Hi,

A security fix has been released in Katello, a content management plugin for
Foreman.

CVE-2026-56097: Katello: SQL injection in Registry Proxy labels

An authenticated low-privilege user can inject SQL through Katello Registry
Proxy label parameters because input is interpolated into database queries
without sufficient sanitization. This can expose data across authorization
boundaries.

Affected versions: Katello 4.13.0 through 4.21.1.1, and 5.0.0
CVSS: 6.5 (Moderate)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Fixed versions: Katello 4.21.2 and 5.0.1
Credit: Guilherme Suckevicz

References:
- Foreman Security: https://theforeman.org/security.html#2026-56097
- Redmine: https://projects.theforeman.org/issues/39843
- Fix: https://github.com/Katello/katello/pull/11887

Thanks,
Ondrej Gajdusek
Foreman Release Team

Reply via email to