RHSA-2026:74624HighCVSS 7.5

Red Hat Security Advisory: Technical preview of the satellite/iop-vulnerability-frontend-rhel9 container image

Published
October 1, 2026
Last Modified
October 2, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies

🎯 Affected products2

  • Red Hat Satellite 6.19
  • registry.redhat.io/satellite/iop-vulnerability-frontend-rhel9@sha256:059b28a4878677f15bd8ae0f591df8605df1a23a1d97c59ccfa1c9c0a9cd36df_amd64 as a component of Red Hat Satellite 6.19

✅ Remediation

For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (9)