RHSA-2026:34975HighCVSS 8.1

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
July 2, 2026
Last Modified
July 21, 2026

🔗 CVE IDs covered (23)

📋 Description

CVE-2026-8286 — curl: curl: Insecure connection establishment due to TLS configuration mismatch CVE-2026-8924 — curl: curl: Cookie injection via malicious HTTP server using super cookies CVE-2026-8925 — curl: curl: Double-free vulnerability in SASL authentication CVE-2026-8926 — curl: curl: Information disclosure via incorrect .netrc password lookup CVE-2026-8927 — libcurl: libcurl: Information disclosure due to uncleared proxy authentication state CVE-2026-8932 — libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse CVE-2026-9079 — libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials CVE-2026-9080 — libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback CVE-2026-9546 — libcurl: libcurl: Information disclosure due to persistent Referer header CVE-2026-9547 — curl: curl: Man-in-the-middle attack via SSH host key bypass CVE-2026-11352 — curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability CVE-2026-11564 — libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse CVE-2026-11586 — curl: curl: Denial of Service via WebSocket PING flood CVE-2026-11856 — curl: curl: Information disclosure via incorrect Digest authentication header reuse CVE-2026-12064 — curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP CVE-2026-14683 — HdrHistogram: HdrHistogram: Denial of Service via uncontrolled memory allocation CVE-2026-14684 — org.hdrhistogram/HdrHistogram: HdrHistogram: HdrHistogram: Denial of Service via uncontrolled memory allocation in decodeFromByteBuffer CVE-2026-14685 — HdrHistogram: HdrHistogram: Local state issue via 'Count' argument manipulation CVE-2026-14686 — HdrHistogram: HdrHistogram: Data integrity impact due to incorrect comparison CVE-2026-15187 — enquirer: Enquirer: Prototype pollution vulnerability allows remote attackers to modify object attributes CVE-2026-38969 — webrick: rubygem-webrick: WEBrick: Request smuggling via re-parsing of Content-Length header CVE-2026-59868 — js-yaml: js-yaml: Denial of Service via quadratic CPU time parsing with merge keys CVE-2026-59870 — js-yaml: js-yaml: Denial of Service via crafted YAML ordered-map document

🔗 References (28)