Red Hat Security Advisory: zero trust workload identity manager for Red Hat OpenShift 1.0.1
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2026-21441 — urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
🎯 Affected products5
- Zero Trust Workload Identity Manager 1.0
- registry.redhat.io/zero-trust-workload-identity-manager/spiffe-spire-controller-manager-rhel9@sha256:3776b0ba86480e3daa898957ef0e6f0486d0e0baf5de9413ee36ad32b3226650_ppc64le as a component of Zero Trust Workload Identity Manager 1.0
- registry.redhat.io/zero-trust-workload-identity-manager/spiffe-spire-controller-manager-rhel9@sha256:49d899eaabcb2504c80a2f88913fe1b47ab311d5669bbb90691f59b092d0e142_arm64 as a component of Zero Trust Workload Identity Manager 1.0
- registry.redhat.io/zero-trust-workload-identity-manager/spiffe-spire-controller-manager-rhel9@sha256:81ca6a7578a4fddb37ad711c0fa7d173b42b7d6bae09351cba024d85e5e5aa84_s390x as a component of Zero Trust Workload Identity Manager 1.0
- registry.redhat.io/zero-trust-workload-identity-manager/spiffe-spire-controller-manager-rhel9@sha256:fcd19d7b5c774ada1c7f9abf3367796ef7a113c4d2e2566ffc3cc0f0be222c4d_amd64 as a component of Zero Trust Workload Identity Manager 1.0
✅ Remediation
Before installing the operator, make sure all previously released errata relevant to your system have been applied. The steps to apply the upgraded images will differ depending on the installation plan approval policy that will be used while installing thezero trust workload identity manager for Red Hat OpenShift. - If the approval policy is set to `Automatic`, then the Operator will be upgraded automatically when there is a new version of the Operator. No further action is required to upgrade. This is the default setting. - If you changed the approval policy to `Manual`, then you must manually approve the upgrade to the Operator. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:17460
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2026-21441
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/security_and_compliance/zero-trust-workload-identity-manager
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_17460.json