Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
RHSA-2026:63385
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2026:63385
Import Source
https://security.access.redhat.com/data/osv/RHSA-2026:63385.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2026:63385
Upstream
CVE-2026-10051
CVE-2026-11332
CVE-2026-16493
CVE-2026-34993
CVE-2026-42215
CVE-2026-42284
CVE-2026-44244
CVE-2026-45363
CVE-2026-54512
CVE-2026-68494
CVE-2026-69243
CVE-2026-69244
CVE-2026-73620
CVE-2026-73622
CVE-2026-73623
CVE-2026-73624
CVE-2026-73625
CVE-2026-76218
CVE-2026-76219
CVE-2026-76220
CVE-2026-76221
CVE-2026-76222
Published
2026-09-04T10:14:03Z
Modified
2026-09-04T10:15:26.284216115Z
Severity
8.8 (High)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Calculator
Summary
Red Hat Security Advisory: Satellite 6.19.4 Async Update
Details
References
https://access.redhat.com/errata/RHSA-2026:63385
https://access.redhat.com/security/updates/classification/#important
https://issues.redhat.com/browse/SAT-45592
https://issues.redhat.com/browse/SAT-46105
https://issues.redhat.com/browse/SAT-48574
https://issues.redhat.com/browse/SAT-48584
https://issues.redhat.com/browse/SAT-48585
https://issues.redhat.com/browse/SAT-48586
https://issues.redhat.com/browse/SAT-48587
https://issues.redhat.com/browse/SAT-48588
https://issues.redhat.com/browse/SAT-48589
https://issues.redhat.com/browse/SAT-48628
https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_63385.json
https://access.redhat.com/security/cve/CVE-2026-10051
https://bugzilla.redhat.com/show_bug.cgi?id=2499928
https://www.cve.org/CVERecord?id=CVE-2026-10051
https://nvd.nist.gov/vuln/detail/CVE-2026-10051
https://gitlab.eclipse.org/security/cve-assignment/-/work_items/119
https://access.redhat.com/security/cve/CVE-2026-11332
https://bugzilla.redhat.com/show_bug.cgi?id=2485379
https://www.cve.org/CVERecord?id=CVE-2026-11332
https://nvd.nist.gov/vuln/detail/CVE-2026-11332
https://github.com/ansible/ansible
https://access.redhat.com/security/cve/CVE-2026-16493
https://bugzilla.redhat.com/show_bug.cgi?id=2503724
https://www.cve.org/CVERecord?id=CVE-2026-16493
https://nvd.nist.gov/vuln/detail/CVE-2026-16493
https://access.redhat.com/security/cve/CVE-2026-34993
https://bugzilla.redhat.com/show_bug.cgi?id=2484099
https://www.cve.org/CVERecord?id=CVE-2026-34993
https://nvd.nist.gov/vuln/detail/CVE-2026-34993
https://github.com/aio-libs/aiohttp/commit/dcf40f30637e8752c76781cf6703b5a236749a00
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jg22-mg44-37j8
https://access.redhat.com/security/cve/CVE-2026-42215
https://bugzilla.redhat.com/show_bug.cgi?id=2467802
https://www.cve.org/CVERecord?id=CVE-2026-42215
https://nvd.nist.gov/vuln/detail/CVE-2026-42215
https://github.com/gitpython-developers/GitPython/releases/tag/3.1.47
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rpm5-65cw-6hj4
https://access.redhat.com/security/cve/CVE-2026-42284
https://bugzilla.redhat.com/show_bug.cgi?id=2467800
https://www.cve.org/CVERecord?id=CVE-2026-42284
https://nvd.nist.gov/vuln/detail/CVE-2026-42284
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-x2qx-6953-8485
https://access.redhat.com/security/cve/CVE-2026-44244
https://bugzilla.redhat.com/show_bug.cgi?id=2467804
https://www.cve.org/CVERecord?id=CVE-2026-44244
https://nvd.nist.gov/vuln/detail/CVE-2026-44244
https://github.com/gitpython-developers/GitPython/releases/tag/3.1.49
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-v87r-6q3f-2j67
https://access.redhat.com/security/cve/CVE-2026-45363
https://bugzilla.redhat.com/show_bug.cgi?id=2500739
https://www.cve.org/CVERecord?id=CVE-2026-45363
https://nvd.nist.gov/vuln/detail/CVE-2026-45363
https://github.com/jwt/ruby-jwt/commit/9820020869ad147b941e49d96ab8beba35532964
https://github.com/jwt/ruby-jwt/commit/db560b769a07bd9724e77ff505011ac01872106f
https://github.com/jwt/ruby-jwt/releases/tag/v2.10.3
https://github.com/jwt/ruby-jwt/releases/tag/v3.2.0
https://github.com/jwt/ruby-jwt/security/advisories/GHSA-c32j-vqhx-rx3x
https://access.redhat.com/security/cve/CVE-2026-54512
https://bugzilla.redhat.com/show_bug.cgi?id=2492015
https://www.cve.org/CVERecord?id=CVE-2026-54512
https://nvd.nist.gov/vuln/detail/CVE-2026-54512
https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5
https://github.com/FasterXML/jackson-databind/issues/5988
https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm
https://access.redhat.com/security/cve/CVE-2026-68494
https://bugzilla.redhat.com/show_bug.cgi?id=2511026
https://www.cve.org/CVERecord?id=CVE-2026-68494
https://nvd.nist.gov/vuln/detail/CVE-2026-68494
https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd
https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641
https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8
https://github.com/FasterXML/jackson-core/pull/1611
https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9
https://github.com/advisories/GHSA-72hv-8253-57qq
https://www.cve.org/CVERecord?id=CVE-2026-18401
https://access.redhat.com/security/cve/CVE-2026-69243
https://bugzilla.redhat.com/show_bug.cgi?id=2510831
https://www.cve.org/CVERecord?id=CVE-2026-69243
https://nvd.nist.gov/vuln/detail/CVE-2026-69243
https://github.com/aio-libs/aiohttp/commit/6ae358f0983c3f4d6f67692b2f8e65dc8e091c98
https://github.com/aio-libs/aiohttp/pull/13017
https://github.com/aio-libs/aiohttp/releases/tag/v3.14.2
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mfx4-hv73-q22v
https://access.redhat.com/security/cve/CVE-2026-69244
https://bugzilla.redhat.com/show_bug.cgi?id=2510825
https://www.cve.org/CVERecord?id=CVE-2026-69244
https://nvd.nist.gov/vuln/detail/CVE-2026-69244
https://github.com/aio-libs/aiohttp/commit/49f65d54150397892f7bcc4aae887767d51c322d
https://github.com/aio-libs/aiohttp/pull/13223
https://github.com/aio-libs/aiohttp/releases/tag/v3.14.3
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-cq5v-8q36-5273
https://access.redhat.com/security/cve/CVE-2026-73620
https://bugzilla.redhat.com/show_bug.cgi?id=2515261
https://www.cve.org/CVERecord?id=CVE-2026-73620
https://nvd.nist.gov/vuln/detail/CVE-2026-73620
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3f7w-8rr8-f37f
https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-overwrite-and-read
https://access.redhat.com/security/cve/CVE-2026-73622
https://bugzilla.redhat.com/show_bug.cgi?id=2515269
https://www.cve.org/CVERecord?id=CVE-2026-73622
https://nvd.nist.gov/vuln/detail/CVE-2026-73622
https://github.com/gitpython-developers/GitPython/commit/8ac5a30519b6f4af85398b9b9d7064ff4d452da2
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-94p4-4cq8-9g67
https://www.vulncheck.com/advisories/gitpython-before-environment-variable-exfiltration-via-remote-add
https://access.redhat.com/security/cve/CVE-2026-73623
https://bugzilla.redhat.com/show_bug.cgi?id=2515275
https://www.cve.org/CVERecord?id=CVE-2026-73623
https://nvd.nist.gov/vuln/detail/CVE-2026-73623
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-6p8h-3wgx-97gf
https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-template
https://access.redhat.com/security/cve/CVE-2026-73624
https://bugzilla.redhat.com/show_bug.cgi?id=2515243
https://www.cve.org/CVERecord?id=CVE-2026-73624
https://nvd.nist.gov/vuln/detail/CVE-2026-73624
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-fjr4-x663-mwxc
https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-overwrite-via-diff
https://access.redhat.com/security/cve/CVE-2026-73625
https://bugzilla.redhat.com/show_bug.cgi?id=2515272
https://www.cve.org/CVERecord?id=CVE-2026-73625
https://nvd.nist.gov/vuln/detail/CVE-2026-73625
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-r9mr-m37c-5fr3
https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-kwarg-value-smuggling
https://access.redhat.com/security/cve/CVE-2026-76218
https://bugzilla.redhat.com/show_bug.cgi?id=2519603
https://www.cve.org/CVERecord?id=CVE-2026-76218
https://nvd.nist.gov/vuln/detail/CVE-2026-76218
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-9rj7-rf2p-w77r
https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-repo-init
https://access.redhat.com/security/cve/CVE-2026-76219
https://bugzilla.redhat.com/show_bug.cgi?id=2519597
https://www.cve.org/CVERecord?id=CVE-2026-76219
https://nvd.nist.gov/vuln/detail/CVE-2026-76219
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-4gmw-gg2m-w46p
https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-overwrite-via-read-tree
https://access.redhat.com/security/cve/CVE-2026-76220
https://bugzilla.redhat.com/show_bug.cgi?id=2519610
https://www.cve.org/CVERecord?id=CVE-2026-76220
https://nvd.nist.gov/vuln/detail/CVE-2026-76220
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-wvpp-8hx9-p66j
https://www.vulncheck.com/advisories/gitpython-before-command-execution-via-split-single-char-options
https://access.redhat.com/security/cve/CVE-2026-76221
https://bugzilla.redhat.com/show_bug.cgi?id=2519596
https://www.cve.org/CVERecord?id=CVE-2026-76221
https://nvd.nist.gov/vuln/detail/CVE-2026-76221
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-jm78-9fvv-mhgr
https://www.vulncheck.com/advisories/gitpython-before-config-injection-via-option-name
https://access.redhat.com/security/cve/CVE-2026-76222
https://bugzilla.redhat.com/show_bug.cgi?id=2519609
https://www.cve.org/CVERecord?id=CVE-2026-76222
https://nvd.nist.gov/vuln/detail/CVE-2026-76222
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hmq2-w58f-27jc
https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-gitmodules-submodule-name
Affected packages
Red Hat:satellite:6.19::el9
openvox-server
Package
Name
openvox-server
Purl
pkg:rpm/redhat/openvox-server
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.15.2-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:63385.json"
ansible-core
Package
Name
ansible-core
Purl
pkg:rpm/redhat/ansible-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:2.16.19-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:63385.json"
ansible-test
Package
Name
ansible-test
Purl
pkg:rpm/redhat/ansible-test
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:2.16.19-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:63385.json"
python3.12-aiohttp
Package
Name
python3.12-aiohttp
Purl
pkg:rpm/redhat/python3.12-aiohttp
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.14.3-1.el9pc
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:63385.json"
python3.12-aiohttp-debuginfo
Package
Name
python3.12-aiohttp-debuginfo
Purl
pkg:rpm/redhat/python3.12-aiohttp-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.14.3-1.el9pc
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:63385.json"
python3.12-aiohttp-debugsource
Package
Name
python3.12-aiohttp-debugsource
Purl
pkg:rpm/redhat/python3.12-aiohttp-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.14.3-1.el9pc
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:63385.json"
python3.12-gitpython
Package
Name
python3.12-gitpython
Purl
pkg:rpm/redhat/python3.12-gitpython
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.1.59-1.el9pc
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:63385.json"
rubygem-jwt
Package
Name
rubygem-jwt
Purl
pkg:rpm/redhat/rubygem-jwt
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.10.3-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:63385.json"
Red Hat:satellite_capsule:6.19::el9
openvox-server
Package
Name
openvox-server
Purl
pkg:rpm/redhat/openvox-server
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.15.2-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:63385.json"
ansible-core
Package
Name
ansible-core
Purl
pkg:rpm/redhat/ansible-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:2.16.19-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:63385.json"
ansible-test
Package
Name
ansible-test
Purl
pkg:rpm/redhat/ansible-test
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:2.16.19-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:63385.json"
python3.12-aiohttp
Package
Name
python3.12-aiohttp
Purl
pkg:rpm/redhat/python3.12-aiohttp
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.14.3-1.el9pc
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:63385.json"
python3.12-aiohttp-debuginfo
Package
Name
python3.12-aiohttp-debuginfo
Purl
pkg:rpm/redhat/python3.12-aiohttp-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.14.3-1.el9pc
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:63385.json"
python3.12-aiohttp-debugsource
Package
Name
python3.12-aiohttp-debugsource
Purl
pkg:rpm/redhat/python3.12-aiohttp-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.14.3-1.el9pc
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:63385.json"
python3.12-gitpython
Package
Name
python3.12-gitpython
Purl
pkg:rpm/redhat/python3.12-gitpython
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.1.59-1.el9pc
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:63385.json"
rubygem-jwt
Package
Name
rubygem-jwt
Purl
pkg:rpm/redhat/rubygem-jwt
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.10.3-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:63385.json"
Red Hat:satellite_maintenance:6.19::el9
ansible-core
Package
Name
ansible-core
Purl
pkg:rpm/redhat/ansible-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:2.16.19-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:63385.json"
Red Hat:satellite_utils:6.19::el9
rubygem-jwt
Package
Name
rubygem-jwt
Purl
pkg:rpm/redhat/rubygem-jwt
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.10.3-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:63385.json"
RHSA-2026:63385 - OSV