RHSA-2026:57541: Important: osbuild-composer security update
A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.Security Fix(es): golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: osbuild-composer security update
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/osbuild-composerto a version that resolves this vulnerability.Fixed in 132.2-10.el9_6 - Upgrade
Upgrade
redhat/osbuild-composer-coreto a version that resolves this vulnerability.Fixed in 132.2-10.el9_6 - Upgrade
Upgrade
redhat/osbuild-composer-core-debuginfoto a version that resolves this vulnerability.Fixed in 132.2-10.el9_6 - Upgrade
Upgrade
redhat/osbuild-composer-debuginfoto a version that resolves this vulnerability.Fixed in 132.2-10.el9_6 - Upgrade
Upgrade
redhat/osbuild-composer-debugsourceto a version that resolves this vulnerability.Fixed in 132.2-10.el9_6 - Upgrade
Upgrade
redhat/osbuild-composer-tests-debuginfoto a version that resolves this vulnerability.Fixed in 132.2-10.el9_6 - Upgrade
Upgrade
redhat/osbuild-composer-workerto a version that resolves this vulnerability.Fixed in 132.2-10.el9_6 - Upgrade
Upgrade
redhat/osbuild-composer-worker-debuginfoto a version that resolves this vulnerability.Fixed in 132.2-10.el9_6 - Upgrade
Upgrade
redhat/osbuild-composerto a version that resolves this vulnerability.Fixed in 132.2-10.el9_6.aa - Upgrade
Upgrade
redhat/osbuild-composer-coreto a version that resolves this vulnerability.Fixed in 132.2-10.el9_6.aa - Upgrade
Upgrade
redhat/osbuild-composer-core-debuginfoto a version that resolves this vulnerability.Fixed in 132.2-10.el9_6.aa - Upgrade
Upgrade
redhat/osbuild-composer-debuginfoto a version that resolves this vulnerability.Fixed in 132.2-10.el9_6.aa - Upgrade
Upgrade
redhat/osbuild-composer-debugsourceto a version that resolves this vulnerability.Fixed in 132.2-10.el9_6.aa - Upgrade
Upgrade
redhat/osbuild-composer-tests-debuginfoto a version that resolves this vulnerability.Fixed in 132.2-10.el9_6.aa - Upgrade
Upgrade
redhat/osbuild-composer-workerto a version that resolves this vulnerability.Fixed in 132.2-10.el9_6.aa - Upgrade
Upgrade
redhat/osbuild-composer-worker-debuginfoto a version that resolves this vulnerability.Fixed in 132.2-10.el9_6.aa - Upgrade
Upgrade
osbuild-composerto a version that resolves this vulnerability.Patch osbuild-composer security update - Upgrade
Upgrade
golang.org/x/net/idnato a version that resolves this vulnerability.Patch CVE-2026-39821
Event History
Frequently Asked Questions
Which components are covered by this update?
The update covers osbuild-composer and osbuild-composer-core, along with the osbuild-composer-worker package and the listed debuginfo, debugsource, and test debuginfo packages.
What security issues are addressed?
The update addresses CVE-2026-39821, a privilege-escalation issue in golang.org/x/net/idna related to incorrect Punycode label processing, and CVE-2026-55677, an unauthorized information-disclosure issue in github.com/labstack/echo caused by URL path decoding discrepancies.