Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
This update includes the following RPMs: prometheus3.13: * prometheus3.13-3.13.2-0.2.hum1 (aarch64, x86_64) * prometheus3.13-3.13.2-0.2.hum1.src (src) Security Fix(es): prometheus3.13: * CVE-2026-69153
AI Analysis
Technical Summary
This vulnerability (CVE-2026-69153) in PostCSS arises from improper handling of the sourceMappingURL when the 'from' parameter is unset, leading to a path traversal that exposes source-map files (.map) containing source code paths and content. The issue affects Red Hat Hardened Images RPMs, including prometheus3.5 versions before 3.5.5-0.7.hum1. Red Hat classifies the impact as Moderate because the attacker cannot read arbitrary files beyond source maps. Exploitation requires the application to process attacker-controlled CSS on the server side. The recommended mitigation is to disable source map auto-loading by passing map: false to PostCSS, which prevents the vulnerability but disables source map support. No official patch is currently provided for the affected Red Hat Hardened Images RPMs, and users should refer to Red Hat advisories for updates.
Potential Impact
The vulnerability allows an attacker to read unintended source-map files (.map) via a crafted sourceMappingURL, potentially exposing sensitive information about the application's source code. However, the attacker cannot read arbitrary files on the system. The impact is limited to confidentiality exposure of source map contents. There is no impact on integrity or availability. Exploitation requires server-side processing of attacker-controlled CSS through PostCSS.
Mitigation Recommendations
Red Hat advises disabling source map auto-loading by passing map: false when invoking PostCSS to prevent the path traversal vulnerability. This mitigation removes source map support entirely but effectively blocks exploitation. No official fix or patch is currently available for the affected Red Hat Hardened Images RPMs. Users should monitor Red Hat advisories for updates and apply mitigations as appropriate.
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
Description
This update includes the following RPMs: prometheus3.13: * prometheus3.13-3.13.2-0.2.hum1 (aarch64, x86_64) * prometheus3.13-3.13.2-0.2.hum1.src (src) Security Fix(es): prometheus3.13: * CVE-2026-69153
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-69153) in PostCSS arises from improper handling of the sourceMappingURL when the 'from' parameter is unset, leading to a path traversal that exposes source-map files (.map) containing source code paths and content. The issue affects Red Hat Hardened Images RPMs, including prometheus3.5 versions before 3.5.5-0.7.hum1. Red Hat classifies the impact as Moderate because the attacker cannot read arbitrary files beyond source maps. Exploitation requires the application to process attacker-controlled CSS on the server side. The recommended mitigation is to disable source map auto-loading by passing map: false to PostCSS, which prevents the vulnerability but disables source map support. No official patch is currently provided for the affected Red Hat Hardened Images RPMs, and users should refer to Red Hat advisories for updates.
Potential Impact
The vulnerability allows an attacker to read unintended source-map files (.map) via a crafted sourceMappingURL, potentially exposing sensitive information about the application's source code. However, the attacker cannot read arbitrary files on the system. The impact is limited to confidentiality exposure of source map contents. There is no impact on integrity or availability. Exploitation requires server-side processing of attacker-controlled CSS through PostCSS.
Mitigation Recommendations
Red Hat advises disabling source map auto-loading by passing map: false when invoking PostCSS to prevent the path traversal vulnerability. This mitigation removes source map support entirely but effectively blocks exploitation. No official fix or patch is currently available for the affected Red Hat Hardened Images RPMs. Users should monitor Red Hat advisories for updates and apply mitigations as appropriate.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-fxqj-rqcc-2cmp
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-69153"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a710664bf32cb7a343946fd
Added to database: 08/03/2026, 21:21:40 UTC
Last enriched: 08/12/2026, 17:56:48 UTC
Last updated: 09/17/2026, 22:01:37 UTC
Views: 50
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.