RHSA-2026:59326: Important: webkit2gtk3 security update
Important: webkit2gtk3 security update
Other sources
WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.Security Fix(es): Mozilla: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-39872) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43663) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43676) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43699) webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43701) webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43705) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43707) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43712) webkitgtk: webkitgtk: Visiting a website may leak sensitive data (CVE-2026-43713) webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43715) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43716) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43720) webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data (CVE-2026-43721) webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43725) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43726) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43727) webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43731) webkitgtk: webkitgtk: Maliciously crafted web content may disclose sensitive user information (CVE-2026-43732) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43734) webkitgtk: webkitgtk: Maliciously crafted web content may disclose process memory (CVE-2026-43740) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43742) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43745) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/webkit2gtk3to a version that resolves this vulnerability.Fixed in 2.52.5-1.el8_8 - Upgrade
Upgrade
redhat/webkit2gtk3-debuginfoto a version that resolves this vulnerability.Fixed in 2.52.5-1.el8_8 - Upgrade
Upgrade
redhat/webkit2gtk3-debugsourceto a version that resolves this vulnerability.Fixed in 2.52.5-1.el8_8 - Upgrade
Upgrade
redhat/webkit2gtk3-develto a version that resolves this vulnerability.Fixed in 2.52.5-1.el8_8 - Upgrade
Upgrade
redhat/webkit2gtk3-devel-debuginfoto a version that resolves this vulnerability.Fixed in 2.52.5-1.el8_8 - Upgrade
Upgrade
redhat/webkit2gtk3-jscto a version that resolves this vulnerability.Fixed in 2.52.5-1.el8_8 - Upgrade
Upgrade
redhat/webkit2gtk3-jsc-debuginfoto a version that resolves this vulnerability.Fixed in 2.52.5-1.el8_8 - Upgrade
Upgrade
redhat/webkit2gtk3-jsc-develto a version that resolves this vulnerability.Fixed in 2.52.5-1.el8_8 - Upgrade
Upgrade
redhat/webkit2gtk3-jsc-devel-debuginfoto a version that resolves this vulnerability.Fixed in 2.52.5-1.el8_8
Event History
Frequently Asked Questions
Which environments are covered by this advisory?
The advisory applies to the listed Red Hat Enterprise Linux Server for Power LE and x86_64 offerings, including Update Services for SAP Solutions, TUS, and x86_64 Extended Life Cycle Long Life subscriptions.
How severe is this update?
This is rated Important by Red Hat and has a reported severity of high (7), with a risk value of 33.
When was the advisory issued?
RHSA-2026:59326 was published and last modified on 2026-08-25.