Red Hat Security Advisory: Red Hat Web Terminal Operator 1.12.0 release.
🔗 CVE IDs covered (5)
📋 Description
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-27137 — crypto/x509: Incorrect enforcement of email constraints in crypto/x509
🎯 Affected products5
- Red Hat Web Terminal 1.12
- registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:0d1d6a7ab4d79ce38526b5cba5b2bf7cfcb4229384115e71770a4f47db5575e2_amd64 as a component of Red Hat Web Terminal 1.12
- registry.redhat.io/web-terminal/web-terminal-operator-bundle@sha256:1be7fa359ffbd5516fe2edea73d6357c14487043300bbdedf638442995a48a05_amd64 as a component of Red Hat Web Terminal 1.12
- registry.redhat.io/web-terminal/web-terminal-rhel9-operator@sha256:78bf63531eca4a31679ce352adf95cbce86ecaa9dded662cc5d19e573c5e8c38_amd64 as a component of Red Hat Web Terminal 1.12
- registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:74189cad04c4a910367bd79b404f36f42f6379d943a1c96a4d99aa5d8aa8fe15_amd64 as a component of Red Hat Web Terminal 1.12
✅ Remediation
To start using the Web Terminal Operator, install the Web Terminal Operator from OpenShift OperatorHub on OpenShift Container Platform 4.17 or higher. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2026:10225
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/CVE-2026-25679
- externalhttps://access.redhat.com/security/cve/CVE-2026-27137
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://redhat.atlassian.net/browse/WTO-360
- externalhttps://redhat.atlassian.net/browse/WTO-362
- externalhttps://redhat.atlassian.net/browse/WTO-365
- externalhttps://redhat.atlassian.net/browse/WTO-370
- externalhttps://redhat.atlassian.net/browse/WTO-380
- externalhttps://redhat.atlassian.net/browse/WTO-385
- externalhttps://redhat.atlassian.net/browse/WTO-389
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_10225.json