{
  "threat_severity" : "Moderate",
  "public_date" : "2026-03-20T05:17:03Z",
  "bugzilla" : {
    "description" : "fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass",
    "id" : "2449458",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2449458"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-776",
  "details" : [ "fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass vulnerability where numeric character references (&#NNN;, &#xHH;) and standard XML entities completely evade the entity expansion limits (e.g., maxTotalExpansions, maxExpandedLength) added to fix CVE-2026-26278, enabling XML entity expansion Denial of Service. The root cause is that replaceEntitiesValue() in OrderedObjParser.js only enforces expansion counting on DOCTYPE-defined entities while the lastEntities loop handling numeric/standard entities performs no counting at all. An attacker supplying 1M numeric entity references like &#65; can force ~147MB of memory allocation and heavy CPU usage, potentially crashing the process—even when developers have configured strict limits. This issue has been fixed in version 5.5.6.", "A flaw was found in fast-xml-parser. A remote attacker can exploit this vulnerability by supplying specially crafted XML input containing numeric character references or standard XML entities. This input can bypass configured entity expansion limits, leading to excessive memory allocation and high CPU usage. The primary consequence is a Denial of Service (DoS), which can crash the affected process." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Advanced Cluster Security for Kubernetes 4.8",
    "release_date" : "2026-04-08T00:00:00Z",
    "advisory" : "RHSA-2026:7110",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
    "package" : "advanced-cluster-security/rhacs-main-rhel8:1775594119"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security for Kubernetes 4.9",
    "release_date" : "2026-04-08T00:00:00Z",
    "advisory" : "RHSA-2026:7128",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
    "package" : "advanced-cluster-security/rhacs-main-rhel8:1775594284"
  }, {
    "product_name" : "Red Hat Developer Hub 1.8",
    "release_date" : "2026-04-22T00:00:00Z",
    "advisory" : "RHSA-2026:9742",
    "cpe" : "cpe:/a:redhat:rhdh:1.8::el9",
    "package" : "rhdh/rhdh-hub-rhel9:1776784286"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.16",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17549",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/cephcsi-rhel9:1778076673"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.16",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17549",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/mcg-core-rhel9:1778076741"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.16",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17549",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/mcg-rhel9-operator:1778076916"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.16",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17549",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/ocs-client-console-rhel9:1778077421"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.16",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17549",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/ocs-client-rhel9-operator:1778076861"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.16",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17549",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/ocs-metrics-exporter-rhel9:1778077066"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.16",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17549",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/ocs-rhel9-operator:1778077002"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.16",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17549",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/odf-cli-rhel9:1778077164"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.16",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17549",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/odf-console-rhel9:1778077913"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.16",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17549",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/odf-cosi-sidecar-rhel9:1778077379"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.16",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17549",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/odf-csi-addons-rhel9-operator:1778077455"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.16",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17549",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/odf-csi-addons-sidecar-rhel9:1778077447"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.16",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17549",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/odf-multicluster-console-rhel9:1778078096"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.16",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17549",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/odf-multicluster-rhel9-operator:1778077527"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.16",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17549",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/odf-must-gather-rhel9:1778077651"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.16",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17549",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/odf-rhel9-operator:1778077920"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.16",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17549",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/odr-rhel9-operator:1778077737"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.16",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17549",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/rook-ceph-rhel9-operator:1778077839"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.17",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17550",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/cephcsi-rhel9:1778049594"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.17",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17550",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/cephcsi-rhel9-operator:1778049298"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.17",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17550",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/mcg-core-rhel9:1778049745"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.17",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17550",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/mcg-rhel9-operator:1778049753"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.17",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17550",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/ocs-client-console-rhel9:1778050558"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.17",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17550",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/ocs-client-rhel9-operator:1778049818"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.17",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17550",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/ocs-metrics-exporter-rhel9:1778049878"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.17",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17550",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/ocs-rhel9-operator:1778049920"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.17",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17550",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/odf-cli-rhel9:1778049945"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.17",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17550",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/odf-console-rhel9:1778060364"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.17",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17550",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/odf-cosi-sidecar-rhel9:1778050037"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.17",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17550",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/odf-csi-addons-rhel9-operator:1778050035"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.17",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17550",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/odf-csi-addons-sidecar-rhel9:1778050048"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.17",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17550",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/odf-multicluster-console-rhel9:1778050508"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.17",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17550",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/odf-multicluster-rhel9-operator:1778050119"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.17",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17550",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/odf-must-gather-rhel9:1778050290"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.17",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17550",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/odf-rhel9-operator:1778059723"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.17",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17550",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/odr-rhel9-operator:1778050352"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.17",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17550",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/rook-ceph-rhel9-operator:1778050482"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.18",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17547",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/cephcsi-rhel9:1778045210"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.18",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17547",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/cephcsi-rhel9-operator:1778044961"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.18",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17547",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/mcg-core-rhel9:1778045359"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.18",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17547",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/mcg-rhel9-operator:1778045374"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.18",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17547",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/ocs-client-console-rhel9:1778045891"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.18",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17547",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/ocs-client-rhel9-operator:1778045472"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.18",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17547",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/ocs-metrics-exporter-rhel9:1778045534"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.18",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17547",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/ocs-rhel9-operator:1778045524"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.18",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17547",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/odf-cli-rhel9:1778045587"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.18",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17547",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/odf-console-rhel9:1778046067"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.18",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17547",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/odf-cosi-sidecar-rhel9:1778045627"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.18",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17547",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/odf-csi-addons-rhel9-operator:1778045731"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.18",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17547",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/odf-csi-addons-sidecar-rhel9:1778045700"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.18",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17547",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/odf-multicluster-console-rhel9:1778046234"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.18",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17547",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/odf-multicluster-rhel9-operator:1778045792"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.18",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17547",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/odf-must-gather-rhel9:1778045858"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.18",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17547",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/odf-rhel9-operator:1778045945"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.18",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17547",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/odr-rhel9-operator:1778045931"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.18",
    "release_date" : "2026-05-14T00:00:00Z",
    "advisory" : "RHSA-2026:17547",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/rook-ceph-rhel9-operator:1778046079"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/cephcsi-rhel9:1776079019"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/cephcsi-rhel9-operator:1776706744"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/mcg-core-rhel9:1776707205"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/mcg-rhel9-operator:1776707231"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/ocs-client-console-rhel9:1776707760"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/ocs-client-rhel9-operator:1776707301"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/ocs-metrics-exporter-rhel9:1776079295"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/ocs-rhel9-operator:1776707362"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/odf-cli-rhel9:1776707418"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/odf-cloudnative-pg-rhel9-operator:1776707377"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/odf-console-rhel9:1776707947"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/odf-cosi-sidecar-rhel9:1776707456"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/odf-csi-addons-rhel9-operator:1776707526"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/odf-csi-addons-sidecar-rhel9:1776707526"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/odf-multicluster-console-rhel9:1776707945"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/odf-multicluster-rhel9-operator:1776707569"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/odf-must-gather-rhel9:1776707724"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/odf-rhel9-operator:1776707763"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/odr-rhel9-operator:1776707771"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.19",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12279",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.19::el9",
    "package" : "odf4/rook-ceph-rhel9-operator:1776079774"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/cephcsi-rhel9:1775822432"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/cephcsi-rhel9-operator:1776403457"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/mcg-core-rhel9:1776403991"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/mcg-rhel9-operator:1776404009"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/ocs-client-console-rhel9:1776404539"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/ocs-client-rhel9-operator:1776404060"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/ocs-metrics-exporter-rhel9:1775822689"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/ocs-rhel9-operator:1776404131"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/odf-cli-rhel9:1776406225"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/odf-cloudnative-pg-rhel9-operator:1776406131"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/odf-console-rhel9:1776406770"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/odf-cosi-sidecar-rhel9:1776406247"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/odf-csi-addons-rhel9-operator:1776406286"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/odf-csi-addons-sidecar-rhel9:1776406291"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/odf-external-snapshotter-rhel9-operator:1776406284"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/odf-external-snapshotter-sidecar-rhel9:1776406291"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/odf-multicluster-console-rhel9:1776406771"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/odf-multicluster-rhel9-operator:1776406384"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/odf-must-gather-rhel9:1776406540"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/odf-rhel9-operator:1776406595"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/odr-rhel9-operator:1776406594"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4.2",
    "release_date" : "2026-04-30T00:00:00Z",
    "advisory" : "RHSA-2026:12277",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.20::el9",
    "package" : "odf4/rook-ceph-rhel9-operator:1775823207"
  } ],
  "package_state" : [ {
    "product_name" : "Migration Toolkit for Applications 8",
    "fix_state" : "Affected",
    "package_name" : "mta/mta-ui-rhel9",
    "cpe" : "cpe:/a:redhat:migration_toolkit_applications:8"
  }, {
    "product_name" : "Red Hat Developer Hub",
    "fix_state" : "Will not fix",
    "package_name" : "rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor",
    "cpe" : "cpe:/a:redhat:rhdh:1"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Not affected",
    "package_name" : "rhoai/odh-mlflow-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift GitOps",
    "fix_state" : "Will not fix",
    "package_name" : "openshift-gitops-1/argocd-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_gitops:1"
  }, {
    "product_name" : "Red Hat OpenShift GitOps",
    "fix_state" : "Will not fix",
    "package_name" : "openshift-gitops-1/argocd-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_gitops:1"
  }, {
    "product_name" : "Red Hat OpenShift Virtualization 4",
    "fix_state" : "Affected",
    "package_name" : "container-native-virtualization/kubevirt-console-plugin",
    "cpe" : "cpe:/a:redhat:container_native_virtualization:4"
  }, {
    "product_name" : "Red Hat OpenShift Virtualization 4",
    "fix_state" : "Affected",
    "package_name" : "container-native-virtualization/kubevirt-console-plugin-rhel9",
    "cpe" : "cpe:/a:redhat:container_native_virtualization:4"
  }, {
    "product_name" : "Red Hat Satellite 6",
    "fix_state" : "Affected",
    "package_name" : "satellite/iop-host-inventory-frontend-rhel9",
    "cpe" : "cpe:/a:redhat:satellite:6"
  }, {
    "product_name" : "Red Hat Satellite 6",
    "fix_state" : "Affected",
    "package_name" : "satellite/iop-vulnerability-frontend-rhel9",
    "cpe" : "cpe:/a:redhat:satellite:6"
  }, {
    "product_name" : "Self-service automation portal 2",
    "fix_state" : "Affected",
    "package_name" : "ansible-automation-platform/automation-portal",
    "cpe" : "cpe:/a:redhat:ansible_portal:2"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-33036\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33036\nhttps://github.com/NaturalIntelligence/fast-xml-parser/commit/bd26122c838e6a55e7d7ac49b4ccc01a49999a01\nhttps://github.com/NaturalIntelligence/fast-xml-parser/releases/tag/v5.5.6\nhttps://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-8gc5-j5rx-235r" ],
  "name" : "CVE-2026-33036",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}