RHSA-2026:14874
Advisory lineage Upstream: 5 Downstream: 0
Published: 08 May 2026, 10:05
Last modified:19 Sept 2026, 10:06
Vulnerability Summary
Overall Risk (default)
medium
33/100 CVSS Score
8.3 HIGH
3.1 (osv_red_hat)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
08 May 2026, 10:05
Published
Vulnerability first disclosed
19 Sept 2026, 10:06
Last Modified
Vulnerability information updated
Description
Red Hat Security Advisory: Satellite 6.16.8 Async Update
CVSS Metrics
- v3.1•HIGH•Score: 8.3CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Systems
- redhat•candlepin
< 0:4.4.25-1.el8sat | < 0:4.4.25-1.el9sat
- redhat•candlepin-selinux
< 0:4.4.25-1.el8sat | < 0:4.4.25-1.el9sat
- redhat•python-markdown
< 0:3.8.2-1.el8pc | < 0:3.8.2-1.el9pc
- redhat•python-pillow
< 0:12.1.1-1.el8pc | < 0:12.1.1-1.el9pc
- redhat•python-pillow-debugsource
< 0:12.1.1-1.el8pc | < 0:12.1.1-1.el9pc
- redhat•python-pyOpenSSL
< 0:24.1.0-2.el8pc | < 0:24.1.0-2.el9pc
- redhat•python3.11-markdown
< 0:3.8.2-1.el8pc | < 0:3.8.2-1.el9pc
- redhat•python3.11-pillow
< 0:12.1.1-1.el8pc | < 0:12.1.1-1.el9pc
- redhat•python3.11-pillow-debuginfo
< 0:12.1.1-1.el8pc | < 0:12.1.1-1.el9pc
- redhat•python3.11-pyOpenSSL
< 0:24.1.0-2.el8pc | < 0:24.1.0-2.el9pc
- redhat•rubygem-activesupport
< 0:6.1.7.8-2.el8sat | < 0:6.1.7.8-2.el9sat
References (50)
- https://access.redhat.com/errata/RHSA-2026:14874
- https://access.redhat.com/security/updates/classification/#important
- https://bugzilla.redhat.com/show_bug.cgi?id=2439170
- https://bugzilla.redhat.com/show_bug.cgi?id=2442671
- https://bugzilla.redhat.com/show_bug.cgi?id=2444839
- https://bugzilla.redhat.com/show_bug.cgi?id=2448503
- https://bugzilla.redhat.com/show_bug.cgi?id=2450551
- https://issues.redhat.com/browse/SAT-43834
- https://issues.redhat.com/browse/SAT-44030
- https://issues.redhat.com/browse/SAT-44031
- https://issues.redhat.com/browse/SAT-44032
- https://issues.redhat.com/browse/SAT-44033
- https://issues.redhat.com/browse/SAT-44034
- https://issues.redhat.com/browse/SAT-44035
- https://issues.redhat.com/browse/SAT-44036
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_14874.json
- https://access.redhat.com/security/cve/CVE-2025-69534
- https://www.cve.org/CVERecord?id=CVE-2025-69534
- https://nvd.nist.gov/vuln/detail/CVE-2025-69534
- https://github.com/Python-Markdown/markdown
- https://github.com/Python-Markdown/markdown/actions/runs/15736122892
- https://github.com/Python-Markdown/markdown/issues/1534
- https://access.redhat.com/security/cve/CVE-2026-25990
- https://www.cve.org/CVERecord?id=CVE-2026-25990
- https://nvd.nist.gov/vuln/detail/CVE-2026-25990
- https://github.com/python-pillow/Pillow/commit/9000313cc5d4a31bdcdd6d7f0781101abab553aa
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc
- https://access.redhat.com/security/cve/CVE-2026-27459
- https://www.cve.org/CVERecord?id=CVE-2026-27459
- https://nvd.nist.gov/vuln/detail/CVE-2026-27459
- https://github.com/pyca/pyopenssl/blob/358cbf29c4e364c59930e53a270116249581eaa3/CHANGELOG.rst
- https://github.com/pyca/pyopenssl/commit/57f09bb4bb051d3bc2a1abd36e9525313d5cd408
- https://github.com/pyca/pyopenssl/security/advisories/GHSA-5pwr-322w-8jr4
- https://access.redhat.com/security/cve/CVE-2026-27727
- https://www.cve.org/CVERecord?id=CVE-2026-27727
- https://nvd.nist.gov/vuln/detail/CVE-2026-27727
- https://github.com/swaldman/mchange-commons-java/security/advisories/GHSA-m2cm-222f-qw44
- https://mogwailabs.de/en/blog/2025/02/c3p0-you-little-rascal
- https://www.mchange.com/projects/c3p0/#configuring_security
- https://www.mchange.com/projects/c3p0/#security-note
- https://access.redhat.com/security/cve/CVE-2026-33176
- https://www.cve.org/CVERecord?id=CVE-2026-33176
- https://nvd.nist.gov/vuln/detail/CVE-2026-33176
- https://github.com/rails/rails/commit/19dbab51ca086a657bb86458042bc44314916bcb
- https://github.com/rails/rails/commit/ebd6be18120d1136511eb516338e27af25ac0a1a
- https://github.com/rails/rails/commit/ee2c59e730e5b8faed502cd2c573109df093f856
- https://github.com/rails/rails/releases/tag/v7.2.3.1
- https://github.com/rails/rails/releases/tag/v8.0.4.1
- https://github.com/rails/rails/releases/tag/v8.1.2.1
- https://github.com/rails/rails/security/advisories/GHSA-2j26-frm8-cmj9