Red Hat Security Advisory: Red Hat Edge Manager Version 1.1.4 Security Update
🔗 CVE IDs covered (23)
📋 Description
CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-33810 — crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42306 — github.com/docker/docker: github.com/moby/moby: Moby container framework: Host file overwrite via race condition in docker cp mount setup CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-48050 — net/http/pprof: github.com/basekick-labs/arc: Arc: Information disclosure and Denial of Service via unauthenticated debug endpoints CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL CVE-2026-71556 — github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution CVE-2026-81521 — go.mongodb.org/mongo-driver: MongoDB Go Driver: Write redirection via unvalidated database name in Client.BulkWrite
🎯 Affected products38
- RHEM 1.1 for RHEL 10
- RHEM 1.1 for RHEL 9
- flightctl-0:1.1.4-1.el10em.src as a component of RHEM 1.1 for RHEL 10
- flightctl-0:1.1.4-1.el9em.src as a component of RHEM 1.1 for RHEL 9
- flightctl-agent-0:1.1.4-1.el10em.aarch64 as a component of RHEM 1.1 for RHEL 10
- flightctl-agent-0:1.1.4-1.el10em.ppc64le as a component of RHEM 1.1 for RHEL 10
- flightctl-agent-0:1.1.4-1.el10em.s390x as a component of RHEM 1.1 for RHEL 10
- flightctl-agent-0:1.1.4-1.el10em.x86_64 as a component of RHEM 1.1 for RHEL 10
- flightctl-agent-0:1.1.4-1.el9em.aarch64 as a component of RHEM 1.1 for RHEL 9
- flightctl-agent-0:1.1.4-1.el9em.ppc64le as a component of RHEM 1.1 for RHEL 9
- flightctl-agent-0:1.1.4-1.el9em.s390x as a component of RHEM 1.1 for RHEL 9
- flightctl-agent-0:1.1.4-1.el9em.x86_64 as a component of RHEM 1.1 for RHEL 9
- flightctl-cli-0:1.1.4-1.el10em.aarch64 as a component of RHEM 1.1 for RHEL 10
- flightctl-cli-0:1.1.4-1.el10em.ppc64le as a component of RHEM 1.1 for RHEL 10
- flightctl-cli-0:1.1.4-1.el10em.s390x as a component of RHEM 1.1 for RHEL 10
- flightctl-cli-0:1.1.4-1.el10em.x86_64 as a component of RHEM 1.1 for RHEL 10
- flightctl-cli-0:1.1.4-1.el9em.aarch64 as a component of RHEM 1.1 for RHEL 9
- flightctl-cli-0:1.1.4-1.el9em.ppc64le as a component of RHEM 1.1 for RHEL 9
- flightctl-cli-0:1.1.4-1.el9em.s390x as a component of RHEM 1.1 for RHEL 9
- flightctl-cli-0:1.1.4-1.el9em.x86_64 as a component of RHEM 1.1 for RHEL 9
- flightctl-observability-0:1.1.4-1.el10em.aarch64 as a component of RHEM 1.1 for RHEL 10
- flightctl-observability-0:1.1.4-1.el10em.ppc64le as a component of RHEM 1.1 for RHEL 10
- flightctl-observability-0:1.1.4-1.el10em.s390x as a component of RHEM 1.1 for RHEL 10
- flightctl-observability-0:1.1.4-1.el10em.x86_64 as a component of RHEM 1.1 for RHEL 10
- flightctl-observability-0:1.1.4-1.el9em.aarch64 as a component of RHEM 1.1 for RHEL 9
- flightctl-observability-0:1.1.4-1.el9em.ppc64le as a component of RHEM 1.1 for RHEL 9
- flightctl-observability-0:1.1.4-1.el9em.s390x as a component of RHEM 1.1 for RHEL 9
- flightctl-observability-0:1.1.4-1.el9em.x86_64 as a component of RHEM 1.1 for RHEL 9
- flightctl-selinux-0:1.1.4-1.el10em.noarch as a component of RHEM 1.1 for RHEL 10
- flightctl-selinux-0:1.1.4-1.el9em.noarch as a component of RHEM 1.1 for RHEL 9
- +8 more not shown
✅ Remediation
See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: No mitigation is required. Red Hat products do not ship or include the affected Arc component (github.com/basekick-labs/arc), so they are not exposed to this vulnerability. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely. Workaround: To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later).
🔗 References (24)
- selfhttps://access.redhat.com/errata/RHSA-2026:68334
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2456335
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2467809
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2467820
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2480675
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2480678
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2480757
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2480761
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2483894
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2484204
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2484207
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2484830
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488484
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2504233
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510719
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2512562
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515815
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515820
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515827
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515838
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515839
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515840
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_68334.json