RHSA-2026:17457HighCVSS 7.5

Red Hat Security Advisory: zero trust workload identity manager for Red Hat OpenShift 1.0.1

Published
May 14, 2026
Last Modified
August 2, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-21441 — urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)

🎯 Affected products5

  • Zero Trust Workload Identity Manager 1.0
  • registry.redhat.io/zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9@sha256:402eabe171ba8129489ddd12eccea03e475da226fcd230eba5bfdeff3d73dc8e_amd64 as a component of Zero Trust Workload Identity Manager 1.0
  • registry.redhat.io/zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9@sha256:79a3eb4b2ec11831c61aa0efbaaf3486ffed4546757dfbc4c541e3632a4c4333_arm64 as a component of Zero Trust Workload Identity Manager 1.0
  • registry.redhat.io/zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9@sha256:aea5bbed8fe42f9e9440578752bab1d2a28237df91bbaf8cacd1c7d8317ce07a_ppc64le as a component of Zero Trust Workload Identity Manager 1.0
  • registry.redhat.io/zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9@sha256:f86fd4e6ef238e3be6d6ccc8c2787db92c9f9a83220c7d1038be10818e2a91c5_s390x as a component of Zero Trust Workload Identity Manager 1.0

✅ Remediation

Before installing the operator, make sure all previously released errata relevant to your system have been applied. The steps to apply the upgraded images will differ depending on the installation plan approval policy that will be used while installing thezero trust workload identity manager for Red Hat OpenShift. - If the approval policy is set to `Automatic`, then the Operator will be upgraded automatically when there is a new version of the Operator. No further action is required to upgrade. This is the default setting. - If you changed the approval policy to `Manual`, then you must manually approve the upgrade to the Operator.

🔗 References (5)