Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
Red Hat osbuild-composer Update: Unauthenticated Access Risk
RHSA-2026:27856
Summary
An update is available for Red Hat's osbuild-composer, a tool for creating operating system images. This update addresses a security issue that could allow unauthorized access to the system. Businesses using osbuild-composer should apply this update to ensure their systems remain secure.
What to do
- Update redhat osbuild-composer to version 0:134.1-9.el10_0.
- Update redhat osbuild-composer-core to version 0:134.1-9.el10_0.
- Update redhat osbuild-composer-core-debuginfo to version 0:134.1-9.el10_0.
- Update redhat osbuild-composer-debugsource to version 0:134.1-9.el10_0.
- Update redhat osbuild-composer-tests-debuginfo to version 0:134.1-9.el10_0.
- Update redhat osbuild-composer-worker to version 0:134.1-9.el10_0.
- Update redhat osbuild-composer-worker-debuginfo to version 0:134.1-9.el10_0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Red Hat:enterprise_linux_eus:10.0 | redhat | osbuild-composer |
< 0:134.1-9.el10_0 Fix: upgrade to 0:134.1-9.el10_0
|
| Red Hat:enterprise_linux_eus:10.0 | redhat | osbuild-composer-core |
< 0:134.1-9.el10_0 Fix: upgrade to 0:134.1-9.el10_0
|
| Red Hat:enterprise_linux_eus:10.0 | redhat | osbuild-composer-core-debuginfo |
< 0:134.1-9.el10_0 Fix: upgrade to 0:134.1-9.el10_0
|
| Red Hat:enterprise_linux_eus:10.0 | redhat | osbuild-composer-debugsource |
< 0:134.1-9.el10_0 Fix: upgrade to 0:134.1-9.el10_0
|
| Red Hat:enterprise_linux_eus:10.0 | redhat | osbuild-composer-tests-debuginfo |
< 0:134.1-9.el10_0 Fix: upgrade to 0:134.1-9.el10_0
|
| Red Hat:enterprise_linux_eus:10.0 | redhat | osbuild-composer-worker |
< 0:134.1-9.el10_0 Fix: upgrade to 0:134.1-9.el10_0
|
| Red Hat:enterprise_linux_eus:10.0 | redhat | osbuild-composer-worker-debuginfo |
< 0:134.1-9.el10_0 Fix: upgrade to 0:134.1-9.el10_0
|
Original title
Red Hat Security Advisory: osbuild-composer security update
osv CVSS3.1
9.1
- https://access.redhat.com/errata/RHSA-2026:27856 Vendor Advisory
- https://access.redhat.com/security/updates/classification/#important Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2449833 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2455470 Third Party Advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_27856.... Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-33186 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-33186 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-33186 Vendor Advisory
- https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3 Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-34986 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-34986 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-34986 Vendor Advisory
- https://github.com/go-jose/go-jose/security/advisories/GHSA-78h2-9frx-2jm8 Third Party Advisory
- https://pkg.go.dev/github.com/go-jose/go-jose/v4#pkg-constants Third Party Advisory
Published: 23 Jun 2026 · Updated: 24 Jun 2026 · First seen: 24 Jun 2026