RHSA-2026:8165HighCVSS 8.8

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
April 14, 2026
Last Modified
August 23, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2025-67746 — composer: Composer: Terminal output manipulation leading to Denial of Service CVE-2026-40176 — composer: command injection via malicious Perforce repository definition CVE-2026-40261 — composer: command injection via malicious Perforce source reference/url

🎯 Affected products3

  • Red Hat Hardened Images
  • composer-main@noarch as a component of Red Hat Hardened Images
  • composer-main@src as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: To mitigate this vulnerability, only run Composer commands on projects from trusted sources. Also, inspect composer.json files before running Composer commands on them, specifically checking that Perforce-related fields contain valid values. Workaround: To mitigate this issue, only run Composer commands on projects and dependencies from trusted sources. Also, use the '--prefer-dist' or the 'preferred-install: dist' configuration setting to prevent Composer from installing dependencies from source.

🔗 References (7)