BlackTreeCVE Intelligence
← Back to the CVE catalogue
Full vulnerability report · 2026
CVE-2026-92000High confidence

adm-zip 0.5.14 through 0.6.0 Denial of Service via Zero Declared Uncompressed Size

cthackers · adm-zip

Official source article: GitHub GHSA-RCW4-F5RP-G42V ↗. Check the applicable product and release in the original source.

8.7HighCVSS 4.0
Recommended action
Within 7 days

High technical severity; prioritise exposed affected systems while verifying vendor guidance.

Patch available
R
Operational reassessment

Published severity in operational context

Open reassessment dashboard →
Published severityHighOperational priority:High, unchanged from published severity.unchanged

Evidence used

  • No CISA KEV confirmation is currently recorded.
  • The selected CVSS metric records a network-reachable, unauthenticated path with no user interaction.
  • EPSS is 0.68% for the current model date.

Compensating controls

  • Validate the affected product branch and deploy the verified fixed release.
  • Restrict the affected network interface to trusted sources where business-safe.
  • Monitor vendor guidance and exploitation sources for a material change.

Verification

  1. Confirm that the asset runs cthackers adm-zip and falls inside the recorded affected range.
  2. Verify the installed build against the product-specific fixed version after deployment.
  3. Validate exposure, authentication requirements and compensating controls in the actual environment.
  4. Reopen this reassessment when CVSS, KEV, EPSS, exploit evidence or remediation changes.
Mitigation target: Within 30 daysRemediation target: Within 180 days

This automated reassessment organises public evidence. It does not know asset exposure, business impact or control effectiveness and does not replace CVSS or a human risk decision.

Open-source package ranges1 source-attributed range

These OSV and GitHub advisory ranges apply only to the named package and ecosystem. A listed fixed version is not a universal product patch or proof that an update is installed.

Ecosystem and packageAffected rangeFirst fixed versionEvidence
npmadm-zipSEMVER: introduced 0; fixed 0.6.10.6.1OSV record ↗aggregator derived · 29 Sep 2026
Direct vendor intelligence

Authoritative vendor CSAF and VEX advisories

Structured product status and remediation from the issuing vendor. Product-state explanations are always visible; large lists can be searched or downloaded.

1 current
CVE-2026-92000 · CSAF 2.0 · revision 3 · finalRed Hat Product Securityadm-zip: adm-zip: Denial of Service via crafted ZIP archives with zero declared uncompressed size
20 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • rh-podman-desktop.git as a component of Red Hat Build of Podman Desktop
  • mozjs60 as a component of Red Hat Enterprise Linux 8
  • mozjs60-devel as a component of Red Hat Enterprise Linux 8
  • mozjs60.src as a component of Red Hat Enterprise Linux 8
  • gjs-devel as a component of Red Hat Enterprise Linux 9
  • gjs.src as a component of Red Hat Enterprise Linux 9
  • adm-zip as a component of Red Hat Fuse 7
  • rhoai/odh-core-bff-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
  • rhoai/odh-dashboard-operator-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
  • rhoai/odh-dashboard-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
  • rhoai/odh-mod-arch-agent-ops-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
  • rhoai/odh-mod-arch-automl-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
Summary
A flaw was found in adm-zip. A remote attacker could exploit this vulnerability by crafting a malicious ZIP archive containing highly compressible entries that declare a zero uncompressed size. This oversight prevents the application of zlib decompression output limits, leading to excessive memory consumption and ultimately a Denial of Service (DoS) condition.
Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Choose official national sources for this report. Each advisory shows its original language. Your selection is remembered on this device and included in shared links.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2026-80001

No EUVD known-exploited evidence

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.

EUVD state
Present in the current official mapping
Known exploitation
Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
ENISA score
8.7 · CVSS 4.0
Advisory evidence
No linked advisory details stored yet
Recommended actionWithin 7 days

High technical severity; prioritise exposed affected systems while verifying vendor guidance.

Patch available
01

What, why and how

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.

What

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.

Why

The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may disrupt the affected service.

What

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.

Why

The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may disrupt the affected service.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
No confirmed evidence

No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
None recorded

No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.

Likely attack path
a network path → Improper Handling of Highly Compressed Data (Data Amplification) → disrupt the affected service
Attack surface
Network
Privileges required
None: unauthenticated exploitation is possible
User interaction
None
Attack complexity
Low: no specialised conditions are recorded
Security boundary
Not a CVSS 4.0 base metric
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-409 ↗

CWE-409: Improper Handling of Highly Compressed Data (Data Amplification). The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Common Vulnerability Scoring System 4.0: the compact vector below is decoded into plain language.

AVNetworkAttack vector: The vulnerable component can be reached over a network.ACLowAttack complexity: No specialised conditions are required beyond attacker-controlled input.ATNoneAttack requirements: No additional deployment or execution condition is required.PRNonePrivileges required: The attacker does not need an account or existing privileges.UINoneUser interaction: No action by another user is required.VCNoneVulnerable-system confidentiality: No direct loss is represented by this metric.VINoneVulnerable-system integrity: No direct loss is represented by this metric.VAHighVulnerable-system availability: A successful attack can cause a major loss.SCNoneSubsequent-system confidentiality: No direct loss is represented by this metric.SINoneSubsequent-system integrity: No direct loss is represented by this metric.SANoneSubsequent-system availability: No direct loss is represented by this metric.
Post-exploitation / living off the land
No specific living-off-the-land technique is confirmed in the structured sources. Monitor normal administration tools for activity inconsistent with the affected service's baseline.
NetworkUnauthenticatedDenial of serviceCWE-409
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

ENISA EUVD · EUVD-2026-80001Official EUVD mapping

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.

Official EUVD record ↗
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Patch available
Affected
Fixed
Action
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
Workaround
No verified workaround is recorded. If business-safe, reduce exposure to the affected interface and allow only trusted sources until authoritative guidance is available.
04

Evidence and provenance

Published 15 Sept 2026 · Last source change 24 Sept 2026, 14:22 UTC · CWE-409 · Improper Handling of Highly Compressed Data (Data Amplification)

CVE recordCVE.org · 5.2
CVSS sourceCNA
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-09-16
European sourceENISA EUVD · EUVD-2026-80001
Product sourceVendor CSAF · Red Hat Product Security
Remediation sourceVendor CSAF · Red Hat Product Security
CWE sourceCNA
NVD statusNVD not scheduled

Core structured fields are present and their contributing authorities are shown above.

Material change intelligence

What changed after publication

View recent updates ↗
  1. Affected versionsThe structured affected or fixed version information changed.
    Before
    adm-zip: 0.5.14 < 0.6.1 · Fixed: For more about Ansible plugins for Red Hat Developer Hub, see References links
    After
    adm-zip: 0.5.14 < 0.6.1 · Fixed: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
    Red Hat Product Security ↗
  2. Vendor guidanceAuthoritative vendor guidance changed from remediation: access.redhat.com/CVE-2026-92000 to remediation: access.redhat.com/CVE-2026-92000.
    Before
    remediation: access.redhat.com/CVE-2026-92000
    After
    remediation: access.redhat.com/CVE-2026-92000
    Red Hat Product Security ↗
  3. Affected versionsThe structured affected or fixed version information changed.
    Before
    rh-podman-desktop.git as a component of Red Hat Build of Podman Desktop; mozjs60 as a component of Red Hat Enterprise Linux 8; mozjs60-devel as a component of Red Hat Enterprise Linux 8; mozjs60.src as a component of Red Hat Enterprise Linux 8; gjs-devel as a component of Red Hat Enterprise Linux 9; gjs.src as a component of Red Hat Enterprise Linux 9; adm-zip as a component of Red Hat Fuse 7; rhoai/odh-core-bff-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-operator-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-agent-ops-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-automl-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-autorag-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-eval-hub-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-gen-ai-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-maas-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-mlflow-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-model-registry-rhel9 as a component of Red Hat OpenShift AI (RHOAI); openshift4/ose-console as a component of Red Hat OpenShift Container Platform 4; openshift4/ose-monitoring-plugin-rhel9 as a component of Red Hat OpenShift Container Platform 4 · Fixed: registry.redhat.io/ansible-automation-platform/automation-portal@sha256:2659ae04974d930322789112efc9181bc7cf3990999a204eba45aec0639f0c3d_amd64 as a component of Red Hat Ansible Automation Platform 2.1; registry.redhat.io/ansible-automation-platform/automation-portal@sha256:ca5c8160a6cb0fa122c3cc91852325af72b9713db1c2683b68e91433b762e604_amd64 as a component of Red Hat Ansible Automation Platform 2.2
    After
    rh-podman-desktop.git as a component of Red Hat Build of Podman Desktop; mozjs60 as a component of Red Hat Enterprise Linux 8; mozjs60-devel as a component of Red Hat Enterprise Linux 8; mozjs60.src as a component of Red Hat Enterprise Linux 8; gjs-devel as a component of Red Hat Enterprise Linux 9; gjs.src as a component of Red Hat Enterprise Linux 9; adm-zip as a component of Red Hat Fuse 7; rhoai/odh-core-bff-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-operator-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-agent-ops-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-automl-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-autorag-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-eval-hub-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-gen-ai-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-maas-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-mlflow-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-model-registry-rhel9 as a component of Red Hat OpenShift AI (RHOAI); openshift4/ose-console as a component of Red Hat OpenShift Container Platform 4; openshift4/ose-monitoring-plugin-rhel9 as a component of Red Hat OpenShift Container Platform 4 · Fixed: registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9@sha256:4f8298d72b446cf43419ea4c44fb11e77559961e8c544c6e5381b5c9494bfe8c_s390x as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9@sha256:8e201126c5732fc4b52a7dff62aa6752918365e0d4c17040123a55b5ca361d17_amd64 as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9@sha256:a4465e2a727fbcb5b097ff433ad5be533879df2196e94c17c8e5be06a19ee3a4_arm64 as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9@sha256:c51811c8b2725911126b9fbfa27c84e22bedf8949dbe5ff2fe13516b6cf061d7_ppc64le as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf5-rhel9@sha256:015934e8094bbdbf93e7efdd2c64b429d2d56646c5a3ce1e11d4c5a6cffd4c07_s390x as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf5-rhel9@sha256:2e5ca6c5f3ffb09af7e515720b743a9199e59bc0cd9d9cb2393d70db5c9fb46d_ppc64le as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf5-rhel9@sha256:7e75aba089cb03d3e3184a34b372dda8d351ffb14ab073dcca4417b93d96abef_arm64 as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf5-rhel9@sha256:f46f950a2726714dbbac66acbebaa2136aeffa9932b6145279c66d316bc3b833_amd64 as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf6-rhel9@sha256:630d93f0951c828ccc39e39460e4e2fcc39e7dd1b964f27444b436aaf7ce9e5b_amd64 as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf6-rhel9@sha256:795d1b20e846376dd6605224dc8956e3a764344601ae126a287562a70aa9ce47_s390x as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf6-rhel9@sha256:eefb6cceecf47f9ebf981be50d3a13e78f7fb63670b211b9c1e39c7b0e6f7e07_arm64 as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf6-rhel9@sha256:f7c23fcc84c59bfda30418a8b20f700e116df9b7367c86a6cdcaffaf59b85516_ppc64le as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-rhel9@sha256:5d965d20008578a28d099ea0e645a02240231887b4a015e7ccfcc6fd8d76ae1a_ppc64le as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-rhel9@sha256:a7160a5a977d5d2f26dbaf4559247ff43056dfce48f68f2ee39349b7ed645d8c_arm64 as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-rhel9@sha256:a74e4dabd62c57c99f5136c405d4f1d9290a46ec3a29d8264be3021ff8b97417_amd64 as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-rhel9@sha256:cbfd934355f48003eadbb126fb6194bf4243235df21af42631c2eb595a06efd6_s390x as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/monitoring-console-plugin-pf5-rhel9@sha256:813a727ec5ecd081dcb84628d3469330664be30fda80c4086ba6d9c0bfb12a8c_arm64 as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/monitoring-console-plugin-pf5-rhel9@sha256:92bed5537c071080310bd6f8fabe4296fcde0fc9e6d451143a031728b3038498_s390x as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/monitoring-console-plugin-pf5-rhel9@sha256:9967e5f284cf61cb58a739dd0d8f803a797fa3f55512e4a35cd98443a77ecf09_ppc64le as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/monitoring-console-plugin-pf5-rhel9@sha256:a9ec40ac7c184197b401913f5bfc2b3e964e7f0b0b5b9208b0c781354bf8f7bd_amd64 as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/monitoring-console-plugin-pf6-rhel9@sha256:0784bb3215a532562102de3445f88d964281cf60a58fee60eee8bb8d1487448a_s390x as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/monitoring-console-plugin-pf6-rhel9@sha256:2abaf8de5493555f311b14114ed5409ef152bdd6663ce7e4271d111ec6de96d2_ppc64le as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/monitoring-console-plugin-pf6-rhel9@sha256:42e99d9fd0149aa8d2c0712026b51b1286ec7508e5a5d675d1fe3c585ce399cb_amd64 as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/monitoring-console-plugin-pf6-rhel9@sha256:d30621a360a427e24b0bcce578baac6944a6322647406ef5947a9015cd3df46f_arm64 as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/monitoring-console-plugin-rhel9@sha256:0656b4651b88985ba0cc345fd5b88b0d0b1168e1bf9de57a055591d09522b2ee_s390x as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/monitoring-console-plugin-rhel9@sha256:1c38fce61f0ac9e6143a55b4ea9358006fd8726cf5c5a745de95d5fcefa726a9_ppc64le as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/monitoring-console-plugin-rhel9@sha256:5682858e462879a431fd4bbfec9c788a4989fbd64b8e48a57e876efd06af4b9f_amd64 as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/cluster-observability-operator/monitoring-console-plugin-rhel9@sha256:d3596621e3ce33b574228862376b53e8384a15d0a9c3ca66331cdff8213c81bd_arm64 as a component of Cluster Observability Operator 1.5.3; registry.redhat.io/ansible-automation-platform/automation-portal@sha256:2659ae04974d930322789112efc9181bc7cf3990999a204eba45aec0639f0c3d_amd64 as a component of Red Hat Ansible Automation Platform 2.1; registry.redhat.io/ansible-automation-platform/automation-portal@sha256:ca5c8160a6cb0fa122c3cc91852325af72b9713db1c2683b68e91433b762e604_amd64 as a component of Red Hat Ansible Automation Platform 2.2
    Red Hat Product Security ↗
  4. Affected versionsThe structured affected or fixed version information changed.
    Before
    rh-podman-desktop as a component of Red Hat Build of Podman Desktop; rh-podman-desktop.git as a component of Red Hat Build of Podman Desktop; mozjs60 as a component of Red Hat Enterprise Linux 8; mozjs60-devel as a component of Red Hat Enterprise Linux 8; mozjs60.src as a component of Red Hat Enterprise Linux 8; gjs-devel as a component of Red Hat Enterprise Linux 9; gjs.src as a component of Red Hat Enterprise Linux 9; adm-zip as a component of Red Hat Fuse 7; rhoai/odh-core-bff-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-operator-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-agent-ops-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-automl-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-autorag-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-eval-hub-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-gen-ai-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-maas-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-mlflow-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-model-registry-rhel9 as a component of Red Hat OpenShift AI (RHOAI); openshift4/ose-console as a component of Red Hat OpenShift Container Platform 4; openshift4/ose-monitoring-plugin-rhel9 as a component of Red Hat OpenShift Container Platform 4 · Fixed: registry.redhat.io/ansible-automation-platform/automation-portal@sha256:2659ae04974d930322789112efc9181bc7cf3990999a204eba45aec0639f0c3d_amd64 as a component of Red Hat Ansible Automation Platform 2.1; registry.redhat.io/ansible-automation-platform/automation-portal@sha256:ca5c8160a6cb0fa122c3cc91852325af72b9713db1c2683b68e91433b762e604_amd64 as a component of Red Hat Ansible Automation Platform 2.2
    After
    rh-podman-desktop.git as a component of Red Hat Build of Podman Desktop; mozjs60 as a component of Red Hat Enterprise Linux 8; mozjs60-devel as a component of Red Hat Enterprise Linux 8; mozjs60.src as a component of Red Hat Enterprise Linux 8; gjs-devel as a component of Red Hat Enterprise Linux 9; gjs.src as a component of Red Hat Enterprise Linux 9; adm-zip as a component of Red Hat Fuse 7; rhoai/odh-core-bff-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-operator-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-agent-ops-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-automl-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-autorag-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-eval-hub-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-gen-ai-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-maas-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-mlflow-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-model-registry-rhel9 as a component of Red Hat OpenShift AI (RHOAI); openshift4/ose-console as a component of Red Hat OpenShift Container Platform 4; openshift4/ose-monitoring-plugin-rhel9 as a component of Red Hat OpenShift Container Platform 4 · Fixed: registry.redhat.io/ansible-automation-platform/automation-portal@sha256:2659ae04974d930322789112efc9181bc7cf3990999a204eba45aec0639f0c3d_amd64 as a component of Red Hat Ansible Automation Platform 2.1; registry.redhat.io/ansible-automation-platform/automation-portal@sha256:ca5c8160a6cb0fa122c3cc91852325af72b9713db1c2683b68e91433b762e604_amd64 as a component of Red Hat Ansible Automation Platform 2.2
    Red Hat Product Security ↗
  5. Affected versionsThe structured affected or fixed version information changed.
    Before
    adm-zip: 0.5.14 < 0.6.1 · Fixed: No fixed version is explicitly recorded in the structured CVE data.
    After
    adm-zip: 0.5.14 < 0.6.1 · Fixed: For more about Ansible plugins for Red Hat Developer Hub, see References links
    Red Hat Product Security ↗
  6. Remediation statusRemediation status changed from Awaiting fix to Patch available.
    Before
    Awaiting fix
    After
    Patch available
    Red Hat Product Security ↗
  7. Vendor guidanceAuthoritative vendor guidance changed from remediation: access.redhat.com/CVE-2026-92000 to remediation: access.redhat.com/CVE-2026-92000.
    Before
    remediation: access.redhat.com/CVE-2026-92000
    After
    remediation: access.redhat.com/CVE-2026-92000
    Red Hat Product Security ↗
  8. Remediation statusRemediation status changed from Mitigation available to Patch available.
    Before
    Mitigation available
    After
    Patch available
    Red Hat Product Security ↗
  9. Affected versionsThe structured affected or fixed version information changed.
    Before
    rh-podman-desktop.git as a component of Red Hat Build of Podman Desktop; mozjs60 as a component of Red Hat Enterprise Linux 8; mozjs60-devel as a component of Red Hat Enterprise Linux 8; mozjs60.src as a component of Red Hat Enterprise Linux 8; gjs-devel as a component of Red Hat Enterprise Linux 9; gjs.src as a component of Red Hat Enterprise Linux 9; adm-zip as a component of Red Hat Fuse 7; rhoai/odh-core-bff-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-operator-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-agent-ops-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-automl-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-autorag-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-eval-hub-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-gen-ai-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-maas-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-mlflow-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-model-registry-rhel9 as a component of Red Hat OpenShift AI (RHOAI); openshift4/ose-console as a component of Red Hat OpenShift Container Platform 4; openshift4/ose-monitoring-plugin-rhel9 as a component of Red Hat OpenShift Container Platform 4; ansible-automation-platform/automation-portal as a component of Self-service automation portal 2
    After
    rh-podman-desktop as a component of Red Hat Build of Podman Desktop; rh-podman-desktop.git as a component of Red Hat Build of Podman Desktop; mozjs60 as a component of Red Hat Enterprise Linux 8; mozjs60-devel as a component of Red Hat Enterprise Linux 8; mozjs60.src as a component of Red Hat Enterprise Linux 8; gjs-devel as a component of Red Hat Enterprise Linux 9; gjs.src as a component of Red Hat Enterprise Linux 9; adm-zip as a component of Red Hat Fuse 7; rhoai/odh-core-bff-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-operator-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-agent-ops-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-automl-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-autorag-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-eval-hub-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-gen-ai-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-maas-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-mlflow-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-model-registry-rhel9 as a component of Red Hat OpenShift AI (RHOAI); openshift4/ose-console as a component of Red Hat OpenShift Container Platform 4; openshift4/ose-monitoring-plugin-rhel9 as a component of Red Hat OpenShift Container Platform 4 · Fixed: registry.redhat.io/ansible-automation-platform/automation-portal@sha256:2659ae04974d930322789112efc9181bc7cf3990999a204eba45aec0639f0c3d_amd64 as a component of Red Hat Ansible Automation Platform 2.1; registry.redhat.io/ansible-automation-platform/automation-portal@sha256:ca5c8160a6cb0fa122c3cc91852325af72b9713db1c2683b68e91433b762e604_amd64 as a component of Red Hat Ansible Automation Platform 2.2
    Red Hat Product Security ↗
  10. Affected versionsThe structured affected or fixed version information changed.
    Before
    rh-podman-desktop.git as a component of Red Hat Build of Podman Desktop; rhdh/rhdh-hub-rhel9 as a component of Red Hat Developer Hub; mozjs60 as a component of Red Hat Enterprise Linux 8; mozjs60-devel as a component of Red Hat Enterprise Linux 8; mozjs60.src as a component of Red Hat Enterprise Linux 8; gjs-devel as a component of Red Hat Enterprise Linux 9; gjs.src as a component of Red Hat Enterprise Linux 9; adm-zip as a component of Red Hat Fuse 7; rhoai/odh-core-bff-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-operator-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-agent-ops-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-automl-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-autorag-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-eval-hub-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-gen-ai-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-maas-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-mlflow-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-model-registry-rhel9 as a component of Red Hat OpenShift AI (RHOAI); openshift4/ose-console as a component of Red Hat OpenShift Container Platform 4; openshift4/ose-monitoring-plugin-rhel9 as a component of Red Hat OpenShift Container Platform 4; ansible-automation-platform/automation-portal as a component of Self-service automation portal 2
    After
    rh-podman-desktop.git as a component of Red Hat Build of Podman Desktop; mozjs60 as a component of Red Hat Enterprise Linux 8; mozjs60-devel as a component of Red Hat Enterprise Linux 8; mozjs60.src as a component of Red Hat Enterprise Linux 8; gjs-devel as a component of Red Hat Enterprise Linux 9; gjs.src as a component of Red Hat Enterprise Linux 9; adm-zip as a component of Red Hat Fuse 7; rhoai/odh-core-bff-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-operator-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-agent-ops-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-automl-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-autorag-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-eval-hub-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-gen-ai-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-maas-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-mlflow-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-model-registry-rhel9 as a component of Red Hat OpenShift AI (RHOAI); openshift4/ose-console as a component of Red Hat OpenShift Container Platform 4; openshift4/ose-monitoring-plugin-rhel9 as a component of Red Hat OpenShift Container Platform 4; ansible-automation-platform/automation-portal as a component of Self-service automation portal 2
    Red Hat Product Security ↗
  11. Affected versionsThe structured affected or fixed version information changed.
    Before
    redhat-user-workloads/volsync-0-12 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; redhat-user-workloads/volsync-bundle-0-12 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rh-podman-desktop.git as a component of Red Hat Build of Podman Desktop; rhdh/rhdh-hub-rhel9 as a component of Red Hat Developer Hub; mozjs60 as a component of Red Hat Enterprise Linux 8; mozjs60-devel as a component of Red Hat Enterprise Linux 8; mozjs60.src as a component of Red Hat Enterprise Linux 8; gjs-devel as a component of Red Hat Enterprise Linux 9; gjs.src as a component of Red Hat Enterprise Linux 9; adm-zip as a component of Red Hat Fuse 7; rhoai/odh-core-bff-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-operator-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-agent-ops-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-automl-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-autorag-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-eval-hub-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-gen-ai-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-maas-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-mlflow-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-model-registry-rhel9 as a component of Red Hat OpenShift AI (RHOAI); openshift4/ose-console as a component of Red Hat OpenShift Container Platform 4; openshift4/ose-monitoring-plugin-rhel9 as a component of Red Hat OpenShift Container Platform 4; ansible-automation-platform/automation-portal as a component of Self-service automation portal 2
    After
    rh-podman-desktop.git as a component of Red Hat Build of Podman Desktop; rhdh/rhdh-hub-rhel9 as a component of Red Hat Developer Hub; mozjs60 as a component of Red Hat Enterprise Linux 8; mozjs60-devel as a component of Red Hat Enterprise Linux 8; mozjs60.src as a component of Red Hat Enterprise Linux 8; gjs-devel as a component of Red Hat Enterprise Linux 9; gjs.src as a component of Red Hat Enterprise Linux 9; adm-zip as a component of Red Hat Fuse 7; rhoai/odh-core-bff-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-operator-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-agent-ops-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-automl-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-autorag-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-eval-hub-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-gen-ai-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-maas-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-mlflow-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-model-registry-rhel9 as a component of Red Hat OpenShift AI (RHOAI); openshift4/ose-console as a component of Red Hat OpenShift Container Platform 4; openshift4/ose-monitoring-plugin-rhel9 as a component of Red Hat OpenShift Container Platform 4; ansible-automation-platform/automation-portal as a component of Self-service automation portal 2
    Red Hat Product Security ↗
  12. Vendor guidanceAuthoritative vendor guidance changed from remediation: access.redhat.com/CVE-2026-92000 to remediation: access.redhat.com/CVE-2026-92000.
    Before
    remediation: access.redhat.com/CVE-2026-92000
    After
    remediation: access.redhat.com/CVE-2026-92000
    Red Hat Product Security ↗
  13. Remediation statusRemediation status changed from Awaiting fix to Mitigation available.
    Before
    Awaiting fix
    After
    Mitigation available
    Red Hat Product Security ↗
  14. Affected versionsThe structured affected or fixed version information changed.
    Before
    rh-podman-desktop.git as a component of Red Hat Build of Podman Desktop; rhdh/rhdh-hub-rhel9 as a component of Red Hat Developer Hub; mozjs60 as a component of Red Hat Enterprise Linux 8; mozjs60-devel as a component of Red Hat Enterprise Linux 8; mozjs60.src as a component of Red Hat Enterprise Linux 8; gjs-devel as a component of Red Hat Enterprise Linux 9; gjs.src as a component of Red Hat Enterprise Linux 9; adm-zip as a component of Red Hat Fuse 7; rhoai/odh-core-bff-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-operator-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-agent-ops-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-automl-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-autorag-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-eval-hub-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-gen-ai-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-maas-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-mlflow-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-model-registry-rhel9 as a component of Red Hat OpenShift AI (RHOAI); openshift4/ose-console as a component of Red Hat OpenShift Container Platform 4; openshift4/ose-monitoring-plugin-rhel9 as a component of Red Hat OpenShift Container Platform 4; ansible-automation-platform/automation-portal as a component of Self-service automation portal 2
    After
    redhat-user-workloads/volsync-0-12 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; redhat-user-workloads/volsync-bundle-0-12 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rh-podman-desktop.git as a component of Red Hat Build of Podman Desktop; rhdh/rhdh-hub-rhel9 as a component of Red Hat Developer Hub; mozjs60 as a component of Red Hat Enterprise Linux 8; mozjs60-devel as a component of Red Hat Enterprise Linux 8; mozjs60.src as a component of Red Hat Enterprise Linux 8; gjs-devel as a component of Red Hat Enterprise Linux 9; gjs.src as a component of Red Hat Enterprise Linux 9; adm-zip as a component of Red Hat Fuse 7; rhoai/odh-core-bff-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-operator-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-dashboard-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-agent-ops-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-automl-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-autorag-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-eval-hub-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-gen-ai-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-maas-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-mlflow-rhel9 as a component of Red Hat OpenShift AI (RHOAI); rhoai/odh-mod-arch-model-registry-rhel9 as a component of Red Hat OpenShift AI (RHOAI); openshift4/ose-console as a component of Red Hat OpenShift Container Platform 4; openshift4/ose-monitoring-plugin-rhel9 as a component of Red Hat OpenShift Container Platform 4; ansible-automation-platform/automation-portal as a component of Self-service automation portal 2
    Red Hat Product Security ↗
  15. ENISA EUVD mappingEUVD-2026-80001 was added to the official ENISA EUVD mapping for this CVE.
    Before
    not recorded
    After
    {"euvdId":"EUVD-2026-80001"}
    ENISA EUVD ↗
  16. Catalogue recordCVE added to the BlackTree catalogue.
    CNA ↗
Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
CVE published
Fixed release recorded from official guidance
Fixed release recorded from official guidance
Fixed release recorded from official guidance
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2026-92000 · cve.blacktree.nl