CVE-2026-103262
CVE-2026-103262: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh7.5
High [CVE-2026-103262] Denial of Service via decompression bomb in CurlAsyncHTTPClient
CVE-2026-103262Source published Source updated
Denial of Service via decompression bomb in CurlAsyncHTTPClient. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Affected products named by the advisory: Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 10 more.
- Related products — impact not confirmed
- Lightspeed Core
- Migration Toolkit for Applications 8
- OpenShift Lightspeed
- Red Hat Ansible Automation Platform 2
10 more entries in the full advisory.
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- Restrict outbound HTTP client requests to trusted destinations and avoid using the CurlAsyncHTTPClient backend when fetching untrusted web content. 1. Application configuration: Configure Tornado applications to utilize the default SimpleAsyncHTTPClient instead of CurlAsyncHTTPClient, provided specialized libcurl functionality (such as custom proxy configurations or specific TLS options) is not required. The default client enforces strict size boundaries on compressed and uncompressed response bodies. 2. Network egress filtering: Implement firewall rules or egress network policies to restrict outbound HTTP/HTTPS connections exclusively to verified, trustworthy endpoints, preventing the client from contacting potentially malicious third-party servers. 3. Operational controls: Ensure that user-supplied or untrusted URLs are validated, sanitized, or rejected before initiating outbound retrieval requests. Caveats: Switching the HTTP client backend from CurlAsyncHTTPClient to SimpleAsyncHTTPClient may disrupt services that depend on libcurl-specific features. Enforcing egress filtering may block connections to unlisted external services.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.