CVE-2026-56097Medium· 6.5▾ SunlitA flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController.…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController. The methods check_blob_push_org_label and get_matching_products_from_org take user-supplied labels directly from the request path and interpolate them into raw SQL fragments. This flaw is accessible to a user with only the create_personal_access_tokens permission, even if the user access is restricted, with no Organization or Location assigned.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56098Medium· 4.3A flaw was found in rubygem-katello
CVE-2026-79654Medium· 4.3A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user
CVE-2026-12545Medium· 6.7A flaw was found in rubygem-hammer_cli
CVE-2026-12542Medium· 5.3A flaw was found in Foreman
CVE-2026-96659Critical· 9.1A flaw was found in Foreman
CVE-2026-96658Critical· 9.9A flaw was found in Foreman