Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
A security update for Red Hat Hardened Images RPMs addresses vulnerabilities including CVE-2026-72815, CVE-2026-72816, and CVE-2026-72817. Notably, CVE-2026-72816 involves an IP spoofing flaw in the go-chi/chi RealIP middleware, allowing remote attackers to supply arbitrary IP addresses in client-controlled headers, potentially bypassing IP-based access controls and evading rate limiting. The update includes new versions of spire1.15 packages for aarch64 and x86_64 architectures. No explicit patch details are provided for CVE-2026-72815 specifically. The vendor advisory indicates the update is available and provides guidance on mitigation for the IP spoofing issue.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This Red Hat security advisory covers a bug fix and enhancement update for Red Hat Hardened Images RPMs, including spire1.15 packages version 1.15.2-0.4.hum1 for aarch64 and x86_64. Among the addressed vulnerabilities is CVE-2026-72816, an IP spoofing vulnerability in the go-chi/chi RealIP middleware. The RealIP middleware improperly trusts client-supplied HTTP headers (True-Client-IP, X-Real-IP, X-Forwarded-For) without validating the upstream proxy, allowing remote unauthenticated attackers to spoof IP addresses. This can lead to bypassing IP-restricted endpoints, subverting rate-limiting controls, and polluting audit logs. The impact on confidentiality and integrity is low. The advisory recommends not using the RealIP middleware directly with untrusted networks and instead sanitizing forwarding headers at an upstream proxy. The update includes fixes for multiple CVEs but does not explicitly detail fixes for CVE-2026-72815 in the provided content.
Potential Impact
The IP spoofing vulnerability (CVE-2026-72816) allows remote attackers to bypass IP-based access controls, evade rate limiting and geo-IP restrictions, and poison audit logs by supplying arbitrary IP addresses in HTTP headers. This poses a low impact on confidentiality and integrity. No known exploits are reported in the wild. The overall impact of the update is to mitigate these risks by updating the affected RPMs.
Mitigation Recommendations
A fix is available via the updated Red Hat Hardened Images RPMs (spire1.15 version 1.15.2-0.4.hum1). For the IP spoofing vulnerability in the RealIP middleware, Red Hat advises not to use this middleware when receiving traffic directly from untrusted networks or unverified proxies. Instead, client-supplied forwarding headers should be stripped or sanitized at an upstream edge or reverse proxy (e.g., NGINX or HAProxy) before requests reach the application. Refer to the Red Hat advisory and https://images.redhat.com/ for update application instructions.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:49732
- Cve Count
- 3
- Additional Cves
- ["CVE-2026-72816","CVE-2026-72817"]
- State
- PUBLISHED
Threat ID: 6a870a50acd9273b49b58582
Added to database: 08/20/2026, 14:08:16 UTC
Last enriched: 09/11/2026, 04:47:54 UTC
Last updated: 10/05/2026, 06:48:18 UTC
Views: 39
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.