RLSA-2026:67139

Source
https://errata.rockylinux.org/RLSA-2026:67139
Import Source
https://storage.googleapis.com/resf-osv-data/RLSA-2026:67139.json
JSON Data
https://api.osv.dev/v1/vulns/RLSA-2026:67139
Upstream
CVE (4)
Published
2026-09-15T12:08:56Z
Modified
2026-09-15T12:30:03Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Important: image-builder security update
Details

A local binary for building customized OS artifacts such as VM images and OSTree commits. Uses osbuild under the hood.

Security Fix(es):

  • golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136)

  • golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)

  • golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering (CVE-2026-42502)

  • github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Database specific
{
    "license":  "CC-BY-4.0",
    "license_url":  "https://creativecommons.org/licenses/by/4.0/",
    "source_advisory":  "RHSA-2026:67139"
}
References
Credits
    • Rocky Enterprise Software Foundation
    • Red Hat

Affected packages

Rocky Linux:10 / image-builder

Package

Name
image-builder
Purl
pkg:rpm/rocky-linux/image-builder?distro=rocky-linux-10&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0:52.1-2.el10_2.rocky.0.1
Database specific
Show details
{
    "yum_repository":  "AppStream"
}

Database specific

source
"https://storage.googleapis.com/resf-osv-data/RLSA-2026:67139.json"