Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:66327 - Security Advisory
Issued:
2026-09-10
Updated:
2026-09-10

RHSA-2026:66327 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: osbuild-composer security, bug fix, and enhancement update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for osbuild-composer is now available for Red Hat Enterprise Linux 10.0 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810)
  • net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
  • net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)
  • mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)
  • github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)
  • encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
  • net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
  • net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
  • html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
  • crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
  • encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)

Bug Fix(es) and Enhancement(s):

  • backport: osbuild-composer from el10 ships el9 google repos (JIRA:RHEL-127068)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x
  • Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64

Fixes

  • BZ - 2456335 - CVE-2026-33810 crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application
  • BZ - 2467809 - CVE-2026-42499 net/mail: golang: net/mail: Denial of Service via pathological email address parsing
  • BZ - 2467820 - CVE-2026-39820 net/mail: golang: Go net/mail: Denial of Service via crafted email inputs
  • BZ - 2484204 - CVE-2026-42504 mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header
  • BZ - 2484830 - CVE-2026-41178 github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers
  • BZ - 2515815 - CVE-2026-33818 encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
  • BZ - 2515820 - CVE-2026-56860 net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution
  • BZ - 2515827 - CVE-2026-56853 net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
  • BZ - 2515838 - CVE-2026-56858 html/template: golang: Go html/template: Cross-Site Scripting via pathological input
  • BZ - 2515839 - CVE-2026-56862 crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
  • BZ - 2515840 - CVE-2026-56859 encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue
  • RHEL-127068 - backport: osbuild-composer from el10 ships el9 google repos

CVEs

  • CVE-2026-33810
  • CVE-2026-33818
  • CVE-2026-39820
  • CVE-2026-41178
  • CVE-2026-42499
  • CVE-2026-42504
  • CVE-2026-56853
  • CVE-2026-56858
  • CVE-2026-56859
  • CVE-2026-56860
  • CVE-2026-56862

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0

SRPM
osbuild-composer-134.1-12.el10_0.src.rpm SHA-256: 71efbc00af4c767b27b4f52275259a77861fa01fcbe3b8c39a42a8db0bece608
x86_64
osbuild-composer-134.1-12.el10_0.x86_64.rpm SHA-256: 6c72d37e689ae1a60188a633ab5a572f2d2d546bc5a3b18f858c52864997ce30
osbuild-composer-core-134.1-12.el10_0.x86_64.rpm SHA-256: 2b49e184bd816333f91aa0731242cd657ac66f0c5ac7e848900278c8acba8b71
osbuild-composer-core-debuginfo-134.1-12.el10_0.x86_64.rpm SHA-256: 39465bab89e6e5cf6678549e83e0b933b4eea0a13d6984933394805be34d0c1c
osbuild-composer-debugsource-134.1-12.el10_0.x86_64.rpm SHA-256: c6cd0495fd9c116b54fccf22a18bf3a80137a8ca779914abfa28a80597f037b0
osbuild-composer-tests-debuginfo-134.1-12.el10_0.x86_64.rpm SHA-256: 713b755e677e4b980fe89a9e75ad9585a9bfb0a39f82ec08a3a8baf095639a08
osbuild-composer-worker-134.1-12.el10_0.x86_64.rpm SHA-256: fce876400b5fe11a28e9750afdebd1f95ec809e126733b85cb378707bfbd3c1b
osbuild-composer-worker-debuginfo-134.1-12.el10_0.x86_64.rpm SHA-256: 48d09c1827eb1a28f3e95419927d7e3e3ff779a91d5512b68aea1f264b46f871

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0

SRPM
osbuild-composer-134.1-12.el10_0.src.rpm SHA-256: 71efbc00af4c767b27b4f52275259a77861fa01fcbe3b8c39a42a8db0bece608
s390x
osbuild-composer-134.1-12.el10_0.s390x.rpm SHA-256: 21c3842a9cd5058a3d2e5d584afd31b6125937e5b787aad802140fd90c68d650
osbuild-composer-core-134.1-12.el10_0.s390x.rpm SHA-256: 97d433bd5fb0db0495c9957c29160fd1b8c8c6e5a2f4b07fb298deb56fdf54d1
osbuild-composer-core-debuginfo-134.1-12.el10_0.s390x.rpm SHA-256: 24a6d2098a54b20d58bbf876d6b8bf6ace0003b59355cd05a71e3e8cff93ae9a
osbuild-composer-debugsource-134.1-12.el10_0.s390x.rpm SHA-256: 0a21e2c5119beaae82717d345e42f102f78283b384dbbae1569ec6ed4adc60a9
osbuild-composer-tests-debuginfo-134.1-12.el10_0.s390x.rpm SHA-256: 4d05365e25b5f37aded49b796a258b0389acfad40f2e141b2273b7d2257a7904
osbuild-composer-worker-134.1-12.el10_0.s390x.rpm SHA-256: 64afd971dd5002ede625590c6c6c255c290c28396bd8b8aaf6284631d6c1fa28
osbuild-composer-worker-debuginfo-134.1-12.el10_0.s390x.rpm SHA-256: 2758f28cdab5b9ac716dfb534b17aeb8a9d6aad7b1b46d9048cc6316a07494a5

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0

SRPM
osbuild-composer-134.1-12.el10_0.src.rpm SHA-256: 71efbc00af4c767b27b4f52275259a77861fa01fcbe3b8c39a42a8db0bece608
ppc64le
osbuild-composer-134.1-12.el10_0.ppc64le.rpm SHA-256: d87f6cd7e5fcc5d9486aced86ee192bc67f52a557a32506d1cc3e73aea985014
osbuild-composer-core-134.1-12.el10_0.ppc64le.rpm SHA-256: 91dcce16a7b81e637a53fa0f648c75d23d1683d896f2f36dbae0eb91510446ee
osbuild-composer-core-debuginfo-134.1-12.el10_0.ppc64le.rpm SHA-256: ed29d095732a062989ba658a3e5c23274a7b4350e9b71095a8f14d6801e8d796
osbuild-composer-debugsource-134.1-12.el10_0.ppc64le.rpm SHA-256: 821c1217763e7549378ed1bc2a4b0cec00901b5dd5871ab68c8919fb2eab2117
osbuild-composer-tests-debuginfo-134.1-12.el10_0.ppc64le.rpm SHA-256: f8d292e37800ad0908c96d7034afa0d4652369e96e817cd52bd22af78b962299
osbuild-composer-worker-134.1-12.el10_0.ppc64le.rpm SHA-256: 9ddd2cdd970acd7444cf5c3b97dbc17b25a1b0ec507591a68d253d3107bea7fa
osbuild-composer-worker-debuginfo-134.1-12.el10_0.ppc64le.rpm SHA-256: 11dab4c89d5c713b7bea432b484252a10ab8b5531a641e33279b7e562ebd8477

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0

SRPM
osbuild-composer-134.1-12.el10_0.src.rpm SHA-256: 71efbc00af4c767b27b4f52275259a77861fa01fcbe3b8c39a42a8db0bece608
aarch64
osbuild-composer-134.1-12.el10_0.aarch64.rpm SHA-256: 41577d611f10c90bbcf25502ae80797c9424e975ec49eeb9088e2d1e9dc6669a
osbuild-composer-core-134.1-12.el10_0.aarch64.rpm SHA-256: cfe8ece8ff4192dd6f363a14805ba0ea97518b6d9b47cbd91a88de183e02edd3
osbuild-composer-core-debuginfo-134.1-12.el10_0.aarch64.rpm SHA-256: fa707c255c6fd47d29672652e7c0a82a29ce9d41f51d40928d48b7f68e386071
osbuild-composer-debugsource-134.1-12.el10_0.aarch64.rpm SHA-256: 303f4ab446431709d9650ec95aa5ec17216e943dfc30db713c04fd745e42fc3a
osbuild-composer-tests-debuginfo-134.1-12.el10_0.aarch64.rpm SHA-256: 2c0605fe815733263c4026dbad15e1377e05227c77eddff058aada3891c83624
osbuild-composer-worker-134.1-12.el10_0.aarch64.rpm SHA-256: bbbdfdd69a30f563c961e04028cda8482624de34159eff47e82d6cc5c65f7153
osbuild-composer-worker-debuginfo-134.1-12.el10_0.aarch64.rpm SHA-256: ec3a2f73648a486c2304769d0845960479bd61f767fcfbe10f5f240e1dfd1fee

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0

SRPM
osbuild-composer-134.1-12.el10_0.src.rpm SHA-256: 71efbc00af4c767b27b4f52275259a77861fa01fcbe3b8c39a42a8db0bece608
aarch64
osbuild-composer-134.1-12.el10_0.aarch64.rpm SHA-256: 41577d611f10c90bbcf25502ae80797c9424e975ec49eeb9088e2d1e9dc6669a
osbuild-composer-core-134.1-12.el10_0.aarch64.rpm SHA-256: cfe8ece8ff4192dd6f363a14805ba0ea97518b6d9b47cbd91a88de183e02edd3
osbuild-composer-core-debuginfo-134.1-12.el10_0.aarch64.rpm SHA-256: fa707c255c6fd47d29672652e7c0a82a29ce9d41f51d40928d48b7f68e386071
osbuild-composer-debugsource-134.1-12.el10_0.aarch64.rpm SHA-256: 303f4ab446431709d9650ec95aa5ec17216e943dfc30db713c04fd745e42fc3a
osbuild-composer-tests-debuginfo-134.1-12.el10_0.aarch64.rpm SHA-256: 2c0605fe815733263c4026dbad15e1377e05227c77eddff058aada3891c83624
osbuild-composer-worker-134.1-12.el10_0.aarch64.rpm SHA-256: bbbdfdd69a30f563c961e04028cda8482624de34159eff47e82d6cc5c65f7153
osbuild-composer-worker-debuginfo-134.1-12.el10_0.aarch64.rpm SHA-256: ec3a2f73648a486c2304769d0845960479bd61f767fcfbe10f5f240e1dfd1fee

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0

SRPM
osbuild-composer-134.1-12.el10_0.src.rpm SHA-256: 71efbc00af4c767b27b4f52275259a77861fa01fcbe3b8c39a42a8db0bece608
s390x
osbuild-composer-134.1-12.el10_0.s390x.rpm SHA-256: 21c3842a9cd5058a3d2e5d584afd31b6125937e5b787aad802140fd90c68d650
osbuild-composer-core-134.1-12.el10_0.s390x.rpm SHA-256: 97d433bd5fb0db0495c9957c29160fd1b8c8c6e5a2f4b07fb298deb56fdf54d1
osbuild-composer-core-debuginfo-134.1-12.el10_0.s390x.rpm SHA-256: 24a6d2098a54b20d58bbf876d6b8bf6ace0003b59355cd05a71e3e8cff93ae9a
osbuild-composer-debugsource-134.1-12.el10_0.s390x.rpm SHA-256: 0a21e2c5119beaae82717d345e42f102f78283b384dbbae1569ec6ed4adc60a9
osbuild-composer-tests-debuginfo-134.1-12.el10_0.s390x.rpm SHA-256: 4d05365e25b5f37aded49b796a258b0389acfad40f2e141b2273b7d2257a7904
osbuild-composer-worker-134.1-12.el10_0.s390x.rpm SHA-256: 64afd971dd5002ede625590c6c6c255c290c28396bd8b8aaf6284631d6c1fa28
osbuild-composer-worker-debuginfo-134.1-12.el10_0.s390x.rpm SHA-256: 2758f28cdab5b9ac716dfb534b17aeb8a9d6aad7b1b46d9048cc6316a07494a5

Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0

SRPM
osbuild-composer-134.1-12.el10_0.src.rpm SHA-256: 71efbc00af4c767b27b4f52275259a77861fa01fcbe3b8c39a42a8db0bece608
ppc64le
osbuild-composer-134.1-12.el10_0.ppc64le.rpm SHA-256: d87f6cd7e5fcc5d9486aced86ee192bc67f52a557a32506d1cc3e73aea985014
osbuild-composer-core-134.1-12.el10_0.ppc64le.rpm SHA-256: 91dcce16a7b81e637a53fa0f648c75d23d1683d896f2f36dbae0eb91510446ee
osbuild-composer-core-debuginfo-134.1-12.el10_0.ppc64le.rpm SHA-256: ed29d095732a062989ba658a3e5c23274a7b4350e9b71095a8f14d6801e8d796
osbuild-composer-debugsource-134.1-12.el10_0.ppc64le.rpm SHA-256: 821c1217763e7549378ed1bc2a4b0cec00901b5dd5871ab68c8919fb2eab2117
osbuild-composer-tests-debuginfo-134.1-12.el10_0.ppc64le.rpm SHA-256: f8d292e37800ad0908c96d7034afa0d4652369e96e817cd52bd22af78b962299
osbuild-composer-worker-134.1-12.el10_0.ppc64le.rpm SHA-256: 9ddd2cdd970acd7444cf5c3b97dbc17b25a1b0ec507591a68d253d3107bea7fa
osbuild-composer-worker-debuginfo-134.1-12.el10_0.ppc64le.rpm SHA-256: 11dab4c89d5c713b7bea432b484252a10ab8b5531a641e33279b7e562ebd8477

Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0

SRPM
osbuild-composer-134.1-12.el10_0.src.rpm SHA-256: 71efbc00af4c767b27b4f52275259a77861fa01fcbe3b8c39a42a8db0bece608
x86_64
osbuild-composer-134.1-12.el10_0.x86_64.rpm SHA-256: 6c72d37e689ae1a60188a633ab5a572f2d2d546bc5a3b18f858c52864997ce30
osbuild-composer-core-134.1-12.el10_0.x86_64.rpm SHA-256: 2b49e184bd816333f91aa0731242cd657ac66f0c5ac7e848900278c8acba8b71
osbuild-composer-core-debuginfo-134.1-12.el10_0.x86_64.rpm SHA-256: 39465bab89e6e5cf6678549e83e0b933b4eea0a13d6984933394805be34d0c1c
osbuild-composer-debugsource-134.1-12.el10_0.x86_64.rpm SHA-256: c6cd0495fd9c116b54fccf22a18bf3a80137a8ca779914abfa28a80597f037b0
osbuild-composer-tests-debuginfo-134.1-12.el10_0.x86_64.rpm SHA-256: 713b755e677e4b980fe89a9e75ad9585a9bfb0a39f82ec08a3a8baf095639a08
osbuild-composer-worker-134.1-12.el10_0.x86_64.rpm SHA-256: fce876400b5fe11a28e9750afdebd1f95ec809e126733b85cb378707bfbd3c1b
osbuild-composer-worker-debuginfo-134.1-12.el10_0.x86_64.rpm SHA-256: 48d09c1827eb1a28f3e95419927d7e3e3ff779a91d5512b68aea1f264b46f871

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility