RHSA-2026:10130HighCVSS 9.1

Red Hat Security Advisory: RHTAS 1.3.4 - Red Hat Trusted Artifact Signer Release

Published
April 23, 2026
Last Modified
August 15, 2026

🔗 CVE IDs covered (3)

CVE-2026-4427 · pendingCVE-2026-33186CVE-2026-34986

📋 Description

CVE-2026-4427 — github.com/jackc/pgproto3: pgproto3: Denial of Service via negative field length in DataRow message CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object

🎯 Affected products6

  • Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/cosign-rhel9@sha256:b7599fcedc9a0777b71b048f7a5ca39371484483d25ddf33c4b4949a66d7eb78_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/fetch-tsa-certs-rhel9@sha256:aebd17387291c5044ca5f6fd38032fbb0039552306a1602b2bc92edecd904927_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/gitsign-rhel9@sha256:576459d1b82dc036d46c167a82d637e7924300668bffd8e3eebc0e9b349157c6_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/rekor-cli-rhel9@sha256:cb4533fbe1dbda3a253719cf1bea345e91e1eac6f0ba4665ee66016d02e0e296_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/updatetree-rhel9@sha256:49d1968ed236c78da3f355f228f24d0048ac11c83bea82025a83630c9bc39c99_amd64 as a component of Red Hat Trusted Artifact Signer 1.3

✅ Remediation

Red Hat Trusted Artifact Signer simplifies cryptographic signing and verifying of software artifacts such as container images, binaries and source code changes. It is a self-managed on-premise deployment of the Sigstore project available at https://sigstore.dev Platform Engineers, Software Developers and Security Professionals may use RHTAS to ensure the integrity, transparency and assurance of their organization's software supply chain. For details on using the operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/index Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (8)