RHBA-2026:12433HighCVSS 7.7

Red Hat Bug Fix Advisory: Red Hat OpenShift GitOps v1.20.3 bug fix and enhancement update

Published
April 30, 2026
Last Modified
August 10, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-42880 — argoproj/argo-cd: Argo CD: Information disclosure of Kubernetes Secret data via Server-Side Apply dry-run mechanism

🎯 Affected products42

  • Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:1a7f35f6a4bce49d2068b3a1c876d05b5cbfd89bbd6ac19dc8f04f57494869ae_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:58bcb00e510f89d9f1ad42dc5d9f1154f98ac8a58cb1b2a0c387bfe4f7660710_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:7254d6fb620373192a144f0d7c5a3cd31c92baf130bbb2dc4a99be283488924c_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:8c0d04403c2d09ae0856fc71a77ec2115a98c72d472c000158acd45ece7c8778_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:0d4ad1f17e7255f4d162bc2965a636982f813afab6e012ce60d2fed7a61c6ac8_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:66c8d917f40f7392692198310bd126a9e92d6356b13d42242ce037e671b3398e_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:a70018a41022e1476a644fc4fd52b2889b763c96f23ed1f71b89956717494865_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:c9849fc3254f51f999e587e838c4a208eeaabe1bdac50a0924487fe248b7ced3_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:4da1b7b3189054bb621aa106298cc2bcf3d02cb91a36e5363a18dfd612252320_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:5731b669139fe6fc7a6c56342b7ca2055b74b44d41fc59757b96ccbfe2f008d7_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:86b44929860d7967c829a4ceddc46cb3b312d89cea2bc615b55e2a2cc8fe32dc_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:bcde82b5b8b78976b401454ad1ed6b58bb8adaf7f5cbe5264e589a6b477d6f53_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:14e5938a315a67d3fda421c65a20b097ab159be4ad031b3035b948dc4515d558_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:6ca26d9abf4896f1dd209b1518c986d2940e0b1a9d21564020a555e1f135d12e_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:b06d918cd673cb2a6511177e34d8150fbf37b0feefaa6e96675bcfda3dc5d573_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:b8b5a507013980e7750c4edbe3e07f4b16f4792ac904cfe6ecd6be036afb4192_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:1294587dd6ee8821ed7499fcc4c11b336ea6bda4bee6316caa24cbb15595d425_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:14579fb8c01043418b1180ff8c8341f18161544a2072151fa977c09f15151d22_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:6e4afba0bfbe3b6d727faa6a2dcb8dae618d6bf548052483909af5262704e1a5_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:f393bbb1dba662e6387dbaacdcd0dc2bb4a8e486218273c66ec9f50e8bc360fb_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:007eadbc0e74cc6e603d0c1de0eef404ec7a0849355563bd94c0312396200789_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:4b1d0d11ef2352bd08ed140d6a0a57c41b087c4cec85089873349da2fa32fc7e_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:9af499c49ef9616512081baeaaae96d437639ce2aa348b2dacb9d803e913844e_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:d126e9cb83898ac364bff9ee71fbf20fb16751f9e5fe6d237a41b0810ed5b70b_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:6d16d32879c21194a75fcbd2bd7a08c0dece7e876c8b5a490e589460c31772f1_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:b07da7bffb7e86461f16343dfb854d80242adb49ac9fd99c93c1b2cf0a157a4b_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:d0367c2f27364cb4f9f494cabc4c062bd1f550443299e3ab7c48e7a1f08730b3_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:f79e4f91fc209ed6de6f5983d422a64f540290d20f99016c49ecddaec9205596_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/gitops-operator-bundle@sha256:407b2310e342ddde5229624bac66ec364840c368f36e4831502a8ce4e45d972b_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • +12 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (4)