RHSA-2026:22993HighCVSS 8.1
Red Hat Security Advisory: satellite/foreman-mcp-server-rhel9 container image available as a Technology Preview
🔗 CVE IDs covered (4)
📋 Description
CVE-2025-62727 — starlette: Starlette DoS via Range header merging CVE-2026-26007 — cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves CVE-2026-34444 — lupa: Lupa: Arbitrary Code Execution due to inconsistent attribute filtering CVE-2026-48710 — starlette: Starlette: Security restriction bypass via malformed HTTP Host header
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:22993
- externalhttps://access.redhat.com/security/cve/CVE-2026-34444
- externalhttps://access.redhat.com/security/cve/CVE-2026-48710
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/software/containers/search
- externalhttps://access.redhat.com/documentation/en-us/red_hat_satellite/6.18/html/updating_red_hat_satellite/index
- externalhttps://access.redhat.com/security/cve/CVE-2026-26007
- externalhttps://access.redhat.com/security/cve/CVE-2025-62727
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_22993.json