RHSA-2026:52389: Important: osbuild-composer security update
A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.Security Fix(es): net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: osbuild-composer security update
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/osbuild-composerto a version that resolves this vulnerability.Fixed in 75-9.el8_8 - Upgrade
Upgrade
redhat/osbuild-composer-coreto a version that resolves this vulnerability.Fixed in 75-9.el8_8 - Upgrade
Upgrade
redhat/osbuild-composer-core-debuginfoto a version that resolves this vulnerability.Fixed in 75-9.el8_8 - Upgrade
Upgrade
redhat/osbuild-composer-debuginfoto a version that resolves this vulnerability.Fixed in 75-9.el8_8 - Upgrade
Upgrade
redhat/osbuild-composer-debugsourceto a version that resolves this vulnerability.Fixed in 75-9.el8_8 - Upgrade
Upgrade
redhat/osbuild-composer-dnf-jsonto a version that resolves this vulnerability.Fixed in 75-9.el8_8 - Upgrade
Upgrade
redhat/osbuild-composer-tests-debuginfoto a version that resolves this vulnerability.Fixed in 75-9.el8_8 - Upgrade
Upgrade
redhat/osbuild-composer-workerto a version that resolves this vulnerability.Fixed in 75-9.el8_8 - Upgrade
Upgrade
redhat/osbuild-composer-worker-debuginfoto a version that resolves this vulnerability.Fixed in 75-9.el8_8
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:52389?
The severity of RHSA-2026:52389 is classified as high with a score of 7.
How do I fix RHSA-2026:52389?
To fix RHSA-2026:52389, apply the latest security update for osbuild-composer and its related packages.
What impact does RHSA-2026:52389 have on osbuild-composer?
RHSA-2026:52389 addresses critical security vulnerabilities that could affect the integrity and security of images built by osbuild-composer.
Which products are affected by RHSA-2026:52389?
The impacted products include redhat/osbuild-composer and related components such as redhat/osbuild-composer-core and redhat/osbuild-composer-worker.
When was RHSA-2026:52389 published?
RHSA-2026:52389 was published on August 10, 2026.