Red Hat Offline Knowledge Portal
Red Hat Offline Knowledge Portal (RHOKP) is a secure, offline version of Red Hat's proprietary knowledge content for our products. It's a pocket library of our award winning Knowledgebase, product documentation, CVEs, Errata, and more that's light enough to run at the edge. RHOKP is useful anywhere Red Hat products are used where connectivity is limited, from intentionally disconnected secure sites to situations with planned intervals of low or no bandwidth. A single small container image, it is easy to install and use and compatible with Red Hat OpenShift, podman, or any OCI compliant container runtime.
browse_doc
latest_security
| severity | advisory_cve | synopsis | date |
|---|---|---|---|
| severity Important | advisory_cveCVE-2026-68494 | synopsis A flaw was found in jackson-core. A remote attacker can exploit an incomplete fix in the non-blocking JSON parser by streaming specially crafted JSON data in small chunks. This bypasses the intended number length constraint, causing the parser to accumulate excessive memory per connection. This uncontrolled memory growth can lead to a denial of service (DoS) by exhausting the Java Virtual Machine (JVM) heap. | date |
| severity Moderate | advisory_cveCVE-2026-18401 | synopsis A flaw was found in jackson-core. The non-blocking (asynchronous) JSON parser does not properly enforce the maximum number length constraint. A remote attacker can exploit this by submitting a specially crafted JSON document containing an arbitrarily long number to an application using the asynchronous parser. This can lead to excessive memory allocation and CPU exhaustion, resulting in a denial of service (DoS) for the affected application. | date |
| severity Important | advisory_cveCVE-2026-10050 | synopsis A flaw was found in Eclipse Jetty, a widely used web server and servlet container. This vulnerability affects its HTTP Digest authentication mechanism, which is used to verify user identities. The issue arises because Jetty's hash computation for passwords does not correctly handle certain characters, leading to a weakness in how passwords are processed. A remote attacker could exploit this by crafting a specific password that generates the same internal hash as a legitimate user's password, thereby bypassing authentication and gaining unauthorized access to the victim's account. | date |
| severity Moderate | advisory_cveCVE-2026-59888 | synopsis A flaw was found in jackson-databind. When Java Records use a PropertyNamingStrategy, an attacker can bypass the @JsonIgnore annotation during deserialization. This allows a renamed JSON key to be assigned to a Record constructor parameter, even if it was intended to be ignored. Consequently, an untrusted client could set internal or privileged components from external input, potentially leading to unauthorized modification or disclosure of sensitive data. | date |
| severity Moderate | advisory_cveCVE-2026-10051 | synopsis A flaw was found in Eclipse Jetty. This vulnerability allows a remote attacker to cause the server to retain HTTP/1.1 request trailers from a prior connection. Consequently, subsequent requests made over the same connection may unintentionally disclose information by reporting the previously retained trailers, or a combination of previous and current request trailers. | date |
top_resources
Documentation
Find more technical content about how to use your products or services.
Access Key Generator
This is the app to get a key to access the subscriber content in the image.
Red Hat Satellite subscription required for Offline Knowledge Portal
The Red Hat Offline Knowledge Portal is only available as an add-on to the Red Hat Satellite Infrastructure Subscription (SKU MCT3718).
Obtaining an Access Key
Running the RHOKP image results in “Missing ACCESS_KEY” banner.