RHSA-2026:5459HighCVSS 7.5

Red Hat Security Advisory: RHTAS 1.3.3 - Red Hat Trusted Artifact Signer Release

Published
March 23, 2026
Last Modified
June 2, 2026

🔗 CVE IDs covered (5)

CVE-2026-21441CVE-2026-31812CVE-2025-66471CVE-2026-3336 · pendingCVE-2026-3338 · pending

📋 Description

CVE-2025-66471 — urllib3: urllib3 Streaming API improperly handles highly compressed data CVE-2026-3336 — aws-lc: aws-lc: Certificate validation bypass via improper handling of PKCS7 objects CVE-2026-3338 — aws-lc: AWS-LC: Signature bypass due to improper validation in PKCS7_verify() CVE-2026-21441 — urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) CVE-2026-31812 — quinn-proto: quinn-proto: Denial of Service via crafted QUIC Initial packet

🔗 References (10)