Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2026:7136 - Bug Fix Advisory
Issued:
2026-04-08
Updated:
2026-04-08

RHBA-2026:7136 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-9 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-9 based Middleware Containers container images are now available

Description

The RHEL-9 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2026:6766 (see References)

Users of RHEL-9 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-9 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat JBoss Middleware 1 x86_64

Fixes

  • BZ - 2449649 - CVE-2026-4519 python: Python: Command-line option injection in webbrowser.open() via crafted URLs

CVEs

  • CVE-2026-4519

References

  • https://access.redhat.com/errata/RHSA-2026:6766
  • https://access.redhat.com/containers

aarch64

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:31b659bb585558d1a9a5662a23a17f197683f11cc675345b22770d8f171889b9
ubi9/openjdk-17@sha256:3d229c629465df5378b4dc0d22b5ab11897ba986e1874c3331234da2460a50b6
ubi9/openjdk-17-runtime@sha256:e6fb8bba34403dd9999ac4536b5eee249ab07d2dafdb94779774f04c6cf994cb
ubi9/openjdk-21@sha256:c7447f340ae368315124c974c9980d0549fcc7759e8536765dee5968778e80d2
ubi9/openjdk-21-runtime@sha256:e8f6be9ed35550e90aa65054749f5f48a41caf2973962e2541bfa121d478c083
ubi9/openjdk-25@sha256:b33c466b6ecc8d1e685bde89fd1f5a0563bea73d3392b8e6be0b136b5d963613
ubi9/openjdk-25-runtime@sha256:fc1310ac1a6cf4a91d3c29908f622acf7df4423a5ad2e07a22cef3f5440ca292

ppc64le

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:db6c14b722c926bf3602b011a5f34ae129acbae2d35c1adaee9f8795033b50c4
ubi9/openjdk-17@sha256:0333884931484e6a62d15c2608ef9f82430271e3d93d1d055d9ebcff8cf1d524
ubi9/openjdk-17-runtime@sha256:d3aba3f75ea65782557555d2b1bb08f5cb16e280802273eeea8f7c4334935836
ubi9/openjdk-21@sha256:924d2124f7e9f1e17e02d85ff145c9bfac0203c53acc1628e66a30609460de7a
ubi9/openjdk-21-runtime@sha256:09157743e198b7912257b4a62f2909e74fa1eb555fe65fd5b9af19dd85dfa385
ubi9/openjdk-25@sha256:65f250a0e2562def5d33c672731e45b202a1e9272b542863b08f4c1d155302d8
ubi9/openjdk-25-runtime@sha256:47d957b15ce0c12633bd5925407b809bf79cee90106fb2fb02c5657401ee412f

s390x

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:093eed31d712d8209f2adb7df941a32ea8c7f1591423bd7d74f87870de96c584
ubi9/openjdk-17@sha256:3d013b7da09c822cb589e003067802d3ac7610deaa6db6d625d6a9d9d0b4b742
ubi9/openjdk-17-runtime@sha256:43a5f7c46161e78e7b36201d6e64dac533192d46fbd4a59e895e8da9b0f01d50
ubi9/openjdk-21@sha256:7b45483f9d1f6a206caf4904991e86e56d51fd3192e2dcf29c7a2972700be123
ubi9/openjdk-21-runtime@sha256:9f22cc21c90b4b500dc32f06902d6ad55508e3e1a5d2c9809512024fd7bb7920
ubi9/openjdk-25@sha256:1f00c7e6888fd0f7bfe48b198b05f6db6fa143961abe7ee951c6ee3b5a266f6a
ubi9/openjdk-25-runtime@sha256:8954b2969044b306bb8b66a0e1a356a38e0a9554c89a54df48674e1588d96479

x86_64

openjdk-tech-preview/openjdk-21-jlink-rhel9@sha256:797a380213775ca1356d94b540c2539b03d5590a7b4810df051b834f36d27169
ubi9/openjdk-17@sha256:8f5742e3c32a82a8dacfa266c899d8149f01abc08520319f2257d43b64bf4ea7
ubi9/openjdk-17-runtime@sha256:c47dbdfd828a5abeb3c78043459bed065af6fc0b0970d73bb9f5bd7fe46c2729
ubi9/openjdk-21@sha256:f730783fb00561b2e3db4f911888586bcc9eeed6ca7156b326e83994ff83f409
ubi9/openjdk-21-runtime@sha256:389274b30dd349e6d379637e0890245309d67b72341ca21969c16b12a94d81ea
ubi9/openjdk-25@sha256:1566dcc2b515b268350a4a6ef7ee0da6714e51e63ab626205bb02e5aa4322df8
ubi9/openjdk-25-runtime@sha256:5253f28d4f2496b607b31af252353bdea1b952f6fb025277a66a0a84a48a071a

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility