Red Hat Security Advisory: Technical preview of the satellite/iop-vmaas-rhel9 container image
🔗 CVE IDs covered (27)
📋 Description
CVE-2026-27459 — pyOpenSSL: DTLS cookie callback buffer overflow
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs
CVE-2026-42215 — GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks
CVE-2026-42284 — GitPython: GitPython: Arbitrary code execution via improper validation of clone options
CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing
CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header
CVE-2026-44244 — GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration
CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input
CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue
CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution
CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
CVE-2026-73620 — gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding
CVE-2026-73622 — gitpython: GitPython: Information disclosure via environment variable expansion in URL handling
CVE-2026-73623 — gitpython: GitPython: Remote Code Execution via malicious Git template
CVE-2026-73624 — gitpython: GitPython: Arbitrary File Overwrite via improper git option validation
CVE-2026-73625 — gitpython: GitPython: Remote Code Execution via kwarg value smuggling
CVE-2026-76218 — gitpython: GitPython: Remote Code Execution via malicious Git hooks
CVE-2026-76219 — gitpython: GitPython: Arbitrary File Overwrite via git read-tree option injection
CVE-2026-76220 — gitpython: GitPython: Arbitrary command execution via crafted kwargs
CVE-2026-76221 — gitpython: GitPython: Arbitrary code execution via config-name injection
CVE-2026-76222 — gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names
CVE-2026-78676 — gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection
CVE-2026-78679 — GitPython: GitPython: Arbitrary file read via TagReference.create()
CVE-2026-87817 — GitPython: GitPython: Remote Code Execution via Git directory impersonation
🎯 Affected products2
- Red Hat Satellite 6.19
- registry.redhat.io/satellite/iop-vmaas-rhel9@sha256:ed38f427171a53e7086288bf875a521b1048142aebc9276e47f4d8dc4d7cf145_amd64 as a component of Red Hat Satellite 6.19
✅ Remediation
For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. Workaround: To mitigate this flaw, ensure the callback provided to the set_cookie_generate_callback function strictly limits the returned cookie string or byte sequence to under 256 bytes. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: To mitigate this issue, applications that use GitPython and process untrusted input for Git configuration values must implement robust input validation and sanitization. This prevents the injection of newlines that could manipulate `core.hooksPath` and lead to arbitrary code execution. Additionally, ensure that applications interacting with Git repositories operate with the principle of least privilege to limit the potential impact of any successful exploitation. Workaround: Do not pass untrusted or attacker-influenced input as the template parameter (or other forwarded options) to GitPython's Repo.init. Upgrade to GitPython 3.1.58 or later, where the unsafe option forwarding is fixed. Workaround: Do not pass untrusted or attacker-influenced treeish arguments to GitPython's IndexFile.from_tree, IndexFile.reset, or IndexFile.merge_tree. Upgrade to GitPython 3.1.58 or later, where option injection into `git read-tree` is fixed. Workaround: Do not pass untrusted or attacker-influenced keyword arguments to GitPython's guarded methods such as clone_from, and do not set split_single_char_options=False on untrusted input. Upgrade to GitPython 3.1.58 or later, where the check_unsafe_options bypass is fixed. Workaround: Do not pass untrusted or attacker-influenced git option names to GitPython. Upgrade to GitPython 3.1.58 or later, where option-name (config) injection is fixed. Workaround: There is no mitigation beyond not cloning or initializing git submodules from untrusted repositories. Upgrade to GitPython 3.1.58 or later when it becomes available. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. For additional information, refer to the upstream advisory at https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg.
🔗 References (34)
- selfhttps://access.redhat.com/errata/RHSA-2026:68780
- externalhttps://access.redhat.com/documentation/en-us/red_hat_satellite/6.19/html/updating_red_hat_satellite/index
- externalhttps://access.redhat.com/security/cve/CVE-2026-27459
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-42215
- externalhttps://access.redhat.com/security/cve/CVE-2026-42284
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-44244
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-73620
- externalhttps://access.redhat.com/security/cve/CVE-2026-73622
- externalhttps://access.redhat.com/security/cve/CVE-2026-73623
- externalhttps://access.redhat.com/security/cve/CVE-2026-73624
- externalhttps://access.redhat.com/security/cve/CVE-2026-73625
- externalhttps://access.redhat.com/security/cve/CVE-2026-76218
- externalhttps://access.redhat.com/security/cve/CVE-2026-76219
- externalhttps://access.redhat.com/security/cve/CVE-2026-76220
- externalhttps://access.redhat.com/security/cve/CVE-2026-76221
- externalhttps://access.redhat.com/security/cve/CVE-2026-76222
- externalhttps://access.redhat.com/security/cve/CVE-2026-78676
- externalhttps://access.redhat.com/security/cve/CVE-2026-78679
- externalhttps://access.redhat.com/security/cve/CVE-2026-87817
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/software/containers/search
- externalhttps://docs.redhat.com/en/documentation/red_hat_satellite/6.19/html/installing_satellite_server_in_a_connected_network_environment/performing-additional-configuration-on-server_satellite#installing-and-configuring-red-hat-lightspeed-in-satellite
- externalhttps://docs.redhat.com/en/documentation/red_hat_satellite/6.19/html/installing_satellite_server_in_a_disconnected_network_environment/performing-additional-configuration#installing-and-configuring-red-hat-lightspeed-in-satellite
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_68780.json