Red Hat Update Infrastructure
Red Hat® Update Infrastructure (RHUI) offers a highly scalable solution to manage yum repository content for Red Hat Enterprise Linux® cloud instances.
browse_doc
Release NotesProduct Documentation
Installation and Management GuideProduct Documentation
latest_security
| severity | advisory_cve | synopsis | date |
|---|---|---|---|
| severity Important | advisory_cve(RHSA-2026:54387) Important: Red Hat Update Infrastructure 5.2 security update | synopsis Important: Red Hat Update Infrastructure 5.2 security update | date |
| severity Moderate | advisory_cveCVE-2026-73229 | synopsis A flaw was found in Django REST framework. The AdminRenderer component, when processing an invalid write request, can improperly invoke a GET request without adequate permission checks. This oversight allows an unauthenticated attacker to access data that they are not authorized to view, leading to information disclosure. This vulnerability affects the confidentiality of sensitive information. | date |
| severity Moderate | advisory_cveCVE-2026-73228 | synopsis A flaw was found in Django REST framework. A remote attacker could exploit a vulnerability in the `request.data` parsing mechanism, which bypasses Django's `DATA_UPLOAD_MAX_MEMORY_SIZE` protection. This allows an attacker to send oversized JSON and URL-encoded request bodies, leading to excessive consumption of memory and CPU resources. This could result in a Denial of Service (DoS) for the affected application. | date |
| severity Important | advisory_cveCVE-2026-15307 | synopsis A flaw was found in Django. GeoDjango's spatial lookups can be exploited by a staff user with view permissions who submits a specially crafted spatial-field filter. This vulnerability allows an attacker to write arbitrary files to the server, which can lead to remote code execution. Additionally, it can be used to make outbound network requests, resulting in server-side request forgery. | date |
| severity Important | advisory_cveCVE-2026-69244 | synopsis A flaw was found in AIOHTTP, an asynchronous HTTP client/server framework. This vulnerability involves an out-of-bounds heap read in the C response parser when processing malformed HTTP responses. An attacker operating a malicious server, or even an accidental malformed response, could exploit this to trigger a Denial of Service (DoS) in the client application, making it unavailable. | date |
top_resources
Knowledgebase
Access articles and solutions to find answers to your questions.
Troubleshooting
Connect to the right information to self-solve issues quickly and efficiently.
Lifecycle
View the various levels of maintenance for each release of a product over a period from initial release to the end of maintenance.
Documentation
Find more technical content about how to use your products or services.