Red Hat Security Advisory: Red Hat Web Terminal Operator 1.11.0 release.
🔗 CVE IDs covered (5)
📋 Description
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-27137 — crypto/x509: Incorrect enforcement of email constraints in crypto/x509
🎯 Affected products5
- Red Hat Web Terminal 1.11
- registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:3f023579aeb7ef51b78419eadc9a5336ad13d22d437566f57f134ffe8b195a44_amd64 as a component of Red Hat Web Terminal 1.11
- registry.redhat.io/web-terminal/web-terminal-operator-bundle@sha256:02e55ec3e1891323a0a33432610bd6a1d792aa4a3d3d74419c862cd22b4d012c_amd64 as a component of Red Hat Web Terminal 1.11
- registry.redhat.io/web-terminal/web-terminal-rhel9-operator@sha256:4a962859025e5e34351919c61cd8b62c31117ee85810675ef9a2f9e13f805395_amd64 as a component of Red Hat Web Terminal 1.11
- registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:da64b849bc965960d18250fe15ad3c07a9a648618c546a017d0a1c843e623d4a_amd64 as a component of Red Hat Web Terminal 1.11
✅ Remediation
To start using the Web Terminal Operator, install the Web Terminal Operator from OpenShift OperatorHub on OpenShift Container Platform 4.16 or higher. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2026:10250
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/CVE-2026-25679
- externalhttps://access.redhat.com/security/cve/CVE-2026-27137
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://redhat.atlassian.net/browse/WTO-364
- externalhttps://redhat.atlassian.net/browse/WTO-369
- externalhttps://redhat.atlassian.net/browse/WTO-374
- externalhttps://redhat.atlassian.net/browse/WTO-379
- externalhttps://redhat.atlassian.net/browse/WTO-384
- externalhttps://redhat.atlassian.net/browse/WTO-387
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_10250.json