RHSA-2026:22714
Critical
Red Hat Security Advisory: osbuild-composer security update
Exploit probability
Not scored
Published
June 3, 2026
Required by
Not available
Last source change
August 20, 2026
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
RHSA-2026:22714
View original source
Red Hat Security Advisory: osbuild-composer security update
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2026:22714
- https://access.redhat.com/security/cve/CVE-2025-61726
- https://access.redhat.com/security/cve/CVE-2025-61728
- https://access.redhat.com/security/cve/CVE-2025-68121
- https://access.redhat.com/security/cve/CVE-2026-25679
- https://access.redhat.com/security/cve/CVE-2026-27137
- https://access.redhat.com/security/cve/CVE-2026-32282
- https://access.redhat.com/security/cve/CVE-2026-32283
- https://access.redhat.com/security/cve/CVE-2026-32286
- https://access.redhat.com/security/cve/CVE-2026-33186
- https://access.redhat.com/security/cve/CVE-2026-34986
- https://access.redhat.com/security/cve/CVE-2026-4427
- https://access.redhat.com/security/updates/classification/#important
- https://bugzilla.redhat.com/show_bug.cgi?id=2434431
- https://bugzilla.redhat.com/show_bug.cgi?id=2434432
- https://bugzilla.redhat.com/show_bug.cgi?id=2437111
- https://bugzilla.redhat.com/show_bug.cgi?id=2445345
- https://bugzilla.redhat.com/show_bug.cgi?id=2445356
- https://bugzilla.redhat.com/show_bug.cgi?id=2448626
- https://bugzilla.redhat.com/show_bug.cgi?id=2449833
- https://bugzilla.redhat.com/show_bug.cgi?id=2451847
- https://bugzilla.redhat.com/show_bug.cgi?id=2455470
- https://bugzilla.redhat.com/show_bug.cgi?id=2456336
- https://bugzilla.redhat.com/show_bug.cgi?id=2456338
- https://github.com/go-jose/go-jose/security/advisories/GHSA-78h2-9frx-2jm8
- https://github.com/golang/vulndb/issues/4518
- https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3
- https://github.com/jackc/pgproto3
- https://github.com/jackc/pgx/issues/2507
- https://go.dev/cl/736712
- https://go.dev/cl/736713
- https://go.dev/cl/737700
- https://go.dev/cl/752180
- https://go.dev/cl/752182
- https://go.dev/cl/763761
- https://go.dev/cl/763767
- https://go.dev/issue/77101
- https://go.dev/issue/77102
- https://go.dev/issue/77217
- https://go.dev/issue/77578
- https://go.dev/issue/77952
- https://go.dev/issue/78293
- https://go.dev/issue/78334
- https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU
- https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk
- https://groups.google.com/g/golang-announce/c/K09ubi9FQFk
- https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc
- https://issues.redhat.com/browse/RHEL-179251
- https://issues.redhat.com/browse/RHEL-180018
- https://nvd.nist.gov/vuln/detail/CVE-2025-61726
- https://nvd.nist.gov/vuln/detail/CVE-2025-61728
- https://nvd.nist.gov/vuln/detail/CVE-2025-68121
- https://nvd.nist.gov/vuln/detail/CVE-2026-25679
- https://nvd.nist.gov/vuln/detail/CVE-2026-27137
- https://nvd.nist.gov/vuln/detail/CVE-2026-32282
- https://nvd.nist.gov/vuln/detail/CVE-2026-32283
- https://nvd.nist.gov/vuln/detail/CVE-2026-32286
- https://nvd.nist.gov/vuln/detail/CVE-2026-33186
- https://nvd.nist.gov/vuln/detail/CVE-2026-34986
- https://nvd.nist.gov/vuln/detail/CVE-2026-4427
- https://pkg.go.dev/github.com/go-jose/go-jose/v4#pkg-constants
- https://pkg.go.dev/vuln/GO-2026-4337
- https://pkg.go.dev/vuln/GO-2026-4341
- https://pkg.go.dev/vuln/GO-2026-4342
- https://pkg.go.dev/vuln/GO-2026-4518
- https://pkg.go.dev/vuln/GO-2026-4599
- https://pkg.go.dev/vuln/GO-2026-4601
- https://pkg.go.dev/vuln/GO-2026-4864
- https://pkg.go.dev/vuln/GO-2026-4870
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_22714.json
- https://securityinfinity.com/research/memory-safety-vulnerabilities-in-go-postgresql-wire-protocol-parsers-pgproto3-pgx
- https://www.cve.org/CVERecord?id=CVE-2025-61726
- https://www.cve.org/CVERecord?id=CVE-2025-61728
- https://www.cve.org/CVERecord?id=CVE-2025-68121
- https://www.cve.org/CVERecord?id=CVE-2026-25679
- https://www.cve.org/CVERecord?id=CVE-2026-27137
- https://www.cve.org/CVERecord?id=CVE-2026-32282
- https://www.cve.org/CVERecord?id=CVE-2026-32283
- https://www.cve.org/CVERecord?id=CVE-2026-32286
- https://www.cve.org/CVERecord?id=CVE-2026-33186
- https://www.cve.org/CVERecord?id=CVE-2026-34986
- https://www.cve.org/CVERecord?id=CVE-2026-4427