Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:0845 - Security Advisory
Issued:
2026-01-20
Updated:
2026-01-20

RHSA-2026:0845 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: brotli security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for brotli is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Brotli is a generic-purpose lossless compression algorithm that compresses data using a combination of a modern variant of the LZ77 algorithm, Huffman coding and 2nd order context modeling, with a compression ratio comparable to the best currently available general-purpose compression methods. It is similar in speed with deflate but offers more dense compression.

Security Fix(es):

  • Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS (CVE-2025-6176)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 10 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for ARM 64 10 aarch64

Fixes

  • BZ - 2408762 - CVE-2025-6176 Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS

CVEs

  • CVE-2025-6176

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 10

SRPM
brotli-1.1.0-7.el10_1.src.rpm SHA-256: 3c06552ab1d70705a78107ccc980ce9043793c4bb0fd945962e023f1c6e41141
x86_64
brotli-1.1.0-7.el10_1.x86_64.rpm SHA-256: 33e0882009f96bdc4e1b9aaa4ed72a121e4486c256e4ffce343d27da11dffb25
brotli-debuginfo-1.1.0-7.el10_1.x86_64.rpm SHA-256: 4ba1bbb824132ba9b5e9e672efc4d5c55e09377cd1d507f47ee942cd3242e167
brotli-debuginfo-1.1.0-7.el10_1.x86_64.rpm SHA-256: 4ba1bbb824132ba9b5e9e672efc4d5c55e09377cd1d507f47ee942cd3242e167
brotli-debugsource-1.1.0-7.el10_1.x86_64.rpm SHA-256: 385d728f3024cf1874bb2289a4b13ba95428661d024d1b9db65427e2418b6c60
brotli-debugsource-1.1.0-7.el10_1.x86_64.rpm SHA-256: 385d728f3024cf1874bb2289a4b13ba95428661d024d1b9db65427e2418b6c60
brotli-devel-1.1.0-7.el10_1.x86_64.rpm SHA-256: 3105e04c4f520ba21ffe151550bf2a178ca26d966124cdce5e02eee12d02a0b4
libbrotli-1.1.0-7.el10_1.x86_64.rpm SHA-256: 894800ee7893f8e4aa1d3870afb22b54d92624134bc7cf5d2cdc1a1db92366db
libbrotli-debuginfo-1.1.0-7.el10_1.x86_64.rpm SHA-256: ad8fbdbd01272eb2674a0ae09542ffdfa0071d3fa5dda0643e8cd817883a869e
libbrotli-debuginfo-1.1.0-7.el10_1.x86_64.rpm SHA-256: ad8fbdbd01272eb2674a0ae09542ffdfa0071d3fa5dda0643e8cd817883a869e
python3-brotli-1.1.0-7.el10_1.x86_64.rpm SHA-256: f625ddaac270004e7eecc972cdfd354e1e2904f6b6bc65a02b32694a0ab741d4
python3-brotli-debuginfo-1.1.0-7.el10_1.x86_64.rpm SHA-256: bfba3fbd1497165c55fa29395ea03b0991ec6d714f5cc426fbc8723102136504
python3-brotli-debuginfo-1.1.0-7.el10_1.x86_64.rpm SHA-256: bfba3fbd1497165c55fa29395ea03b0991ec6d714f5cc426fbc8723102136504

Red Hat Enterprise Linux for IBM z Systems 10

SRPM
brotli-1.1.0-7.el10_1.src.rpm SHA-256: 3c06552ab1d70705a78107ccc980ce9043793c4bb0fd945962e023f1c6e41141
s390x
brotli-1.1.0-7.el10_1.s390x.rpm SHA-256: eca814f5093715d4388be709a87ec0cd4d5ada56f0a29743fe5c1a18d6f02844
brotli-debuginfo-1.1.0-7.el10_1.s390x.rpm SHA-256: 9dffcd578b7eee70c4e929cfd229c394cc16619956f7ccc9481f4646724f4e20
brotli-debuginfo-1.1.0-7.el10_1.s390x.rpm SHA-256: 9dffcd578b7eee70c4e929cfd229c394cc16619956f7ccc9481f4646724f4e20
brotli-debugsource-1.1.0-7.el10_1.s390x.rpm SHA-256: 8cb6fb39ad31c5b47a6c1066f8bc0e2fa5188dd8f9197a83fb619170a09998e3
brotli-debugsource-1.1.0-7.el10_1.s390x.rpm SHA-256: 8cb6fb39ad31c5b47a6c1066f8bc0e2fa5188dd8f9197a83fb619170a09998e3
brotli-devel-1.1.0-7.el10_1.s390x.rpm SHA-256: 4c91a022199f95730794f7e2e1778eb5fd591df748269d6c67ae5baecad51078
libbrotli-1.1.0-7.el10_1.s390x.rpm SHA-256: ecd5f06f949f6d99b7c0f1b5ecb46d4342b8db0e7b70a400c90bb909e3a00c0d
libbrotli-debuginfo-1.1.0-7.el10_1.s390x.rpm SHA-256: 8bc5b04d669d7e4946bc2f27f11d0455df8ccaadc5857660fccb4016d40e1649
libbrotli-debuginfo-1.1.0-7.el10_1.s390x.rpm SHA-256: 8bc5b04d669d7e4946bc2f27f11d0455df8ccaadc5857660fccb4016d40e1649
python3-brotli-1.1.0-7.el10_1.s390x.rpm SHA-256: bfaf09ffd55bb0de201582a6f745c6c1a580ca876e94432582308294b2c4acab
python3-brotli-debuginfo-1.1.0-7.el10_1.s390x.rpm SHA-256: 5dd9bde5be07dcb4b1e8e6670fe8ac90128b3b692326b94231b27ae27b63b935
python3-brotli-debuginfo-1.1.0-7.el10_1.s390x.rpm SHA-256: 5dd9bde5be07dcb4b1e8e6670fe8ac90128b3b692326b94231b27ae27b63b935

Red Hat Enterprise Linux for Power, little endian 10

SRPM
brotli-1.1.0-7.el10_1.src.rpm SHA-256: 3c06552ab1d70705a78107ccc980ce9043793c4bb0fd945962e023f1c6e41141
ppc64le
brotli-1.1.0-7.el10_1.ppc64le.rpm SHA-256: 8f21497c1f96652a7b937b34e42809ecc1171459a992420c851dc03e03797f2d
brotli-debuginfo-1.1.0-7.el10_1.ppc64le.rpm SHA-256: add5d19fb90fcb04ddc2e04e46b0c0353db89d2ae8243bb80c62c9a2a1c7a438
brotli-debuginfo-1.1.0-7.el10_1.ppc64le.rpm SHA-256: add5d19fb90fcb04ddc2e04e46b0c0353db89d2ae8243bb80c62c9a2a1c7a438
brotli-debugsource-1.1.0-7.el10_1.ppc64le.rpm SHA-256: 5fdfc26532db567091af4344fdf008c99180478f804a53a73c3f373add48c6c7
brotli-debugsource-1.1.0-7.el10_1.ppc64le.rpm SHA-256: 5fdfc26532db567091af4344fdf008c99180478f804a53a73c3f373add48c6c7
brotli-devel-1.1.0-7.el10_1.ppc64le.rpm SHA-256: 8dc146a16b0e28d320c3ebb7c2621039659bcb82870e4a3e60e749ebbfb350fb
libbrotli-1.1.0-7.el10_1.ppc64le.rpm SHA-256: 06f8a158a4d6520e6ef51deb0768dad65885a56a9392381145805d4eaa156b66
libbrotli-debuginfo-1.1.0-7.el10_1.ppc64le.rpm SHA-256: a2a594a2b5e0b55327c79d55cfebdb4b8c1311d436064ce829b8ee32c48b1bf5
libbrotli-debuginfo-1.1.0-7.el10_1.ppc64le.rpm SHA-256: a2a594a2b5e0b55327c79d55cfebdb4b8c1311d436064ce829b8ee32c48b1bf5
python3-brotli-1.1.0-7.el10_1.ppc64le.rpm SHA-256: c079d15453efdceb3867080189fc2daba361b5653dd9c8d671ea1118447170fd
python3-brotli-debuginfo-1.1.0-7.el10_1.ppc64le.rpm SHA-256: 567f1f7bc229903075e92091b254fdcfe257e735e3905293fcf0f9ff8055a7a9
python3-brotli-debuginfo-1.1.0-7.el10_1.ppc64le.rpm SHA-256: 567f1f7bc229903075e92091b254fdcfe257e735e3905293fcf0f9ff8055a7a9

Red Hat Enterprise Linux for ARM 64 10

SRPM
brotli-1.1.0-7.el10_1.src.rpm SHA-256: 3c06552ab1d70705a78107ccc980ce9043793c4bb0fd945962e023f1c6e41141
aarch64
brotli-1.1.0-7.el10_1.aarch64.rpm SHA-256: 215828011f0e2aca0227cd12bf6610fea1791ac5c3b631507473a1b6c8b2bc7d
brotli-debuginfo-1.1.0-7.el10_1.aarch64.rpm SHA-256: 1d098167c9ec8e5c836c598b585e9bbec9d91619be97475a09dea5eda965280b
brotli-debuginfo-1.1.0-7.el10_1.aarch64.rpm SHA-256: 1d098167c9ec8e5c836c598b585e9bbec9d91619be97475a09dea5eda965280b
brotli-debugsource-1.1.0-7.el10_1.aarch64.rpm SHA-256: 139421d230667581edc22bff8d99bd0ee12cc2e131d50fed08660d6c55a3be21
brotli-debugsource-1.1.0-7.el10_1.aarch64.rpm SHA-256: 139421d230667581edc22bff8d99bd0ee12cc2e131d50fed08660d6c55a3be21
brotli-devel-1.1.0-7.el10_1.aarch64.rpm SHA-256: 50c7af6c7922b5d69dd244373297157f0e791fe75d33bb705aac5e857106b127
libbrotli-1.1.0-7.el10_1.aarch64.rpm SHA-256: 652770c1f5a3a3d438da8dabe21809c534791a0a1e63ba5aadc3a9efd2b6022c
libbrotli-debuginfo-1.1.0-7.el10_1.aarch64.rpm SHA-256: 5a11164cece28c344e2baac89e39585ac11f992216fa987c93528b4c5a777f0c
libbrotli-debuginfo-1.1.0-7.el10_1.aarch64.rpm SHA-256: 5a11164cece28c344e2baac89e39585ac11f992216fa987c93528b4c5a777f0c
python3-brotli-1.1.0-7.el10_1.aarch64.rpm SHA-256: e40164a469e950cd87ea91d275a2c4a7a794c88b621d7393429cbcd991ce3485
python3-brotli-debuginfo-1.1.0-7.el10_1.aarch64.rpm SHA-256: b647174dc390a9de87d61ad1a9f31888a520aca1d77202aca51d2068f80084f3
python3-brotli-debuginfo-1.1.0-7.el10_1.aarch64.rpm SHA-256: b647174dc390a9de87d61ad1a9f31888a520aca1d77202aca51d2068f80084f3

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility