{"id":"RHSA-2026:76130","summary":"Red Hat Security Advisory: Red Hat Single Sign-On 7.6.13 security update on RHEL 9","modified":"2026-10-07T10:42:38.154537352Z","published":"2026-10-07T10:19:59Z","upstream":["CVE-2025-12543","CVE-2025-14813","CVE-2025-9784","CVE-2026-0603","CVE-2026-15563","CVE-2026-2092","CVE-2026-2575","CVE-2026-3505","CVE-2026-42578","CVE-2026-42579","CVE-2026-42581","CVE-2026-42587","CVE-2026-44249","CVE-2026-44893","CVE-2026-45416","CVE-2026-45674","CVE-2026-4634","CVE-2026-47691","CVE-2026-48043","CVE-2026-48059","CVE-2026-50010","CVE-2026-50193","CVE-2026-54512","CVE-2026-5588","CVE-2026-68494","CVE-2026-7307","CVE-2026-7507"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:76130"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/#important"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_76130.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-9784"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2392306"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2025-9784"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-9784"},{"type":"ARTICLE","url":"https://github.com/undertow-io/undertow/pull/1778"},{"type":"ARTICLE","url":"https://github.com/undertow-io/undertow/releases/tag/2.2.38.Final"},{"type":"ARTICLE","url":"https://issues.redhat.com/browse/UNDERTOW-2598"},{"type":"ARTICLE","url":"https://kb.cert.org/vuls/id/767506"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-12543"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2408784"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2025-12543"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-12543"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-14813"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2458640"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2025-14813"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-14813"},{"type":"ARTICLE","url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%9014813"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-0603"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2427147"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-0603"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0603"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-2092"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2437296"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-2092"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2092"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-2575"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2440149"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-2575"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2575"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-3505"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2458638"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-3505"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3505"},{"type":"ARTICLE","url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%903505"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-4634"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2450250"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-4634"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4634"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-5588"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2458634"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-5588"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5588"},{"type":"ARTICLE","url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%905588"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-7307"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2476526"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-7307"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-7307"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-7507"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2464145"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-7507"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-7507"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-15563"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2483138"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-15563"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15563"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-42578"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477226"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-42578"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42578"},{"type":"ARTICLE","url":"https://github.com/netty/netty/security/advisories/GHSA-45q3-82m4-75jr"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-42579"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477217"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-42579"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42579"},{"type":"ARTICLE","url":"https://github.com/netty/netty/security/advisories/GHSA-cm33-6792-r9fm"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-42581"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477232"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-42581"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42581"},{"type":"ARTICLE","url":"https://github.com/netty/netty/security/advisories/GHSA-xxqh-mfjm-7mv9"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-42587"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477220"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-42587"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42587"},{"type":"ARTICLE","url":"https://github.com/netty/netty/security/advisories/GHSA-f6hv-jmp6-3vwv"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-44249"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2488081"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-44249"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44249"},{"type":"ARTICLE","url":"https://github.com/netty/netty/releases/tag/netty-4.1.135.Final"},{"type":"ARTICLE","url":"https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"},{"type":"ARTICLE","url":"https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-44893"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2488383"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-44893"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44893"},{"type":"ARTICLE","url":"https://github.com/netty/netty/security/advisories/GHSA-cc37-9q2j-3hfv"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-45416"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2488391"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-45416"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45416"},{"type":"ARTICLE","url":"https://github.com/netty/netty/security/advisories/GHSA-x4gw-5cx5-pgmh"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-45674"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2488400"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-45674"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45674"},{"type":"ARTICLE","url":"https://github.com/netty/netty/security/advisories/GHSA-676x-f7gg-47vc"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-47691"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2488439"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-47691"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47691"},{"type":"ARTICLE","url":"https://github.com/netty/netty/security/advisories/GHSA-5pvg-856g-cp85"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-48043"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2488442"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-48043"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48043"},{"type":"ARTICLE","url":"https://github.com/netty/netty/security/advisories/GHSA-c2gf-v879-257j"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-48059"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2488437"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-48059"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48059"},{"type":"ARTICLE","url":"https://github.com/netty/netty/security/advisories/GHSA-h2qv-fj59-j46j"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-50010"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2488429"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-50010"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50010"},{"type":"ARTICLE","url":"https://github.com/netty/netty/security/advisories/GHSA-c653-97m9-rcg9"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-50193"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491999"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-50193"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50193"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-databind/commit/a1fa4ae4ecf5cee16da465985f135f3e81816f8c"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-databind/issues/3447"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3wrr-7qpf-2prh"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-54512"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492015"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-54512"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54512"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-databind/issues/5988"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-68494"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2511026"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-68494"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68494"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-core/pull/1611"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-72hv-8253-57qq"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-18401"}],"affected":[{"package":{"name":"rh-sso7-keycloak","ecosystem":"Red Hat:red_hat_single_sign_on:7.6::el9","purl":"pkg:rpm/redhat/rh-sso7-keycloak"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.0.20-1.redhat_00001.1.el9sso"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:76130.json"}},{"package":{"name":"rh-sso7-keycloak-server","ecosystem":"Red Hat:red_hat_single_sign_on:7.6::el9","purl":"pkg:rpm/redhat/rh-sso7-keycloak-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.0.20-1.redhat_00001.1.el9sso"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:76130.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L"}]}