Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:59360: Important: Apicurio Registry (container images) release and security update [ 3.3.1 GA ]

This security update for Red Hat's Apicurio Registry container images addresses six vulnerabilities, including multiple high-severity flaws (CVE-2026-12975 CVSS 8.5, CVE-2026-12992 CVSS 7.4) enabling Server-Side Request Forgery (SSRF), XML External Entity (XXE) attacks, and denial of service via unhardened XML parsers. The affected versions are Red Hat build of Apicurio Registry 3.0 through 3.2. The fix is provided in the updated container images for version 3.3.1 GA.
Read Full Article →

Red Hat Product Errata RHSA-2026:59360 - Security Advisory Issued: 2026-08-25 Updated: 2026-08-25 RHSA-2026:59360 - Security Advisory Overview Synopsis Important: Apicurio Registry (container images) release and security update [ 3.3.1 GA ] Type/Severity Security Advisory: Important Topic An update to the images for Red Hat build of Apicurio Registry is now available from the Red Hat Container Catalog. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description This release of Red Hat build of Apicurio Registry 3.3.1 GA includes the following security fixes. Security Fix(es): DOMPurify: Cross-site scripting vulnerability allows code execution [rhint-serv-3] (CVE-2026-49978) apicurio-registry: Unhardened SAXParser in content-type detection leads to blind XXE / SSRF / billion-laughs DoS [rhint-serv-3] (CVE-2026-12975) apicurio-registry: SSRF via wsdl4j import dereference in WSDL FULL validation [rhint-serv-3] (CVE-2026-12992) apicurio-registry: XML entity-expansion denial of service via internal DTD subset [rhint-serv-3] (CVE-2026-12993) Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name [rhint-serv-3] (CVE-2026-44496) DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization [rhint-serv-3] (CVE-2026-41240) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Integration - Service Registry 1 x86_64 Fixes BZ - 2461147 - CVE-2026-41240 DOMPurify: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization BZ - 2487943 - CVE-2026-44496 axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name BZ - 2491688 - CVE-2026-12975 Apicurio/apicurio-registry: apicurio-registry: Unhardened SAXParser in content-type detection leads to blind XXE / SSRF / billion-laughs DoS BZ - 2491691 - CVE-2026-12992 Apicurio/apicurio-registry: apicurio-registry: SSRF via wsdl4j import dereference in WSDL FULL validation BZ - 2491692 - CVE-2026-12993 Apicurio/apicurio-registry: apicurio-registry: XML entity-expansion denial of service via internal DTD subset BZ - 2500695 - CVE-2026-49978 dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution CVEs CVE-2026-12975 CVE-2026-12992 CVE-2026-12993 CVE-2026-41240 CVE-2026-44496 CVE-2026-49978 References https://access.redhat.com/security/updates/classification/#important The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article