://access.redhat.com/security/cve/CVE-2026-75899
- externalhttps://access.redhat.com/security/cve/CVE-2026-75931
- externalhttps://access.redhat.com/security/cve/CVE-2026-75975
- externalhttps://access.redhat.com/security/cve/CVE-2026-76172
- externalhttps://access.redhat.com/security/cve/CVE-2026-84292
- externalhttps://access.redhat.com/security/cve/CVE-2026-84375
- externalhttps://access.redhat.com/security/cve/CVE-2026-84394
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/software/containers/search
- externalhttps://docs.redhat.com/en/documentation/red_hat_satellite/6.19/html/installing_satellite_server_in_a_connected_network_environment/performing-additional-configuration-on-server_satellite#installing-and-configuring-red-hat-lightspeed-in-satellite
- externalhttps://docs.redhat.com/en/documentation/red_hat_satellite/6.19/html/installing_satellite_server_in_a_disconnected_network_environment/performing-additional-configuration#installing-and-configuring-red-hat-lightspeed-in-satellite
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_68748.json