Red Hat Security Advisory: Red Hat Quay 3.14.9
🔗 CVE IDs covered (75)
📋 Description
CVE-2026-4427 — github.com/jackc/pgproto3: pgproto3: Denial of Service via negative field length in DataRow message
CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling
CVE-2026-9277 — shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators
CVE-2026-10143 — kafka-python: kafka-python: Denial of Service via excessive SCRAM authentication iteration count
CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection
CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization
CVE-2026-14257 — brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function
CVE-2026-15792 — github.com/moby/buildkit: BuildKit: Denial of Service via malicious client request
CVE-2026-15927 — quay: mirror-registry: SSRF: repo-level mirror accepts external_reference without URL validation
CVE-2026-16221 — fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency
CVE-2026-18255 — quay: quay: Global read-only superuser can view robot account tokens
CVE-2026-32591 — mirror-registry: quay: server-side request forgery in proxy cache upstream registry configuration
CVE-2026-33747 — BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend
CVE-2026-33748 — github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs
CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-39822 — golang: Go os.Root: Symlink following vulnerability allows directory traversal
CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions
CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses
CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check
CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions
CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API
CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint
CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing
CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header
CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression
CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects
CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows
CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits
CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability
CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
CVE-2026-44705 — tmp: path Traversal via unsanitized prefix/postfix enables directory escape
CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass
CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens
CVE-2026-49477 — soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings
CVE-2026-54058 — Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image
CVE-2026-54060 — python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files
CVE-2026-55379 — python-pillow: Pillow: Denial of Service via crafted BDF font file
CVE-2026-55380 — python-pillow: Pillow: Denial of Service via crafted GD 2.x image file
CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input
CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue
CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution
CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
CVE-2026-57231 — podman: Podman: Information disclosure via malicious container image environment variables
CVE-2026-59197 — Pillow: Pillow: Native heap out-of-bounds write
CVE-2026-59199 — Pillow: Pillow: Denial of Service via out-of-bounds write in image processing
CVE-2026-59200 — Pillow: Pillow: Denial of service via crafted PDF stream
CVE-2026-59204 — Pillow: Pillow: Denial of Service via crafted JPEG2000 image
CVE-2026-59205 — Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API
CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
CVE-2026-59885 — pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER
CVE-2026-59886 — pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values
CVE-2026-67213 — nanoid: nanoid: Denial of Service via infinite loop in random ID generation
CVE-2026-67214 — nanoid: nanoid: Denial of Service via negative size input in non-secure module functions
CVE-2026-67313 — axios: axios: Denial of Service via uncontrolled recursion in formDataToJSON
CVE-2026-67314 — axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth
CVE-2026-67320 — axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter
CVE-2026-67321 — axios: axios: Denial of Service via object serialization bypass
CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL
CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow
CVE-2026-73088 — browserslist: Browserslist: Prototype pollution leading to denial of service
CVE-2026-73089 — browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results
CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing
🎯 Affected products32
- Red Hat Quay 3.14
- registry.redhat.io/quay/clair-rhel8@sha256:1a1eaf93cb0d184c940fb5faf3d8d4a6348919a7f0318b98d95e04cc84a10bd0_s390x as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/clair-rhel8@sha256:1f694daf74afa33a0d94fb8858a6878793d5b96148dcc77ef9291451966b7138_arm64 as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/clair-rhel8@sha256:242cebeb09263d507c51315918c1f6af3843d95090d15b5cb6d509d2a4850f50_ppc64le as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/clair-rhel8@sha256:f668385cf19dd0402bc1bd7bc085e3ddb3ee8a07a3b178bdeccd1331f742406a_amd64 as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:f80a60db45e7833e69e42a08f08f848fe58f8e7c9cdcec41a40d6a204142793b_amd64 as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:18d8d95e9fd69f705b79759579922ae7bc892b9fc713354ee3413a3272b53d9b_arm64 as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:2a06097fa7a38f2c06ff9d16e2bb5a691b7d3eb5b3d0474e854239ee85114f3e_ppc64le as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:88b3a9ac2fc065ecf22284f201a4b3f08a2d0855566d9724ad1db1d782963360_s390x as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:c25fea72a35277ae55647d93908f16d968944ef4401893b7001e0a5cfbdfbdf8_amd64 as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:3a18dd4bf159bb844b805630958b834d561b747e530304bce72c8edff533bb05_amd64 as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:4438575e5faa8c34d4c42327ebec71a590a3ef6aba43fccbb2437d5b176fa64c_arm64 as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:ac5b77ab6ff988eb0a4590aa06f7f5c6ec7b8ca20532a2dc8273cf9c418550f3_s390x as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:c53d4d738b80e960b1858ae5d1b6ddf2aea24e9b571092acff475bfbfb5606dc_ppc64le as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-builder-rhel8@sha256:73f69e28443a678474d5c4b22cfc1cb7f399a297b3c856dc4838c5d139771551_amd64 as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-builder-rhel8@sha256:90265feb2504477c4669609911a642bf93f79e6181e528c264fcdda5eba2f6af_s390x as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-builder-rhel8@sha256:d8c30b66bb001b9a4aee84e3f8160aa604db7b078da069b6cc4a2a5fcdb3e7b8_arm64 as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-builder-rhel8@sha256:fe7fa40620e9e4a45118b6d97ea7fb94e30b95b90bb110732d5640744c195d0a_ppc64le as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:16cf30e26cc9394960f5d67f7ce4ce77c4633456a7220000fe7b2f7676ae8905_amd64 as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:745ef44b9fb3d4074af1d9ab2a01db555283cf2e3e3d11deede64e5dd4a67785_arm64 as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:839938dad861101606c706996240537e734dbba2d46792a3a1b277d9fbf81f2c_ppc64le as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:8c54f9c121acfe6d861f24d7ca3b9f330af63cd6ad9bf5d9ca87e5d414e827ce_amd64 as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:d11700d820614043a3b36025faad080b3d48146d80f293670927d844ea5ed725_s390x as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-operator-bundle@sha256:5f89f2c53adcf4221f10ea0f55ae8b7ba8e5ebbd0094303803831d8c2ae02686_amd64 as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-operator-rhel8@sha256:360e96f5762ee46b0b49e2d4553096072f22574e9c3822733c15fc5860d715f5_ppc64le as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-operator-rhel8@sha256:5b84a0eaf797a5d7cbfa7d99ac3df0e8fe4e7c627a7d462001d56f17f745fd80_s390x as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-operator-rhel8@sha256:868d14a60728a32b816af8ac03a95be11e004ec6ccf73afc6c90847eba0600da_arm64 as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-operator-rhel8@sha256:a4c208d9862637179906b3ef6c3804ec8b4b2c5aa6e373245d90375b0583bef3_amd64 as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-rhel8@sha256:5ab9413d3b6291049d4d2e6c4f3b1ac0db9587e5ea946e1853f60eabed49d8bd_s390x as a component of Red Hat Quay 3.14
- registry.redhat.io/quay/quay-rhel8@sha256:7a1ac0915d132e9fcedd015a34579bb62eb09e80113448c21aa65387d1c502aa_arm64 as a component of Red Hat Quay 3.14
- +2 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11458 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion. Where possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output. As an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as cgroups or Kubernetes resource limits (spec.containers[].resources.limits.memory) to prevent a single process from exhausting system memory and causing a wider outage. Workaround: Avoid building container images using BuildKit frontends from untrusted sources. A BuildKit frontend is typically specified using a "# syntax" directive at the top of a Dockerfile, or with the "--frontend" option to the "buildctl build" command. Only use frontend images that come from a trusted source. Workaround: Restrict network egress from Quay mirror worker pods/containers using network policies or firewall rules to block access to internal network ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and cloud metadata endpoints (169.254.169.254, metadata.google.internal). Limit repository creation and admin privileges to trusted users via Quay's RBAC configuration. If repository-level mirroring is not required, disable the feature or restrict access to the mirror API endpoints through a reverse proxy. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Remove users who can not be trusted with robot account credentials from GLOBAL_READONLY_SUPER_USERS. Workaround: To mitigate this vulnerability, avoid using untrusted BuildKit frontends. Restrict the use of custom BuildKit frontends to only those from verified and trusted sources. Do not specify untrusted frontends via `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: There is no mitigation for this issue other than updating the Go toolchain to Go 1.25.12 or Go 1.26.5. Programs compiled with Go >= 1.24 that do not use the os.Root API are not affected by this vulnerability. The os.Root API was introduced in Go 1.24. Go versions prior to 1.24 are not affected. This issue is fixed in Go 1.25.12 and Go 1.26.5. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: To mitigate this vulnerability, validate and sanitize any user-controlled data before it is passed to the prefix, postfix or dir options of the file or directory creation functions, specifically rejecting or stripping input containing path traversal sequences. Workaround: Do not load BDF font files from untrusted sources. Applications that only process standard image formats (PNG, JPEG, etc.) and do not use BdfFontFile or ImageFont.load() with BDF files are not affected. Workaround: Avoid processing untrusted GD 2.x image files with PIL.GdImageFile.open(). Use Image.open() instead, which includes decompression bomb protections for supported formats. If GdImageFile must be used, validate the image dimensions before calling load(). Restricting accepted image formats at the application boundary to only those explicitly needed can reduce exposure. Workaround: If the application does not need JPEG2000 support, block .jp2, .j2k, .jpf, and .jpx uploads at the input layer. For services that do process JPEG2000, set memory limits on the process or container (LimitAS= in systemd, or memory limits in Kubernetes/Podman) so a crafted image can only crash the worker, not the whole host. Add automatic restarts (Restart=always in systemd, or container restart policies) so the service recovers from OOM kills without someone having to intervene. Workaround: Most applications using Pillow's color management via profileToProfile() or applyTransform() are not exposed. Only code that calls ImageCmsTransform.apply() directly with a user-controlled output image whose mode does not match the transform can trigger the heap corruption. Audit your code for direct apply() calls to confirm. RHEL builds ship with ASLR, full RELRO/PIE, and FORTIFY_SOURCE by default, making escalation from crash to code execution much harder. For DoS containment, configure automatic service restart (Restart=always in systemd, or container restart policies) so the process recovers without manual intervention. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Update to pyasn1 version 0.6.4 or later when available for your product stream. The impact is limited to availability (denial of service) — an attacker cannot access or modify data. Applications that do not process untrusted ASN.1 input are at reduced risk. Workaround: When processing untrusted ASN.1 data with pyasn1, avoid calling prettyPrint(), str(), float(), int(), or performing comparisons or arithmetic on decoded Real (ASN.1 REAL type) objects. Instead, inspect the raw (mantissa, base, exponent) tuple directly. Where logging decoded ASN.1 structures is necessary, filter out or sani…
🔗 References (78)
- selfhttps://access.redhat.com/errata/RHSA-2026:70267
- externalhttps://access.redhat.com/security/cve/CVE-2026-10143
- externalhttps://access.redhat.com/security/cve/CVE-2026-12143
- externalhttps://access.redhat.com/security/cve/CVE-2026-13149
- externalhttps://access.redhat.com/security/cve/CVE-2026-13676
- externalhttps://access.redhat.com/security/cve/CVE-2026-14257
- externalhttps://access.redhat.com/security/cve/CVE-2026-15792
- externalhttps://access.redhat.com/security/cve/CVE-2026-15927
- externalhttps://access.redhat.com/security/cve/CVE-2026-16221
- externalhttps://access.redhat.com/security/cve/CVE-2026-18255
- externalhttps://access.redhat.com/security/cve/CVE-2026-32591
- externalhttps://access.redhat.com/security/cve/CVE-2026-33747
- externalhttps://access.redhat.com/security/cve/CVE-2026-33748
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-39822
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-39832
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-42151
- externalhttps://access.redhat.com/security/cve/CVE-2026-42154
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-42508
- externalhttps://access.redhat.com/security/cve/CVE-2026-4427
- externalhttps://access.redhat.com/security/cve/CVE-2026-44432
- externalhttps://access.redhat.com/security/cve/CVE-2026-44486
- externalhttps://access.redhat.com/security/cve/CVE-2026-44487
- externalhttps://access.redhat.com/security/cve/CVE-2026-44488
- externalhttps://access.redhat.com/security/cve/CVE-2026-44492
- externalhttps://access.redhat.com/security/cve/CVE-2026-44494
- externalhttps://access.redhat.com/security/cve/CVE-2026-44495
- externalhttps://access.redhat.com/security/cve/CVE-2026-44496
- externalhttps://access.redhat.com/security/cve/CVE-2026-44705
- externalhttps://access.redhat.com/security/cve/CVE-2026-44990
- externalhttps://access.redhat.com/security/cve/CVE-2026-46595
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-48526
- externalhttps://access.redhat.com/security/cve/CVE-2026-49477
- externalhttps://access.redhat.com/security/cve/CVE-2026-54058
- externalhttps://access.redhat.com/security/cve/CVE-2026-54060
- externalhttps://access.redhat.com/security/cve/CVE-2026-55379
- externalhttps://access.redhat.com/security/cve/CVE-2026-55380
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-57231
- externalhttps://access.redhat.com/security/cve/CVE-2026-59197
- externalhttps://access.redhat.com/security/cve/CVE-2026-59199
- externalhttps://access.redhat.com/security/cve/CVE-2026-59200
- externalhttps://access.redhat.com/security/cve/CVE-2026-59204
- externalhttps://access.redhat.com/security/cve/CVE-2026-59205
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/cve/CVE-2026-59885
- externalhttps://access.redhat.com/security/cve/CVE-2026-59886
- externalhttps://access.redhat.com/security/cve/CVE-2026-6322
- externalhttps://access.redhat.com/security/cve/CVE-2026-67213
- externalhttps://access.redhat.com/security/cve/CVE-2026-67214
- externalhttps://access.redhat.com/security/cve/CVE-2026-67313
- externalhttps://access.redhat.com/security/cve/CVE-2026-67314
- externalhttps://access.redhat.com/security/cve/CVE-2026-67320
- externalhttps://access.redhat.com/security/cve/CVE-2026-67321
- externalhttps://access.redhat.com/security/cve/CVE-2026-69152
- externalhttps://access.redhat.com/security/cve/CVE-2026-69153
- externalhttps://access.redhat.com/security/cve/CVE-2026-73086
- externalhttps://access.redhat.com/security/cve/CVE-2026-73088
- externalhttps://access.redhat.com/security/cve/CVE-2026-73089
- externalhttps://access.redhat.com/security/cve/CVE-2026-84375
- externalhttps://access.redhat.com/security/cve/CVE-2026-9277
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_70267.json