Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2026:54536 - Bug Fix Advisory
Issued:
2026-08-13
Updated:
2026-08-13

RHBA-2026:54536 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 container images

Type/Severity

Bug Fix Advisory

Topic

Updated Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 container images are now available

Description

The Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 container images have been updated to address the following security advisory: RHSA-2026:54268 (see References)

Users of Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • JBoss Enterprise Application Platform 8.1 for RHEL 9 x86_64

Fixes

  • BZ - 2491848 - CVE-2026-11940 python: cpython: CPython: tarfile extraction filter bypass allows escaping the destination directory

CVEs

  • CVE-2026-11940

References

  • https://access.redhat.com/errata/RHSA-2026:54268
  • https://access.redhat.com/containers

aarch64

jboss-eap-8/eap81-openjdk17-builder-openshift-rhel9@sha256:bba962f9cdfb5f21e5facc1df4d2f159277d52b36104e1c716f162e267c3bc4b
jboss-eap-8/eap81-openjdk17-runtime-openshift-rhel9@sha256:2a425e6894f3a462d3973f13e45ca7e578e76a38d0d9b81815176e358ba7fd3d
jboss-eap-8/eap81-openjdk21-builder-openshift-rhel9@sha256:a4b5540fc1b1a830af05607b49eff26080830b0ce61bc4b5c72a35b6526a57eb
jboss-eap-8/eap81-openjdk21-runtime-openshift-rhel9@sha256:4dc9c16612683e8334c80b49f86ecb1d3a4dc976c8b60dfff173bc6b8ab27b72

ppc64le

jboss-eap-8/eap81-openjdk17-builder-openshift-rhel9@sha256:733bff6838f47628664bf5664ee0642087072e4f66987a0aa992eb724ad8ab62
jboss-eap-8/eap81-openjdk17-runtime-openshift-rhel9@sha256:8945fba23f5b6beeed0cb5d52ea8cfbd01b8db0d881e7e49ade6962fc13d3d49
jboss-eap-8/eap81-openjdk21-builder-openshift-rhel9@sha256:9a9dd5ef75e5132f2cfcc529dbd09e0af8b1dc74208db3f9ac15baf2b9b5c215
jboss-eap-8/eap81-openjdk21-runtime-openshift-rhel9@sha256:231450686a0056625bafd94cb462b2a8143334aa7d076f1992de89787d3b04c8

s390x

jboss-eap-8/eap81-openjdk17-builder-openshift-rhel9@sha256:09672b2fb35a39e1923dc4b6b8142d6c60e7e49583d314d77f990621d74f5163
jboss-eap-8/eap81-openjdk17-runtime-openshift-rhel9@sha256:0bfc6df2511f0936c1fc6ed56c2a75572f5b745da1f9e6f2d2571e24eb79c87a
jboss-eap-8/eap81-openjdk21-builder-openshift-rhel9@sha256:3db4590cff5e44c0c25a1b0ecd737db4186135f4d57e3c43704a486206b770e9
jboss-eap-8/eap81-openjdk21-runtime-openshift-rhel9@sha256:32e707823b54ba71421c2ac55e81038d957f17320ac54b1f524e9a1c413a59ee

x86_64

jboss-eap-8/eap81-openjdk17-builder-openshift-rhel9@sha256:f023f1bfb93d7728ce9c0e748c08ee4f275cc73cc0353a290a739d7461da0f5e
jboss-eap-8/eap81-openjdk17-runtime-openshift-rhel9@sha256:1cf02988597f632fd93ae049f05c3e58e945b19e07897019e127779e5e2d5a83
jboss-eap-8/eap81-openjdk21-builder-openshift-rhel9@sha256:9607e27b2a87e859e305b0225b3c1640fd201d75cbeb6dca6ad71bb44118f11c
jboss-eap-8/eap81-openjdk21-runtime-openshift-rhel9@sha256:69046afab4471ac87bd6482ffaa66c60267d8b47e66b48ab20bc353fc2e704bc

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility