rubygem-katello vulnerabilities
CVEs whose affected-version data names the rubygem-katello package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-56098Medium· 4.3A flaw was found in rubygem-katello
A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While the application identifies unauthorized…
CVE-2026-56097Medium· 6.5A flaw was found in rubygem-katello
A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController.…
CVE-2026-79654Medium· 4.3A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user
A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization m…