SB2026092458 - Red Hat Enterprise Linux 10 update for cockpit-image-builder
Published: September 24, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 vulnerabilities.
1) Double Decoding of the Same Data (CVE-ID: CVE-2026-75899)
CWE-ID: CWE-174 - Double Decoding of the Same Data
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform server-side request forgery.
The vulnerability exists due to double decoding of the same data in the fast-uri normalize() and resolve() hostname handling logic when processing a URI with a nested percent-encoded host. A remote attacker can supply a specially crafted URI to perform server-side request forgery.
The issue can cause the hostname to be interpreted as a different destination than the input appears to contain, including internal addresses such as loopback or a cloud metadata endpoint.
2) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-75975)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass host-policy checks and perform server-side request forgery.
The vulnerability exists due to improper input validation in the IPv6 literal normalization logic of fast-uri when normalizing untrusted URLs containing malformed bracketed IPv6 literals. A remote attacker can supply a specially crafted URL to bypass host-policy checks and perform server-side request forgery.
Malformed bracketed IPv6 literals with invalid trailing text are silently truncated to different valid IPv6 addresses, and parse().error is not set for these inputs.
3) Improper Handling of URL Encoding (Hex Encoding) (CVE-ID: CVE-2026-76172)
CWE-ID: CWE-177 - Improper Handling of URL Encoding (Hex Encoding)
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass host validation and inject carriage return and line feed characters into output.
The vulnerability exists due to improper handling of url encoding in the scheme component normalization logic when normalizing or resolving untrusted URLs. A remote attacker can supply a specially crafted percent-encoded scheme to bypass host validation and inject carriage return and line feed characters into output.
Applications that treat a missing authority as same-origin during redirect checks, host allowlist enforcement, or outbound request decisions are particularly exposed.
4) Improper Encoding or Escaping of Output (CVE-ID: CVE-2026-84292)
CWE-ID: CWE-116 - Improper Encoding or Escaping of Output
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to redirect URI authority to an attacker-controlled host.
The vulnerability exists due to improper encoding or escaping of output in the authority recomposition logic when serializing a URI with an unvalidated port component. A remote attacker can supply a non-digit port value containing authority delimiters to redirect URI authority to an attacker-controlled host.
The issue is reachable through the object forms of serialize(), normalize(), and equal(). A port value obtained from parse() is always digits and is not affected.
Remediation
Install update from vendor's website.