RHSA-2026:8498HighCVSS 8.1

Red Hat Security Advisory: General availability of the satellite/iop-remediations-rhel9 container image

Published
April 16, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-30951 — sequelize: Sequelize: Data exfiltration via SQL injection in JSON/JSONB where clause processing

🎯 Affected products2

  • Red Hat Satellite 6.18
  • registry.redhat.io/satellite/iop-remediations-rhel9@sha256:94bfbcac75fca25a6babc06844a05703c5e745939c62288131f56e039877601c_amd64 as a component of Red Hat Satellite 6.18

✅ Remediation

For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (9)