Red Hat Product Errata RHSA-2026:10133 - Security Advisory Issued: 2026-04-23 Updated: 2026-04-23 RHSA-2026:10133 - Security Advisory Overview Updated Packages Synopsis Important: golang-github-openprinting-ipp-usb security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for golang-github-openprinting-ipp-usb is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description HTTP reverse proxy, backed by IPP-over-USB connection to device. It enables driverless support for USB devices capable of using IPP-over-USB protocol. Security Fix(es): net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2445356 - CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url CVEs CVE-2026-25679 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM golang-github-openprinting-ipp-usb-0.9.27-3.el10_0.3.src.rpm SHA-256: 302ebc7ad60a0a2be4766f429961e749b8d044d49544e278ac2a13de514149b9 x86_64 golang-github-openprinting-ipp-usb-debugsource-0.9.27-3.el10_0.3.x86_64.rpm SHA-256: 4d46a41909597fd33a89949e9e8332886801f1e0b93074f8824d020ed3c2cd67 ipp-usb-0.9.27-3.el10_0.3.x86_64.rpm SHA-256: 576f2d270584ec344c922ca2ec509d901482f247036106f9284367cf4e3cdae6 ipp-usb-debuginfo-0.9.27-3.el10_0.3.x86_64.rpm SHA-256: d760f8fe5b57bcfa3ee6f625d249883f85e8cd2b65eba3f1f2aea6da59f40720 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 SRPM golang-github-openprinting-ipp-usb-0.9.27-3.el10_0.3.src.rpm SHA-256: 302ebc7ad60a0a2be4766f429961e749b8d044d49544e278ac2a13de514149b9 s390x golang-github-openprinting-ipp-usb-debugsource-0.9.27-3.el10_0.3.s390x.rpm SHA-256: 50a41de2e3f62a7c32fcd12ac1fa18815e8debaa7a613eb3ea473db81c93a56c ipp-usb-0.9.27-3.el10_0.3.s390x.rpm SHA-256: 76059032c19af13b54674fc8f6fe7cf0d87a782440612a3abcfaef8f1f57f5b6 ipp-usb-debuginfo-0.9.27-3.el10_0.3.s390x.rpm SHA-256: c04ba0d63d6ea444c6b56452bba775193553a974073b53214185cfc6b3f27a8d Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 SRPM golang-github-openprinting-ipp-usb-0.9.27-3.el10_0.3.src.rpm SHA-256: 302ebc7ad60a0a2be4766f429961e749b8d044d49544e278ac2a13de514149b9 ppc64le golang-github-openprinting-ipp-usb-debugsource-0.9.27-3.el10_0.3.ppc64le.rpm SHA-256: ed679afaba2716f17e74cfb93f00d9097eee627e68f6a076f11746d6a8603724 ipp-usb-0.9.27-3.el10_0.3.ppc64le.rpm SHA-256: c5c9b274a4a472b89d8ce3164f4e4d61b961bb698634e8de9966716c39462fe5 ipp-usb-debuginfo-0.9.27-3.el10_0.3.ppc64le.rpm SHA-256: c5f957cdcd19288bca85473dfc770d17fd52eb944d5ff0a2e1b03a8e592e04b2 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 SRPM golang-github-openprinting-ipp-usb-0.9.27-3.el10_0.3.src.rpm SHA-256: 302ebc7ad60a0a2be4766f429961e749b8d044d49544e278ac2a13de514149b9 aarch64 golang-github-openprinting-ipp-usb-debugsource-0.9.27-3.el10_0.3.aarch64.rpm SHA-256: 7f36c197139f8b95d2aa4d4251c0108722ee705aca7a234ede3e966db4fae6a6 ipp-usb-0.9.27-3.el10_0.3.aarch64.rpm SHA-256: dcd5d08f2554161a301654cdbf3d82064fbda62d8b3c5ca34e932554f9c25422 ipp-usb-debuginfo-0.9.27-3.el10_0.3.aarch64.rpm SHA-256: cb5d232e3248e2b6ac6f1d09cbdcb22f34107c12ecbbf46012c8682cf73bef74 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 SRPM golang-github-openprinting-ipp-usb-0.9.27-3.el10_0.3.src.rpm SHA-256: 302ebc7ad60a0a2be4766f429961e749b8d044d49544e278ac2a13de514149b9 aarch64 golang-github-openprinting-ipp-usb-debugsource-0.9.27-3.el10_0.3.aarch64.rpm SHA-256: 7f36c197139f8b95d2aa4d4251c0108722ee705aca7a234ede3e966db4fae6a6 ipp-usb-0.9.27-3.el10_0.3.aarch64.rpm SHA-256: dcd5d08f2554161a301654cdbf3d82064fbda62d8b3c5ca34e932554f9c25422 ipp-usb-debuginfo-0.9.27-3.el10_0.3.aarch64.rpm SHA-256: cb5d232e3248e2b6ac6f1d09cbdcb22f34107c12ecbbf46012c8682cf73bef74 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 SRPM golang-github-openprinting-ipp-usb-0.9.27-3.el10_0.3.src.rpm SHA-256: 302ebc7ad60a0a2be4766f429961e749b8d044d49544e278ac2a13de514149b9 s390x golang-github-openprinting-ipp-usb-debugsource-0.9.27-3.el10_0.3.s390x.rpm SHA-256: 50a41de2e3f62a7c32fcd12ac1fa18815e8debaa7a613eb3ea473db81c93a56c ipp-usb-0.9.27-3.el10_0.3.s390x.rpm SHA-256: 76059032c19af13b54674fc8f6fe7cf0d87a782440612a3abcfaef8f1f57f5b6 ipp-usb-debuginfo-0.9.27-3.el10_0.3.s390x.rpm SHA-256: c04ba0d63d6ea444c6b56452bba775193553a974073b53214185cfc6b3f27a8d Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 SRPM golang-github-openprinting-ipp-usb-0.9.27-3.el10_0.3.src.rpm SHA-256: 302ebc7ad60a0a2be4766f429961e749b8d044d49544e278ac2a13de514149b9 ppc64le golang-github-openprinting-ipp-usb-debugsource-0.9.27-3.el10_0.3.ppc64le.rpm SHA-256: ed679afaba2716f17e74cfb93f00d9097eee627e68f6a076f11746d6a8603724 ipp-usb-0.9.27-3.el10_0.3.ppc64le.rpm SHA-256: c5c9b274a4a472b89d8ce3164f4e4d61b961bb698634e8de9966716c39462fe5 ipp-usb-debuginfo-0.9.27-3.el10_0.3.ppc64le.rpm SHA-256: c5f957cdcd19288bca85473dfc770d17fd52eb944d5ff0a2e1b03a8e592e04b2 Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 SRPM golang-github-openprinting-ipp-usb-0.9.27-3.el10_0.3.src.rpm SHA-256: 302ebc7ad60a0a2be4766f429961e749b8d044d49544e278ac2a13de514149b9 x86_64 golang-github-openprinting-ipp-usb-debugsource-0.9.27-3.el10_0.3.x86_64.rpm SHA-256: 4d46a41909597fd33a89949e9e8332886801f1e0b93074f8824d020ed3c2cd67 ipp-usb-0.9.27-3.el10_0.3.x86_64.rpm SHA-256: 576f2d270584ec344c922ca2ec509d901482f247036106f9284367cf4e3cdae6 ipp-usb-debuginfo-0.9.27-3.el10_0.3.x86_64.rpm SHA-256: d760f8fe5b57bcfa3ee6f625d249883f85e8cd2b65eba3f1f2aea6da59f40720 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
A vulnerability (CVE-2026-25679, CVSS 7.5 HIGH) in the `net/url` package of Go allows incorrect parsing of IPv6 host literals. The flaw affects the `golang-github-openprinting-ipp-usb` package for Red Hat Enterprise Linux 10.0 EUS, which provides an HTTP reverse proxy for IPP-over-USB printing. The underlying Go versions affected are prior to 1.25.8 and version 1.26.0, requiring an update to the patched package version provided in the Red Hat advisory.