Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:28043: Important: Red Hat OpenStack Platform 17.1 (python-urllib3) security update

This Important security update for Red Hat OpenStack Platform 17.1 addresses three vulnerabilities in python-urllib3 (CVE-2025-66418, CVE-2025-66471, CVE-2026-21441) involving resource exhaustion and decompression-bomb safeguard bypasses via the streaming API and HTTP redirects. The article does not provide specific CVSS scores or detailed affected/fixed version ranges for the python-urllib3 package itself. The advisory instructs administrators to apply the update, which provides the patched packages `python-urllib3-1.26.5-3.el8ost.3.src.rpm` and `python3-urllib3-1.26.5-3.el8ost.3.noarch.rpm`, referencing the provided solution link for deployment details.
Read Full Article →

Red Hat Product Errata RHSA-2026:28043 - Security Advisory Issued: 2026-06-22 Updated: 2026-06-22 RHSA-2026:28043 - Security Advisory Overview Updated Packages Synopsis Important: Red Hat OpenStack Platform 17.1 (python-urllib3) security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for python-urllib3 is now available for Red Hat OpenStack Platform 17.1 (Wallaby). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Python HTTP module with connection pooling and file POST abilities. Security Fix(es): urllib3: Unbounded decompression chain leads to resource exhaustion (CVE-2025-66418) urllib3 Streaming API improperly handles highly compressed data (CVE-2025-66471) urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) (CVE-2026-21441) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat OpenStack 17.1 for RHEL 8 x86_64 Red Hat OpenStack Director Deployment Tools 17.1 for RHEL 8 x86_64 Red Hat Enterprise Linux for x86_64 8 x86_64 Fixes BZ - 2419455 - CVE-2025-66418 urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion BZ - 2419467 - CVE-2025-66471 urllib3: urllib3 Streaming API improperly handles highly compressed data BZ - 2427726 - CVE-2026-21441 urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) CVEs CVE-2025-66418 CVE-2025-66471 CVE-2026-21441 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat OpenStack 17.1 for RHEL 8 SRPM python-urllib3-1.26.5-3.el8ost.3.src.rpm SHA-256: 067e7c0edcff0132b94336da78c0ab27906a5491e6930b13b522a22911e846c6 x86_64 python3-urllib3-1.26.5-3.el8ost.3.noarch.rpm SHA-256: 33ba5ae074493d545099bc32cb3c59f34453a3f178b391d41eb43f8d59351f80 Red Hat OpenStack Director Deployment Tools 17.1 for RHEL 8 SRPM python-urllib3-1.26.5-3.el8ost.3.src.rpm SHA-256: 067e7c0edcff0132b94336da78c0ab27906a5491e6930b13b522a22911e846c6 x86_64 python3-urllib3-1.26.5-3.el8ost.3.noarch.rpm SHA-256: 33ba5ae074493d545099bc32cb3c59f34453a3f178b391d41eb43f8d59351f80 Red Hat Enterprise Linux for x86_64 8 SRPM python-urllib3-1.26.5-3.el8ost.3.src.rpm SHA-256: 067e7c0edcff0132b94336da78c0ab27906a5491e6930b13b522a22911e846c6 x86_64 python3-urllib3-1.26.5-3.el8ost.3.noarch.rpm SHA-256: 33ba5ae074493d545099bc32cb3c59f34453a3f178b391d41eb43f8d59351f80 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article