RHSA-2026:74503CriticalCVSS 9.9

Red Hat Security Advisory: Satellite 6.19.5 Async Update

Published
October 1, 2026
Last Modified
October 4, 2026

🔗 CVE IDs covered (31)

📋 Description

CVE-2026-12405 — rubygem-foreman_remote_execution: command injection in job invocations via effective_user parameter CVE-2026-12423 — foreman: unauthenticated information disclosure via provisioning token validation flaw CVE-2026-12540 — foreman: command injection in foreman-rake errors:fetch_log via request_id parameter CVE-2026-12541 — foreman: command injection in foreman-rake database tasks CVE-2026-12542 — foreman: command injection in foreman-tail CVE-2026-12544 — foreman: SSTI and insecure deserialization in foreman-rake configuration CVE-2026-12545 — rubygem-hammer_cli: command injection via insecure editor invocation CVE-2026-33154 — dynaconf: jinja2: Dynaconf: Arbitrary code execution via Server-Side Template Injection CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input CVE-2026-54284 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing CVE-2026-56097 — rubygem-katello: SQL injection in Registry Proxy via labels CVE-2026-56098 — rubygem-katello: improper authorization logic allows resource enumeration CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-59879 — immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations CVE-2026-59893 — sqlparse: sqlparse: Denial of Service via inefficient SQL parsing CVE-2026-71491 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in comment grouping CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-78679 — GitPython: GitPython: Arbitrary file read via TagReference.create() CVE-2026-79654 — ketello: Katello Content View History API Cross-Organization Authorization Bypass CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies CVE-2026-87817 — GitPython: GitPython: Remote Code Execution via Git directory impersonation CVE-2026-96658 — foreman: Safemode Bypass leading to RCE CVE-2026-96659 — foreman: Excessive Permissions for Viewer Role on Preview

🎯 Affected products45

  • Red Hat Satellite 6.19 for RHEL 9
  • ansible-collection-redhat-satellite-0:5.13.0-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • ansible-collection-redhat-satellite-0:5.13.0-1.el9sat.src as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-0:3.18.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-0:3.18.0.14-1.el9sat.src as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-cli-0:3.18.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-debug-0:3.18.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-dynflow-sidekiq-0:3.18.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-ec2-0:3.18.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-journald-0:3.18.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-libvirt-0:3.18.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-openstack-0:3.18.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-pcp-0:3.18.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-postgresql-0:3.18.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-redis-0:3.18.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-service-0:3.18.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-telemetry-0:3.18.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • foreman-vmware-0:3.18.0.14-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • pulpcore-obsolete-packages-0:1.3.1-6.el9pc.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • pulpcore-obsolete-packages-0:1.3.1-6.el9pc.src as a component of Red Hat Satellite 6.19 for RHEL 9
  • python3.12-dynaconf-0:3.2.13-2.el9pc.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • python3.12-dynaconf-0:3.2.13-2.el9pc.src as a component of Red Hat Satellite 6.19 for RHEL 9
  • python3.12-gitpython-0:3.1.62-1.el9pc.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • python3.12-gitpython-0:3.1.62-1.el9pc.src as a component of Red Hat Satellite 6.19 for RHEL 9
  • python3.12-sqlparse-0:0.6.0-1.el9pc.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • python3.12-sqlparse-0:0.6.0-1.el9pc.src as a component of Red Hat Satellite 6.19 for RHEL 9
  • rubygem-foreman_remote_execution-0:16.5.3-2.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • rubygem-foreman_remote_execution-0:16.5.3-2.el9sat.src as a component of Red Hat Satellite 6.19 for RHEL 9
  • rubygem-foreman_remote_execution-cockpit-0:16.5.3-2.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • rubygem-foreman_webhooks-0:5.0.3-1.el9sat.noarch as a component of Red Hat Satellite 6.19 for RHEL 9
  • +15 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_satellite/6.19/html/updating_red_hat_satellite/index Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: To mitigate this issue, applications should implement input validation to reject or clamp any externally supplied List index or key-path segment that exceeds a sane maximum, specifically values greater than or equal to 2^30. Additionally, running request handling in isolated worker processes with capped heap sizes (e.g., using `--max-old-space-size`) can contain the impact of a potential process abort. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. For additional information, refer to the upstream advisory at https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg. Workaround: Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.

🔗 References (9)