RHSA-2026:2350HighCVSS 8.7

Red Hat Security Advisory: RHACS 4.9.3 security and bug fix update

Published
February 9, 2026
Last Modified
June 3, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2025-12816 — node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications CVE-2025-15284 — qs: qs: Denial of Service via improper input validation in array parsing CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2025-66031 — node-forge: node-forge ASN.1 Unbounded Recursion CVE-2025-66506 — github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token CVE-2025-66564 — github.com/sigstore/timestamp-authority: Sigstore Timestamp Authority: Denial of Service via excessive OID or Content-Type header parsing CVE-2025-68428 — jspdf: jsPDF Local File Inclusion/Path Traversal vulnerability CVE-2025-68973 — GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects

🔗 References (13)