- What: Security update for resource-agents in Red Hat Enterprise Linux
- Impact: Systems using Pacemaker and RGManager may be vulnerable to unspecified security issues
Red Hat Product Errata RHSA-2026:47092 - Security Advisory Issued: 2026-07-28 Updated: 2026-07-28 RHSA-2026:47092 - Security Advisory Overview Updated Packages Synopsis Moderate: resource-agents security update Type/Severity Security Advisory: Moderate Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for resource-agents is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The resource-agents packages provide the Pacemaker and RGManager service managers with a set of scripts. These scripts interface with several services to allow operating in a high-availability (HA) environment. Security Fix(es): urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers (CVE-2026-44431) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux High Availability for x86_64 - Extended Life Cycle Long Life 8.6 x86_64 Fixes BZ - 2477167 - CVE-2026-44431 urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers CVEs CVE-2026-44431 References https://access.redhat.com/security/updates/classification/#moderate Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux High Availability for x86_64 - Extended Life Cycle Long Life 8.6 SRPM resource-agents-4.9.0-16.el8_6.23.src.rpm SHA-256: f95700c600e4d8bd7361425a04c85a837a02d4f235d3953bb12a4d9061e82f8a x86_64 resource-agents-4.9.0-16.el8_6.23.x86_64.rpm SHA-256: 7516da0536f317963f5824a28c9e980bdd2a7439f30afbf0bb5a33180f928494 resource-agents-aliyun-4.9.0-16.el8_6.23.x86_64.rpm SHA-256: 56d2f3cf66e255962f732a7f94cb9f33e34a34dabeff71c2953d6acbe445c1ba resource-agents-aliyun-debuginfo-4.9.0-16.el8_6.23.x86_64.rpm SHA-256: 41c24332fb14eeb9a2e1ff616d386e0c747a99fe30de4c9a1fea19b694879299 resource-agents-debuginfo-4.9.0-16.el8_6.23.x86_64.rpm SHA-256: dffb1e8e7f096dfdc7c39b1d057bcd82e25d66f0d1870739dc5f5af16c9ce22f resource-agents-debugsource-4.9.0-16.el8_6.23.x86_64.rpm SHA-256: ad6d8ed35a8fb6078bd07e0289e7d17d910501d49e6ae1cdcad079f98b1c0f30 resource-agents-gcp-4.9.0-16.el8_6.23.x86_64.rpm SHA-256: 6add2f7e8dc674bea797302e6190eac3f957eb0b566abe7ceb5dce8c86c95561 resource-agents-paf-4.9.0-16.el8_6.23.x86_64.rpm SHA-256: 795c8fcc061d4faec5dc9c8c14b2960a7d16ef921c3c7d5f83118ec42ecb94de The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .