{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-1530","assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","state":"PUBLISHED","assignerShortName":"redhat","dateReserved":"2026-01-28T12:41:52.835Z","datePublished":"2026-02-02T05:47:10.049Z","dateUpdated":"2026-03-26T20:31:44.599Z"},"containers":{"cna":{"title":"Fog-kubevirt: fog-kubevirt: man-in-the-middle vulnerability due to disabled certificate validation","metrics":[{"other":{"content":{"value":"Important","namespace":"https://access.redhat.com/security/updates/classification/"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"format":"CVSS"}],"descriptions":[{"lang":"en","value":"A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) attack due to disabled certificate validation. This enables the attacker to intercept and potentially alter sensitive communications between Satellite and OpenShift, resulting in information disclosure and data integrity compromise."}],"affected":[{"vendor":"Red Hat","product":"Red Hat Satellite 6.16 for RHEL 8","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rubygem-fog-kubevirt","defaultStatus":"affected","versions":[{"version":"0:1.5.1-1.el8sat","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_capsule:6.16::el9","cpe:/a:redhat:satellite_maintenance:6.16::el9","cpe:/a:redhat:satellite_capsule:6.16::el8","cpe:/a:redhat:satellite_utils:6.16::el8","cpe:/a:redhat:satellite:6.16::el9","cpe:/a:redhat:satellite:6.16::el8","cpe:/a:redhat:satellite_utils:6.16::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.16 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rubygem-fog-kubevirt","defaultStatus":"affected","versions":[{"version":"0:1.5.1-1.el9sat","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_capsule:6.16::el9","cpe:/a:redhat:satellite_maintenance:6.16::el9","cpe:/a:redhat:satellite_capsule:6.16::el8","cpe:/a:redhat:satellite_utils:6.16::el8","cpe:/a:redhat:satellite:6.16::el9","cpe:/a:redhat:satellite:6.16::el8","cpe:/a:redhat:satellite_utils:6.16::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"foreman","defaultStatus":"affected","versions":[{"version":"0:3.14.0.14-1.el9sat","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"libcomps","defaultStatus":"affected","versions":[{"version":"0:0.1.23-0.3.el9pc","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python-brotli","defaultStatus":"affected","versions":[{"version":"0:1.2.0-0.1.el9pc","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python-django","defaultStatus":"affected","versions":[{"version":"0:4.2.28-0.1.el9pc","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python-pulp-container","defaultStatus":"affected","versions":[{"version":"0:2.22.3-1.el9pc","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python-pulp-rpm","defaultStatus":"affected","versions":[{"version":"0:3.27.10-2.el9pc","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rubygem-fog-kubevirt","defaultStatus":"affected","versions":[{"version":"0:1.5.1-1.el9sat","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rubygem-foreman_kubevirt","defaultStatus":"affected","versions":[{"version":"0:0.4.3-1.el9sat","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rubygem-katello","defaultStatus":"affected","versions":[{"version":"0:4.16.0.14-1.el9sat","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rubygem-rubyipmi","defaultStatus":"affected","versions":[{"version":"0:0.13.0-1.el9sat","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"satellite","defaultStatus":"affected","versions":[{"version":"0:6.17.7-1.el9sat","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"yggdrasil-worker-forwarder","defaultStatus":"affected","versions":[{"version":"0:0.0.3-4.el9sat","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"foreman","defaultStatus":"affected","versions":[{"version":"0:3.14.0.14-1.el9sat","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"libcomps","defaultStatus":"affected","versions":[{"version":"0:0.1.23-0.3.el9pc","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python-brotli","defaultStatus":"affected","versions":[{"version":"0:1.2.0-0.1.el9pc","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python-django","defaultStatus":"affected","versions":[{"version":"0:4.2.28-0.1.el9pc","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python-pulp-container","defaultStatus":"affected","versions":[{"version":"0:2.22.3-1.el9pc","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python-pulp-rpm","defaultStatus":"affected","versions":[{"version":"0:3.27.10-2.el9pc","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rubygem-fog-kubevirt","defaultStatus":"affected","versions":[{"version":"0:1.5.1-1.el9sat","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rubygem-foreman_kubevirt","defaultStatus":"affected","versions":[{"version":"0:0.4.3-1.el9sat","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rubygem-katello","defaultStatus":"affected","versions":[{"version":"0:4.16.0.14-1.el9sat","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rubygem-rubyipmi","defaultStatus":"affected","versions":[{"version":"0:0.13.0-1.el9sat","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"satellite","defaultStatus":"affected","versions":[{"version":"0:6.17.7-1.el9sat","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.17 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"yggdrasil-worker-forwarder","defaultStatus":"affected","versions":[{"version":"0:0.0.3-4.el9sat","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:satellite_utils:6.17::el9","cpe:/a:redhat:satellite_maintenance:6.17::el9","cpe:/a:redhat:satellite:6.17::el9","cpe:/a:redhat:satellite_capsule:6.17::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"satellite:el8/rubygem-fog-kubevirt","defaultStatus":"affected","cpes":["cpe:/a:redhat:satellite:6"]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:5970","name":"RHSA-2026:5970","tags":["vendor-advisory","x_refsource_REDHAT"]},{"url":"https://access.redhat.com/errata/RHSA-2026:5971","name":"RHSA-2026:5971","tags":["vendor-advisory","x_refsource_REDHAT"]},{"url":"https://access.redhat.com/security/cve/CVE-2026-1530","tags":["vdb-entry","x_refsource_REDHAT"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2433784","name":"RHBZ#2433784","tags":["issue-tracking","x_refsource_REDHAT"]}],"datePublic":"2026-01-28T12:40:37.424Z","problemTypes":[{"descriptions":[{"cweId":"CWE-295","description":"Improper Certificate Validation","lang":"en","type":"CWE"}]}],"x_redhatCweChain":"CWE-295: Improper Certificate Validation","workarounds":[{"lang":"en","value":"Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability."}],"timeline":[{"lang":"en","time":"2026-01-28T12:39:43.076Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-01-28T12:40:37.424Z","value":"Made public."}],"credits":[{"lang":"en","value":"This issue was discovered by Evgeni Golov (Red Hat)."}],"providerMetadata":{"orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat","dateUpdated":"2026-03-26T20:31:44.599Z"},"x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-02-02T16:26:13.539148Z","id":"CVE-2026-1530","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-02-02T16:28:31.327Z"}}]}}