RHSA-2026:74644HighCVSS 8.8
Red Hat Security Advisory: satellite/iop-vulnerability-engine-rhel9 container image available as a Technology Preview
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-78679 — GitPython: GitPython: Arbitrary file read via TagReference.create() CVE-2026-87817 — GitPython: GitPython: Remote Code Execution via Git directory impersonation
🎯 Affected products2
- Red Hat Satellite 6.18
- registry.redhat.io/satellite/iop-vulnerability-engine-rhel9@sha256:e51de88ff2b7919ce3b3f56153de57158dcf02125a12ce793e4cdaf52fd339bd_amd64 as a component of Red Hat Satellite 6.18
✅ Remediation
For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. For additional information, refer to the upstream advisory at https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:74644
- externalhttps://access.redhat.com/documentation/en-us/red_hat_satellite/6.18/html/updating_red_hat_satellite/index
- externalhttps://access.redhat.com/security/cve/CVE-2026-78679
- externalhttps://access.redhat.com/security/cve/CVE-2026-87817
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/software/containers/search
- externalhttps://docs.redhat.com/en/documentation/red_hat_satellite/6.18/html/installing_satellite_server_in_a_connected_network_environment/performing-additional-configuration-on-server_satellite#installing-and-configuring-red-hat-lightspeed-in-satellite
- externalhttps://docs.redhat.com/en/documentation/red_hat_satellite/6.18/html/installing_satellite_server_in_a_disconnected_network_environment/performing-additional-configuration#installing-and-configuring-red-hat-lightspeed-in-satellite
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74644.json