Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:63134 - Security Advisory
Issued:
2026-09-03
Updated:
2026-09-03

RHSA-2026:63134 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: osbuild-composer security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for osbuild-composer is now available for Red Hat Enterprise Linux 10.0 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
  • golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136)
  • golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)
  • golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering (CVE-2026-42502)
  • github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x
  • Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64

Fixes

  • BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
  • BZ - 2480757 - CVE-2026-27136 golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
  • BZ - 2480761 - CVE-2026-25681 golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting
  • BZ - 2480762 - CVE-2026-42502 golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering
  • BZ - 2493622 - CVE-2026-55677 github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy

CVEs

  • CVE-2026-25681
  • CVE-2026-27136
  • CVE-2026-39821
  • CVE-2026-42502
  • CVE-2026-55677

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0

SRPM
osbuild-composer-134.1-10.el10_0.src.rpm SHA-256: ea25416542f716a93ae7fa2edfcea3a3d15c240e20d03bae1f15c4c9014967df
x86_64
osbuild-composer-134.1-10.el10_0.x86_64.rpm SHA-256: 98bfd4413f278b2f91a228a0f19e5bc517e79dcc8bf983511cdcc1808675b2fb
osbuild-composer-core-134.1-10.el10_0.x86_64.rpm SHA-256: 882a5f9411764ed6311f078e4958ee59899ffe85f347633e3a3bbdb84e189161
osbuild-composer-core-debuginfo-134.1-10.el10_0.x86_64.rpm SHA-256: 0e2b1ee0ea2c4a356bdafb9f2074455a864c01eafe372d9d42601dbf9ac4cba8
osbuild-composer-debugsource-134.1-10.el10_0.x86_64.rpm SHA-256: 1ba84fe0868601ec7895ef93292fbb579f23aa7b0146acd0b8ef910bab70aec9
osbuild-composer-tests-debuginfo-134.1-10.el10_0.x86_64.rpm SHA-256: e3b2b11bdaa26d2f48774c0b8bc993429055a3622f7b9f156fb3baed127df81c
osbuild-composer-worker-134.1-10.el10_0.x86_64.rpm SHA-256: dfe0d50bf82f82a52044cd92b5ca08166a1b2e6de8c4c73b71568c052c7620e8
osbuild-composer-worker-debuginfo-134.1-10.el10_0.x86_64.rpm SHA-256: f700c43246641870c9ecf11b1f46eb0450b9fc84ed0ff896a8b5f819d0fe8d4e

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0

SRPM
osbuild-composer-134.1-10.el10_0.src.rpm SHA-256: ea25416542f716a93ae7fa2edfcea3a3d15c240e20d03bae1f15c4c9014967df
s390x
osbuild-composer-134.1-10.el10_0.s390x.rpm SHA-256: 5f715e299315b1ff8fbffde7b0756e98d7232a433d74073f8320bea1f1574396
osbuild-composer-core-134.1-10.el10_0.s390x.rpm SHA-256: 8a01bae5c89e72c767fcbf08a643052008859a7cf38dae9b652309d7306761c9
osbuild-composer-core-debuginfo-134.1-10.el10_0.s390x.rpm SHA-256: b65fc8440209c32d3e4e9cd86284421f615119d673e66b0c1f7fcfa24885ac8f
osbuild-composer-debugsource-134.1-10.el10_0.s390x.rpm SHA-256: 1618d5deb3f3da94c0c7f7f4b82745fc5f5bfb0fa5777075a353800487a84e7d
osbuild-composer-tests-debuginfo-134.1-10.el10_0.s390x.rpm SHA-256: 01e35ec3c1f95388e5f22f43e9a8d20f27315854110fca7ef7e5f4d326206616
osbuild-composer-worker-134.1-10.el10_0.s390x.rpm SHA-256: 8329fc2af47c2d44a812f4a93ddcb858903eddfcf2ab1e272fbc7c7631dfe148
osbuild-composer-worker-debuginfo-134.1-10.el10_0.s390x.rpm SHA-256: 7380302b7215f12b0ce8a92c4ab64ca7a55d9bf43042035806d7f0833efd8b6e

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0

SRPM
osbuild-composer-134.1-10.el10_0.src.rpm SHA-256: ea25416542f716a93ae7fa2edfcea3a3d15c240e20d03bae1f15c4c9014967df
ppc64le
osbuild-composer-134.1-10.el10_0.ppc64le.rpm SHA-256: a21e4ede3ee700bd714602333d6a593e7433449ef7ef4ec1e562c38cfa79d75b
osbuild-composer-core-134.1-10.el10_0.ppc64le.rpm SHA-256: 472bc1686ae5e6d2cc4c4435e8545f53e328fa8a0b6305e220c4cfb34846ddca
osbuild-composer-core-debuginfo-134.1-10.el10_0.ppc64le.rpm SHA-256: 6377b38ed4f7821bccc457d240977c39017b299c068dae79be413fea7b2f3372
osbuild-composer-debugsource-134.1-10.el10_0.ppc64le.rpm SHA-256: 201a588e502604bcc2de869707e3333b6668773705d2b164c5694cc3c69d5053
osbuild-composer-tests-debuginfo-134.1-10.el10_0.ppc64le.rpm SHA-256: 81ffffaf457a0d0e764c34f5a3596b9d77bf152846cf21375be01bde8aeb9060
osbuild-composer-worker-134.1-10.el10_0.ppc64le.rpm SHA-256: c35a9b7173606681ccc3a1f3282d810975bb1c9b1e43446bca8912ef78f91038
osbuild-composer-worker-debuginfo-134.1-10.el10_0.ppc64le.rpm SHA-256: d80df56eb8a0030393f9f65d755dbeace56123d1f33b8d0b5e7e59e83d14b2c5

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0

SRPM
osbuild-composer-134.1-10.el10_0.src.rpm SHA-256: ea25416542f716a93ae7fa2edfcea3a3d15c240e20d03bae1f15c4c9014967df
aarch64
osbuild-composer-134.1-10.el10_0.aarch64.rpm SHA-256: 2c9245e380933791f3dd03461caefcf3065e202a363edbe95305be91bfebdfa1
osbuild-composer-core-134.1-10.el10_0.aarch64.rpm SHA-256: 896bce44df8a17b7469aec8db9e180675b316d783f5a049066d06f8f19c2a58d
osbuild-composer-core-debuginfo-134.1-10.el10_0.aarch64.rpm SHA-256: 975c124c46cb3ff1b7457f6fe1768f52c53072164fd12f45694e7ece8e7cb5bb
osbuild-composer-debugsource-134.1-10.el10_0.aarch64.rpm SHA-256: 0274380ae1bf245f74c600be2ab2347dc84b353e5fa152b9e76a6f36e237b556
osbuild-composer-tests-debuginfo-134.1-10.el10_0.aarch64.rpm SHA-256: 071be5597a935f03ffebe34fe0cfae0ac7a4df982ed037084689147e45e6f2a8
osbuild-composer-worker-134.1-10.el10_0.aarch64.rpm SHA-256: 3340671da15e3bf18fe4a856abb5e6c283a5eb863780412a5b45b634227bc3fe
osbuild-composer-worker-debuginfo-134.1-10.el10_0.aarch64.rpm SHA-256: 467bf9d85782c3426d00a9ab02b858439a104ff9a7fad24d46a7ac670436a366

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0

SRPM
osbuild-composer-134.1-10.el10_0.src.rpm SHA-256: ea25416542f716a93ae7fa2edfcea3a3d15c240e20d03bae1f15c4c9014967df
aarch64
osbuild-composer-134.1-10.el10_0.aarch64.rpm SHA-256: 2c9245e380933791f3dd03461caefcf3065e202a363edbe95305be91bfebdfa1
osbuild-composer-core-134.1-10.el10_0.aarch64.rpm SHA-256: 896bce44df8a17b7469aec8db9e180675b316d783f5a049066d06f8f19c2a58d
osbuild-composer-core-debuginfo-134.1-10.el10_0.aarch64.rpm SHA-256: 975c124c46cb3ff1b7457f6fe1768f52c53072164fd12f45694e7ece8e7cb5bb
osbuild-composer-debugsource-134.1-10.el10_0.aarch64.rpm SHA-256: 0274380ae1bf245f74c600be2ab2347dc84b353e5fa152b9e76a6f36e237b556
osbuild-composer-tests-debuginfo-134.1-10.el10_0.aarch64.rpm SHA-256: 071be5597a935f03ffebe34fe0cfae0ac7a4df982ed037084689147e45e6f2a8
osbuild-composer-worker-134.1-10.el10_0.aarch64.rpm SHA-256: 3340671da15e3bf18fe4a856abb5e6c283a5eb863780412a5b45b634227bc3fe
osbuild-composer-worker-debuginfo-134.1-10.el10_0.aarch64.rpm SHA-256: 467bf9d85782c3426d00a9ab02b858439a104ff9a7fad24d46a7ac670436a366

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0

SRPM
osbuild-composer-134.1-10.el10_0.src.rpm SHA-256: ea25416542f716a93ae7fa2edfcea3a3d15c240e20d03bae1f15c4c9014967df
s390x
osbuild-composer-134.1-10.el10_0.s390x.rpm SHA-256: 5f715e299315b1ff8fbffde7b0756e98d7232a433d74073f8320bea1f1574396
osbuild-composer-core-134.1-10.el10_0.s390x.rpm SHA-256: 8a01bae5c89e72c767fcbf08a643052008859a7cf38dae9b652309d7306761c9
osbuild-composer-core-debuginfo-134.1-10.el10_0.s390x.rpm SHA-256: b65fc8440209c32d3e4e9cd86284421f615119d673e66b0c1f7fcfa24885ac8f
osbuild-composer-debugsource-134.1-10.el10_0.s390x.rpm SHA-256: 1618d5deb3f3da94c0c7f7f4b82745fc5f5bfb0fa5777075a353800487a84e7d
osbuild-composer-tests-debuginfo-134.1-10.el10_0.s390x.rpm SHA-256: 01e35ec3c1f95388e5f22f43e9a8d20f27315854110fca7ef7e5f4d326206616
osbuild-composer-worker-134.1-10.el10_0.s390x.rpm SHA-256: 8329fc2af47c2d44a812f4a93ddcb858903eddfcf2ab1e272fbc7c7631dfe148
osbuild-composer-worker-debuginfo-134.1-10.el10_0.s390x.rpm SHA-256: 7380302b7215f12b0ce8a92c4ab64ca7a55d9bf43042035806d7f0833efd8b6e

Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0

SRPM
osbuild-composer-134.1-10.el10_0.src.rpm SHA-256: ea25416542f716a93ae7fa2edfcea3a3d15c240e20d03bae1f15c4c9014967df
ppc64le
osbuild-composer-134.1-10.el10_0.ppc64le.rpm SHA-256: a21e4ede3ee700bd714602333d6a593e7433449ef7ef4ec1e562c38cfa79d75b
osbuild-composer-core-134.1-10.el10_0.ppc64le.rpm SHA-256: 472bc1686ae5e6d2cc4c4435e8545f53e328fa8a0b6305e220c4cfb34846ddca
osbuild-composer-core-debuginfo-134.1-10.el10_0.ppc64le.rpm SHA-256: 6377b38ed4f7821bccc457d240977c39017b299c068dae79be413fea7b2f3372
osbuild-composer-debugsource-134.1-10.el10_0.ppc64le.rpm SHA-256: 201a588e502604bcc2de869707e3333b6668773705d2b164c5694cc3c69d5053
osbuild-composer-tests-debuginfo-134.1-10.el10_0.ppc64le.rpm SHA-256: 81ffffaf457a0d0e764c34f5a3596b9d77bf152846cf21375be01bde8aeb9060
osbuild-composer-worker-134.1-10.el10_0.ppc64le.rpm SHA-256: c35a9b7173606681ccc3a1f3282d810975bb1c9b1e43446bca8912ef78f91038
osbuild-composer-worker-debuginfo-134.1-10.el10_0.ppc64le.rpm SHA-256: d80df56eb8a0030393f9f65d755dbeace56123d1f33b8d0b5e7e59e83d14b2c5

Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0

SRPM
osbuild-composer-134.1-10.el10_0.src.rpm SHA-256: ea25416542f716a93ae7fa2edfcea3a3d15c240e20d03bae1f15c4c9014967df
x86_64
osbuild-composer-134.1-10.el10_0.x86_64.rpm SHA-256: 98bfd4413f278b2f91a228a0f19e5bc517e79dcc8bf983511cdcc1808675b2fb
osbuild-composer-core-134.1-10.el10_0.x86_64.rpm SHA-256: 882a5f9411764ed6311f078e4958ee59899ffe85f347633e3a3bbdb84e189161
osbuild-composer-core-debuginfo-134.1-10.el10_0.x86_64.rpm SHA-256: 0e2b1ee0ea2c4a356bdafb9f2074455a864c01eafe372d9d42601dbf9ac4cba8
osbuild-composer-debugsource-134.1-10.el10_0.x86_64.rpm SHA-256: 1ba84fe0868601ec7895ef93292fbb579f23aa7b0146acd0b8ef910bab70aec9
osbuild-composer-tests-debuginfo-134.1-10.el10_0.x86_64.rpm SHA-256: e3b2b11bdaa26d2f48774c0b8bc993429055a3622f7b9f156fb3baed127df81c
osbuild-composer-worker-134.1-10.el10_0.x86_64.rpm SHA-256: dfe0d50bf82f82a52044cd92b5ca08166a1b2e6de8c4c73b71568c052c7620e8
osbuild-composer-worker-debuginfo-134.1-10.el10_0.x86_64.rpm SHA-256: f700c43246641870c9ecf11b1f46eb0450b9fc84ed0ff896a8b5f819d0fe8d4e

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility