Skip to main content
EPSS 0.3%top 74%

Red Hat Security Advisory: Red Hat Hardened Images RPM Release

0
Medium
Published: 03/20/2026 (03/20/2026, 19:45:06 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat Hardened Images RPM Release

Affected software

Affected versions
Red HatRed Hat Hardened Imagesaarch64golang1-25-main@aarch64MicrosoftAzure Linux3.0Azure Linux 3.02.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 17:42:17 UTC

Technical Analysis

An input escaping flaw exists in the golang html/template module where URLs inserted into the content attribute of HTML meta tags are not properly escaped if the meta tag also has an http-equiv attribute with the value "refresh". This can enable cross-site scripting (CWE-79) attacks. Red Hat Hardened Images RPMs are affected. A new GODEBUG setting (htmlmetacontenturlescape) allows disabling escaping of URLs in meta content attributes, but this is not considered a sufficient mitigation by Red Hat. No patches or fixes have been released as of the advisory date. The vulnerability could allow execution of unauthorized code or disclosure of sensitive information via XSS, but no known exploits are reported in the wild.

Potential Impact

The vulnerability enables cross-site scripting attacks by failing to escape URLs in meta refresh tags, potentially allowing attackers to execute unauthorized scripts in the context of affected web applications. This can lead to disclosure of sensitive information such as cookies or session data, and possibly unauthorized actions performed on behalf of users. The impact is rated medium by Red Hat. No active exploitation has been reported.

Mitigation Recommendations

No official fix or patch is currently available for this vulnerability. Red Hat states that existing mitigation options do not meet their criteria for ease of use, applicability, or stability. Users should monitor Red Hat advisories for future updates. The GODEBUG environment variable htmlmetacontenturlescape can be set to 0 to disable URL escaping in meta content attributes, but this is not recommended as a reliable mitigation. No additional vendor-recommended mitigations are provided at this time.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:5192
Cve Count
1

Threat ID: 6a4049d527e9c7971982d056

Added to database: 06/27/2026, 22:08:21 UTC

Last enriched: 08/16/2026, 17:42:17 UTC

Last updated: 09/10/2026, 19:24:59 UTC

Views: 67

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses