RHSA-2026:0629HighCVSS 8.1
Red Hat Security Advisory: satellite/foreman-mcp-server-rhel9 container image available as a Technology Preview
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-62706 — authlib: Authlib : JWE zip=DEF decompression bomb enables DoS CVE-2025-66416 — mcp: DNS Rebinding Protection Disabled by Default in Model Context Protocol Python SDK
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:0629
- externalhttps://access.redhat.com/documentation/en-us/red_hat_satellite/6.18/html/updating_red_hat_satellite/index
- externalhttps://access.redhat.com/security/cve/CVE-2025-62706
- externalhttps://access.redhat.com/security/cve/CVE-2025-66416
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/software/containers/search
- externalhttps://docs.redhat.com/en/documentation/red_hat_satellite/6.18/html-single/managing_hosts/index#configuring-the-mcp-server-for-Satellite
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_0629.json