RHSA-2026:68764CriticalCVSS 9.8

Red Hat Security Advisory: Technical preview of the satellite/iop-vmaas-rhel9 container image

Published
September 17, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (22)

📋 Description

CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-42215 — GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks CVE-2026-42284 — GitPython: GitPython: Arbitrary code execution via improper validation of clone options CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-44244 — GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration CVE-2026-54876 — openssl: openssl-src: OpenSSL: Memory leak leads to Denial of Service in OCSP response checking CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-73620 — gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding CVE-2026-73622 — gitpython: GitPython: Information disclosure via environment variable expansion in URL handling CVE-2026-73623 — gitpython: GitPython: Remote Code Execution via malicious Git template CVE-2026-73624 — gitpython: GitPython: Arbitrary File Overwrite via improper git option validation CVE-2026-73625 — gitpython: GitPython: Remote Code Execution via kwarg value smuggling CVE-2026-76218 — gitpython: GitPython: Remote Code Execution via malicious Git hooks CVE-2026-76219 — gitpython: GitPython: Arbitrary File Overwrite via git read-tree option injection CVE-2026-76220 — gitpython: GitPython: Arbitrary command execution via crafted kwargs CVE-2026-76221 — gitpython: GitPython: Arbitrary code execution via config-name injection CVE-2026-76222 — gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names CVE-2026-78676 — gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection CVE-2026-78679 — GitPython: GitPython: Arbitrary file read via TagReference.create() CVE-2026-87817 — GitPython: GitPython: Remote Code Execution via Git directory impersonation

🎯 Affected products2

  • Red Hat Satellite 6.18
  • registry.redhat.io/satellite/iop-vmaas-rhel9@sha256:9dc5a13c4d75f07c2c3df2cd276c49f172224bd9b472babf5170eaf8d4652816_amd64 as a component of Red Hat Satellite 6.18

✅ Remediation

For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, applications that use GitPython and process untrusted input for Git configuration values must implement robust input validation and sanitization. This prevents the injection of newlines that could manipulate `core.hooksPath` and lead to arbitrary code execution. Additionally, ensure that applications interacting with Git repositories operate with the principle of least privilege to limit the potential impact of any successful exploitation. Workaround: No broadly applicable mitigation is available. If an affected client application provides a configuration setting for OCSP response checking, operators can temporarily disable it where their certificate revocation policy permits. This blocks the vulnerable response-checking path but removes OCSP-based revocation checks. Clients that must keep OCSP response checking enabled remain exposed. Workaround: Do not pass untrusted or attacker-influenced input as the template parameter (or other forwarded options) to GitPython's Repo.init. Upgrade to GitPython 3.1.58 or later, where the unsafe option forwarding is fixed. Workaround: Do not pass untrusted or attacker-influenced treeish arguments to GitPython's IndexFile.from_tree, IndexFile.reset, or IndexFile.merge_tree. Upgrade to GitPython 3.1.58 or later, where option injection into `git read-tree` is fixed. Workaround: Do not pass untrusted or attacker-influenced keyword arguments to GitPython's guarded methods such as clone_from, and do not set split_single_char_options=False on untrusted input. Upgrade to GitPython 3.1.58 or later, where the check_unsafe_options bypass is fixed. Workaround: Do not pass untrusted or attacker-influenced git option names to GitPython. Upgrade to GitPython 3.1.58 or later, where option-name (config) injection is fixed. Workaround: There is no mitigation beyond not cloning or initializing git submodules from untrusted repositories. Upgrade to GitPython 3.1.58 or later when it becomes available. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. For additional information, refer to the upstream advisory at https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg.

🔗 References (29)