Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.5

Red Hat osbuild-composer Software Allows Unauthenticated Access

RHSA-2026:3752
Summary

A security update is available for osbuild-composer on Red Hat systems. This update fixes a vulnerability that could allow an attacker to access the system without a password. To resolve this issue, apply the latest update to ensure your system is secure.

What to do
  • Update redhat osbuild-composer to version 0:149-5.el10_1.
  • Update redhat osbuild-composer-core to version 0:149-5.el10_1.
  • Update redhat osbuild-composer-core-debuginfo to version 0:149-5.el10_1.
  • Update redhat osbuild-composer-debugsource to version 0:149-5.el10_1.
  • Update redhat osbuild-composer-tests-debuginfo to version 0:149-5.el10_1.
  • Update redhat osbuild-composer-worker to version 0:149-5.el10_1.
  • Update redhat osbuild-composer-worker-debuginfo to version 0:149-5.el10_1.
Affected software
VendorProductAffected versionsFix available
redhat osbuild-composer <= 0:149-5.el10_1 0:149-5.el10_1
redhat osbuild-composer-core <= 0:149-5.el10_1 0:149-5.el10_1
redhat osbuild-composer-core-debuginfo <= 0:149-5.el10_1 0:149-5.el10_1
redhat osbuild-composer-debugsource <= 0:149-5.el10_1 0:149-5.el10_1
redhat osbuild-composer-tests-debuginfo <= 0:149-5.el10_1 0:149-5.el10_1
redhat osbuild-composer-worker <= 0:149-5.el10_1 0:149-5.el10_1
redhat osbuild-composer-worker-debuginfo <= 0:149-5.el10_1 0:149-5.el10_1
Original title
Red Hat Security Advisory: osbuild-composer security update
osv CVSS3.1 7.5
Published: 5 Mar 2026 · Updated: 7 Mar 2026 · First seen: 6 Mar 2026