Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
RHSA-2026:74504
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2026:74504
Import Source
https://security.access.redhat.com/data/osv/RHSA-2026:74504.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2026:74504
Upstream
CVE (23)
CVE-2026-12405
CVE-2026-12423
CVE-2026-12540
CVE-2026-12541
CVE-2026-12542
CVE-2026-12544
CVE-2026-12545
CVE-2026-33154
CVE-2026-33818
CVE-2026-42504
CVE-2026-54284
CVE-2026-56097
CVE-2026-56098
CVE-2026-56858
CVE-2026-56860
CVE-2026-56862
CVE-2026-59893
CVE-2026-71491
CVE-2026-78679
CVE-2026-79654
CVE-2026-87817
CVE-2026-96658
CVE-2026-96659
Related
GO (5)
GO-2026-5038
GO-2026-5972
GO-2026-6090
GO-2026-6091
GO-2026-6218
Published
2026-10-02T10:25:58Z
Modified
2026-10-02T10:41:44Z
Severity
9.9 (Critical)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Calculator
Summary
Red Hat Security Advisory: Satellite 6.18.10 Async Update
Details
References
https://access.redhat.com/errata/RHSA-2026:74504
https://access.redhat.com/security/updates/classification/#critical
https://bugzilla.redhat.com/show_bug.cgi?id=2449774
https://bugzilla.redhat.com/show_bug.cgi?id=2484204
https://bugzilla.redhat.com/show_bug.cgi?id=2488952
https://bugzilla.redhat.com/show_bug.cgi?id=2488956
https://bugzilla.redhat.com/show_bug.cgi?id=2489969
https://bugzilla.redhat.com/show_bug.cgi?id=2489970
https://bugzilla.redhat.com/show_bug.cgi?id=2489971
https://bugzilla.redhat.com/show_bug.cgi?id=2489992
https://bugzilla.redhat.com/show_bug.cgi?id=2489993
https://bugzilla.redhat.com/show_bug.cgi?id=2490542
https://bugzilla.redhat.com/show_bug.cgi?id=2490543
https://bugzilla.redhat.com/show_bug.cgi?id=2515815
https://bugzilla.redhat.com/show_bug.cgi?id=2515820
https://bugzilla.redhat.com/show_bug.cgi?id=2515838
https://bugzilla.redhat.com/show_bug.cgi?id=2515839
https://bugzilla.redhat.com/show_bug.cgi?id=2517518
https://bugzilla.redhat.com/show_bug.cgi?id=2517523
https://bugzilla.redhat.com/show_bug.cgi?id=2517527
https://bugzilla.redhat.com/show_bug.cgi?id=2523205
https://bugzilla.redhat.com/show_bug.cgi?id=2523348
https://bugzilla.redhat.com/show_bug.cgi?id=2530744
https://bugzilla.redhat.com/show_bug.cgi?id=2534185
https://bugzilla.redhat.com/show_bug.cgi?id=2536844
https://issues.redhat.com/browse/SAT-50952
https://issues.redhat.com/browse/SAT-50953
https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74504.json
https://access.redhat.com/security/cve/CVE-2026-12405
https://www.cve.org/CVERecord?id=CVE-2026-12405
https://nvd.nist.gov/vuln/detail/CVE-2026-12405
https://access.redhat.com/security/cve/CVE-2026-12423
https://www.cve.org/CVERecord?id=CVE-2026-12423
https://nvd.nist.gov/vuln/detail/CVE-2026-12423
https://access.redhat.com/security/cve/CVE-2026-12540
https://www.cve.org/CVERecord?id=CVE-2026-12540
https://nvd.nist.gov/vuln/detail/CVE-2026-12540
https://access.redhat.com/security/cve/CVE-2026-12541
https://www.cve.org/CVERecord?id=CVE-2026-12541
https://nvd.nist.gov/vuln/detail/CVE-2026-12541
https://access.redhat.com/security/cve/CVE-2026-12542
https://www.cve.org/CVERecord?id=CVE-2026-12542
https://nvd.nist.gov/vuln/detail/CVE-2026-12542
https://access.redhat.com/security/cve/CVE-2026-12544
https://www.cve.org/CVERecord?id=CVE-2026-12544
https://nvd.nist.gov/vuln/detail/CVE-2026-12544
https://access.redhat.com/security/cve/CVE-2026-12545
https://www.cve.org/CVERecord?id=CVE-2026-12545
https://nvd.nist.gov/vuln/detail/CVE-2026-12545
https://access.redhat.com/security/cve/CVE-2026-33154
https://www.cve.org/CVERecord?id=CVE-2026-33154
https://nvd.nist.gov/vuln/detail/CVE-2026-33154
https://github.com/dynaconf/dynaconf/commit/2fbb45ee36b8c0caa5b924fe19f3c1a5e8603fa7
https://github.com/dynaconf/dynaconf/releases/tag/3.2.13
https://github.com/dynaconf/dynaconf/security/advisories/GHSA-pxrr-hq57-q35p
https://access.redhat.com/security/cve/CVE-2026-33818
https://www.cve.org/CVERecord?id=CVE-2026-33818
https://nvd.nist.gov/vuln/detail/CVE-2026-33818
https://go.dev/cl/814980
https://go.dev/issue/80405
https://groups.google.com/g/golang-announce/c/94pEornpRlI
https://pkg.go.dev/vuln/GO-2026-5972
https://access.redhat.com/security/cve/CVE-2026-42504
https://www.cve.org/CVERecord?id=CVE-2026-42504
https://nvd.nist.gov/vuln/detail/CVE-2026-42504
https://go.dev/cl/774481
https://go.dev/issue/79217
https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw
https://pkg.go.dev/vuln/GO-2026-5038
https://access.redhat.com/security/cve/CVE-2026-54284
https://www.cve.org/CVERecord?id=CVE-2026-54284
https://nvd.nist.gov/vuln/detail/CVE-2026-54284
https://github.com/andialbrecht/sqlparse/commit/939b129e24c0ad5d51368b1aa72fffcaca76f06f
https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-pwgv-4x5q-6m9f
https://access.redhat.com/security/cve/CVE-2026-56097
https://www.cve.org/CVERecord?id=CVE-2026-56097
https://nvd.nist.gov/vuln/detail/CVE-2026-56097
https://access.redhat.com/security/cve/CVE-2026-56098
https://www.cve.org/CVERecord?id=CVE-2026-56098
https://nvd.nist.gov/vuln/detail/CVE-2026-56098
https://access.redhat.com/security/cve/CVE-2026-56858
https://www.cve.org/CVERecord?id=CVE-2026-56858
https://nvd.nist.gov/vuln/detail/CVE-2026-56858
https://go.dev/cl/807100
https://go.dev/issue/80435
https://pkg.go.dev/vuln/GO-2026-6091
https://access.redhat.com/security/cve/CVE-2026-56860
https://www.cve.org/CVERecord?id=CVE-2026-56860
https://nvd.nist.gov/vuln/detail/CVE-2026-56860
https://go.dev/cl/803681
https://go.dev/issue/80494
https://pkg.go.dev/vuln/GO-2026-6218
https://access.redhat.com/security/cve/CVE-2026-56862
https://www.cve.org/CVERecord?id=CVE-2026-56862
https://nvd.nist.gov/vuln/detail/CVE-2026-56862
https://go.dev/cl/804261
https://go.dev/issue/80528
https://pkg.go.dev/vuln/GO-2026-6090
https://access.redhat.com/security/cve/CVE-2026-59893
https://www.cve.org/CVERecord?id=CVE-2026-59893
https://nvd.nist.gov/vuln/detail/CVE-2026-59893
https://github.com/andialbrecht/sqlparse/commit/d1d80602741f77ec78e5a04ce4719244cf32352e
https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-prg7-hcfm-mfcr
https://access.redhat.com/security/cve/CVE-2026-71491
https://www.cve.org/CVERecord?id=CVE-2026-71491
https://nvd.nist.gov/vuln/detail/CVE-2026-71491
https://github.com/andialbrecht/sqlparse/commit/ef2012a5eeb491e604dea2b00d516904a3830c87
https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-f2ff-p2ww-7p4p
https://access.redhat.com/security/cve/CVE-2026-78679
https://www.cve.org/CVERecord?id=CVE-2026-78679
https://nvd.nist.gov/vuln/detail/CVE-2026-78679
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg
https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-tagreference-create
https://access.redhat.com/security/cve/CVE-2026-79654
https://www.cve.org/CVERecord?id=CVE-2026-79654
https://nvd.nist.gov/vuln/detail/CVE-2026-79654
https://github.com/Katello/katello/pull/11847
https://projects.theforeman.org/issues/39701
https://access.redhat.com/security/cve/CVE-2026-87817
https://www.cve.org/CVERecord?id=CVE-2026-87817
https://nvd.nist.gov/vuln/detail/CVE-2026-87817
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-239g-whfq-7xj9
https://www.vulncheck.com/advisories/gitpython-before-3.1.60-remote-code-execution-via-git-directory-impersonation
https://access.redhat.com/security/cve/CVE-2026-96658
https://www.cve.org/CVERecord?id=CVE-2026-96658
https://nvd.nist.gov/vuln/detail/CVE-2026-96658
https://access.redhat.com/security/cve/CVE-2026-96659
https://www.cve.org/CVERecord?id=CVE-2026-96659
https://nvd.nist.gov/vuln/detail/CVE-2026-96659
Affected packages
Red Hat:satellite:6.18::el9
rubygem-foreman_remote_execution
Package
Name
rubygem-foreman_remote_execution
Purl
pkg:rpm/redhat/rubygem-foreman_remote_execution
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:16.2.3-2.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
rubygem-foreman_remote_execution-cockpit
Package
Name
rubygem-foreman_remote_execution-cockpit
Purl
pkg:rpm/redhat/rubygem-foreman_remote_execution-cockpit
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:16.2.3-2.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
foreman
Package
Name
foreman
Purl
pkg:rpm/redhat/foreman
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0.25-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
foreman-cli
Package
Name
foreman-cli
Purl
pkg:rpm/redhat/foreman-cli
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0.25-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
foreman-debug
Package
Name
foreman-debug
Purl
pkg:rpm/redhat/foreman-debug
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0.25-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
foreman-dynflow-sidekiq
Package
Name
foreman-dynflow-sidekiq
Purl
pkg:rpm/redhat/foreman-dynflow-sidekiq
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0.25-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
foreman-ec2
Package
Name
foreman-ec2
Purl
pkg:rpm/redhat/foreman-ec2
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0.25-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
foreman-journald
Package
Name
foreman-journald
Purl
pkg:rpm/redhat/foreman-journald
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0.25-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
foreman-libvirt
Package
Name
foreman-libvirt
Purl
pkg:rpm/redhat/foreman-libvirt
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0.25-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
foreman-openstack
Package
Name
foreman-openstack
Purl
pkg:rpm/redhat/foreman-openstack
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0.25-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
foreman-pcp
Package
Name
foreman-pcp
Purl
pkg:rpm/redhat/foreman-pcp
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0.25-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
foreman-postgresql
Package
Name
foreman-postgresql
Purl
pkg:rpm/redhat/foreman-postgresql
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0.25-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
foreman-redis
Package
Name
foreman-redis
Purl
pkg:rpm/redhat/foreman-redis
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0.25-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
foreman-service
Package
Name
foreman-service
Purl
pkg:rpm/redhat/foreman-service
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0.25-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
foreman-telemetry
Package
Name
foreman-telemetry
Purl
pkg:rpm/redhat/foreman-telemetry
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0.25-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
foreman-vmware
Package
Name
foreman-vmware
Purl
pkg:rpm/redhat/foreman-vmware
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0.25-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
rubygem-hammer_cli
Package
Name
rubygem-hammer_cli
Purl
pkg:rpm/redhat/rubygem-hammer_cli
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0-2.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
python3.12-dynaconf
Package
Name
python3.12-dynaconf
Purl
pkg:rpm/redhat/python3.12-dynaconf
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.2.13-2.el9pc
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
yggdrasil-worker-forwarder
Package
Name
yggdrasil-worker-forwarder
Purl
pkg:rpm/redhat/yggdrasil-worker-forwarder
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.1.0-2.1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
python3.12-sqlparse
Package
Name
python3.12-sqlparse
Purl
pkg:rpm/redhat/python3.12-sqlparse
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.6.0-1.el9pc
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
rubygem-katello
Package
Name
rubygem-katello
Purl
pkg:rpm/redhat/rubygem-katello
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.18.0.24-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
python3.12-gitpython
Package
Name
python3.12-gitpython
Purl
pkg:rpm/redhat/python3.12-gitpython
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.1.62-1.el9pc
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
rubygem-safemode
Package
Name
rubygem-safemode
Purl
pkg:rpm/redhat/rubygem-safemode
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.0-2.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
Red Hat:satellite_capsule:6.18::el9
foreman
Package
Name
foreman
Purl
pkg:rpm/redhat/foreman
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0.25-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
foreman-debug
Package
Name
foreman-debug
Purl
pkg:rpm/redhat/foreman-debug
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0.25-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
foreman-pcp
Package
Name
foreman-pcp
Purl
pkg:rpm/redhat/foreman-pcp
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0.25-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
python3.12-dynaconf
Package
Name
python3.12-dynaconf
Purl
pkg:rpm/redhat/python3.12-dynaconf
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.2.13-2.el9pc
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
python3.12-sqlparse
Package
Name
python3.12-sqlparse
Purl
pkg:rpm/redhat/python3.12-sqlparse
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.6.0-1.el9pc
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
python3.12-gitpython
Package
Name
python3.12-gitpython
Purl
pkg:rpm/redhat/python3.12-gitpython
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.1.62-1.el9pc
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
Red Hat:satellite_utils:6.18::el9
foreman
Package
Name
foreman
Purl
pkg:rpm/redhat/foreman
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0.25-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
foreman-cli
Package
Name
foreman-cli
Purl
pkg:rpm/redhat/foreman-cli
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0.25-1.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
rubygem-hammer_cli
Package
Name
rubygem-hammer_cli
Purl
pkg:rpm/redhat/rubygem-hammer_cli
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.16.0-2.el9sat
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:74504.json"
RHSA-2026:74504 - OSV