Skip to main content
EPSS 1.2%top 33%

Red Hat Security Advisory: Red Hat Update Infrastructure 5.2 Technology Preview security update

0
High
Published: 04/29/2026 (04/29/2026, 14:26:51 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Technology Preview features are not fully supported, may not be functionally complete, and are not suitable for deployment in production.

Affected software

Affected versions
Red HatRed Hat Update InfrastructureRed Hat Update Infrastructure 5amd64registry.redhat.io/rhui5/cds-kubernetes-tp-rhel9@sha256:9c099abe9fe9f06816a9ddd95c8123bd2909e66aa31b05ce5a143495efedd274_amd64Red Hat OpenShift EnterpriseRed Hat OpenShift Container Platform 4.12x86_64rhcos-x86_64-412.86.202604281506-0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 23:58:12 UTC

Technical Analysis

Red Hat Update Infrastructure 5.2 Technology Preview container images contain multiple security vulnerabilities, including CVE-2026-4424 and eight additional CVEs. One example is CVE-2026-25679, where the Go standard library function net/url.Parse improperly validates host/authority components, accepting invalid URLs by ignoring garbage before an IP-literal. The Technology Preview status means these features are not fully supported or functionally complete and are unsuitable for production deployment. The advisory does not indicate any available patches or fixes for these vulnerabilities. Red Hat recommends consulting the Technology Preview release notes for instructions on usage. The vulnerabilities cover a range of CWEs such as CWE-125 (out-of-bounds read), CWE-88 (argument injection), CWE-190 (integer overflow), and others.

Potential Impact

The vulnerabilities affect the Red Hat Update Infrastructure 5.2 Technology Preview container images, potentially allowing attackers to exploit improper input validation and parsing flaws. The CVSS score for CVE-2026-25679 is 7.5 (high) with an impact primarily on availability. However, the overall impact varies by vulnerability and context. Since these are Technology Preview features, they are not recommended for production use, limiting the practical impact. No known exploits in the wild have been reported. The lack of official fixes means the vulnerabilities remain unmitigated in this release.

Mitigation Recommendations

No official patches or fixes are currently available for these vulnerabilities in the Technology Preview release. Red Hat advises that Technology Preview features are not suitable for production deployment. Users should consult the RHUI Technology Preview Release Notes at https://access.redhat.com/articles/7141172 for guidance on usage. If production use is required, users should avoid Technology Preview versions and use fully supported releases. Monitoring Red Hat advisories for future updates or fixes is recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:11768
Cve Count
9
Additional Cves
["CVE-2026-4786","CVE-2026-5121","CVE-2026-6100","CVE-2026-25679","CVE-2026-27135","CVE-2026-28417","CVE-2026-28421","CVE-2026-33412"]
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a16097ce29bf47b506487e0

Added to database: 05/26/2026, 20:58:36 UTC

Last enriched: 08/14/2026, 23:58:12 UTC

Last updated: 09/14/2026, 00:46:50 UTC

Views: 103

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses