Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:54624 - Security Advisory
Issued:
2026-08-13
Updated:
2026-08-13

RHSA-2026:54624 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: yelp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for yelp is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Yelp is the help browser for the GNOME desktop. It is designed to help you browse all the documentation on your system in one central tool, including traditional man pages, info pages and documentation written in DocBook.

Security Fix(es):

  • yelp: yelp-xsl: Overly Permissive Content Security Policy in Yelp Allows Host File Disclosure from Flatpak Applications (CVE-2026-13601)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.8 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64

Fixes

  • BZ - 2494110 - CVE-2026-13601 yelp: yelp-xsl: Overly Permissive Content Security Policy in Yelp Allows Host File Disclosure from Flatpak Applications

CVEs

  • CVE-2026-13601

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8

SRPM
yelp-3.28.1-3.el8_8.2.src.rpm SHA-256: e01554719784d81eee45af8a67cedfc557562fa1aeed952c7ef823cf5e388ff0
x86_64
yelp-3.28.1-3.el8_8.2.x86_64.rpm SHA-256: a7ffbe82cc78a73f21986352f1bcffefa0690e60a45b427759d21851e88f1734
yelp-debuginfo-3.28.1-3.el8_8.2.i686.rpm SHA-256: 4bd4eee9e7119f18683113a391eccdb5536726ed10020303e6fc042a0d833647
yelp-debuginfo-3.28.1-3.el8_8.2.x86_64.rpm SHA-256: 7b4367828a33ec494bd6e16feaf3b1d43ce1e7882a37ade9d51f7f9a97b86c69
yelp-debugsource-3.28.1-3.el8_8.2.i686.rpm SHA-256: 4258753bb53dafddbe055ab2418167df270ebfaf122dbbe7340febda23b12fee
yelp-debugsource-3.28.1-3.el8_8.2.x86_64.rpm SHA-256: 6eee526701d9b5d75489231e88b648c45a78efd02abba43f815b7402d4c9d8f1
yelp-libs-3.28.1-3.el8_8.2.i686.rpm SHA-256: ba56c7a69bd05670924a3178a3d0c1a86fe5823ff609920ec00fb177411f8c85
yelp-libs-3.28.1-3.el8_8.2.x86_64.rpm SHA-256: 2d23c5ec7af437d3767fdff907e98dda15e67da89d0fbdcc062bba800a55809e
yelp-libs-debuginfo-3.28.1-3.el8_8.2.i686.rpm SHA-256: 5a20b81a6d7099386d62d5f3016cdd0c1c18e23ccf5eee186a435be89cb0878b
yelp-libs-debuginfo-3.28.1-3.el8_8.2.x86_64.rpm SHA-256: 1b154c51e84a168af524c3ad19939d746b2164754c381efaca1ed515530fa74b

Red Hat Enterprise Linux Server - TUS 8.8

SRPM
yelp-3.28.1-3.el8_8.2.src.rpm SHA-256: e01554719784d81eee45af8a67cedfc557562fa1aeed952c7ef823cf5e388ff0
x86_64
yelp-3.28.1-3.el8_8.2.x86_64.rpm SHA-256: a7ffbe82cc78a73f21986352f1bcffefa0690e60a45b427759d21851e88f1734
yelp-debuginfo-3.28.1-3.el8_8.2.i686.rpm SHA-256: 4bd4eee9e7119f18683113a391eccdb5536726ed10020303e6fc042a0d833647
yelp-debuginfo-3.28.1-3.el8_8.2.x86_64.rpm SHA-256: 7b4367828a33ec494bd6e16feaf3b1d43ce1e7882a37ade9d51f7f9a97b86c69
yelp-debugsource-3.28.1-3.el8_8.2.i686.rpm SHA-256: 4258753bb53dafddbe055ab2418167df270ebfaf122dbbe7340febda23b12fee
yelp-debugsource-3.28.1-3.el8_8.2.x86_64.rpm SHA-256: 6eee526701d9b5d75489231e88b648c45a78efd02abba43f815b7402d4c9d8f1
yelp-libs-3.28.1-3.el8_8.2.i686.rpm SHA-256: ba56c7a69bd05670924a3178a3d0c1a86fe5823ff609920ec00fb177411f8c85
yelp-libs-3.28.1-3.el8_8.2.x86_64.rpm SHA-256: 2d23c5ec7af437d3767fdff907e98dda15e67da89d0fbdcc062bba800a55809e
yelp-libs-debuginfo-3.28.1-3.el8_8.2.i686.rpm SHA-256: 5a20b81a6d7099386d62d5f3016cdd0c1c18e23ccf5eee186a435be89cb0878b
yelp-libs-debuginfo-3.28.1-3.el8_8.2.x86_64.rpm SHA-256: 1b154c51e84a168af524c3ad19939d746b2164754c381efaca1ed515530fa74b

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8

SRPM
yelp-3.28.1-3.el8_8.2.src.rpm SHA-256: e01554719784d81eee45af8a67cedfc557562fa1aeed952c7ef823cf5e388ff0
ppc64le
yelp-3.28.1-3.el8_8.2.ppc64le.rpm SHA-256: 060e39ab5b8b02ae4ce1277c1beeb942e9c204d8ee3c28c34d0ba63d0d25ad07
yelp-debuginfo-3.28.1-3.el8_8.2.ppc64le.rpm SHA-256: 8d8b2c379b857cac10b26e7e33e12a073b4fe2cb87d92701ed83211c34f2bcd1
yelp-debugsource-3.28.1-3.el8_8.2.ppc64le.rpm SHA-256: 045c2bcb06a4c08fc133d6e6aa80f96725b9676b0edc8e4df4cbf84be32b6242
yelp-libs-3.28.1-3.el8_8.2.ppc64le.rpm SHA-256: 2db499ab40890dc127b5fa362bfd400964d8b8dd2d5f77edf6da53eaabd18573
yelp-libs-debuginfo-3.28.1-3.el8_8.2.ppc64le.rpm SHA-256: 1eea160b2548f100c86cd122164794d575459d947ef9549119fa3ab773f0d54e

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8

SRPM
yelp-3.28.1-3.el8_8.2.src.rpm SHA-256: e01554719784d81eee45af8a67cedfc557562fa1aeed952c7ef823cf5e388ff0
x86_64
yelp-3.28.1-3.el8_8.2.x86_64.rpm SHA-256: a7ffbe82cc78a73f21986352f1bcffefa0690e60a45b427759d21851e88f1734
yelp-debuginfo-3.28.1-3.el8_8.2.i686.rpm SHA-256: 4bd4eee9e7119f18683113a391eccdb5536726ed10020303e6fc042a0d833647
yelp-debuginfo-3.28.1-3.el8_8.2.x86_64.rpm SHA-256: 7b4367828a33ec494bd6e16feaf3b1d43ce1e7882a37ade9d51f7f9a97b86c69
yelp-debugsource-3.28.1-3.el8_8.2.i686.rpm SHA-256: 4258753bb53dafddbe055ab2418167df270ebfaf122dbbe7340febda23b12fee
yelp-debugsource-3.28.1-3.el8_8.2.x86_64.rpm SHA-256: 6eee526701d9b5d75489231e88b648c45a78efd02abba43f815b7402d4c9d8f1
yelp-libs-3.28.1-3.el8_8.2.i686.rpm SHA-256: ba56c7a69bd05670924a3178a3d0c1a86fe5823ff609920ec00fb177411f8c85
yelp-libs-3.28.1-3.el8_8.2.x86_64.rpm SHA-256: 2d23c5ec7af437d3767fdff907e98dda15e67da89d0fbdcc062bba800a55809e
yelp-libs-debuginfo-3.28.1-3.el8_8.2.i686.rpm SHA-256: 5a20b81a6d7099386d62d5f3016cdd0c1c18e23ccf5eee186a435be89cb0878b
yelp-libs-debuginfo-3.28.1-3.el8_8.2.x86_64.rpm SHA-256: 1b154c51e84a168af524c3ad19939d746b2164754c381efaca1ed515530fa74b

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility