Red Hat Security Advisory: General availability of the satellite/iop-advisor-frontend-rhel9 container image
Red Hat Lightspeed in Satellite analyzes system health and configuration by applying predefined rules to a small set of local data, such as installed packages, running services, and configuration settings. When you install Red Hat Lightspeed in Satellite locally, you can generate Red Hat Lightspeed recommendations without sending system data to Red Hat services.
AI Analysis
Technical Summary
The ajv library used in Red Hat Satellite's Lightspeed component has a ReDoS vulnerability (CVE-2025-69873) when the $data option is enabled. This option allows dynamic regular expressions, but the pattern keyword's value is passed directly to JavaScript's RegExp() constructor without sufficient validation. An attacker able to supply a malicious regular expression pattern can cause excessive backtracking, leading to high CPU usage and denial of service. Exploitation requires the $data feature enabled and attacker input controlling the pattern. A 31-character crafted payload can cause about 44 seconds of execution delay, doubling with each additional character. Red Hat rates this as important severity but assigns a low CVSS score (2.9) for their products. The advisory recommends disabling $data if not needed or validating inputs strictly. No official fix or patch is currently provided in the advisory. The vulnerability affects ajv versions >=4.19.0 <4.19.29 and =6.18 as used in Red Hat Satellite 6.18 and related container images.
Potential Impact
Exploitation of this vulnerability can cause a denial of service by making the application unresponsive due to CPU resource exhaustion triggered by crafted regular expressions. There is no impact on confidentiality or integrity. The attack complexity is high because it requires the $data option enabled and attacker-controlled input. No known exploits in the wild have been reported. The impact is limited to availability degradation.
Mitigation Recommendations
Red Hat's advisory does not list an official patch or fix at this time. To mitigate this issue, disable the $data feature in ajv if it is not required by your application. If $data must be used, implement strict validation on input fields referenced by the pattern keyword to ensure only safe and expected characters are allowed. Monitor Red Hat advisories for updates or patches. Since this is not a cloud service, remediation depends on applying configuration changes or updates when available.
Red Hat Security Advisory: General availability of the satellite/iop-advisor-frontend-rhel9 container image
Description
Red Hat Lightspeed in Satellite analyzes system health and configuration by applying predefined rules to a small set of local data, such as installed packages, running services, and configuration settings. When you install Red Hat Lightspeed in Satellite locally, you can generate Red Hat Lightspeed recommendations without sending system data to Red Hat services.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The ajv library used in Red Hat Satellite's Lightspeed component has a ReDoS vulnerability (CVE-2025-69873) when the $data option is enabled. This option allows dynamic regular expressions, but the pattern keyword's value is passed directly to JavaScript's RegExp() constructor without sufficient validation. An attacker able to supply a malicious regular expression pattern can cause excessive backtracking, leading to high CPU usage and denial of service. Exploitation requires the $data feature enabled and attacker input controlling the pattern. A 31-character crafted payload can cause about 44 seconds of execution delay, doubling with each additional character. Red Hat rates this as important severity but assigns a low CVSS score (2.9) for their products. The advisory recommends disabling $data if not needed or validating inputs strictly. No official fix or patch is currently provided in the advisory. The vulnerability affects ajv versions >=4.19.0 <4.19.29 and =6.18 as used in Red Hat Satellite 6.18 and related container images.
Potential Impact
Exploitation of this vulnerability can cause a denial of service by making the application unresponsive due to CPU resource exhaustion triggered by crafted regular expressions. There is no impact on confidentiality or integrity. The attack complexity is high because it requires the $data option enabled and attacker-controlled input. No known exploits in the wild have been reported. The impact is limited to availability degradation.
Mitigation Recommendations
Red Hat's advisory does not list an official patch or fix at this time. To mitigate this issue, disable the $data feature in ajv if it is not required by your application. If $data must be used, implement strict validation on input fields referenced by the pattern keyword to ensure only safe and expected characters are allowed. Monitor Red Hat advisories for updates or patches. Since this is not a cloud service, remediation depends on applying configuration changes or updates when available.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:10093
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-33186"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a160956e29bf47b5061baea
Added to database: 05/26/2026, 20:57:58 UTC
Last enriched: 08/10/2026, 20:31:00 UTC
Last updated: 09/11/2026, 07:31:51 UTC
Views: 120
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.