Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
Red Hat Hardened Images: Unvalidated Input Risk
published 21 days ago
Summary
Red Hat Hardened Images are affected by a security risk where unvalidated input can lead to arbitrary code execution. This affects the security of systems using these images. Users should apply the latest security update to mitigate this risk.
What to do
- Update redhat hugo to version 0:0.165.0-0.1.hum1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Red Hat:hummingbird:1 | redhat | hugo |
< 0:0.165.0-0.1.hum1 Fix: upgrade to 0:0.165.0-0.1.hum1
|
Original advisory text
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
References
- https://access.redhat.com/errata/RHSA-2026:54549 Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-56852 Third Party Advisory
- https://access.redhat.com/security/updates/classification/ Third Party Advisory
- https://images.redhat.com/ Third Party Advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54549.... Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2504233 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-56852 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-56852 Vendor Advisory
- https://go.dev/cl/794100 Third Party Advisory
- https://go.dev/issue/80142 Third Party Advisory
- https://pkg.go.dev/vuln/GO-2026-5970 Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-73501 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2515006 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-73501 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-73501 Vendor Advisory
- https://github.com/getkin/kin-openapi/commit/f0407d53b0730280266f454b755010e7eeb... Third Party Advisory
- https://github.com/getkin/kin-openapi/releases/tag/v0.144.0 Third Party Advisory
- https://github.com/getkin/kin-openapi/security/advisories/GHSA-r277-6w6q-xmqw Third Party Advisory
Severity
9.1
Critical
CVSS 3.1: 7.5 (OSV)
Timeline
Published14 Aug 2026
Updated28 Aug 2026
First seen15 Aug 2026
Sources
RHSA-2026:54549 · OSV
Monitor software like this
Free during beta