RHSA-2026:2924HighCVSS 7.5

Red Hat Security Advisory: RHTAS 1.2.2 - Red Hat Trusted Artifact Signer Release

Published
February 18, 2026
Last Modified
June 3, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2025-66418 — urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion CVE-2025-66471 — urllib3: urllib3 Streaming API improperly handles highly compressed data CVE-2025-66506 — github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token CVE-2026-21441 — urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) CVE-2026-22772 — fulcio: Fulcio: Server-Side Request Forgery (SSRF) via unanchored regex in MetaIssuer URL validation

🔗 References (10)