Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:5145 - Security Advisory
Issued:
2026-03-19
Updated:
2026-03-19

RHSA-2026:5145 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: yggdrasil-worker-package-manager security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for yggdrasil-worker-package-manager is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

yggdrasil-worker-package-manager is a simple package manager yggd worker. It knows how to install and remove packages, add, remove, enable and disable repositories, and does rudimentary detection of the host it is running on to guess the package manager to use. It only installs packages that match one of the provided allow-pattern regular expressions.

Security Fix(es):

  • golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 10 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for ARM 64 10 aarch64

Fixes

  • BZ - 2434432 - CVE-2025-61726 golang: net/url: Memory exhaustion in query parameter parsing in net/url

CVEs

  • CVE-2025-61726

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 10

SRPM
yggdrasil-worker-package-manager-0.2.3-4.el10_1.src.rpm SHA-256: 557c5e265e9ee30e1f194f98e9d6efffd31edca7c25dfbacb2a9c458e336bdf0
x86_64
yggdrasil-worker-package-manager-0.2.3-4.el10_1.x86_64.rpm SHA-256: 83a40e87b81050377673838550ab3151df41d500e390b77b76edfefa4a9b9152
yggdrasil-worker-package-manager-debuginfo-0.2.3-4.el10_1.x86_64.rpm SHA-256: 43bb6dc2b0e2a2ae9d66ed3ac7b27f4e8b13803c8db69d599ac20b579823e324
yggdrasil-worker-package-manager-debugsource-0.2.3-4.el10_1.x86_64.rpm SHA-256: 7fb3a93cdb0b9a19ba21f786b0509861e89b99c32de33032f4b8e99faaafa998

Red Hat Enterprise Linux for IBM z Systems 10

SRPM
yggdrasil-worker-package-manager-0.2.3-4.el10_1.src.rpm SHA-256: 557c5e265e9ee30e1f194f98e9d6efffd31edca7c25dfbacb2a9c458e336bdf0
s390x
yggdrasil-worker-package-manager-0.2.3-4.el10_1.s390x.rpm SHA-256: df2710cccd678f57bc881887a27d51ab18e6f45ad77ebba4ebb979f8ff288712
yggdrasil-worker-package-manager-debuginfo-0.2.3-4.el10_1.s390x.rpm SHA-256: e0a751c711704d3b17f91c735521882ade929b83cabce120b794f0a33597d8b9
yggdrasil-worker-package-manager-debugsource-0.2.3-4.el10_1.s390x.rpm SHA-256: 25173c058e390dd2b1356fc04d3ca72f0b30913e0aebc7448f6b5aea4e4d5830

Red Hat Enterprise Linux for Power, little endian 10

SRPM
yggdrasil-worker-package-manager-0.2.3-4.el10_1.src.rpm SHA-256: 557c5e265e9ee30e1f194f98e9d6efffd31edca7c25dfbacb2a9c458e336bdf0
ppc64le
yggdrasil-worker-package-manager-0.2.3-4.el10_1.ppc64le.rpm SHA-256: a3400d712792b46df4d64b941949e5601fe601ca1a9e83115b163239f51af85e
yggdrasil-worker-package-manager-debuginfo-0.2.3-4.el10_1.ppc64le.rpm SHA-256: 6819ae048dd167b6ab14618ab652cd02fd44088fd8f557841534c0557ed26203
yggdrasil-worker-package-manager-debugsource-0.2.3-4.el10_1.ppc64le.rpm SHA-256: 0debd5e60a40a3b493af59ccaf0feccf3e19eb96fefe15b274c67fdeafedaf7c

Red Hat Enterprise Linux for ARM 64 10

SRPM
yggdrasil-worker-package-manager-0.2.3-4.el10_1.src.rpm SHA-256: 557c5e265e9ee30e1f194f98e9d6efffd31edca7c25dfbacb2a9c458e336bdf0
aarch64
yggdrasil-worker-package-manager-0.2.3-4.el10_1.aarch64.rpm SHA-256: 1cf2e735b7dfe27a7d20ceac8721c134c74b19d6f3c8e91cfe16b7b735ee1668
yggdrasil-worker-package-manager-debuginfo-0.2.3-4.el10_1.aarch64.rpm SHA-256: 32e87adbaeb6a0144f9f538f75a0cc9a09f6803d607e6458e8f45124b63642a0
yggdrasil-worker-package-manager-debugsource-0.2.3-4.el10_1.aarch64.rpm SHA-256: c3045f06cc30eaee2bdc279947f08100ef05445d61b807ac2d5bb0dcfd5502e4

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility