RHSA-2026:8501CriticalCVSS 9.0

Red Hat Security Advisory: Technical preview of the satellite/iop-vulnerability-frontend-rhel9 container image

Published
April 16, 2026
Last Modified
June 2, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-21441 — urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation

🔗 References (10)