RHSA-2026:63386
Advisory lineage Upstream: 9 Downstream: 0
Published: 04 Sept 2026, 10:14
Last modified:19 Sept 2026, 10:13
Vulnerability Summary
Overall Risk (default)
medium
32/100 CVSS Score
8.1 HIGH
3.1 (osv_red_hat)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
04 Sept 2026, 10:14
Published
Vulnerability first disclosed
19 Sept 2026, 10:13
Last Modified
Vulnerability information updated
Description
Red Hat Security Advisory: Satellite 6.18.9 Async Update
CVSS Metrics
- v3.1•HIGH•Score: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- redhat•ansible-core
< 1:2.16.19-1.el9sat
- redhat•ansible-test
< 1:2.16.19-1.el9sat
- redhat•openvox-server
< 0:8.15.2-1.el9sat
- redhat•pulpcore-obsolete-packages
< 0:1.3.1-5.el9pc
- redhat•python3.12-aiohttp
< 0:3.14.3-1.el9pc
- redhat•python3.12-aiohttp-debuginfo
< 0:3.14.3-1.el9pc
- redhat•python3.12-aiohttp-debugsource
< 0:3.14.3-1.el9pc
- redhat•python3.12-pulpcore
< 0:3.73.30-3.el9pc
- redhat•rubygem-jwt
< 0:2.10.3-1.el9sat
References (73)
- https://access.redhat.com/errata/RHSA-2026:63386
- https://access.redhat.com/security/updates/classification/#important
- https://bugzilla.redhat.com/show_bug.cgi?id=2484099
- https://bugzilla.redhat.com/show_bug.cgi?id=2485379
- https://bugzilla.redhat.com/show_bug.cgi?id=2492015
- https://bugzilla.redhat.com/show_bug.cgi?id=2499928
- https://bugzilla.redhat.com/show_bug.cgi?id=2500739
- https://bugzilla.redhat.com/show_bug.cgi?id=2503724
- https://bugzilla.redhat.com/show_bug.cgi?id=2510825
- https://bugzilla.redhat.com/show_bug.cgi?id=2510831
- https://bugzilla.redhat.com/show_bug.cgi?id=2511026
- https://issues.redhat.com/browse/SAT-46099
- https://issues.redhat.com/browse/SAT-48690
- https://issues.redhat.com/browse/SAT-48691
- https://issues.redhat.com/browse/SAT-48692
- https://issues.redhat.com/browse/SAT-48693
- https://issues.redhat.com/browse/SAT-48697
- https://issues.redhat.com/browse/SAT-49372
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_63386.json
- https://access.redhat.com/security/cve/CVE-2026-10051
- https://www.cve.org/CVERecord?id=CVE-2026-10051
- https://nvd.nist.gov/vuln/detail/CVE-2026-10051
- https://gitlab.eclipse.org/security/cve-assignment/-/work_items/119
- https://access.redhat.com/security/cve/CVE-2026-11332
- https://www.cve.org/CVERecord?id=CVE-2026-11332
- https://nvd.nist.gov/vuln/detail/CVE-2026-11332
- https://github.com/ansible/ansible
- https://access.redhat.com/security/cve/CVE-2026-16493
- https://www.cve.org/CVERecord?id=CVE-2026-16493
- https://nvd.nist.gov/vuln/detail/CVE-2026-16493
- https://access.redhat.com/security/cve/CVE-2026-34993
- https://www.cve.org/CVERecord?id=CVE-2026-34993
- https://nvd.nist.gov/vuln/detail/CVE-2026-34993
- https://github.com/aio-libs/aiohttp/commit/dcf40f30637e8752c76781cf6703b5a236749a00
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jg22-mg44-37j8
- https://access.redhat.com/security/cve/CVE-2026-45363
- https://www.cve.org/CVERecord?id=CVE-2026-45363
- https://nvd.nist.gov/vuln/detail/CVE-2026-45363
- https://github.com/jwt/ruby-jwt/commit/9820020869ad147b941e49d96ab8beba35532964
- https://github.com/jwt/ruby-jwt/commit/db560b769a07bd9724e77ff505011ac01872106f
- https://github.com/jwt/ruby-jwt/releases/tag/v2.10.3
- https://github.com/jwt/ruby-jwt/releases/tag/v3.2.0
- https://github.com/jwt/ruby-jwt/security/advisories/GHSA-c32j-vqhx-rx3x
- https://access.redhat.com/security/cve/CVE-2026-54512
- https://www.cve.org/CVERecord?id=CVE-2026-54512
- https://nvd.nist.gov/vuln/detail/CVE-2026-54512
- https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5
- https://github.com/FasterXML/jackson-databind/issues/5988
- https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm
- https://access.redhat.com/security/cve/CVE-2026-68494
- https://www.cve.org/CVERecord?id=CVE-2026-68494
- https://nvd.nist.gov/vuln/detail/CVE-2026-68494
- https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd
- https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641
- https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8
- https://github.com/FasterXML/jackson-core/pull/1611
- https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9
- https://github.com/advisories/GHSA-72hv-8253-57qq
- https://www.cve.org/CVERecord?id=CVE-2026-18401
- https://access.redhat.com/security/cve/CVE-2026-69243
- https://www.cve.org/CVERecord?id=CVE-2026-69243
- https://nvd.nist.gov/vuln/detail/CVE-2026-69243
- https://github.com/aio-libs/aiohttp/commit/6ae358f0983c3f4d6f67692b2f8e65dc8e091c98
- https://github.com/aio-libs/aiohttp/pull/13017
- https://github.com/aio-libs/aiohttp/releases/tag/v3.14.2
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mfx4-hv73-q22v
- https://access.redhat.com/security/cve/CVE-2026-69244
- https://www.cve.org/CVERecord?id=CVE-2026-69244
- https://nvd.nist.gov/vuln/detail/CVE-2026-69244
- https://github.com/aio-libs/aiohttp/commit/49f65d54150397892f7bcc4aae887767d51c322d
- https://github.com/aio-libs/aiohttp/pull/13223
- https://github.com/aio-libs/aiohttp/releases/tag/v3.14.3
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-cq5v-8q36-5273