VDB

CVE-2026-13601

CVE-2026-13601 PUBLISHED CVSS 7.1 HIGH

Reported by redhat · Published June 29, 2026

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.

Risk Scores

CVSS 3.1
7.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Affected Products

VendorProductVersions
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support2:3.28.1-2.el7_9
Red HatRed Hat Enterprise Linux 82:3.28.1-3.el8_10.2
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support2:3.28.1-3.el8_4.2
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On2:3.28.1-3.el8_4.2
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support2:3.28.1-3.el8_6.2
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On2:3.28.1-3.el8_6.2
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service2:3.28.1-3.el8_8.2
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions2:3.28.1-3.el8_8.2
Red HatRed Hat Enterprise Linux 92:40.3-3.el9_8.1
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions2:40.3-2.el9_2.2
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions2:40.3-2.el9_4.2
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support2:40.3-2.el9_6.2
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions2:40.3-2.el9_4.2, 2:40.3-2.el9_4.2
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service2:3.28.1-3.el8_8.2, 2:3.28.1-3.el8_8.2
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support2:3.28.1-3.el8_6.2, 2:3.28.1-3.el8_6.2
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions2:3.28.1-3.el8_8.2, 2:3.28.1-3.el8_8.2

…and 24 more

Timeline

  • Jun 29, 2026 CVE Published
  • Jun 30, 2026 EPSS Score
  • Jun 30, 2026 Coalition ESS Score
  • Aug 3, 2026 Distribution Patch
  • Aug 3, 2026 Security Advisory
  • Aug 4, 2026 Distribution Patch
  • Aug 4, 2026 Security Advisory
  • Aug 7, 2026 EPSS Score
  • Aug 13, 2026 Distribution Patch
  • Aug 13, 2026 Distribution Patch
  • Aug 13, 2026 Security Advisory
  • Aug 16, 2026 Distribution Patch

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›