Red Hat Security Advisory: RHACS 4.8.10 security and bug fix update
🔗 CVE IDs covered (12)
📋 Description
CVE-2026-25128 — fast-xml-parser: fast-xml-parser has RangeError DoS Numeric Entities Bug CVE-2026-25535 — jsPDF: denial of service via malicious GIF dimensions CVE-2026-25755 — jsPDF: PDF object injection via unsanitized input in addJS method CVE-2026-25896 — fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling CVE-2026-25940 — jsPDF: PDF injection in AcroForm module allows arbitrary JavaScript execution (RadioButton children) CVE-2026-26278 — fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion CVE-2026-27942 — fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service CVE-2026-29074 — svgo: SVGO: Denial of Service via XML entity expansion CVE-2026-31898 — jspdf: jsPDF: Arbitrary code execution via unsanitized input in createAnnotation method CVE-2026-31938 — jspdf: jsPDF: Cross site scripting via unsanitized output options CVE-2026-33036 — fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2026:7110
- externalhttps://access.redhat.com/security/cve/CVE-2026-25128
- externalhttps://access.redhat.com/security/cve/CVE-2026-25535
- externalhttps://access.redhat.com/security/cve/CVE-2026-25755
- externalhttps://access.redhat.com/security/cve/CVE-2026-25896
- externalhttps://access.redhat.com/security/cve/CVE-2026-25940
- externalhttps://access.redhat.com/security/cve/CVE-2026-26278
- externalhttps://access.redhat.com/security/cve/CVE-2026-27942
- externalhttps://access.redhat.com/security/cve/CVE-2026-29074
- externalhttps://access.redhat.com/security/cve/CVE-2026-31898
- externalhttps://access.redhat.com/security/cve/CVE-2026-31938
- externalhttps://access.redhat.com/security/cve/CVE-2026-33036
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_advanced_cluster_security_for_kubernetes/4.8/html-single/release_notes/index#about-this-release-4810_release-notes-48
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_7110.json