Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
High
Published: 08/14/2026 (08/14/2026, 02:48:22 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat has issued a security advisory (RHSA-2026:54835) for Red Hat Hardened Images RPMs including golang1.26 packages. The update addresses multiple vulnerabilities including CVE-2026-33818 and five others. One notable flaw (CVE-2026-56853) in the Go net/http library allows remote attackers to cause a Denial of Service (DoS) by maintaining open connections indefinitely due to improper application of ReadHeaderTimeout during HTTP/2 connection preface detection. The advisory provides updated RPM packages to fix these issues. No explicit patch status is stated beyond the availability of updated RPMs. No known exploits in the wild have been reported. The severity is rated high by Red Hat.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 01:11:10 UTC

Technical Analysis

This Red Hat security advisory (RHSA-2026:54835) updates Red Hat Hardened Images RPMs, specifically golang1.26 packages, to address six CVEs including CVE-2026-33818 and CVE-2026-56853. The critical issue CVE-2026-56853 involves a flaw in the Go standard library's net/http component where the ReadHeaderTimeout is not properly enforced during unencrypted HTTP/2 connection preface detection. This flaw can be exploited by remote attackers to keep connections open indefinitely, leading to resource exhaustion and Denial of Service (DoS). The advisory lists updated RPM versions (golang1.26-1.26.6-0.1.hum1 and related packages) for aarch64 and x86_64 architectures. Red Hat does not explicitly state the patch status but provides updated packages, indicating a fix is available. No known active exploits have been reported. The advisory includes references to Red Hat's errata and security pages for applying updates.

Potential Impact

The primary impact is a high-severity Denial of Service (DoS) vulnerability due to resource exhaustion by maintaining open HTTP/2 connections indefinitely. This can degrade or disrupt service availability on affected systems running the vulnerable golang1.26 packages. No confidentiality or integrity impacts are reported. The vulnerability affects resource allocation and availability, potentially impacting server stability and responsiveness.

Mitigation Recommendations

Red Hat has released updated RPM packages for golang1.26 (version 1.26.6-0.1.hum1) that address these vulnerabilities. Users should apply these updates promptly to mitigate the risk. Detailed update instructions are available at https://images.redhat.com/. No additional mitigations or workarounds are specified in the advisory. Since this is not a cloud service, remediation is managed by applying the vendor-provided package updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:54835
Cve Count
6
Additional Cves
["CVE-2026-56853","CVE-2026-56858","CVE-2026-56859","CVE-2026-56860","CVE-2026-56862"]
Cvss Version
null

Threat ID: 6a825c60bf8831d539f21ec8

Added to database: 08/17/2026, 00:57:04 UTC

Last enriched: 08/17/2026, 01:11:10 UTC

Last updated: 08/17/2026, 02:41:00 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses