CVE-2026-1616: Red Hat Open Security Issue Management

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0 allows path traversal attacks via query parameters.

Affected products

  • Red Hat Open Security Issue Management: before 2025.9.0 (fixed in 2025.9.0)

Published 2026-01-29. Last modified 2026-06-17.