CVE-2026-100690
CVE-2026-100690: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityMedium5.5
Medium [CVE-2026-100690] Arbitrary file read via symbolic link sandbox escape
CVE-2026-100690Source published Source updated
Arbitrary file read via symbolic link sandbox escape. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:74609 with package hugo-main-0.166.0-0.1.hum1, cluster-observability-operator/korrel8r-rhel9:1790854490. Affected products named by the advisory: Cluster Observability Operator 1.5.3; Red Hat Hardened Images; Red Hat OpenShift GitOps.
- Related products — impact not confirmed
- Cluster Observability Operator 1.5.3
- Red Hat Hardened Images
- Red Hat OpenShift GitOps
- Source-reported affected versions
- 161.0
- 165.0
- Source-reported fixed versions
- hugo-main-0.166.0-0.1.hum1
- cluster-observability-operator/korrel8r-rhel9:1790854490
- RHSA-2026:74609
- Mitigation guidance
- To mitigate this issue, implement the following operational controls: 1. Avoid processing untrusted pull requests, themes, or repository branches that execute Node.js transformation pipelines (such as PostCSS, TailwindCSS, or Babel). Builds that do not execute Node.js tools are unaffected. 2. Isolate Hugo builds inside dedicated containers or ephemeral sandboxes that have no sensitive host directories or files mounted, and run the build process with minimal privileges. Caveat: Disabling or avoiding Node.js asset transformations may prevent custom stylesheets or scripts from compiling properly, which can alter the appearance or functionality of the generated site.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.