Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2026:12484 - Bug Fix Advisory
Issued:
2026-04-30
Updated:
2026-04-30

RHBA-2026:12484 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-9 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-9 based Middleware Containers container images are now available

Description

The RHEL-9 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2026:10949 (see References)

Users of RHEL-9 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-9 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat JBoss Middleware 1 x86_64

Fixes

  • BZ - 2457932 - CVE-2026-6100 python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules
  • BZ - 2458049 - CVE-2026-4786 python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API

CVEs

  • CVE-2026-4786
  • CVE-2026-6100
  • CVE-2026-22007
  • CVE-2026-22013
  • CVE-2026-22016
  • CVE-2026-22018
  • CVE-2026-22021
  • CVE-2026-23865
  • CVE-2026-34268
  • CVE-2026-34282

References

  • https://access.redhat.com/errata/RHSA-2026:10949
  • https://access.redhat.com/containers

aarch64

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:351c20aee1f1525173909a2ad6b12c8173bedea9993b9c2dd619b2b12c814b92
ubi9/openjdk-17@sha256:d04f3c00d7d51b609a5df11e19b689c544df622e484b9092100b4767d143d96d
ubi9/openjdk-17-runtime@sha256:845e56756dc0565524067004ac8cae7a32d7dc7368b3536c799757706f148c98
ubi9/openjdk-21@sha256:0706706187fcc4a3d71af85c4ec7c54b02f458877bf2a20b25285f59db63c219
ubi9/openjdk-21-runtime@sha256:2525e656f64fbed6941af864b4d47caf76de0f7f3a5d2b39e956d782af5ed234
ubi9/openjdk-25@sha256:baeaab7c3eb41f28b103dc2f4b5e2707ef11fea5c3ec57089cc9628bc245abf9
ubi9/openjdk-25-runtime@sha256:0c544ce0ff09a9145167a127ab8a5c03fcfc012265e34800826aafc31c36f088

ppc64le

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:6dd36b42f218fa4e1faa3dd97afa1d79d5408e4fc056864428c19c497187b576
ubi9/openjdk-17@sha256:8700a4dab6c7e903f54649949aca1fad7252e8389c3a70d867280544755076e2
ubi9/openjdk-17-runtime@sha256:1861fb94826ccb8e33ed459be3226d483414e10c2f8586d276e4baf02307a0cd
ubi9/openjdk-21@sha256:e30ce44cb80f90f26779f9a94a472ff9cf83813c8eeee43ba4fc45fd3489a8e3
ubi9/openjdk-21-runtime@sha256:f89357b77be35ed87f27fa3d3a6498bc9dd39168c5466c14f5f0d0184f01d058
ubi9/openjdk-25@sha256:dd7329a6bfb36dc495fb56b0ffbf6c11be063ae5f4bdb7e116994b760c42b599
ubi9/openjdk-25-runtime@sha256:b5b0a0fa598bf4277899a221f5101ac82078e3453a3aa8212ed76f3227ec48b4

s390x

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:639aa3e39f4daf23115e325f13c1f5cb43b7a8ef66bfe6a754ba49b2118fdc74
ubi9/openjdk-17@sha256:2244d4a2329feaefaaa8394f0d24ec687aa07bdba91bb5a2cd207b60fc6dde1f
ubi9/openjdk-17-runtime@sha256:4846cbcabb117450d17ec097b554ecc24e4394162f589d2629a2e00d861419ce
ubi9/openjdk-21@sha256:efa4ca00ebc1ad806da9846260b3ec4581055f80e0c897d17c1874047aae8a9e
ubi9/openjdk-21-runtime@sha256:5b78fdfa98a46728db210ed16b43eee3f62c21b12231242a93d7655b75fde4ec
ubi9/openjdk-25@sha256:18d31b603f927629092ce2973e749f32a3d532c706cc6f096aa221f86ff9110f
ubi9/openjdk-25-runtime@sha256:0b68b45f6522be469e482aa1460c28e8673d046007fb1b95a19efd5beac6c2be

x86_64

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:8d903721ca621bd19734efcf7e513b4905153087f801ae1cf65786a05ecc4a33
ubi9/openjdk-17@sha256:f795becd39b008d280dbd0d6bf7f1a602920f954504bd367c0e5228abace6eac
ubi9/openjdk-17-runtime@sha256:e7c1da3cfcff5c0907709f79796e61a2362bb0cacfd514b4f1f1191f045fe6d9
ubi9/openjdk-21@sha256:bbbafd378d6a7b286589439f192c99b95325643d900f545380d02fad9104c011
ubi9/openjdk-21-runtime@sha256:86f83644f083faeea8ef2150281277771e493bf2f9c6c31fcbf895e8cdeb4668
ubi9/openjdk-25@sha256:b2864d1044540ebc11e2925ab2022c518c8fc7384c6f50c1330aa5bb940d3c48
ubi9/openjdk-25-runtime@sha256:96db30575f32008e06e94c740fb1b3f7624c2559e993320cfa50d05e3132cdc3

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility