Skip to main content
EPSS 0.3%top 74%

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

0
Medium
Published: 07/08/2026 (07/08/2026, 20:16:29 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

A security update for Red Hat Hardened Images includes fixes for vulnerabilities in the Hugo static site generator, specifically CVE-2026-58402 and CVE-2026-58403. One key issue is a cross-site scripting (XSS) vulnerability caused by improper escaping of Markdown code-fence language in Hugo's default code block renderer. This flaw could allow attackers to inject malicious scripts into web pages, potentially leading to arbitrary code execution in users' browsers. The advisory references Red Hat Hardened Images RPMs version 0.163.3-0.1.hum1 as affected. No explicit patch version is stated as fixed in the advisory, and no known exploits are reported in the wild. The severity is assessed as medium.

Affected software

Affected versions
=0.163.3-0.1.hum1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/13/2026, 15:18:43 UTC

Technical Analysis

The Red Hat security advisory addresses vulnerabilities in the Hugo static site generator packaged in Red Hat Hardened Images RPMs version 0.163.3-0.1.hum1. The primary vulnerability (CVE-2026-58402) is a cross-site scripting (XSS) flaw where the default code block renderer fails to properly escape Markdown code-fence language or info-strings, allowing injection of malicious script elements into generated web pages. This can lead to arbitrary code execution within a user's browser. The advisory includes multiple CVEs related to Hugo but does not provide detailed patch information or fixed versions. The vulnerabilities are rated medium severity by Red Hat. No known exploits in the wild have been reported. The vendor advisory does not explicitly confirm a patch but references updated RPMs containing the fixes.

Potential Impact

Successful exploitation of the XSS vulnerability could allow attackers to execute arbitrary scripts in the context of users' browsers visiting affected Hugo-generated sites. This may lead to disclosure of sensitive information such as cookies or session tokens, unauthorized actions performed on behalf of users, and potential compromise of user accounts. The impact is limited to client-side code execution within browsers and does not indicate server compromise. No known active exploitation has been reported.

Mitigation Recommendations

The Red Hat advisory indicates updated RPMs for Hugo version 0.163.3-0.1.hum1 include the security fixes. Users should apply the provided updates from Red Hat Hardened Images RPMs to remediate these vulnerabilities. Since no explicit fixed version is stated, users should follow Red Hat's official update channels and instructions at https://images.redhat.com/ for applying the security update. No additional mitigations are specified or required beyond applying the update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:36862
Cve Count
4
Additional Cves
["CVE-2026-58402","CVE-2026-58403","CVE-2026-58404"]
State
PUBLISHED

Threat ID: 6a6fb633bf32cb7a346e7b10

Added to database: 08/02/2026, 21:27:15 UTC

Last enriched: 09/13/2026, 15:18:43 UTC

Last updated: 09/16/2026, 16:59:11 UTC

Views: 63

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses