Skip to main content
EPSS 1.2%top 35%

Red Hat Security Advisory: RHACS 4.10.3 security and bug fix update

0
Critical
Published: 05/26/2026 (05/26/2026, 11:34:12 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

See the release notes (link in the references section) for a description of the fixes and enhancements in this particular release.

Affected software

Affected versions
Red HatRed Hat DiscoveryRed Hat Discovery 2amd64registry.redhat.io/discovery/discovery-server-rhel9@sha256:3fa38f1ea595af86bc785d2899dbd3aa0694b4f94664481e5eef71b49dbf156b_amd64Red Hat Developer HubRed Hat Developer Hub 1.8registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:bb763e2b7a9d101f73b03b9e1c5688e7034fd9d31413e890817bd4098a7d42f9_amd64Red Hat Trusted Artifact SignerRed Hat Trusted Artifact Signer 1.3registry.redhat.io/rhtas/rhtas-console-rhel9@sha256:d5ac198d56cd63676ab35f8b71d6566daec7688ff3a6dd5bd76500967d27449c_amd64Red Hat QuayRed Hat Quay 3.12registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:d91c880570c005cb2edcb07d29f8df09504b65710dde2b0c95d17c139c92b777_amd64Cluster Observability OperatorCluster Observability Operator 1.5.0registry.redhat.io/cluster-observability-operator/alertmanager-rhel9@sha256:cec172ff439b028db99a42b3fc9dc75b49c2d70ace72f65d36c2f417c43e68ce_amd64Red Hat Quay 3.17registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:4aea7185e69a0d0c235cb7d1ee55c9bf4336fe8c2a5a911a9e298d56673f847c_amd64Red Hat Ansible Automation PlatformRed Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform/platform-operator-bundle@sha256:62f9795ac0590dea90f9075d2d98e29714c5eca29b394933d79e94eec926ff8e_amd64s390xregistry.redhat.io/ansible-automation-platform-26/gateway-rhel9-operator@sha256:449fc770bfe219a1a9d7cf235c0f33e0fa9a244cc80c95baf4d2a5c45dc5859e_s390xRed Hat Advanced Cluster Security for KubernetesRed Hat Advanced Cluster Security for Kubernetes 4.10registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:a32574be1c7a5a9ef0aa8b8ce4946ffe4920cb72b402eb17d1ca07c43925faef_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 20:21:20 UTC

Technical Analysis

The vulnerability CVE-2025-62718 affects Axios, a widely used HTTP client, due to improper handling of hostname normalization in NO_PROXY rule evaluation. This allows attackers to craft requests targeting loopback addresses (e.g., localhost or [::1]) that bypass NO_PROXY configurations and are routed through the configured proxy. This behavior can be exploited to perform Server-Side Request Forgery (SSRF), enabling access to internal or loopback services that should be protected. The impact is limited by the requirement that the attacker must control or influence URLs passed to Axios in a server-side context, the presence of both HTTP_PROXY and NO_PROXY environment variables, and the proxy's ability to intercept or act on the rerouted traffic. Red Hat's advisory indicates no current fix meets their criteria for deployment, and mitigation options are limited.

Potential Impact

Successful exploitation of this vulnerability can lead to SSRF attacks, potentially exposing sensitive internal or loopback services that are normally inaccessible. However, the impact is constrained by several non-default conditions, including the need for attacker control over URLs processed by Axios, specific proxy environment configurations, and proxy behavior. There are no known exploits in the wild at this time.

Mitigation Recommendations

Red Hat currently does not provide an official fix or mitigation that meets their criteria for ease of use, applicability, and stability. Users should monitor Red Hat advisories for future updates. Given the limited exploit conditions, review application usage of Axios and proxy configurations to minimize exposure. Consider restricting or validating URLs passed to Axios in server-side contexts to reduce risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:14937
Cve Count
18
Additional Cves
["CVE-2026-4424","CVE-2026-4878","CVE-2026-5121","CVE-2026-27135","CVE-2026-28390","CVE-2026-35385","CVE-2026-35386","CVE-2026-35387","CVE-2026-35388","CVE-2026-35414","CVE-2026-40175","CVE-2026-40895","CVE-2026-42033","CVE-2026-42035","CVE-2026-42039","CVE-2026-42041","CVE-2026-42043"]

Threat ID: 6a160961e29bf47b5062770c

Added to database: 05/26/2026, 20:58:09 UTC

Last enriched: 08/10/2026, 20:21:20 UTC

Last updated: 09/14/2026, 10:01:28 UTC

Views: 176

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:14937https://access.redhat.com/security/cve/CVE-2025-62718https://access.redhat.com/security/cve/CVE-2026-27135https://access.redhat.com/security/cve/CVE-2026-28390https://access.redhat.com/security/cve/CVE-2026-35385https://access.redhat.com/security/cve/CVE-2026-35386https://access.redhat.com/security/cve/CVE-2026-35387https://access.redhat.com/security/cve/CVE-2026-35388https://access.redhat.com/security/cve/CVE-2026-35414https://access.redhat.com/security/cve/CVE-2026-40175https://access.redhat.com/security/cve/CVE-2026-40895https://access.redhat.com/security/cve/CVE-2026-42033https://access.redhat.com/security/cve/CVE-2026-42035https://access.redhat.com/security/cve/CVE-2026-42039https://access.redhat.com/security/cve/CVE-2026-42041https://access.redhat.com/security/cve/CVE-2026-42043https://access.redhat.com/security/cve/CVE-2026-4424https://access.redhat.com/security/cve/CVE-2026-4878https://access.redhat.com/security/cve/CVE-2026-5121https://access.redhat.com/security/updates/classification/https://access.redhat.com/errata/RHSA-2026:26010https://access.redhat.com/security/cve/CVE-2026-32282https://access.redhat.com/security/updates/classificationhttps://docs.openshift.com/container-platform/latest/observability/cluster_observability_operator/cluster-observability-operator-release-notes.htmlCanonical URLhttps://access.redhat.com/errata/RHSA-2026:22465https://access.redhat.com/security/cve/CVE-2026-27459https://access.redhat.com/security/cve/CVE-2026-29063https://access.redhat.com/security/cve/CVE-2026-29074https://access.redhat.com/security/cve/CVE-2026-32280https://access.redhat.com/security/cve/CVE-2026-32281https://access.redhat.com/security/cve/CVE-2026-32286https://access.redhat.com/security/cve/CVE-2026-32589https://access.redhat.com/security/cve/CVE-2026-32590https://access.redhat.com/security/cve/CVE-2026-33186https://access.redhat.com/security/cve/CVE-2026-33747https://access.redhat.com/security/cve/CVE-2026-33894https://access.redhat.com/security/cve/CVE-2026-34986https://access.redhat.com/security/cve/CVE-2026-39892https://access.redhat.com/security/cve/CVE-2026-40192https://access.redhat.com/errata/RHSA-2026:9742https://access.redhat.com/security/cve/CVE-2025-69534https://access.redhat.com/security/cve/CVE-2025-69873https://access.redhat.com/security/cve/CVE-2026-1525https://access.redhat.com/security/cve/CVE-2026-1526https://access.redhat.com/security/cve/CVE-2026-1528https://access.redhat.com/security/cve/CVE-2026-2229https://access.redhat.com/security/cve/CVE-2026-25679https://access.redhat.com/security/cve/CVE-2026-26996https://access.redhat.com/security/cve/CVE-2026-27601https://access.redhat.com/security/cve/CVE-2026-27904https://access.redhat.com/security/cve/CVE-2026-29186https://access.redhat.com/security/cve/CVE-2026-3118https://access.redhat.com/security/cve/CVE-2026-32141https://access.redhat.com/security/cve/CVE-2026-33036https://access.redhat.com/security/cve/CVE-2026-33228https://access.redhat.com/security/cve/CVE-2026-33891https://access.redhat.com/errata/RHSA-2026:24471https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/indexhttps://access.redhat.com/security/cve/CVE-2026-42044Canonical URLhttps://access.redhat.com/errata/RHSA-2026:22629https://access.redhat.com/security/cve/CVE-2026-2377Canonical URLhttps://access.redhat.com/errata/RHSA-2026:59155https://access.redhat.com/security/cve/CVE-2025-69223https://access.redhat.com/security/cve/CVE-2025-69227https://access.redhat.com/security/cve/CVE-2025-69228https://access.redhat.com/security/cve/CVE-2026-12143https://access.redhat.com/security/cve/CVE-2026-14257https://access.redhat.com/security/cve/CVE-2026-15307https://access.redhat.com/security/cve/CVE-2026-1615https://access.redhat.com/security/cve/CVE-2026-44545https://access.redhat.com/security/cve/CVE-2026-44705https://access.redhat.com/security/cve/CVE-2026-59886https://access.redhat.com/security/cve/CVE-2026-67325https://access.redhat.com/security/cve/CVE-2026-69152https://access.redhat.com/security/cve/CVE-2026-69243https://access.redhat.com/security/cve/CVE-2026-69244https://access.redhat.com/security/cve/CVE-2026-71364https://access.redhat.com/security/cve/CVE-2026-71365https://access.redhat.com/security/cve/CVE-2026-71366https://access.redhat.com/security/cve/CVE-2026-9595https://access.redhat.com/errata/RHSA-2026:22840https://access.redhat.com/security/cve/CVE-2026-4598https://access.redhat.com/errata/RHSA-2026:24866https://access.redhat.com/security/cve/CVE-2026-23490https://access.redhat.com/security/cve/CVE-2026-28684https://access.redhat.com/security/cve/CVE-2026-33154https://access.redhat.com/security/cve/CVE-2026-39363https://access.redhat.com/security/cve/CVE-2026-39364https://access.redhat.com/security/cve/CVE-2026-40217https://access.redhat.com/security/cve/CVE-2026-41140https://access.redhat.com/security/cve/CVE-2026-48710https://access.redhat.com/security/cve/CVE-2026-4926https://access.redhat.com/security/cve/CVE-2026-6321https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updatesCanonical URLhttps://access.redhat.com/errata/RHSA-2026:8491https://access.redhat.com/security/cve/CVE-2026-4800Canonical URLhttps://access.redhat.com/errata/RHSA-2026:20889https://access.redhat.com/security/cve/CVE-2026-42264https://access.redhat.com/security/cve/CVE-2026-44486https://access.redhat.com/security/cve/CVE-2026-44487https://access.redhat.com/security/cve/CVE-2026-44488https://access.redhat.com/security/cve/CVE-2026-44492https://access.redhat.com/security/cve/CVE-2026-44494https://access.redhat.com/security/cve/CVE-2026-44495https://access.redhat.com/security/cve/CVE-2026-44496Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses