Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (9)
📋 Description
CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity CVE-2026-48619 — nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames CVE-2026-48928 — Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency CVE-2026-48930 — nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling CVE-2026-48934 — nodejs: Node.js: Certification validation bypass in TLS host verification CVE-2026-48935 — nodejs: Node.js: Unauthorized file metadata modification CVE-2026-48936 — nodejs: Node.js: Local server can be started without network permission via Permission API flaw CVE-2026-59868 — js-yaml: js-yaml: Denial of Service via quadratic CPU time parsing with merge keys CVE-2026-59870 — js-yaml: js-yaml: Denial of Service via crafted YAML ordered-map document
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2026:35272
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-13149
- externalhttps://access.redhat.com/security/cve/CVE-2026-48936
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-48934
- externalhttps://access.redhat.com/security/cve/CVE-2026-48928
- externalhttps://access.redhat.com/security/cve/CVE-2026-48930
- externalhttps://access.redhat.com/security/cve/CVE-2026-48619
- externalhttps://access.redhat.com/security/cve/CVE-2026-48935
- externalhttps://access.redhat.com/security/cve/CVE-2026-59870
- externalhttps://access.redhat.com/security/cve/CVE-2026-59868
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_35272.json