Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2026-100690

CVE-2026-100690: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityMedium5.5

    Medium [CVE-2026-100690] Arbitrary file read via symbolic link sandbox escape

    CVE-2026-100690Source published Source updated

    Arbitrary file read via symbolic link sandbox escape. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:74609 with package hugo-main-0.166.0-0.1.hum1, cluster-observability-operator/korrel8r-rhel9:1790854490. Affected products named by the advisory: Cluster Observability Operator 1.5.3; Red Hat Hardened Images; Red Hat OpenShift GitOps.

    Related products — impact not confirmed
    • Cluster Observability Operator 1.5.3
    • Red Hat Hardened Images
    • Red Hat OpenShift GitOps
    Source-reported affected versions
    • 161.0
    • 165.0
    Source-reported fixed versions
    • hugo-main-0.166.0-0.1.hum1
    • cluster-observability-operator/korrel8r-rhel9:1790854490
    • RHSA-2026:74609
    Mitigation guidance
    • To mitigate this issue, implement the following operational controls: 1. Avoid processing untrusted pull requests, themes, or repository branches that execute Node.js transformation pipelines (such as PostCSS, TailwindCSS, or Babel). Builds that do not execute Node.js tools are unaffected. 2. Isolate Hugo builds inside dedicated containers or ephemeral sandboxes that have no sensitive host directories or files mounted, and run the build process with minimal privileges. Caveat: Disabling or avoiding Node.js asset transformations may prevent custom stylesheets or scripts from compiling properly, which can alter the appearance or functionality of the generated site.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery