RLSA-2026:64772

    Dashboard / Vulnerabilities / RLSA-2026:64772

    RLSA-2026:64772

    Published: 9 Sept 2026Last Modified: 9 Sept 2026
    Upstream:

    Summary: Important: xmlrpc-c security update

    Details: XML-RPC is a remote procedure call (RPC) protocol that uses XML to encode its calls and HTTP as a transport mechanism. The xmlrpc-c packages provide a network protocol to allow a client program to make a simple RPC (remote procedure call) over the Internet. It converts an RPC into an XML document, sends it to a remote server using HTTP, and gets back the response in XML. Security Fix(es): * xmlrpc-c: XMLRPC-C Library: Cross-Site Scripting in error page component (CVE-2026-15928) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

    Affected packages

    Package

    Name: xmlrpc-c

    Purl: pkg:rpm/rocky-linux/xmlrpc-c?distro=rocky-linux-8&epoch=0

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0:1.51.0-11.el8_10.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    RLSA-2026:64772 | CVE-DB