RHSA-2026:63357HighCVSS 8.6

Red Hat Security Advisory: General availability of the satellite/iop-remediations-rhel9 container image

Published
September 3, 2026
Last Modified
September 6, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass

🎯 Affected products2

  • Red Hat Satellite 6.19
  • registry.redhat.io/satellite/iop-remediations-rhel9@sha256:397fe24981500494a9943782224e84c7ddb9d353a1021d8f0f7a1b9c3305dcbd_amd64 as a component of Red Hat Satellite 6.19

✅ Remediation

For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (10)