Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:2226 - Security Advisory
Issued:
2026-02-09
Updated:
2026-02-09

RHSA-2026:2226 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: brotli security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for brotli is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Brotli is a generic-purpose lossless compression algorithm that compresses data using a combination of a modern variant of the LZ77 algorithm, Huffman coding and 2nd order context modeling, with a compression ratio comparable to the best currently available general-purpose compression methods. It is similar in speed with deflate but offers more dense compression.

Security Fix(es):

  • Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS (CVE-2025-6176)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2408762 - CVE-2025-6176 Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS

CVEs

  • CVE-2025-6176

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
brotli-1.0.9-6.el9_0.1.src.rpm SHA-256: b1a656f0d50db1a2abe0f353a7de7d9570c4854819b3cfd6ed95b6bde7a04e00
ppc64le
brotli-1.0.9-6.el9_0.1.ppc64le.rpm SHA-256: 9ce4bbf5d5e9799cddb28d2072e5c11a250a794923660b790f1a5b7a9478b6ec
brotli-debuginfo-1.0.9-6.el9_0.1.ppc64le.rpm SHA-256: 025369f289e9de7597d581ddc96ddfbce0b977bd760694245b0283b55d577aa8
brotli-debuginfo-1.0.9-6.el9_0.1.ppc64le.rpm SHA-256: 025369f289e9de7597d581ddc96ddfbce0b977bd760694245b0283b55d577aa8
brotli-debugsource-1.0.9-6.el9_0.1.ppc64le.rpm SHA-256: 317b16f3832fd6d9ce21b243fbcd49d39b596f5f9c1d724a115ecc16cf3efeb7
brotli-debugsource-1.0.9-6.el9_0.1.ppc64le.rpm SHA-256: 317b16f3832fd6d9ce21b243fbcd49d39b596f5f9c1d724a115ecc16cf3efeb7
brotli-devel-1.0.9-6.el9_0.1.ppc64le.rpm SHA-256: 806d05a9c81408c61193e6d5fd3f7c1d1004cce4da3c8713d1c707fcd33f9281
libbrotli-1.0.9-6.el9_0.1.ppc64le.rpm SHA-256: f4976c68e982759a91c8a97de588bab029a3cc30c557e92c1bb1157c5adee9fe
libbrotli-debuginfo-1.0.9-6.el9_0.1.ppc64le.rpm SHA-256: 5f4034afdb56253ca85dd2cce4b6f91c8ba0c5ca0c20f75f701dedebc203228d
libbrotli-debuginfo-1.0.9-6.el9_0.1.ppc64le.rpm SHA-256: 5f4034afdb56253ca85dd2cce4b6f91c8ba0c5ca0c20f75f701dedebc203228d
python3-brotli-1.0.9-6.el9_0.1.ppc64le.rpm SHA-256: 4df7fb65f1a31270525eae92ea55bf9c1edb90772925d3cc7a731a133e8ea644
python3-brotli-debuginfo-1.0.9-6.el9_0.1.ppc64le.rpm SHA-256: 67b062fff73367b93807090f97c67851886f1241085ab01038eb256a74a3631a
python3-brotli-debuginfo-1.0.9-6.el9_0.1.ppc64le.rpm SHA-256: 67b062fff73367b93807090f97c67851886f1241085ab01038eb256a74a3631a

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
brotli-1.0.9-6.el9_0.1.src.rpm SHA-256: b1a656f0d50db1a2abe0f353a7de7d9570c4854819b3cfd6ed95b6bde7a04e00
x86_64
brotli-1.0.9-6.el9_0.1.i686.rpm SHA-256: 5520eff1211f6bc9cb0a167d036b6e1313282fe9c4d79db9cd1f34c53b93dfb5
brotli-1.0.9-6.el9_0.1.x86_64.rpm SHA-256: 32013afe6fbfa302fddbf34cfb4fad9838c4468b6dabc1133a05f8620e59ac2f
brotli-debuginfo-1.0.9-6.el9_0.1.i686.rpm SHA-256: 7998fc4350a5ae5dfec4815d6bdcc7a9102dc6c712a4b5c66ecfbe6df0c54e02
brotli-debuginfo-1.0.9-6.el9_0.1.i686.rpm SHA-256: 7998fc4350a5ae5dfec4815d6bdcc7a9102dc6c712a4b5c66ecfbe6df0c54e02
brotli-debuginfo-1.0.9-6.el9_0.1.x86_64.rpm SHA-256: 2eeeb661c99652a765095f4002cbc962c9540cf3186960f36eb8683da19fb793
brotli-debuginfo-1.0.9-6.el9_0.1.x86_64.rpm SHA-256: 2eeeb661c99652a765095f4002cbc962c9540cf3186960f36eb8683da19fb793
brotli-debugsource-1.0.9-6.el9_0.1.i686.rpm SHA-256: 934e69881e37db5569516c0c033c0b2e91f6376385959b5cd3b140e8552374f3
brotli-debugsource-1.0.9-6.el9_0.1.i686.rpm SHA-256: 934e69881e37db5569516c0c033c0b2e91f6376385959b5cd3b140e8552374f3
brotli-debugsource-1.0.9-6.el9_0.1.x86_64.rpm SHA-256: 3f33dbb290caa8d3f6e1d24f05d2840991216285dee49c38b47f227e496e90cb
brotli-debugsource-1.0.9-6.el9_0.1.x86_64.rpm SHA-256: 3f33dbb290caa8d3f6e1d24f05d2840991216285dee49c38b47f227e496e90cb
brotli-devel-1.0.9-6.el9_0.1.i686.rpm SHA-256: a763b799efa93a6137b84ed42c9188709666a5ba29c4a124d9a5d32d57cfdfed
brotli-devel-1.0.9-6.el9_0.1.x86_64.rpm SHA-256: 9b2b5f3495b50b6f01024c73bb1a68b68b6098627c9700db511fd56b473d3936
libbrotli-1.0.9-6.el9_0.1.i686.rpm SHA-256: a28b4937cc09139da90b9aa08b9a9b912295164e70706722f6932e5d714beb54
libbrotli-1.0.9-6.el9_0.1.x86_64.rpm SHA-256: 2f67ff2da0dd539943fd3e1f4103ebeae6cebc8bfa99057929722cd881b046c1
libbrotli-debuginfo-1.0.9-6.el9_0.1.i686.rpm SHA-256: 37b214b5374050624e39e4a3428dff3422e33796a885e554efd5320e3a1fcd90
libbrotli-debuginfo-1.0.9-6.el9_0.1.i686.rpm SHA-256: 37b214b5374050624e39e4a3428dff3422e33796a885e554efd5320e3a1fcd90
libbrotli-debuginfo-1.0.9-6.el9_0.1.x86_64.rpm SHA-256: d176e21e965b964516342ec88e1b5471f27f94d322f856ecb2ca1cb6339e8880
libbrotli-debuginfo-1.0.9-6.el9_0.1.x86_64.rpm SHA-256: d176e21e965b964516342ec88e1b5471f27f94d322f856ecb2ca1cb6339e8880
python3-brotli-1.0.9-6.el9_0.1.x86_64.rpm SHA-256: 91e14efbd04a172dd17fc8ab49978d2afec1e205fc67daeda74f9c0b12b7f1e8
python3-brotli-debuginfo-1.0.9-6.el9_0.1.i686.rpm SHA-256: 35fee896adcca0a27a587d79e4c7e13eda111e5473ff3709cece02d88eda15c6
python3-brotli-debuginfo-1.0.9-6.el9_0.1.i686.rpm SHA-256: 35fee896adcca0a27a587d79e4c7e13eda111e5473ff3709cece02d88eda15c6
python3-brotli-debuginfo-1.0.9-6.el9_0.1.x86_64.rpm SHA-256: 078ff16ff3454dff2b86cb0a424da060aa640a1a29f35d9a341463df962013e7
python3-brotli-debuginfo-1.0.9-6.el9_0.1.x86_64.rpm SHA-256: 078ff16ff3454dff2b86cb0a424da060aa640a1a29f35d9a341463df962013e7

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
brotli-1.0.9-6.el9_0.1.src.rpm SHA-256: b1a656f0d50db1a2abe0f353a7de7d9570c4854819b3cfd6ed95b6bde7a04e00
aarch64
brotli-1.0.9-6.el9_0.1.aarch64.rpm SHA-256: 1b63958d1a471ce99c6da29a522c84be3995462b2d7a4227c4f9ce7a5f59862b
brotli-debuginfo-1.0.9-6.el9_0.1.aarch64.rpm SHA-256: 9cf8eba392ac264ae1f68033d49cc05f5fba82896f5287f340c27b10d2bc724f
brotli-debuginfo-1.0.9-6.el9_0.1.aarch64.rpm SHA-256: 9cf8eba392ac264ae1f68033d49cc05f5fba82896f5287f340c27b10d2bc724f
brotli-debugsource-1.0.9-6.el9_0.1.aarch64.rpm SHA-256: e5f6150ef93b3056e1a497673f35591da82edd18cac6ca46eca208d094cb4457
brotli-debugsource-1.0.9-6.el9_0.1.aarch64.rpm SHA-256: e5f6150ef93b3056e1a497673f35591da82edd18cac6ca46eca208d094cb4457
brotli-devel-1.0.9-6.el9_0.1.aarch64.rpm SHA-256: d7bff5d3c385a8122c2c956769eef13e029825d15a5c49be635308fbefa979b1
libbrotli-1.0.9-6.el9_0.1.aarch64.rpm SHA-256: 507d7f0dd1681827483f85d579f54a44b6ac4a0de60467634981e5acced26609
libbrotli-debuginfo-1.0.9-6.el9_0.1.aarch64.rpm SHA-256: 61c2ceb1461c10541a9b484168c8fb08641a6bad44d0207d5049d98e63feb03f
libbrotli-debuginfo-1.0.9-6.el9_0.1.aarch64.rpm SHA-256: 61c2ceb1461c10541a9b484168c8fb08641a6bad44d0207d5049d98e63feb03f
python3-brotli-1.0.9-6.el9_0.1.aarch64.rpm SHA-256: f1aa738fb42d83d669d4f8e0783c984a6f3e8bee1207c76c470eb91d03bf5696
python3-brotli-debuginfo-1.0.9-6.el9_0.1.aarch64.rpm SHA-256: 25132365fa28240d5e1660d15fc283083c627099dea966ff11f42d8e31db0bad
python3-brotli-debuginfo-1.0.9-6.el9_0.1.aarch64.rpm SHA-256: 25132365fa28240d5e1660d15fc283083c627099dea966ff11f42d8e31db0bad

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
brotli-1.0.9-6.el9_0.1.src.rpm SHA-256: b1a656f0d50db1a2abe0f353a7de7d9570c4854819b3cfd6ed95b6bde7a04e00
s390x
brotli-1.0.9-6.el9_0.1.s390x.rpm SHA-256: 2ff518064e84dafb9ce199a7e9d6ddefe12eb5c27643ce1c42b37b1307f3606b
brotli-debuginfo-1.0.9-6.el9_0.1.s390x.rpm SHA-256: 2a53b6d379755da3cc0fb568c34019e11cfe5995d098d211a51fe006b3ad4f80
brotli-debuginfo-1.0.9-6.el9_0.1.s390x.rpm SHA-256: 2a53b6d379755da3cc0fb568c34019e11cfe5995d098d211a51fe006b3ad4f80
brotli-debugsource-1.0.9-6.el9_0.1.s390x.rpm SHA-256: da685540ed45d2befbe71cb3c9102abf65bbdc2173db413ee9e6e34410378011
brotli-debugsource-1.0.9-6.el9_0.1.s390x.rpm SHA-256: da685540ed45d2befbe71cb3c9102abf65bbdc2173db413ee9e6e34410378011
brotli-devel-1.0.9-6.el9_0.1.s390x.rpm SHA-256: f3022633b51ae20cc90c10465cbcd8f8a3ffd42d527640e9b9e6777d37669683
libbrotli-1.0.9-6.el9_0.1.s390x.rpm SHA-256: ed430b704a866b74ac744370a10039aa7999a5951d920fdb77553c8cecf9a878
libbrotli-debuginfo-1.0.9-6.el9_0.1.s390x.rpm SHA-256: 18b22a4c60b66f27e9b7655b8558286a71dfed35a10a4cbf2fa0d5d2fd39a60d
libbrotli-debuginfo-1.0.9-6.el9_0.1.s390x.rpm SHA-256: 18b22a4c60b66f27e9b7655b8558286a71dfed35a10a4cbf2fa0d5d2fd39a60d
python3-brotli-1.0.9-6.el9_0.1.s390x.rpm SHA-256: f85cb084319e7baf70fa80c66124f03cc79e45684e3343ba4ede743fa1cc4d26
python3-brotli-debuginfo-1.0.9-6.el9_0.1.s390x.rpm SHA-256: 5bf8677aa1cbfd6fe9c8e770c652a271fac16c9d5304ce7547f3b476a8b5c0c9
python3-brotli-debuginfo-1.0.9-6.el9_0.1.s390x.rpm SHA-256: 5bf8677aa1cbfd6fe9c8e770c652a271fac16c9d5304ce7547f3b476a8b5c0c9

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility