Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.3%top 76%

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
High
Published: 04/11/2026 (04/11/2026, 00:49:50 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This update includes the following RPMs: yarnpkg: * yarnpkg-1.22.22-18.1.hum1 (aarch64, x86_64) * yarnpkg-1.22.22-18.1.hum1.src (src)

Affected software

redhat/rhdh-hub-rhel9
pkg:rpm/redhat/rhdh-hub-rhel9
Affected versions
=1.10.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 11:55:33 UTC

Technical Analysis

This Red Hat security advisory (RHSA-2026:7655) announces an update to Red Hat Hardened Images RPMs, specifically the yarnpkg package version 1.22.22-18.1.hum1 for aarch64 and x86_64. The update addresses multiple vulnerabilities identified by CVE identifiers including CVE-2026-2950 and six additional CVEs. The advisory does not provide detailed vulnerability descriptions or CVSS scores. It references Red Hat's official update channels for applying the update. No known active exploitation is reported. The advisory covers Red Hat Hardened Images and related RPMs but does not specify affected software versions beyond the updated RPM version.

Potential Impact

The advisory is rated as high severity and addresses multiple vulnerabilities in the yarnpkg package within Red Hat Hardened Images. The exact impact of each vulnerability is not detailed in the provided information. No known exploits in the wild have been reported, indicating limited or no active exploitation at this time. The update aims to fix security issues that could potentially affect the integrity or security of the affected packages.

Mitigation Recommendations

The advisory references an update including the yarnpkg RPM version 1.22.22-18.1.hum1. Users of Red Hat Hardened Images should apply this update as per Red Hat's official guidance available at https://images.redhat.com/. No explicit patch links are provided in the advisory content, but the vendor's update channels should be used to obtain and apply the fix. Since this is an official Red Hat advisory, the update should be considered the official fix. There are no indications that no action is required or that the issue is already mitigated without update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:24841
Cve Count
7
Additional Cves
["CVE-2026-4923","CVE-2026-22036","CVE-2026-27601","CVE-2026-31988","CVE-2026-32235","CVE-2026-33349"]
Cvss Version
null

Threat ID: 6a294f768dd33fbd853d3d16

Added to database: 06/10/2026, 11:50:14 UTC

Last enriched: 07/30/2026, 11:55:33 UTC

Last updated: 07/31/2026, 19:24:47 UTC

Views: 62

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses