RHSA-2026:54517
Advisory lineage Upstream: 9 Downstream: 0
Published: 13 Aug 2026, 10:17
Last modified:16 Sept 2026, 10:11
Vulnerability Summary
Overall Risk (default)
medium
30/100 CVSS Score
7.5 HIGH
3.1 (osv_red_hat)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
13 Aug 2026, 10:17
Published
Vulnerability first disclosed
16 Sept 2026, 10:11
Last Modified
Vulnerability information updated
Description
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Systems
- redhat•grafana13.1
< 0:13.1.3-0.1.1.hum1
References (60)
- https://access.redhat.com/errata/RHSA-2026:54517
- https://access.redhat.com/security/cve/CVE-2026-73088
- https://access.redhat.com/security/cve/CVE-2026-73089
- https://access.redhat.com/security/updates/classification/
- https://images.redhat.com/
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54517.json
- https://bugzilla.redhat.com/show_bug.cgi?id=2514177
- https://www.cve.org/CVERecord?id=CVE-2026-73088
- https://nvd.nist.gov/vuln/detail/CVE-2026-73088
- https://github.com/browserslist/browserslist/commit/f9914ad9effc865ccc27d816255625890b31ca51
- https://github.com/browserslist/browserslist/releases/tag/4.28.7
- https://github.com/browserslist/browserslist/security/advisories/GHSA-73wf-gq98-2v4g
- https://bugzilla.redhat.com/show_bug.cgi?id=2514195
- https://www.cve.org/CVERecord?id=CVE-2026-73089
- https://nvd.nist.gov/vuln/detail/CVE-2026-73089
- https://github.com/browserslist/browserslist/commit/f2931a3ff2a3a31abf84ef01a7400b270aad6405
- https://github.com/browserslist/browserslist/security/advisories/GHSA-c83g-rgw3-j3cx
- https://access.redhat.com/security/cve/CVE-2026-45819
- https://bugzilla.redhat.com/show_bug.cgi?id=2515240
- https://www.cve.org/CVERecord?id=CVE-2026-45819
- https://nvd.nist.gov/vuln/detail/CVE-2026-45819
- https://github.com/web-platform-dx/baseline-browser-mapping/blob/b7881aa61c8a057e24468ab5ee18c5ecedbbf691/src/index.ts#L142
- https://github.com/web-platform-dx/baseline-browser-mapping/pull/137/changes#diff-7ae45ad102eab3b6d7e7896acd08c427a9b25b346470d7bc6507b6481575d519
- https://www.npmjs.com/package/baseline-browser-mapping
- https://access.redhat.com/security/cve/CVE-2026-16221
- https://access.redhat.com/security/cve/CVE-2026-65904
- https://bugzilla.redhat.com/show_bug.cgi?id=2502307
- https://www.cve.org/CVERecord?id=CVE-2026-16221
- https://nvd.nist.gov/vuln/detail/CVE-2026-16221
- https://cna.openjsf.org/security-advisories.html
- https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx
- https://bugzilla.redhat.com/show_bug.cgi?id=2506426
- https://www.cve.org/CVERecord?id=CVE-2026-65904
- https://nvd.nist.gov/vuln/detail/CVE-2026-65904
- https://github.com/cure53/DOMPurify/security/advisories/GHSA-4w3q-35jp-p934
- https://www.vulncheck.com/advisories/dompurify-before-cross-site-scripting-via-in-place-mode
- https://access.redhat.com/security/cve/CVE-2026-65912
- https://access.redhat.com/security/cve/CVE-2026-65911
- https://access.redhat.com/security/cve/CVE-2026-65914
- https://access.redhat.com/security/cve/CVE-2026-65913
- https://bugzilla.redhat.com/show_bug.cgi?id=2506434
- https://www.cve.org/CVERecord?id=CVE-2026-65911
- https://nvd.nist.gov/vuln/detail/CVE-2026-65911
- https://github.com/cure53/DOMPurify/security/advisories/GHSA-9p3w-6h5p-cv75
- https://www.vulncheck.com/advisories/dompurify-before-xss-via-add-attr-add-tags-state-leakage
- https://bugzilla.redhat.com/show_bug.cgi?id=2506427
- https://www.cve.org/CVERecord?id=CVE-2026-65912
- https://nvd.nist.gov/vuln/detail/CVE-2026-65912
- https://github.com/cure53/DOMPurify/security/advisories/GHSA-cjmm-f4jc-qw8r
- https://www.vulncheck.com/advisories/dompurify-before-uri-validation-bypass-via-add-attr
- https://bugzilla.redhat.com/show_bug.cgi?id=2506429
- https://www.cve.org/CVERecord?id=CVE-2026-65913
- https://nvd.nist.gov/vuln/detail/CVE-2026-65913
- https://github.com/cure53/DOMPurify/security/advisories/GHSA-cj63-jhhr-wcxv
- https://www.vulncheck.com/advisories/dompurify-before-prototype-pollution-via-use-profiles
- https://bugzilla.redhat.com/show_bug.cgi?id=2506430
- https://www.cve.org/CVERecord?id=CVE-2026-65914
- https://nvd.nist.gov/vuln/detail/CVE-2026-65914
- https://github.com/cure53/DOMPurify/security/advisories/GHSA-h8r8-wccr-v5f2
- https://www.vulncheck.com/advisories/dompurify-before-mutation-xss-via-re-contextualization