CVE-2026-88831: Red Hat Hardened Images
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.
Affected products
- Red Hat Red Hat Hardened Images: before 1.37.0-9.1.hum1 (fixed in 1.37.0-9.1.hum1)
Published 2026-09-23. Last modified 2026-09-25.