RHSA-2026:1488HighCVSS 8.8

Red Hat Security Advisory: Red Hat OpenShift GitOps v1.19.1 security update

Published
January 28, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2025-55190 — github.com/argoproj/argo-cd: Project API Token Exposes Repository Credentials CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map

🎯 Affected products46

  • Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:7759a9f38e0870710bafafb9c20c678cda481f1be3293ac2b05533e882916ba2_arm64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:7a1d93b6efd2284984998859de08b44f1d44108ccd90f4f445e769dd228de59f_ppc64le as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:88d3d7cfa9a703b161eb6155eb959afe9ca3608214a58c11520bfda255b2adca_amd64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:f54fef4154d85375f9705b001b4aac6fb5ea51bee62970d218c3837fdec3440e_s390x as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:1724c0b60ac2dd07f86544c8763c4566b4dec34cff2062fceab044f0d38afa13_amd64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:5d7271b447c099a9c283677369bbed47cb4b90199e502759726bafd228c98ba9_arm64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:7f05064d5cb0133a91e5f1503bd886191375bd1fd510d87ecea920e134e6ab35_s390x as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:fc0829f0e0f1c67c0bee823936bc5c810ae185b83aee9cb9498e3752340443e3_ppc64le as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:3b082f03e5dd81d480a65001c7e30c58f3ec6fef0080aea257c6d956e2742a28_amd64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:3b58b1773e11173cce748d2a2272f57176ae234df9757073d3ccd19252c573f0_ppc64le as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:3c156d072f3f6c4decfdb07d4373037eee46d86a85086da963f01b9f8c74ddce_s390x as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:df1b6884eb846d6cb1fb926963cf6029da3317e87ad618f0659064b3beab4166_arm64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:65756086c381a16c062ee3f42fa5b89fb2f97c65a28be74d4a3b59a44d6f1f87_amd64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:798f7ce557d6ea32e7bd352bbc08a04d79647041272f249f97f2494e4efb59c0_ppc64le as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:b2780b4049e679584e23f86b7ba5f5d8c06d034b7143608579fcba4717d0a0b4_s390x as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:dcb742ace3daafa0a67e846ba85c9c3f72a77d1e899623aa89870fa68e16dac2_arm64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:0a21e0f0b30b568deda84fbe54500fe6f3d9f38e66ebf9714ca5d41d7b1ee797_ppc64le as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:33856c2a7babc0b55f47ced41d94617f25ccc9611f701f88238b7c4099677a77_arm64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:d00bfd094c7b46d6064b45f4b090a668fb1fa00ef0f324117637734cc0d183de_amd64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:eaa9c06f5c981a446234152ac20c1fc0015588afd1e800c5276678a2ccae02aa_s390x as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:19f2655fa02dcbd3790cadb89eb3f1d68611a69b1741c63a233567235512e0ca_arm64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:5e89db8a8bc3f942e04a0a333de8fea6dffb8fbbce3ac8b8110bb17a72ad0fe0_amd64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:691fab71b855295cdc85531c591e6fe991c624849cb526e525e768e3cd70ca43_s390x as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:6bbd09a5c58a72a52512204fa56e644cacfa803a49ea0156a7781a74922bacaa_ppc64le as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:35f8db26ea413d78191362567aa644c5032ba98a30562ca1c3308effb6845b11_arm64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:7d7d3de55d0f77b90cb36100a2d4dc7c28f916331e102d4ba75fad5474b51ea8_s390x as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:b451af584644ba4abf602c79a37ed746bc11b4649dcb51178548b3162e40985d_amd64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:f9b39b2f8f8a3940b8e4f04114d885ef6cddb25a27b9883ebdf369ee8f2f7944_ppc64le as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:3b157cc177ad7cc2e542d6fea0ca0cab023bd69c34a3ebd2625140e86528f64d_arm64 as a component of Red Hat OpenShift GitOps 1.19
  • +16 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (6)