RHSA-2026:68780CriticalCVSS 9.8

Red Hat Security Advisory: Technical preview of the satellite/iop-vmaas-rhel9 container image

Published
September 17, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (27)

📋 Description

CVE-2026-27459 — pyOpenSSL: DTLS cookie callback buffer overflow CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-42215 — GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks CVE-2026-42284 — GitPython: GitPython: Arbitrary code execution via improper validation of clone options CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-44244 — GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-73620 — gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding CVE-2026-73622 — gitpython: GitPython: Information disclosure via environment variable expansion in URL handling CVE-2026-73623 — gitpython: GitPython: Remote Code Execution via malicious Git template CVE-2026-73624 — gitpython: GitPython: Arbitrary File Overwrite via improper git option validation CVE-2026-73625 — gitpython: GitPython: Remote Code Execution via kwarg value smuggling CVE-2026-76218 — gitpython: GitPython: Remote Code Execution via malicious Git hooks CVE-2026-76219 — gitpython: GitPython: Arbitrary File Overwrite via git read-tree option injection CVE-2026-76220 — gitpython: GitPython: Arbitrary command execution via crafted kwargs CVE-2026-76221 — gitpython: GitPython: Arbitrary code execution via config-name injection CVE-2026-76222 — gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names CVE-2026-78676 — gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection CVE-2026-78679 — GitPython: GitPython: Arbitrary file read via TagReference.create() CVE-2026-87817 — GitPython: GitPython: Remote Code Execution via Git directory impersonation

🎯 Affected products2

  • Red Hat Satellite 6.19
  • registry.redhat.io/satellite/iop-vmaas-rhel9@sha256:ed38f427171a53e7086288bf875a521b1048142aebc9276e47f4d8dc4d7cf145_amd64 as a component of Red Hat Satellite 6.19

✅ Remediation

For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. Workaround: To mitigate this flaw, ensure the callback provided to the set_cookie_generate_callback function strictly limits the returned cookie string or byte sequence to under 256 bytes. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: To mitigate this issue, applications that use GitPython and process untrusted input for Git configuration values must implement robust input validation and sanitization. This prevents the injection of newlines that could manipulate `core.hooksPath` and lead to arbitrary code execution. Additionally, ensure that applications interacting with Git repositories operate with the principle of least privilege to limit the potential impact of any successful exploitation. Workaround: Do not pass untrusted or attacker-influenced input as the template parameter (or other forwarded options) to GitPython's Repo.init. Upgrade to GitPython 3.1.58 or later, where the unsafe option forwarding is fixed. Workaround: Do not pass untrusted or attacker-influenced treeish arguments to GitPython's IndexFile.from_tree, IndexFile.reset, or IndexFile.merge_tree. Upgrade to GitPython 3.1.58 or later, where option injection into `git read-tree` is fixed. Workaround: Do not pass untrusted or attacker-influenced keyword arguments to GitPython's guarded methods such as clone_from, and do not set split_single_char_options=False on untrusted input. Upgrade to GitPython 3.1.58 or later, where the check_unsafe_options bypass is fixed. Workaround: Do not pass untrusted or attacker-influenced git option names to GitPython. Upgrade to GitPython 3.1.58 or later, where option-name (config) injection is fixed. Workaround: There is no mitigation beyond not cloning or initializing git submodules from untrusted repositories. Upgrade to GitPython 3.1.58 or later when it becomes available. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. For additional information, refer to the upstream advisory at https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg.

🔗 References (34)