RHSA-2026:35272HighCVSS 7.5

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
July 3, 2026
Last Modified
July 22, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity CVE-2026-48619 — nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames CVE-2026-48928 — Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency CVE-2026-48930 — nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling CVE-2026-48934 — nodejs: Node.js: Certification validation bypass in TLS host verification CVE-2026-48935 — nodejs: Node.js: Unauthorized file metadata modification CVE-2026-48936 — nodejs: Node.js: Local server can be started without network permission via Permission API flaw CVE-2026-59868 — js-yaml: js-yaml: Denial of Service via quadratic CPU time parsing with merge keys CVE-2026-59870 — js-yaml: js-yaml: Denial of Service via crafted YAML ordered-map document

🔗 References (13)