Skip to content
Red HatCVE-2026-16531

Red Hat Enterprise Linux 10: path traversal

Medium5.3CVE-2026-16531 · Published Jul 30, 2026 · updated Aug 21, 2026

An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Red Hat OpenShift Container Platform 4
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-22

More Red Hat advisories

All Red Hat
Advisory
ansible-collection-redhat-leapp: information disclosure
Medium6.2Jul 30
ansible-collection-redhat-leapp.: insecure permissions
Medium5.5Jul 30
Red Hat Samba: out-of-bounds read
Medium5.3Jul 30
Red Hat Enterprise Linux 10: improper authorization
High8.8Jul 30
Red Hat Samba: denial of service
Medium5.3Jul 30
Red Hat Cost Management Metrics Operator: server-side request forgery
High7.6Jul 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.