RHSA-2026:74649HighCVSS 8.8

Red Hat Security Advisory: satellite/iop-vulnerability-engine-rhel9 container image available as a Technology Preview

Published
October 1, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-34993 — aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() CVE-2026-78679 — GitPython: GitPython: Arbitrary file read via TagReference.create() CVE-2026-87817 — GitPython: GitPython: Remote Code Execution via Git directory impersonation

🎯 Affected products2

  • Red Hat Satellite 6.19
  • registry.redhat.io/satellite/iop-vulnerability-engine-rhel9@sha256:cb6dd5ad6a52497df84764b8611bfa6473b9b22a939add1e71ae8b842f7b3859_amd64 as a component of Red Hat Satellite 6.19

✅ Remediation

For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. Workaround: Applications using AIOHTTP that are configured to load untrusted files via the `CookieJar.load()` function should implement input sanitization prior to loading. This prevents the injection of malicious code. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. For additional information, refer to the upstream advisory at https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg.

🔗 References (10)