- What: Security update for Red Hat Satellite 6.18
- Impact: RHEL 9 systems using Satellite
Red Hat Product Errata RHSA-2026:63386 - Security Advisory Issued: 2026-09-03 Updated: 2026-09-03 RHSA-2026:63386 - Security Advisory Overview Updated Packages Synopsis Important: Satellite 6.18.9 Async Update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic A new release is now available for Red Hat Satellite 6.18 for RHEL 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Security Fix(es): python3.12-aio http: AIO HTTP: HTTP Request Smuggling via WebSocket Upgrade (CVE-2026-69243) python3.12-aio http: AIO HTTP: Denial of Service via malformed HTTP responses (CVE-2026-69244) openvox-server: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections (CVE-2026-10051) openvox-server: jackson-core: Denial of Service via incomplete fix in async JSON parser (CVE-2026-68494) python3.12-aio http: AIO HTTP: Arbitrary code execution via untrusted input to CookieJar.load() (CVE-2026-34993) ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution (CVE-2026-11332) puppetserver: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) ansible-core: argument injection in ansible-galaxy collection install via git clone (incomplete fix for CVE-2026-11332) (CVE-2026-16493) rubygem-jwt: ruby-jwt: Authentication bypass due to empty key in HMAC verification (CVE-2026-45363) Bug Fix(es): Satellite 6.17 upgrade, foreman-installer reports errors in /var/log/dnf.rpm.log Selected scenario is DISABLED, can not continue (SAT-48693) Non-default umask breaks IoP assets directory permissions (SAT-48690) Unable to upgrade to Red Hat Satellite 6.17 as rubygem-foreman_maintain is not getting updated after running satellite-maintain self-upgrade (SAT-48692) Remove Orphan fails with package_signing_fingerprint cannot be nil error after upgrade to Red Hat satellite 6.18.2 (SAT-48691) Issue when creating filter in content view using openssl package (SAT-48697) Unable to save bookmark report under Hosts → All Hosts → Compliance → Reports (SAT-49372) Sync memory consumption too high in pathological cases (SAT-46099) Solution Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Satellite 6.18 x86_64 Red Hat Satellite Capsule 6.18 x86_64 Red Hat Enterprise Linux for x86_64 9 x86_64 Fixes BZ - 2484099 - CVE-2026-34993 aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() BZ - 2485379 - CVE-2026-11332 ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution BZ - 2492015 - CVE-2026-54512 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass BZ - 2499928 - CVE-2026-10051 jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections BZ - 2500739 - CVE-2026-45363 ruby-jwt: ruby-jwt: Authentication bypass due to empty key in HMAC verification BZ - 2503724 - CVE-2026-16493 ansible-core: argument injection in ansible-galaxy collection install via git clone (incomplete fix for CVE-2026-11332) BZ - 2510825 - CVE-2026-69244 aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses BZ - 2510831 - CVE-2026-69243 aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade BZ - 2511026 - CVE-2026-68494 com.fasterxml.jackson.core/jackson-core: tools.jackson.core/jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser SAT-46099 - Sync memory consumption too high in pathological cases SAT-48690 - Non-default umask breaks IoP assets directory permissions [satellite_6.18] SAT-48691 - Remove Orphan fails with package_signing_fingerprint cannot be nil error after upgrade to Red Hat satellite 6.18.2 [satellite_6.18] SAT-48692 - Unable to upgrade to Red Hat Satellite 6.17 as rubygem-foreman_maintain is not getting updated after running satellite-maintain self-upgrade [satellite_6.18] SAT-48693 - Satellite 6.17 upgrade, foreman-installer reports errors in /var/log/dnf.rpm.log Selected scenario is DISABLED, can not continue [satellite_6.18] SAT-48697 - Issue when creating filter in content view using openssl package [satellite_6.18] SAT-49372 - Unable to save bookmark report under Hosts ? All Hosts ? Compliance ? Reports [satellite_6.18] CVEs CVE-2026-10051 CVE-2026-11332 CVE-2026-16493 CVE-2026-34993 CVE-2026-45363 CVE-2026-54512 CVE-2026-68494 CVE-2026-69243 CVE-2026-69244 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Satellite 6.18 SRPM ansible-core-2.16.19-1.el9sat.src.rpm SHA-256: 7919d28abb806743c56ef7e214d0c4684cee09d8262385c810ef506194ac5ea9 foreman-installer-3.16.0.10-1.el9sat.src.rpm SHA-256: b10c26091a8685e93f7a6c4ea4436331936ba2dea691fe74a00313e0ed9387a2 openvox-server-8.15.2-1.el9sat.src.rpm SHA-256: 5ca61d47de83d8cdc25b4d3c0c7e1d81ca7aa06bfeddb963449bfadc6b0fd788 pulpcore-obsolete-packages-1.3.1-5.el9pc.src.rpm SHA-256: 0d7357ed93542f1ba8eebc55f0200ad9880e107e4c1b7427314d4bc9282d3983 python3.12-aiohttp-3.14.3-1.el9pc.src.rpm SHA-256: 1e9cca38da5c8d3b2c05ee19cc0b83d1f64ee24c72b3d30e54c96adbd91a2e7c python3.12-pulp-rpm-3.29.11-1.el9pc.src.rpm SHA-256: 0ce9ebd515fc0234aaecb01df9ab01627cc2eb0a59a97da7c40eb8912f56c7ef python3.12-pulpcore-3.73.30-3.el9pc.src.rpm SHA-256: bbe028f3389871019d01eddecfa270e22355ca87998588217d86f0c7d2e399c7 rubygem-foreman_maintain-1.13.11-1.el9sat.src.rpm SHA-256: 23f76f23ebe3dba391a9c0da4fc4cb3c343725fffb8d9d66a8436ab24d55aa5d rubygem-jwt-2.10.3-1.el9sat.src.rpm SHA-256: ef8dd245e3d6ed7225369dce86473599555a3543c9759956ac9a0c62537495bd rubygem-katello-4.18.0.21-1.el9sat.src.rpm SHA-256: 5ca0462ec24528f3f54d30bcad091321e6d7d1f955a13bf3802ad4ccd12cfdfb rubygem-pulp_rpm_client-3.29.11-1.el9sat.src.rpm SHA-256: a40aee54d76d9053d6d082d06e97e8fc4edc3b9b6e724367d3eb35642525a8a9 satellite-6.18.9-1.el9sat.src.rpm SHA-256: 08e0b65812c1be1df12ddeb88f97c5b3f735e7b3983a60cd95602f8b800f0924 x86_64 ansible-core-2.16.19-1.el9sat.noarch.rpm SHA-256: 709c338983e27ed34268d872f4b27a8c5b75186fa75c998f24e48e5ca2d8953d ansible-test-2.16.19-1.el9sat.noarch.rpm SHA-256: 9b26b9555eca375ac0e7cd527fa0eeb2e826951fbb8c95c366093d3f5b3f3f96 foreman-installer-3.16.0.10-1.el9sat.noarch.rpm SHA-256: 9c88a9901fddf40faa35ad11973c498f75c4316d187d73ff9446e31a0d91121e foreman-installer-katello-3.16.0.10-1.el9sat.noarch.rpm SHA-256: 309fec68b2d2b6ffbffd1196c0baffebba82d708c72ef6210ccbbeb520861308 openvox-server-8.15.2-1.el9sat.noarch.rpm SHA-256: 59a96fd67b4f972f66dcaad0f151ff4f6f8a290d44e309495ec4980755d85e91 pulpcore-obsolete-packages-1.3.1-5.el9pc.noarch.rpm SHA-256: 20149910c22b4c90a4a749535ddfe0396398aef935e02516c747f45ab9449c58 python3.12-aiohttp-3.14.3-1.el9pc.x86_64.rpm SHA-256: 06ec60c7739b280ede65e87004f114f44081b4c475d83f255e31771be9ea390c python3.12-aiohttp-debuginfo-3.14.3-1.el9pc.x86_64.rpm SHA-256: 638a8730072e9e13db13aedc007e6f0f0e085fb40818ec305e840302c63ee515 python3.12-aiohttp-debugsource-3.14.3-1.el9pc.x86_64.rpm SHA-256: e42b5fb778addf2bee4055e05272fbd4974c3be0eb855eb4cb766e4fd4d7566f python3.12-pulp-rpm-3.29.11-1.el9pc.noarch.rpm SHA-256: bb39eaa1f0df2924397778df6b5a2e092a5364dc7e7522cc53ea60dbc5e22bf3 python3.12-pulpcore-3.73.30-3.el9pc.noarch.rpm SHA-256: 859f297fbb07e61a1dd42b9c65280c36a6ec919a61f2b07dd343729e5e97552d rubygem-foreman_maintain-1.13.11-1.el9sat.noarch.rpm SHA-256: 7b5ce44c831c1b07a080cc333073c0e450ea646d147d282a9d4e480eea981374 rubygem-jwt-2.10.3-1.el9sat.noarch.rpm SHA-256: e5a543dfccd39d32dccb62e71c3c3f2136d076548258c193db4b6eaad9fe25ff rubygem-katello-4.18.0.21-1.el9sat.noarch.rpm SHA-256: f29cbac006a737dd753160bce1868d8840f2d5f92b4472a3697bb5e69edcfeeb rubygem-pulp_rpm_client-3.29.11-1.el9sat.noarch.rpm SHA-256: abba8933c82203b95ad791834e91d16a1be28ad9a155faafb3b7dc12d543fc7f satellite-6.18.9-1.el9sat.noarch.rpm SHA-256: 31ac326e77a3ce0e00ddfc4d4f61f7f092ba29898d733c874a1fc9ce8b42422e satellite-cli-6.18.9-1.el9sat.noarch.rpm SHA-256: 301b80c33628626c2739eefe88be39a9f4a5e8eedd2787d8425658c813aee86e satellite-common-6.18.9-1.el9sat.noarch.rpm SHA-256: 8b65c91f1fe7de1122378ad62f8f91cf30cadbe67bb47a182fd11d9671bd3c65 satellite-obsolete-packages-6.18.9-1.el9sat.noarch.rpm SHA-256: cc4ffde059869c2a56743d22d460e923cbddc3543f08056da1887a468641cda9 Red Hat Satellite Capsule 6.18 SRPM ansible-core-2.16.19-1.el9sat.src.rpm SHA-256: 7919d28abb806743c56ef7e214d0c4684cee09d8262385c810ef506194ac5ea9 foreman-installer-3.16.0.10-1.el9sat.src.rpm SHA-256: b10c26091a8685e93f7a6c4ea4436331936ba2dea691fe74a00313e0ed9387a2 openvox-server-8.15.2-1.el9sat.src.rpm SHA-256: 5ca61d47de83d8cdc25b4d3c0c7e1d81ca7aa06bfeddb963449bfadc6b0fd788 pulpcore-obsolete-packages-1.3.1-5.el9pc.src.rpm SHA-256: 0d7357ed93542f1ba8eebc55f0200ad9880e107e4c1b7427314d4bc9282d3983 python3.12-aiohttp-3.14.3-1.el9pc.src.rpm SHA-256: 1e9cca38da5c8d3b2c05ee19cc0b83d1f64ee24c72b3d30e54c96adbd91a2e7c python3.12-pulp-rpm-3.29.11-1.el9pc.src.rpm SHA-256: 0ce9ebd515fc0234aaecb01df9ab01627cc2eb0a59a97da7c40eb8912f56c7ef python3.12-pulpcore-3.73.30-3.el9pc.src.rpm SHA-256: bbe028f3389871019d01eddecfa270e22355ca87998588217d86f0c7d2e399