RHSA-2026:17456HighCVSS 7.5

Red Hat Security Advisory: zero trust workload identity manager for Red Hat OpenShift 1.0.1

Published
May 14, 2026
Last Modified
August 2, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-21441 — urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)

🎯 Affected products5

  • Zero Trust Workload Identity Manager 1.0
  • registry.redhat.io/zero-trust-workload-identity-manager/spiffe-csi-driver-rhel9@sha256:50bfe2aaeb2197ced2e396a70fa3d993de00d84e0467cbb1a106da4d475e987e_s390x as a component of Zero Trust Workload Identity Manager 1.0
  • registry.redhat.io/zero-trust-workload-identity-manager/spiffe-csi-driver-rhel9@sha256:72aa00cddf53af0329615a684176ea8304ff005def8be0ac79b98f7669d48bac_ppc64le as a component of Zero Trust Workload Identity Manager 1.0
  • registry.redhat.io/zero-trust-workload-identity-manager/spiffe-csi-driver-rhel9@sha256:a1260b241f60c79ae5e211388fcf4718ed7358a99832fc284b377cea52a2b9a0_arm64 as a component of Zero Trust Workload Identity Manager 1.0
  • registry.redhat.io/zero-trust-workload-identity-manager/spiffe-csi-driver-rhel9@sha256:e15e0b3442602833be8e3297cfac1333ce9e45ebc0d9a893f2a758702aff75e1_amd64 as a component of Zero Trust Workload Identity Manager 1.0

✅ Remediation

Before installing the operator, make sure all previously released errata relevant to your system have been applied. The steps to apply the upgraded images will differ depending on the installation plan approval policy that will be used while installing thezero trust workload identity manager for Red Hat OpenShift. - If the approval policy is set to `Automatic`, then the Operator will be upgraded automatically when there is a new version of the Operator. No further action is required to upgrade. This is the default setting. - If you changed the approval policy to `Manual`, then you must manually approve the upgrade to the Operator.

🔗 References (5)