CVE-2026-74860: Red Hat Cert Manager Support For Red Hat Openshift Release 1.20

High severity, CVSS 8.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.

Affected products

  • Red Hat Cert Manager Support For Red Hat Openshift Release 1.20: before 1790589912 (fixed in 1790589912); before 1790589914 (fixed in 1790589914); before 1790589855 (fixed in 1790589855)
  • Red Hat Red Hat Cost Management On-Premise 1: before 1791460851 (fixed in 1791460851)
  • Red Hat Red Hat Enterprise Linux 10: before 0:2.12.5-10.el10_2.4 (fixed in 0:2.12.5-10.el10_2.4)
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8: before 0:2.9.7-21.el8_10.9 (fixed in 0:2.9.7-21.el8_10.9)
  • Red Hat Red Hat Enterprise Linux 9: before 0:2.9.13-14.el9_8.5 (fixed in 0:2.9.13-14.el9_8.5)
  • Red Hat Red Hat Hardened Images: before 2.15.4-0.1.hum1 (fixed in 2.15.4-0.1.hum1)
  • Red Hat Red Hat Openshift Container Platform 4

Published 2026-09-08. Last modified 2026-10-09.