Red Hat Security Advisory: satellite/iop-vulnerability-engine-rhel9 container image available as a Technology Preview
🔗 CVE IDs covered (14)
📋 Description
CVE-2026-42215 — GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks
CVE-2026-42284 — GitPython: GitPython: Arbitrary code execution via improper validation of clone options
CVE-2026-44244 — GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration
CVE-2026-73620 — gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding
CVE-2026-73622 — gitpython: GitPython: Information disclosure via environment variable expansion in URL handling
CVE-2026-73623 — gitpython: GitPython: Remote Code Execution via malicious Git template
CVE-2026-73624 — gitpython: GitPython: Arbitrary File Overwrite via improper git option validation
CVE-2026-73625 — gitpython: GitPython: Remote Code Execution via kwarg value smuggling
CVE-2026-76218 — gitpython: GitPython: Remote Code Execution via malicious Git hooks
CVE-2026-76219 — gitpython: GitPython: Arbitrary File Overwrite via git read-tree option injection
CVE-2026-76220 — gitpython: GitPython: Arbitrary command execution via crafted kwargs
CVE-2026-76221 — gitpython: GitPython: Arbitrary code execution via config-name injection
CVE-2026-76222 — gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names
CVE-2026-78676 — gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection
🎯 Affected products2
- Red Hat Satellite 6.19
- registry.redhat.io/satellite/iop-vulnerability-engine-rhel9@sha256:24ebda962c61b717d8c4f4aff70ba900d3f8c2a278cd03b9d16ace83f8ac2259_amd64 as a component of Red Hat Satellite 6.19
✅ Remediation
For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, applications that use GitPython and process untrusted input for Git configuration values must implement robust input validation and sanitization. This prevents the injection of newlines that could manipulate `core.hooksPath` and lead to arbitrary code execution. Additionally, ensure that applications interacting with Git repositories operate with the principle of least privilege to limit the potential impact of any successful exploitation. Workaround: Do not pass untrusted or attacker-influenced input as the template parameter (or other forwarded options) to GitPython's Repo.init. Upgrade to GitPython 3.1.58 or later, where the unsafe option forwarding is fixed. Workaround: Do not pass untrusted or attacker-influenced treeish arguments to GitPython's IndexFile.from_tree, IndexFile.reset, or IndexFile.merge_tree. Upgrade to GitPython 3.1.58 or later, where option injection into `git read-tree` is fixed. Workaround: Do not pass untrusted or attacker-influenced keyword arguments to GitPython's guarded methods such as clone_from, and do not set split_single_char_options=False on untrusted input. Upgrade to GitPython 3.1.58 or later, where the check_unsafe_options bypass is fixed. Workaround: Do not pass untrusted or attacker-influenced git option names to GitPython. Upgrade to GitPython 3.1.58 or later, where option-name (config) injection is fixed. Workaround: There is no mitigation beyond not cloning or initializing git submodules from untrusted repositories. Upgrade to GitPython 3.1.58 or later when it becomes available.
🔗 References (21)
- selfhttps://access.redhat.com/errata/RHSA-2026:68776
- externalhttps://access.redhat.com/documentation/en-us/red_hat_satellite/6.19/html/updating_red_hat_satellite/index
- externalhttps://access.redhat.com/security/cve/CVE-2026-42215
- externalhttps://access.redhat.com/security/cve/CVE-2026-42284
- externalhttps://access.redhat.com/security/cve/CVE-2026-44244
- externalhttps://access.redhat.com/security/cve/CVE-2026-73620
- externalhttps://access.redhat.com/security/cve/CVE-2026-73622
- externalhttps://access.redhat.com/security/cve/CVE-2026-73623
- externalhttps://access.redhat.com/security/cve/CVE-2026-73624
- externalhttps://access.redhat.com/security/cve/CVE-2026-73625
- externalhttps://access.redhat.com/security/cve/CVE-2026-76218
- externalhttps://access.redhat.com/security/cve/CVE-2026-76219
- externalhttps://access.redhat.com/security/cve/CVE-2026-76220
- externalhttps://access.redhat.com/security/cve/CVE-2026-76221
- externalhttps://access.redhat.com/security/cve/CVE-2026-76222
- externalhttps://access.redhat.com/security/cve/CVE-2026-78676
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/software/containers/search
- externalhttps://docs.redhat.com/en/documentation/red_hat_satellite/6.19/html/installing_satellite_server_in_a_connected_network_environment/performing-additional-configuration-on-server_satellite#installing-and-configuring-red-hat-lightspeed-in-satellite
- externalhttps://docs.redhat.com/en/documentation/red_hat_satellite/6.19/html/installing_satellite_server_in_a_disconnected_network_environment/performing-additional-configuration#installing-and-configuring-red-hat-lightspeed-in-satellite
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_68776.json