RHSA-2025:22058HighCVSS 8.1

Red Hat Security Advisory: RHTAS 1.3.1 - Tech Preview Release Of the Policy Controller Operator

Published
November 25, 2025
Last Modified
September 6, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2025-11621 — github.com/hashicorp/vault: Vault AWS auth method bypass due to AWS client cache CVE-2025-12044 — github.com/hashicorp/vault: Vault Vulnerable to Denial of Service Due to Rate Limit Regression

🎯 Affected products2

  • Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/policy-controller-rhel9@sha256:7172d6a08594cccd155c2f74110cfbafadb812af84bb6b75c8bec1e3c416bd26_amd64 as a component of Red Hat Trusted Artifact Signer 1.3

✅ Remediation

The RHTAS Policy Controller Operator is Helm-based operator for deploying and managing instances of the Sigstore Policy Controller on OpenShift. It is a self-managed on-premise deployment of the Policy Controller Helm Charts available at https://github.com/sigstore/helm-charts/tree/main/charts/policy-controller Platform Engineers, Software Developers and Security Professionals may use the RHTAS Policy Controller Operator to enforce policies on OCP clusters by using supply-chain metadata. For details on using the RHTAS Policy Controller Operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (6)