Skip to main content

Threats Tagged 'cve-2026-78679'

View all threats tagged with 'cve-2026-78679'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-78679

Threats Tagged 'cve-2026-78679'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Security Fix(es): * python-dynaconf: Dynaconf: Arbitrary code execution via Server-Side Template Injection [rhn_satellite_6.16] (CVE-2026-33154) * foreman: Excessive Permissions for Viewer Role on Preview [rhn_satellite_6.16] (CVE-2026-96659) * foreman: Safemode Bypass leading to RCE [rhn_satellite_6.16] (CVE-2026-96658) * satellite:el8/python-sqlparse: sqlparse: Denial of Service via inefficient SQL parsing [rhn_satellite_6.16] (CVE-2026-59893) * python-sqlparse: sqlparse: Denial of Service via inefficient SQL parsing [rhn_satellite_6.16] (CVE-2026-59893) * satellite:el8/python-sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing [rhn_satellite_6.16] (CVE-2026-54284) * python-sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing [rhn_satellite_6.16] (CVE-2026-54284) * satellite:el8/yggdrasil-worker-forwarder: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages [rhn_satellite_6.16] (CVE-2026-56862) * satellite:el8/yggdrasil-worker-forwarder: Go html/template: Cross-Site Scripting via pathological input [rhn_satellite_6.16] (CVE-2026-56858) * satellite:el8/yggdrasil-worker-forwarder: golang net/url: Denial of Service from quadratic complexity in path resolution [rhn_satellite_6.16] (CVE-2026-56860) * satellite:el8/yggdrasil-worker-forwarder: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal [rhn_satellite_6.16] (CVE-2026-33818) * satellite:el8/rubygem-katello: Katello Content View History API Cross-Organization Authorization Bypass [rhn_satellite_6.16] (CVE-2026-79654) * python-gitpython: GitPython: Arbitrary file read via TagReference.create() [rhn_satellite_6.16] (CVE-2026-78679) * python-gitpython: GitPython: Remote Code Execution via Git directory impersonation [rhn_satellite_6.16] (CVE-2026-87817) * satellite-capsule:el8/python-lxml: lxml: URL bypass vulnerability in Cleaner via missing xlink:href [rhn_satellite_6.16] (CVE-2026-49825) * yggdrasil-worker-forwarder: Golang MIME: Denial of Service via maliciously-crafted MIME header [rhn_satellite_6.16] (CVE-2026-42504) * satellite:el8/yggdrasil-worker-forwarder: Golang MIME: Denial of Service via maliciously-crafted MIME header [rhn_satellite_6.16] (CVE-2026-42504) * rubygem-katello: Katello Content View History API Cross-Organization Authorization Bypass [rhn_satellite_6.16] (CVE-2026-79654) * yggdrasil-worker-forwarder: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal [rhn_satellite_6.16] (CVE-2026-33818) * yggdrasil-worker-forwarder: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages [rhn_satellite_6.16] (CVE-2026-56862) * yggdrasil-worker-forwarder: Go html/template: Cross-Site Scripting via pathological input [rhn_satellite_6.16] (CVE-2026-56858) * yggdrasil-worker-forwarder: golang net/url: Denial of Service from quadratic complexity in path resolution [rhn_satellite_6.16] (CVE-2026-56860) * satellite:el8/rubygem-katello: improper authorization logic allows resource enumeration [rhn_satellite_6.16] (CVE-2026-56098) * rubygem-katello: improper authorization logic allows resource enumeration [rhn_satellite_6.16] (CVE-2026-56098) * rubygem-katello: SQL injection in Registry Proxy via labels [rhn_satellite_6.16] (CVE-2026-56097) * satellite:el8/rubygem-katello: SQL injection in Registry Proxy via labels [rhn_satellite_6.16] (CVE-2026-56097) * satellite-utils:el8/rubygem-hammer_cli: command injection via insecure editor invocation [rhn_satellite_6.16] (CVE-2026-12545) * rubygem-hammer_cli: command injection via insecure editor invocation [rhn_satellite_6.16] (CVE-2026-12545) * foreman: SSTI and insecure deserialization in foreman-rake configuration [rhn_satellite_6.16] (CVE-2026-12544) * satellite:el8/foreman: SSTI and insecure deserialization in foreman-rake configuration [rhn_satellite_6.16] (CVE-2026-12544) * satellite:el8/foreman: command injection in foreman-tail [rhn_satellite_6.16] (CVE-2026-12542) * foreman: command injection in foreman-tail [rhn_satellite_6.16] (CVE-2026-12542) * satellite:el8/foreman: command injection in foreman-rake database tasks [rhn_satellite_6.16] (CVE-2026-12541) * foreman: command injection in foreman-rake database tasks [rhn_satellite_6.16] (CVE-2026-12541) * satellite:el8/foreman: command injection in foreman-rake errors:fetch_log via request_id parameter [rhn_satellite_6.16] (CVE-2026-12540) * foreman: command injection in foreman-rake errors:fetch_log via request_id parameter [rhn_satellite_6.16] (CVE-2026-12540) * satellite:el8/foreman: unauthenticated information disclosure via provisioning token validation flaw [rhn_satellit

Join the discussion

Red Hat® Enterprise Linux® AI is a foundation model platform to seamlessly develop, test, and run Granite family large language models (LLMs) for enterprise applications. This update provides the latest Red Hat Enterprise Linux AI 3.3.6 container images. For a full list of changes in this release, see the Red Hat Enterprise Linux AI Release Notes linked in the References section.

Join the discussion

A vulnerability in GitPython's TagReference.create() method allows an attacker to perform an arbitrary local file read by passing a specially crafted positional argument that bypasses unsafe option guards. This leads to the contents of arbitrary files being returned in the annotated tag message. The issue affects GitPython versions up to 3.1.58 and requires the embedding application to forward a user-controlled reference value. A fix is available to properly check positional arguments or separate them with a '--' to prevent this bypass.

Join the discussion

Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Security Fix(es): * rubygem-foreman_remote_execution: command injection in job invocations via effective_user parameter (CVE-2026-12405) * foreman: unauthenticated information disclosure via provisioning token validation flaw (CVE-2026-12423) * foreman: command injection in foreman-rake errors:fetch_log via request_id parameter (CVE-2026-12540) * foreman: command injection in foreman-rake database tasks (CVE-2026-12541) * foreman: command injection in foreman-tail (CVE-2026-12542) * foreman: SSTI and insecure deserialization in foreman-rake configuration (CVE-2026-12544) * rubygem-hammer_cli: command injection via insecure editor invocation (CVE-2026-12545) * python3.12-dynaconf: Dynaconf: Arbitrary code execution via Server-Side Template Injection (CVE-2026-33154) * yggdrasil-worker-forwarder: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * yggdrasil-worker-forwarder: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * nodejs-sanitize-html: PostCSS: Information disclosure and denial of service via crafted CSS input (CVE-2026-45623) * python-sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing (CVE-2026-54284) * python3.12-sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing (CVE-2026-54284) * rubygem-katello: SQL injection in Registry Proxy via labels (CVE-2026-56097) * rubygem-katello: improper authorization logic allows resource enumeration (CVE-2026-56098) * yggdrasil-worker-forwarder: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * yggdrasil-worker-forwarder: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * yggdrasil-worker-forwarder: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * nodejs-connected-react-router: Immutable.js: Denial of Service due to mishandling of large index values in List operations (CVE-2026-59879) * nodejs-sass: Immutable.js: Denial of Service due to mishandling of large index values in List operations (CVE-2026-59879) * python-sqlparse: sqlparse: Denial of Service via inefficient SQL parsing (CVE-2026-59893) * python3.12-sqlparse: sqlparse: Denial of Service via inefficient SQL parsing (CVE-2026-59893) * python-sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in comment grouping (CVE-2026-71491) * python3.12-sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in comment grouping (CVE-2026-71491) * nodejs-css-loader: nanoid: Predictable ID generation due to integer overflow (CVE-2026-73086) * nodejs-sanitize-html: nanoid: Predictable ID generation due to integer overflow (CVE-2026-73086) * nodejs-compression-webpack-plugin: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899) * nodejs-mini-css-extract-plugin: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899) * nodejs-webpack: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899) * nodejs-compression-webpack-plugin: fast-uri: Host confusion via skipped IDN canonicalization (CVE-2026-75931) * nodejs-mini-css-extract-plugin: fast-uri: Host confusion via skipped IDN canonicalization (CVE-2026-75931) * nodejs-webpack: fast-uri: Host confusion via skipped IDN canonicalization (CVE-2026-75931) * nodejs-compression-webpack-plugin: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975) * nodejs-mini-css-extract-plugin: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975) * nodejs-webpack: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975) * python3.12-gitpython: GitPython: Arbitrary file read via TagReference.create() (CVE-2026-78679) * rubygem-katello: Katello Content View History API Cross-Organization Authorization Bypass (CVE-2026-79654) * nodejs-compression-webpack-plugin: fast-uri: Authority Injection via Unvalidated Port Serialization (CVE-2026-84292) * nodejs-mini-css-extract-plugin: fast-uri: Authority Injection via Unvalidated Port Serialization (CVE-2026-84292) * nodejs-webpack: fast-uri: Authority Injection via Unvalidated Port Serialization (CVE-2026-84292) * nodejs-compression-webpack-plugin: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies (CVE-2026-84394) * nodejs-mini-css-extract-plugin: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies (CVE-2026-84394) * nodejs-webpack: fast-uri: Host confusion via unbalanced URI brackets can bypa

Join the discussion

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-controller: GitPython: Remote Code Execution via Git directory impersonation (CVE-2026-87817) * automation-controller: Job template enumeration via unauthenticated Bitbucket webhook oracle (CVE-2026-84717) * automation-controller: Command argument injection via SystemJob extra_vars (CVE-2026-84724) * automation-controller: Masked credential data disclosure via workflow job node artifact search (CVE-2026-84720) * automation-controller: Instance-group privilege escalation via workflow job template copy (CVE-2026-84719) * automation-controller: Audit log falsification via unrestricted X-Forwarded-For trust (CVE-2026-84718) * automation-controller: Mesh certificate issuance for arbitrary hostnames via install bundle (CVE-2026-84716) * automation-controller: Template injection via sanitize_jinja regex bypass (CVE-2026-84714) * automation-controller: Automation mesh topology disclosure via unauthenticated ping endpoint (CVE-2026-84712) * automation-controller: Arbitrary file read via Project scm_branch git argument injection (CVE-2026-84711) * automation-controller: Denial of service via credential type injector Jinja rendering (CVE-2026-84709) * automation-controller: Control-plane secret exposure via container group pod spec override (CVE-2026-84708) * automation-controller: Unauthorized job output disclosure via host filter query traversal (CVE-2026-84707) * automation-controller: Code execution via credential type environment-injector blocklist bypass (CVE-2026-84706) * automation-controller: Cross-tenant credential exposure via execution environment binding (CVE-2026-84703) * automation-controller: Cross-tenant execution privilege bypass via workflow job template node patch (CVE-2026-84692) * automation-controller: Secret key and database credential disclosure via format-string injection (CVE-2026-84691) * automation-controller: Cross-tenant job hijack via Bulk Job Launch node reference (CVE-2026-84689) * automation-controller: Credential token disclosure via notification template type-switch replay (CVE-2026-84686) * automation-controller: Privilege escalation via constructed inventory attachment (CVE-2026-84684) * automation-controller: Stored cross-site scripting via ANSI hyperlink sequence in job output (CVE-2026-84683) * automation-controller: Credential-use privilege escalation via organization Galaxy credential attachment (CVE-2026-84680) * automation-controller: Arbitrary environment variable injection via AWX_TASK_ENV setting (CVE-2026-84679) * automation-controller: Server-side request forgery via Thycotic Secret Server credential test (CVE-2026-84644) * automation-controller: Cross-organization credential exposure via Project signature-validation binding (CVE-2026-84643) * automation-controller: Instance-group privilege escalation via Schedule and workflow node attachment (CVE-2026-84638) * automation-controller: Remote code execution via Project scm_url git argument injection (CVE-2026-84502) * automation-controller: Survey password disclosure via validation error message (CVE-2026-84499) * automation-controller: Unauthenticated scheduler-trigger endpoint exposure (regression) (CVE-2026-84486) * automation-controller: Privilege escalation via provisioning-callback host-match bypass (CVE-2026-84474) * automation-controller: Instance-group privilege escalation via Bulk Job Launch permission check (CVE-2026-84470) * automation-controller: GitPython: Arbitrary file read via TagReference.create() (CVE-2026-78679) * automation-controller: awx: Privilege escalation to OpenShift namespace via pod_spec_override injection in container groups (CVE-2026-75884) * automation-controller: Command-line argument injection via ad hoc command limit field (CVE-2026-71465) * automation-controller: Git argument-injection guard bypass via Schedule scm_branch prompt (CVE-2026-71464) * automation-controller: Stack trace disclosure via notification-template Jinja whitelist bypass (CVE-2026-71463) * automation-controller: Filesystem path-existence oracle via CUSTOM_VENV_PATHS validation (CVE-2026-71462) * automation-controller: Cross-tenant job event data exposure via missing RBAC check (CVE-2026-71459) * automation-controller: Cross-tenant resource enumeration via Named-URL 404 response oracle (CVE-2026-71458) * automation-controller: Unrestricted subscription and license information disclosure (CVE-2026-71460) * automation-controller: GitPython: Command Injection via Git option

Join the discussion

Red Hat Lightspeed in Satellite analyzes system health and configuration by applying predefined rules to a small set of local data, such as installed packages, running services, and configuration settings.

Join the discussion

CVE-2026-39820 is a critical security vulnerability affecting Red Hat build of MicroShift 4.19, a lightweight Kubernetes orchestration solution for edge devices. The vulnerability involves a denial of service (DoS) condition triggered via crafted email inputs in the Go net/mail package. Red Hat has released updated packages and container images to address this issue. Users of affected versions are advised to apply the provided patches to mitigate the risk.

Join the discussion

GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arbitrary files, with contents returned in the annotated tag message.

Join the discussion

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

Join the discussion
0

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-controller: notification backends allow SSRF and credential leakage (CVE-2026-71366) * automation-controller: webhook status callback SSRF leaks the Git PAT (CVE-2026-71365) * automation-controller: project archive extraction allows path traversal file writes (CVE-2026-71364) * automation-controller: AIOHTTP: Denial of Service via malformed HTTP responses (CVE-2026-69244) * automation-controller: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886) * automation-controller: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() (CVE-2026-34993) * automation-controller: path traversal via YAML !include directive (CVE-2026-52902) * automation-controller: JWCrypto: Memory exhaustion via crafted compressed JWE tokens (CVE-2026-39373) * automation-gateway: path Traversal via unsanitized prefix/postfix enables directory escape (CVE-2026-44705) * python3.12-aiohttp: HTTP Request Smuggling via WebSocket Upgrade (CVE-2026-69243) * python3.12-aiohttp: Denial of Service via malformed HTTP responses (CVE-2026-69244) * python3.12-django: Remote code execution via GeoDjango spatial lookups (CVE-2026-15307) * python3.12-gitpython: Command Injection via Git option prefix abbreviation (CVE-2026-67325) * python3.12-gitpython: Arbitrary Code Execution via Joined Short Options Bypass (CVE-2026-67324) * python3.12-gitpython: Arbitrary code execution via command injection due to unguarded Git options (CVE-2026-67323) * python3.12-gitpython: Environment variable exfiltration via attacker-controlled clone URL (CVE-2026-67322) * python3.12-gitpython: Arbitrary file overwrite and read via unsafe git option forwarding (CVE-2026-73620) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. For details about this release, refer to the release notes listed in the References section.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Tag: cve-2026-78679
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses