RHSA-2026:19410HighCVSS 9.1

Red Hat Security Advisory: MTV RHEL9 Images

Published
May 19, 2026
Last Modified
May 27, 2026

🔗 CVE IDs covered (8)

CVE-2026-4598 · pendingCVE-2026-4599 · pendingCVE-2026-4600CVE-2026-4601CVE-2026-4602 · pendingCVE-2026-4800CVE-2026-4926CVE-2026-29063

📋 Description

CVE-2026-4598 — jsrsasign: jsrsasign: Denial of Service via infinite loop in bnModInverse function with crafted inputs CVE-2026-4599 — jsrsasign: jsrsasign: Private key recovery via incomplete comparison checks biasing DSA nonces CVE-2026-4600 — jsrsasign: jsrsasign: Cryptographic signature forgery via malicious DSA domain parameters CVE-2026-4601 — jsrsasign: jsrsasign: Private Key Recovery via Missing Cryptographic Step in DSA Signing CVE-2026-4602 — jsrsasign: jsrsasign: Signature verification bypass via negative exponent handling CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-4926 — path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution

🔗 References (12)