Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:2760 - Security Advisory
Issued:
2026-02-16
Updated:
2026-02-16

RHSA-2026:2760 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: Satellite 6.18.3 Async Update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

A new release is now available for Red Hat Satellite 6.18 for RHEL 9.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

Description

Red Hat Satellite is a system management solution that allows organizations
to configure and maintain their systems without the necessity to provide
public Internet access to their servers or other client systems. It
performs provisioning and configuration management of predefined standard
operating environments.

Security Fix(es):

  • python-aiohttp: AIOHTTP HTTP Request/Response Smuggling (CVE-2025-53643)
  • python3.12-urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) (CVE-2026-21441)
  • python3.12-urllib3: urllib3 Streaming API improperly handles highly compressed data (CVE-2025-66471)

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For detailed instructions how to apply this update, refer to:

https://access.redhat.com/documentation/en-us/red_hat_satellite/6.18/html/updating_red_hat_satellite/index

Affected Products

  • Red Hat Satellite 6.18 x86_64
  • Red Hat Satellite Capsule 6.18 x86_64
  • Red Hat Enterprise Linux for x86_64 9 x86_64

Fixes

  • BZ - 2380000 - CVE-2025-53643 aiohttp: AIOHTTP HTTP Request/Response Smuggling
  • BZ - 2419467 - CVE-2025-66471 urllib3: urllib3 Streaming API improperly handles highly compressed data
  • BZ - 2427726 - CVE-2026-21441 urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
  • SAT-35237 - The Insights Inventory report is not generated within "/var/lib/foreman/red_hat_inventory/generated_reports/" on Satellite 6.18
  • SAT-39454 - rubygem-hammer_cli_foreman_bootdisk-0.4.1-2 has untranslated messages
  • SAT-41521 - Satellite upgrade from 6.17.5 to 6.18 failed during Pulpcore database migration due to incompatible versions detected for some of the pulpcore plugins
  • SAT-41522 - N-1/N-2 Capsule sync fails with error Unable to update hosts ([RestClient::NotFound]: 404 Not Found)
  • SAT-41523 - Firmware type always reverts to Automatic for Compute Profiles in Satellite
  • SAT-41524 - Provide a check that subscription-manager release is not set
  • SAT-41525 - No repositories available through subscriptions on a host after registering it to Red Hat Satellite using global registration method
  • SAT-41526 - Capsule upgrade fails with a package conflict error despite the required repositories being enabled.
  • SAT-41527 - Allow users with EXTERNAL authentication to have blank mail
  • SAT-41528 - Incorrect documentation link under Red Hat Lightspeed ? Inventory Upload in Satellite Web UI
  • SAT-42125 - Custom yum repo sync over authed proxy fails

CVEs

  • CVE-2025-53643
  • CVE-2025-66471
  • CVE-2026-21441

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Satellite 6.18

SRPM
foreman-3.16.0.10-1.el9sat.src.rpm SHA-256: 7956265e2fad72cff746411044168fe90f2f3e3fc622e7f9f5e290e5c93a4260
foreman-installer-3.16.0.4-1.el9sat.src.rpm SHA-256: 0f02172394f92b224d70b8f4e37ba7a1df1b6accdb48a0e3f3e7bca15bc88e7a
python3.12-aiohappyeyeballs-2.6.1-1.el9pc.src.rpm SHA-256: 931963c7867bbd73bed7f794e4795e75db38040dbbb75f4a7582dbdcdc642957
python3.12-aiohttp-3.13.3-1.el9pc.src.rpm SHA-256: 6aaa0fcbab828688c2d0f08c7cc63c1c49eb7eecec37cc70f027f8ba7d141586
python3.12-brotli-1.2.0-1.el9pc.src.rpm SHA-256: cf83744103b9e693c3595f694655e5b361f3fd801daa46fd8af39659b7dcc7b3
python3.12-pulpcore-3.73.22-2.el9pc.src.rpm SHA-256: dc736fd9052bf62d819a312ec6e01045bf705253ffe49be633e52c8942276751
python3.12-urllib3-2.6.3-1.el9pc.src.rpm SHA-256: 80f73ad0b15e718e7eae3b279de2aa522367025baf06d9cee78a011b5b361451
python3.12-yarl-1.20.1-1.el9pc.src.rpm SHA-256: b1701c106aef133c1e737bd9b9a8bb4a98c3da07421a71e8a44b5f0d2ec4beb1
rubygem-foreman_maintain-1.13.7-1.el9sat.src.rpm SHA-256: 18969391f9cc0b88f0e2a0399cfaae296a27c78fc55e1d6be52d638e0fed4465
rubygem-foreman_rh_cloud-12.2.14-1.el9sat.src.rpm SHA-256: 410778f08fb7e4fca6c5c4cde6e126b39ed7eddf25a00d09c46c1427f65f0a60
rubygem-hammer_cli_foreman_bootdisk-0.4.2-1.el9sat.src.rpm SHA-256: 11f52ffc4c50a76b518987d89b39b86070bae7518f9ca0bab92f8b26140923b4
rubygem-katello-4.18.0.6-1.el9sat.src.rpm SHA-256: 6e1468e06845cbd65d67edccb09f14334840df44807e1fe53fa20a667d56f79a
satellite-6.18.3-1.el9sat.src.rpm SHA-256: 8a306753c1fb8a57f8418ad78917a9c2ade97632814e198f6e94ef0e914a85cc
satellite-lifecycle-6.18.0-2.el9sat.src.rpm SHA-256: f4719d6f6df4e9038d42d6130a2ac87a9d446d0eacb990e3f4f6ee942b3ae10f
x86_64
foreman-3.16.0.10-1.el9sat.noarch.rpm SHA-256: 2b13c72dedfabe0af07cc24406f78bc0a54019e2d004f0f426faaebc4efdb91c
foreman-cli-3.16.0.10-1.el9sat.noarch.rpm SHA-256: 0e353e7015defd396cd481880c0594493ccc24e14cf7eafb62d3ee5101f5343e
foreman-debug-3.16.0.10-1.el9sat.noarch.rpm SHA-256: 33851d169daa619e4ffbaf35068cca9a7a91defccdf2be61722e90c0af79b11e
foreman-dynflow-sidekiq-3.16.0.10-1.el9sat.noarch.rpm SHA-256: cc20c8019716be9f36a9628e3c22b736ee2a9b3dcd351c65e410cd4610e60fe5
foreman-ec2-3.16.0.10-1.el9sat.noarch.rpm SHA-256: e7f629cca7ad7b4728a7f8e0059aa2343037459df454871a5ae747cf3264ad7e
foreman-installer-3.16.0.4-1.el9sat.noarch.rpm SHA-256: 9b1992e3f1aee48b0100c8e1e8c0a6ece2acdae3669439ad8609e6f665314cc5
foreman-installer-katello-3.16.0.4-1.el9sat.noarch.rpm SHA-256: 953bcd1a5a30269c7b0e638542b1bdbd7740e16f7f92b3b090980748c36ce5a6
foreman-journald-3.16.0.10-1.el9sat.noarch.rpm SHA-256: b9c3b73d7ec885fb8816d03132ec53eb190ca3007b7443fb9a3abbc225e80761
foreman-libvirt-3.16.0.10-1.el9sat.noarch.rpm SHA-256: 762f1b61ff915529c21bd19c5600ecfb91d9c890af04f5805e878c687ae1bc94
foreman-openstack-3.16.0.10-1.el9sat.noarch.rpm SHA-256: 97808294dcd9e987ae770d1304709473bb1a6be1e2cfc876c7706bc8b19fd93b
foreman-pcp-3.16.0.10-1.el9sat.noarch.rpm SHA-256: 89b5f1d330c972838eee91879067ea0214ee1e54e3ea3d7566db2c212216deb6
foreman-postgresql-3.16.0.10-1.el9sat.noarch.rpm SHA-256: a6b209c2f79e653ebf8768991bae205b6c2c44828f4bbc09ab7fac2616bf7e2a
foreman-redis-3.16.0.10-1.el9sat.noarch.rpm SHA-256: 532f80b05f4c8489f9cefffcc7877dd84e9b4c6fa642bdb32ff71f3bb3a6be39
foreman-service-3.16.0.10-1.el9sat.noarch.rpm SHA-256: 68229d573cf62589cc3d112f83db930ee67ff6a3666286efd9567d80cceb37d4
foreman-telemetry-3.16.0.10-1.el9sat.noarch.rpm SHA-256: 5da76fe2514d9bcf1a68e29eb94534e54d2d9a022273ccfc8652e4a260af203d
foreman-vmware-3.16.0.10-1.el9sat.noarch.rpm SHA-256: 7aa46b89f32ece7a0df9d7ff727942b74038583a6470615ad96ea4b08b15ee9d
python3.12-aiohappyeyeballs-2.6.1-1.el9pc.noarch.rpm SHA-256: c04794da9c9e87dce044a5d3069d59e94c1d3c5d384f6b8e74b1e58085086919
python3.12-aiohttp-3.13.3-1.el9pc.x86_64.rpm SHA-256: d74abec798880a4c294b43df899418075681e6cad4ff2997f7e31ef88b948fbb
python3.12-aiohttp-debuginfo-3.13.3-1.el9pc.x86_64.rpm SHA-256: d74da15fe4d0001dc7211f7219386ab6ebe42f4d578ca593023077989ce3fb31
python3.12-aiohttp-debugsource-3.13.3-1.el9pc.x86_64.rpm SHA-256: 8fa60bd0ada6902d3e392c4766a3327be347f7f31ee6e2dbb15c9bf180aef1eb
python3.12-brotli-1.2.0-1.el9pc.x86_64.rpm SHA-256: c6b00ed27a6466782bbdd7ddb7a7a1c69f4d2be60fd6a6d0ff114031dbf37a4b
python3.12-brotli-debuginfo-1.2.0-1.el9pc.x86_64.rpm SHA-256: 51d780ee422853858ac77b90b21dd5247b85f745deefe753e598e7c4a04e4d4d
python3.12-brotli-debugsource-1.2.0-1.el9pc.x86_64.rpm SHA-256: d826426c1fc47d2f26326f8a2bcef573f2b26c6c0e3e6605582a3a8e9d6379de
python3.12-pulpcore-3.73.22-2.el9pc.noarch.rpm SHA-256: 5ac16b5eb1a14ec9e415f664bd93ca54e08ca200531265c7040f49d0c2b30f19
python3.12-urllib3-2.6.3-1.el9pc.noarch.rpm SHA-256: 05412f94ee7d995fffe6632115369bf72356b18155f68aad5df07aa1edd78207
python3.12-yarl-1.20.1-1.el9pc.noarch.rpm SHA-256: be15927152427bf1ee09a190ac72fdec58e150197d8fdae9f1d3f663c0fd8bd7
rubygem-foreman_maintain-1.13.7-1.el9sat.noarch.rpm SHA-256: a7ba6406744d5cfa108ba3ae0e2b1d5af677030b9fa7766bfd9cb2765e66b345
rubygem-foreman_rh_cloud-12.2.14-1.el9sat.noarch.rpm SHA-256: 1f6d586987906f9e9bf27787e241586ab3ea308c100820259231d84e4b4d04bb
rubygem-hammer_cli_foreman_bootdisk-0.4.2-1.el9sat.noarch.rpm SHA-256: 91dcc94cbaf9742eb8a822ca5525aab72adee9f8191da9c53cfd2d0a37fa6a73
rubygem-katello-4.18.0.6-1.el9sat.noarch.rpm SHA-256: b8a657adfb17d3c53ef75ffbf553e5e65f8da5c8eb32ea93b5901975fce7a33e
satellite-6.18.3-1.el9sat.noarch.rpm SHA-256: 7f3911a7352647ef4d733b4b7bc35b0109cace403e00e370186e74f03a23c555
satellite-cli-6.18.3-1.el9sat.noarch.rpm SHA-256: 5cce7308ca71d0a17c482fe140b6d44387aa29a1f9d997420b23977264f6b845
satellite-common-6.18.3-1.el9sat.noarch.rpm SHA-256: ced18e9a82cad47c6e7e0f984cc30f8c385029633a4a0d2e6fc429cf3a57835c
satellite-lifecycle-6.18.0-2.el9sat.noarch.rpm SHA-256: 0c023b9d6feb0beedc47104b0127220fc507beba047f17dad29c713a2bd7ce8f
satellite-obsolete-packages-6.18.3-1.el9sat.noarch.rpm SHA-256: a3e4da59cfabc61edee0134ec68e6da053c88c6be67775472cc576e71f0e62d1

Red Hat Satellite Capsule 6.18

SRPM
foreman-3.16.0.10-1.el9sat.src.rpm SHA-256: 7956265e2fad72cff746411044168fe90f2f3e3fc622e7f9f5e290e5c93a4260
foreman-installer-3.16.0.4-1.el9sat.src.rpm SHA-256: 0f02172394f92b224d70b8f4e37ba7a1df1b6accdb48a0e3f3e7bca15bc88e7a
python3.12-aiohappyeyeballs-2.6.1-1.el9pc.src.rpm SHA-256: 931963c7867bbd73bed7f794e4795e75db38040dbbb75f4a7582dbdcdc642957
python3.12-aiohttp-3.13.3-1.el9pc.src.rpm SHA-256: 6aaa0fcbab828688c2d0f08c7cc63c1c49eb7eecec37cc70f027f8ba7d141586
python3.12-brotli-1.2.0-1.el9pc.src.rpm SHA-256: cf83744103b9e693c3595f694655e5b361f3fd801daa46fd8af39659b7dcc7b3
python3.12-pulpcore-3.73.22-2.el9pc.src.rpm SHA-256: dc736fd9052bf62d819a312ec6e01045bf705253ffe49be633e52c8942276751
python3.12-urllib3-2.6.3-1.el9pc.src.rpm SHA-256: 80f73ad0b15e718e7eae3b279de2aa522367025baf06d9cee78a011b5b361451
python3.12-yarl-1.20.1-1.el9pc.src.rpm SHA-256: b1701c106aef133c1e737bd9b9a8bb4a98c3da07421a71e8a44b5f0d2ec4beb1
rubygem-foreman_maintain-1.13.7-1.el9sat.src.rpm SHA-256: 18969391f9cc0b88f0e2a0399cfaae296a27c78fc55e1d6be52d638e0fed4465
satellite-6.18.3-1.el9sat.src.rpm SHA-256: 8a306753c1fb8a57f8418ad78917a9c2ade97632814e198f6e94ef0e914a85cc
x86_64
foreman-debug-3.16.0.10-1.el9sat.noarch.rpm SHA-256: 33851d169daa619e4ffbaf35068cca9a7a91defccdf2be61722e90c0af79b11e
foreman-installer-3.16.0.4-1.el9sat.noarch.rpm SHA-256: 9b1992e3f1aee48b0100c8e1e8c0a6ece2acdae3669439ad8609e6f665314cc5
foreman-installer-katello-3.16.0.4-1.el9sat.noarch.rpm SHA-256: 953bcd1a5a30269c7b0e638542b1bdbd7740e16f7f92b3b090980748c36ce5a6
foreman-pcp-3.16.0.10-1.el9sat.noarch.rpm SHA-256: 89b5f1d330c972838eee91879067ea0214ee1e54e3ea3d7566db2c212216deb6
python3.12-aiohappyeyeballs-2.6.1-1.el9pc.noarch.rpm SHA-256: c04794da9c9e87dce044a5d3069d59e94c1d3c5d384f6b8e74b1e58085086919
python3.12-aiohttp-3.13.3-1.el9pc.x86_64.rpm SHA-256: d74abec798880a4c294b43df899418075681e6cad4ff2997f7e31ef88b948fbb
python3.12-aiohttp-debuginfo-3.13.3-1.el9pc.x86_64.rpm SHA-256: d74da15fe4d0001dc7211f7219386ab6ebe42f4d578ca593023077989ce3fb31
python3.12-aiohttp-debugsource-3.13.3-1.el9pc.x86_64.rpm SHA-256: 8fa60bd0ada6902d3e392c4766a3327be347f7f31ee6e2dbb15c9bf180aef1eb
python3.12-brotli-1.2.0-1.el9pc.x86_64.rpm SHA-256: c6b00ed27a6466782bbdd7ddb7a7a1c69f4d2be60fd6a6d0ff114031dbf37a4b
python3.12-brotli-debuginfo-1.2.0-1.el9pc.x86_64.rpm SHA-256: 51d780ee422853858ac77b90b21dd5247b85f745deefe753e598e7c4a04e4d4d
python3.12-brotli-debugsource-1.2.0-1.el9pc.x86_64.rpm SHA-256: d826426c1fc47d2f26326f8a2bcef573f2b26c6c0e3e6605582a3a8e9d6379de
python3.12-pulpcore-3.73.22-2.el9pc.noarch.rpm SHA-256: 5ac16b5eb1a14ec9e415f664bd93ca54e08ca200531265c7040f49d0c2b30f19
python3.12-urllib3-2.6.3-1.el9pc.noarch.rpm SHA-256: 05412f94ee7d995fffe6632115369bf72356b18155f68aad5df07aa1edd78207
python3.12-yarl-1.20.1-1.el9pc.noarch.rpm SHA-256: be15927152427bf1ee09a190ac72fdec58e150197d8fdae9f1d3f663c0fd8bd7
rubygem-foreman_maintain-1.13.7-1.el9sat.noarch.rpm SHA-256: a7ba6406744d5cfa108ba3ae0e2b1d5af677030b9fa7766bfd9cb2765e66b345
satellite-capsule-6.18.3-1.el9sat.noarch.rpm SHA-256: 82c247d35ca50fd0730306dd88cd8ee3c66ee90093fdad52f4bcb91b384b05d1
satellite-common-6.18.3-1.el9sat.noarch.rpm SHA-256: ced18e9a82cad47c6e7e0f984cc30f8c385029633a4a0d2e6fc429cf3a57835c
satellite-obsolete-packages-6.18.3-1.el9sat.noarch.rpm SHA-256: a3e4da59cfabc61edee0134ec68e6da053c88c6be67775472cc576e71f0e62d1

Red Hat Enterprise Linux for x86_64 9

SRPM
foreman-3.16.0.10-1.el9sat.src.rpm SHA-256: 7956265e2fad72cff746411044168fe90f2f3e3fc622e7f9f5e290e5c93a4260
rubygem-foreman_maintain-1.13.7-1.el9sat.src.rpm SHA-256: 18969391f9cc0b88f0e2a0399cfaae296a27c78fc55e1d6be52d638e0fed4465
rubygem-hammer_cli_foreman_bootdisk-0.4.2-1.el9sat.src.rpm SHA-256: 11f52ffc4c50a76b518987d89b39b86070bae7518f9ca0bab92f8b26140923b4
satellite-6.18.3-1.el9sat.src.rpm SHA-256: 8a306753c1fb8a57f8418ad78917a9c2ade97632814e198f6e94ef0e914a85cc
x86_64
foreman-cli-3.16.0.10-1.el9sat.noarch.rpm SHA-256: 0e353e7015defd396cd481880c0594493ccc24e14cf7eafb62d3ee5101f5343e
rubygem-foreman_maintain-1.13.7-1.el9sat.noarch.rpm SHA-256: a7ba6406744d5cfa108ba3ae0e2b1d5af677030b9fa7766bfd9cb2765e66b345
rubygem-hammer_cli_foreman_bootdisk-0.4.2-1.el9sat.noarch.rpm SHA-256: 91dcc94cbaf9742eb8a822ca5525aab72adee9f8191da9c53cfd2d0a37fa6a73
satellite-cli-6.18.3-1.el9sat.noarch.rpm SHA-256: 5cce7308ca71d0a17c482fe140b6d44387aa29a1f9d997420b23977264f6b845

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility