Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (3)
📋 Description
CVE-2025-67746 — composer: Composer: Terminal output manipulation leading to Denial of Service CVE-2026-40176 — composer: command injection via malicious Perforce repository definition CVE-2026-40261 — composer: command injection via malicious Perforce source reference/url
🎯 Affected products3
- Red Hat Hardened Images
- composer-main@noarch as a component of Red Hat Hardened Images
- composer-main@src as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: To mitigate this vulnerability, only run Composer commands on projects from trusted sources. Also, inspect composer.json files before running Composer commands on them, specifically checking that Perforce-related fields contain valid values. Workaround: To mitigate this issue, only run Composer commands on projects and dependencies from trusted sources. Also, use the '--prefer-dist' or the 'preferred-install: dist' configuration setting to prevent Composer from installing dependencies from source.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:8165
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-40261
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-40176
- externalhttps://access.redhat.com/security/cve/CVE-2025-67746
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_8165.json