Skip to main content
EPSS 0.5%top 60%

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
Medium
Published: 08/03/2026 (08/03/2026, 17:08:46 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

A security update for Red Hat Hardened Images RPMs addresses vulnerabilities including CVE-2026-72815, CVE-2026-72816, and CVE-2026-72817. Notably, CVE-2026-72816 involves an IP spoofing flaw in the go-chi/chi RealIP middleware, allowing remote attackers to supply arbitrary IP addresses in client-controlled headers, potentially bypassing IP-based access controls and evading rate limiting. The update includes new versions of spire1.15 packages for aarch64 and x86_64 architectures. No explicit patch details are provided for CVE-2026-72815 specifically. The vendor advisory indicates the update is available and provides guidance on mitigation for the IP spoofing issue.

Affected software

Affected versions
>=1.15.0 <=1.15.2-0.4.hum1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 04:47:54 UTC

Technical Analysis

This Red Hat security advisory covers a bug fix and enhancement update for Red Hat Hardened Images RPMs, including spire1.15 packages version 1.15.2-0.4.hum1 for aarch64 and x86_64. Among the addressed vulnerabilities is CVE-2026-72816, an IP spoofing vulnerability in the go-chi/chi RealIP middleware. The RealIP middleware improperly trusts client-supplied HTTP headers (True-Client-IP, X-Real-IP, X-Forwarded-For) without validating the upstream proxy, allowing remote unauthenticated attackers to spoof IP addresses. This can lead to bypassing IP-restricted endpoints, subverting rate-limiting controls, and polluting audit logs. The impact on confidentiality and integrity is low. The advisory recommends not using the RealIP middleware directly with untrusted networks and instead sanitizing forwarding headers at an upstream proxy. The update includes fixes for multiple CVEs but does not explicitly detail fixes for CVE-2026-72815 in the provided content.

Potential Impact

The IP spoofing vulnerability (CVE-2026-72816) allows remote attackers to bypass IP-based access controls, evade rate limiting and geo-IP restrictions, and poison audit logs by supplying arbitrary IP addresses in HTTP headers. This poses a low impact on confidentiality and integrity. No known exploits are reported in the wild. The overall impact of the update is to mitigate these risks by updating the affected RPMs.

Mitigation Recommendations

A fix is available via the updated Red Hat Hardened Images RPMs (spire1.15 version 1.15.2-0.4.hum1). For the IP spoofing vulnerability in the RealIP middleware, Red Hat advises not to use this middleware when receiving traffic directly from untrusted networks or unverified proxies. Instead, client-supplied forwarding headers should be stripped or sanitized at an upstream edge or reverse proxy (e.g., NGINX or HAProxy) before requests reach the application. Refer to the Red Hat advisory and https://images.redhat.com/ for update application instructions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:49732
Cve Count
3
Additional Cves
["CVE-2026-72816","CVE-2026-72817"]
State
PUBLISHED

Threat ID: 6a870a50acd9273b49b58582

Added to database: 08/20/2026, 14:08:16 UTC

Last enriched: 09/11/2026, 04:47:54 UTC

Last updated: 10/05/2026, 06:48:18 UTC

Views: 39

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses