Red Hat Product Errata RHSA-2026:66432 - Security Advisory Issued: 2026-09-10 Updated: 2026-09-10 RHSA-2026:66432 - Security Advisory Overview Updated Packages Synopsis Important: osbuild-composer security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for osbuild-composer is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients. Security Fix(es): golang.org/x/net/idna: golang: net/ http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136) golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681) golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering (CVE-2026-42502) github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178) github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing BZ - 2480757 - CVE-2026-27136 golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass BZ - 2480761 - CVE-2026-25681 golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting BZ - 2480762 - CVE-2026-42502 golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering BZ - 2484830 - CVE-2026-41178 github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers BZ - 2493622 - CVE-2026-55677 github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy CVEs CVE-2026-25681 CVE-2026-27136 CVE-2026-39821 CVE-2026-41178 CVE-2026-42502 CVE-2026-55677 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM osbuild-composer-165.1-5.el10_2.src.rpm SHA-256: c82564d6500d935c08152fdec862c91ebae0bfc62241db6b405b9a2cf912739b x86_64 osbuild-composer-165.1-5.el10_2.x86_64.rpm SHA-256: 107c2892a9922f6fad900c555cfe15d88e1cd665d72d7bcc20d6f6aff8f26a34 osbuild-composer-core-165.1-5.el10_2.x86_64.rpm SHA-256: d6824b1c15da0218aef522a1e6ff84bf3721b588773d246858660588e9738993 osbuild-composer-core-debuginfo-165.1-5.el10_2.x86_64.rpm SHA-256: 15f3322125c78f23dfa167d7bee45038fe4b6860cea564d91ee21a552a8611f3 osbuild-composer-debuginfo-165.1-5.el10_2.x86_64.rpm SHA-256: 5e6a6b9a8664fa35de7522f8ab6ca30e86b1e09c32972b5f238ae11d9335f9a7 osbuild-composer-debugsource-165.1-5.el10_2.x86_64.rpm SHA-256: 09f2fff61a022d7b7020deee94873440e23d2fb9bb9a864f2e7ea5b0c5a01582 osbuild-composer-tests-debuginfo-165.1-5.el10_2.x86_64.rpm SHA-256: 0baff9c437f7524112293d18ec845195d997fc5c56eb10edf56abcf0ac7fd7fb osbuild-composer-worker-165.1-5.el10_2.x86_64.rpm SHA-256: 97ea4b757417aa77ddc05f6e888df0030c042191d243552269a2a90c7d73fc06 osbuild-composer-worker-debuginfo-165.1-5.el10_2.x86_64.rpm SHA-256: f8edc70d10718ea1f633f0b38e78d6381c57184cc5d7cc6e3a7f292abb77f23f Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM osbuild-composer-165.1-5.el10_2.src.rpm SHA-256: c82564d6500d935c08152fdec862c91ebae0bfc62241db6b405b9a2cf912739b x86_64 osbuild-composer-165.1-5.el10_2.x86_64.rpm SHA-256: 107c2892a9922f6fad900c555cfe15d88e1cd665d72d7bcc20d6f6aff8f26a34 osbuild-composer-core-165.1-5.el10_2.x86_64.rpm SHA-256: d6824b1c15da0218aef522a1e6ff84bf3721b588773d246858660588e9738993 osbuild-composer-core-debuginfo-165.1-5.el10_2.x86_64.rpm SHA-256: 15f3322125c78f23dfa167d7bee45038fe4b6860cea564d91ee21a552a8611f3 osbuild-composer-debuginfo-165.1-5.el10_2.x86_64.rpm SHA-256: 5e6a6b9a8664fa35de7522f8ab6ca30e86b1e09c32972b5f238ae11d9335f9a7 osbuild-composer-debugsource-165.1-5.el10_2.x86_64.rpm SHA-256: 09f2fff61a022d7b7020deee94873440e23d2fb9bb9a864f2e7ea5b0c5a01582 osbuild-composer-tests-debuginfo-165.1-5.el10_2.x86_64.rpm SHA-256: 0baff9c437f7524112293d18ec845195d997fc5c56eb10edf56abcf0ac7fd7fb osbuild-composer-worker-165.1-5.el10_2.x86_64.rpm SHA-256: 97ea4b757417aa77ddc05f6e888df0030c042191d243552269a2a90c7d73fc06 osbuild-composer-worker-debuginfo-165.1-5.el10_2.x86_64.rpm SHA-256: f8edc70d10718ea1f633f0b38e78d6381c57184cc5d7cc6e3a7f292abb77f23f Red Hat Enterprise Linux for IBM z Systems 10 SRPM osbuild-composer-165.1-5.el10_2.src.rpm SHA-256: c82564d6500d935c08152fdec862c91ebae0bfc62241db6b405b9a2cf912739b s390x osbuild-composer-165.1-5.el10_2.s390x.rpm SHA-256: 65c30f1a90721413497a13e2a203e17724185ef08c943a66c5d80bc515f87631 osbuild-composer-core-165.1-5.el10_2.s390x.rpm SHA-256: 9beaa69257edc69659440fe019f1115488d82bf84dd577ab02f4762e8f790ff5 osbuild-composer-core-debuginfo-165.1-5.el10_2.s390x.rpm SHA-256: 1b2f417b55f307637939900c6d780bc6748edef86c7bdc840e443fbc081b1742 osbuild-composer-debuginfo-165.1-5.el10_2.s390x.rpm SHA-256: f941e5672acf8484e0bda561b75fc7e58ce8ec1c06c925fc803776b4aa785472 osbuild-composer-debugsource-165.1-5.el10_2.s390x.rpm SHA-256: 4738e8431d1b363c6fa99134d4a0898e4fc76f042edef6bd9f2b9855da8f3167 osbuild-composer-tests-debuginfo-165.1-5.el10_2.s390x.rpm SHA-256: 46c9a28b02eea5de5f2b66bb6e0344943b8f5080a7a3a62f255406038f1d4fe3 osbuild-composer-worker-165.1-5.el10_2.s390x.rpm SHA-256: ff6967724070edb3e9b59c1266efa00fdfabfcb6f1ac01944b9838246337d30c osbuild-composer-worker-debuginfo-165.1-5.el10_2.s390x.rpm SHA-256: d51ec8d392b77079e57f766d5992f801548ded3defd5feacbcdb704d52623c60 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM osbuild-composer-165.1-5.el10_2.src.rpm SHA-256: c82564d6500d935c08152fdec862c91ebae0bfc62241db6b405b9a2cf912739b s390x osbuild-composer-165.1-5.el10_2.s390x.rpm SHA-256: 65c30f1a90721413497a13e2a203e17724185ef08c943a66c5d80bc515f87631 osbuild-composer-core-165.1-5.el10_2.s390x.rpm SHA-256: 9beaa69257edc69659440fe019f1115488d82bf84dd577ab02f4762e8f790ff5 osbuild-composer-core-debuginfo-165.1-5.el10_2.s390x.rpm SHA-256: 1b2f417b55f307637939900c6d780bc6748edef86c7bdc840e443fbc081b1742 osbuild-composer-debuginfo-165.1-5.el10_2.s390x.rpm SHA-256: f941e5672acf8484e0bda561b75fc7e58ce8ec1c06c925fc803776b4aa785472 osbuild-composer-debugsource-165.1-5.el10_2.s390x.rpm SHA-256: 4738e8431d1b363c6fa99134d4a0898e4fc76f042edef6bd9f2b9855da8f3167 osbuild-composer-tests-debuginfo-165.1-5.el10_2.s390x.rpm SHA-256: 46c9a28b02eea5de5f2b66bb6e0344943b8f5080a7a3a62f255406038f1d4fe3 osbuild-composer-worker-165.1-5.el10_2.s390x.rpm SHA-256: ff6967724070edb3e9b59c1266efa00fdfabfcb6f1ac01944b9838246337d30c osbuild-composer-worker-debuginfo-165.1-5.el10_2.s390x.rpm SHA-256: d51ec8d392b77079e57f766d5992f801548ded3defd5feacbcdb704d52623c60 Red Hat Enterprise Linux for Power, little endian 10 SRPM osbuild-composer-165.1-5.el10_2.src.rpm SHA-256: c82564d6500d935c08152fdec862c91ebae0bfc62241db6b405b9a2cf912739b ppc64le osbuild-composer-165.1-5.el10_2.ppc64le.rpm SHA-256: e8fc243fa7ee821707fee7d1d11bc7c9b40097298e31c1dd097142fd0b1452ff osbuild-composer-core-165.1-5.el10_2.ppc64le.rpm SHA-256: 223c2c432d091bc03fa02b9a5d2c5ffa7a5e3c52c2050b91164db33e9784b0ff osbuild-composer-core-debuginfo-165.1-5.el10_2.ppc64le.rpm SHA-256: 53ac48c19164f6623fb66a2d62ec6a0c661d7b65ed7d6c36f52b01b14d72b08d osbuild-composer-debuginfo-165.1-5.el10_2.ppc64le.rpm SHA-256: 472cdface979d8091f3ad6ef3c7b6b7a4119ea3f0531874c1c969b937e6e3d1d osbuild-composer-debugsou
This security update for osbuild-composer addresses multiple vulnerabilities in its Go dependencies, including a critical (CVSS 9.6) privilege escalation flaw in golang.org/x/net/idna via incorrect Punycode processing (CVE-2026-39821) and several medium-severity cross-site scripting (XSS) and denial-of-service issues. The affected component versions are golang net library versions prior to 0.55.0. The fix is included in the updated osbuild-composer packages for Red Hat Enterprise Linux 10.