RHSA-2026:7655HighCVSS 7.5
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-2950 — lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass
CVE-2026-45149 — brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges
CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray
CVE-2026-59868 — js-yaml: js-yaml: Denial of Service via quadratic CPU time parsing with merge keys
CVE-2026-59870 — js-yaml: js-yaml: Denial of Service via crafted YAML ordered-map document
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:7655
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-2950
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-45149
- externalhttps://access.redhat.com/security/cve/CVE-2026-45736
- externalhttps://access.redhat.com/security/cve/CVE-2026-59870
- externalhttps://access.redhat.com/security/cve/CVE-2026-59868
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_7655.json