Red Hat Ceph Storage
Red Hat Ceph Storage has a software-defined architecture you can integrate into your existing hardware and infrastructure for lower capital costs and more flexibility. Even better for your IT environment, Ceph Storage offers robust, multi-tenant storage for cloud and virtualization applications like Red Hat Enterprise Linux OpenStack Platform.
Browse the latest documentation
Latest security advisories
| Severity | Advisory/CVE | Synopsis | Date |
|---|---|---|---|
| Severity Moderate | Advisory/CVECVE-2026-65902 | Synopsis A flaw was found in DOMPurify. An attacker can exploit a vulnerability in how DOMPurify handles its sanitization hooks when default configurations are used. By manipulating the uponSanitizeElement or uponSanitizeAttribute hooks, an attacker can permanently alter the allowed HTML tags and attributes. This allows malicious content to bypass sanitization, potentially leading to cross-site scripting (XSS) attacks and compromising the integrity of web applications. | Date |
| Severity Moderate | Advisory/CVECVE-2026-65901 | Synopsis A flaw was found in DOMPurify. This cross-site scripting (XSS) vulnerability exists in IN_PLACE mode, where the software trusts attacker-controlled nodeName on live non-form nodes. A remote attacker can supply hostile live Document Object Model (DOM) objects with script children. These scripts can execute when the sanitized tree is inserted into a live document, potentially leading to information disclosure or arbitrary code execution. | Date |
| Severity Moderate | Advisory/CVECVE-2026-65899 | Synopsis A flaw was found in DOMPurify where the clearConfig() function does not properly reset the retained Trusted Types policy. This can lead to a DOMPurify instance, when reused across different security contexts, remaining bound to a previously supplied and potentially unsafe policy. An attacker could leverage this to execute malicious scripts, resulting in client-side arbitrary code execution. | Date |
| Severity Moderate | Advisory/CVECVE-2026-65898 | Synopsis A flaw was found in DOMPurify. When the `setConfig()` function is used with an `uponSanitizeAttribute` hook, the `ALLOWED_ATTR` allowlist is not properly cloned. This allows an attacker to register a hook that can permanently modify the shared allowlist, enabling the conditional allowance of dangerous attributes. Consequently, an attacker can submit untrusted content that inherits the polluted allowlist, leading to stored Cross-site Scripting (XSS) and the execution of event handlers. | Date |
| Severity Important | Advisory/CVE(RHSA-2026:33154) Red Hat Ceph Storage | Synopsis Red Hat Ceph Storage | Date |
Top resources
Knowledgebase
Access articles and solutions to find answers to your questions.
Supported configurations
See your Red Hat-provided production or development support for supported configurations.
Troubleshooting
Connect to the right information to self-solve issues quickly and efficiently.
Lifecycle
View the various levels of maintenance for each release of a product over a period from initial release to the end of maintenance.
Get support
Support cases
Get answers quickly by opening a support case with us.
Live chat
Directly access our support engineers during weekday business hours.
Call or email
Speak directly with a Red Hat Support expert by phone or through email.