See how red hat compares to other vendors in security performance
Low: libarchive security update
Low: mingw-openssl security update
Low: httpd security update
A flaw was found in automation-controller. RunAdHocCommand.buildargs() appends the limit field as a bare positional argument instead of using the -l flag prefix as RunJob does. An attacker can set the limit field to a value beginning with a dash, which is then parsed as an ansible CLI option. The impact is currently limited to short-circuit flags such as --version and --help because the injected element displaces the required pattern positional argument.
A flaw was found in automation-controller. RunAdHocCommand.buildargs() appends the limit field as a bare positional argument instead of using the -l flag prefix as RunJob does. An attacker can set the limit field to a value beginning with a dash, which is then parsed as an ansible CLI option. The impact is currently limited to short-circuit flags such as --version and --help because the injected element displaces the required pattern positional argument.
A flaw was found in automation-controller. The LaunchConfigurationBaseSerializer used by Schedule and WorkflowJobTemplateNode does not implement ▎ validatescmbranch() to reject leading-dash values, unlike the Project, JobTemplate, and JobLaunch serializers. An attacker can set scmbranch to a value such as --upload-pack=/bin/id via the schedule or workflow node API. The injection is currently blocked by a runtime ValueError check in the task layer, but the API validation gap creates a latent risk if that defense-in-depth guard is ever refactored away.
A flaw was found in automation-controller. The LaunchConfigurationBaseSerializer used by Schedule and WorkflowJobTemplateNode does not implement ▎ validatescmbranch() to reject leading-dash values, unlike the Project, JobTemplate, and JobLaunch serializers. An attacker can set scmbranch to a value such as --upload-pack=/bin/id via the schedule or workflow node API. The injection is currently blocked by a runtime ValueError check in the task layer, but the API validation gap creates a latent risk if that defense-in-depth guard is ever refactored away.
A flaw was found in automation-controller. The notification template Jinja whitelist only inspects static Getattr AST nodes. An attacker with notification template admin privileges can bypass the whitelist using dynamic subscript expressions or conditional gating on runtime values that differ from the test-render stub. Exceptions raised during notification rendering write full Python tracebacks into the notification body, which is sent to the attacker-controlled webhook URL, leaking install paths, Python version, and source file line numbers.
A flaw was found in automation-controller. The notification template Jinja whitelist only inspects static Getattr AST nodes. An attacker with notification template admin privileges can bypass the whitelist using dynamic subscript expressions or conditional gating on runtime values that differ from the test-render stub. Exceptions raised during notification rendering write full Python tracebacks into the notification body, which is sent to the attacker-controlled webhook URL, leaking install paths, Python version, and source file line numbers.
Low: php8.4 security, bug fix, and enhancement update
An incomplete fix for CVE-2026-9689 was identified in Keycloak's RedirectUtils.containsForbiddenOidcParameters() method. While the original fix successfully blocks forbidden OIDC parameters (such as code, state, and iss) in the URI query string, it fails to inspect the URI fragment (#). When a client is configured with a wildcard redirect URI, an attacker can supply a redirecturi containing these forbidden parameters within the fragment. Because matchesRedirects strips fragments during prefix matching, the crafted URI is accepted. During the authorization response, Keycloak appends its own parameters to the attacker-supplied fragment, leading to a polluted response where attacker-controlled values appear first. Exploitation Conditions: The target client must have a wildcard-registered redirect URI (e.g., https://app.example.com/).
The attacker must induce a victim to follow a crafted authorization URL.
The relying party (client application) must use a first-wins parsing strategy for duplicate parameters.
Concrete Impact: Injection of attacker-controlled iss (issuer), state, and accesstoken parameters.
Potential for session fixation or account confusion if the relying party does not validate parameters per RFC 9207.
Low: php:8.2 security, bug fix, and enhancement update
Low: php:7.4 security, bug fix, and enhancement update
Low: php:8.3 security, bug fix, and enhancement update
A flaw was found in pki-core. In the Dogtag/pki-core Certificate Authority (CA) profile framework, the certificate enrollment path (EnrollmentProcessor) calls AuthzSubsystem.checkRealm() to verify that the calling principal is authorized to act within the request's configured realm before the request is submitted. The certificate renewal path (RenewalProcessor), which is reachable from the same public REST endpoint (caProfileSubmit, and the legacy v1/CertRequestDAO and ProfileSubmitServlet entry points) and is selected purely by a client-controlled 'isRenewal' flag in the posted request body, runs the same populate-then-submit sequence and stamps the same realm onto the request via the shared AuthzRealmDefault policy default, but never calls checkRealm. As a result, a caller who is only entitled in realm A can submit a renewal naming the serial number of a certificate originally issued under realm B; the renewal request is repopulated with realm B and submitted to realm B's request queue without realm B's authorization manager ever being consulted. This was dynamically reproduced end-to-end in an isolated sandbox: an identity with zero entitlement to a configured realm, freshly confirmed denied on the equivalent enrollment call, successfully renewed another user's certificate in that realm via a single authenticated request, with checkRealm never invoked. Direct testing established the practical impact is narrower than a realm-authorization bypass might suggest: the resulting certificate's content is already retrievable by any unauthenticated caller via the product's own intended read API, confirmed both same-host and across a genuine cross-container network boundary (no net-new confidentiality exposure); no private key material is ever exposed (no impersonation path); and the victim's own certificate and their own ability to renew it are both completely unaffected (no denial-of-service capability via revocation, side-effects, or resource exhaustion -- all tested directly). Attack Complexity is assessed High because exploitability additionally requires a non-default, supported deployment configuration (a realm-mapped authorization manager, the multi-realm/delegated-CA deployment mode), per Red Hat's documented CVSS scoring practice for configuration-dependent flaws. This affects the Dogtag PKI CA codebase across all current Red Hat package names for it: pki-core (RHEL 6-9, Certificate System 9), dogtag-pki (RHEL 10, RHIVOS 2, Fedora), and redhat-pki (Certificate System 10/11) -- the same missing checkRealm call was independently confirmed present in EnrollmentProcessor and absent from RenewalProcessor at the exact upstream versions shipped as dogtag-pki 11.9.0 and redhat-pki 11.10.0, not merely inferred from shared upstream provenance. Git history analysis shows the gap was introduced by omission in commit e2de26769761af04b9c56071bd1a1926903c49b6 (2016-05-09), which added the realm check only to EnrollmentProcessor roughly 63 hours after a separate commit had modified both EnrollmentProcessor and RenewalProcessor symmetrically at the same code location -- indicating an oversight rather than an intentional design decision.
Low: php:8.2 security, bug fix, and enhancement update
Capstone is a disassembly framework with the target of becoming the ultimate disasm engine for binary analysis and reversing in the security community.Security Fix(es): capstone: Capstone: Memory corruption via unchecked vsnprintf return (CVE-2025-68114) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Low: libxml2 security update
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function pbkdf2sha256pwcmp() in ldap/servers/plugins/pwdstorage/pbkdf2pwd.c uses standard memcmp() for hash comparison instead of the project's constant-time slapictmemcmp(). Every other password storage scheme in the same plugin uses slapictmemcmp(), which was introduced specifically to prevent timing side-channels (see CVE-2016-5405). This inconsistency allows a remote attacker with network access to the LDAP service to potentially infer partial hash information through repeated timing measurements of LDAP bind attempts. Practical exploitation is extremely difficult due to the PBKDF2 work factor (8192+ iterations, ~2ms computation time) which dominates and masks the nanosecond-level memcmp timing delta.
A library that provides Abstract Syntax Notation One (ASN.1, as specified by the X.680 ITU-T recommendation) parsing and structures management, and Distinguished Encoding Rules (DER, as per X.690) encoding and decoding functions.Security Fix(es): libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1expendoctetstring (CVE-2025-13151) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Low: libxml2 security update
Low: libxml2 security update
Low: libxml2 security update
Low: libxml2 security update
Low: libxml2 security update
Low: libxml2 security update
Low: libxml2 security update
A heap out-of-bounds read exists in str2entrystateinformationfromtype() (entry.c) in the 389 Directory Server LDIF parser. When importing LDIF with attribute types containing trailing semicolons, the code accesses p[3] through p[6] after finding a semicolon via PLstrchr without verifying sufficient bytes remain in the allocation.
Requires local administrator access via ldif2db import. ASan-proven on instrumented builds; production binaries do not crash due to allocator padding. Present unchanged across all shipped 389-ds-base versions.