RHSA-2026:37577HighCVSS 7.5

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

Published
July 10, 2026
Last Modified
July 17, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-39245 — decompress: decompress: path traversal via indexOf containment bypass allows arbitrary file write (bypass of CVE-2020-12265 fix) CVE-2026-59725 — socket.io: engine.io: Socket.IO: Denial of Service via invalid binary POST requests CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents

🔗 References (9)