Red Hat Security Advisory: zero trust workload identity manager for Red Hat OpenShift 1.0.1
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-21441 — urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
🎯 Affected products5
- Zero Trust Workload Identity Manager 1.0
- registry.redhat.io/zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9@sha256:47142dd4fefad52dcd1c749532f7de761bb9d463a9d90349c8987c769f3e3438_amd64 as a component of Zero Trust Workload Identity Manager 1.0
- registry.redhat.io/zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9@sha256:9bc0f870faac5c6067d19d9f18a326278ca16936649cab980ca38545768ce7b2_arm64 as a component of Zero Trust Workload Identity Manager 1.0
- registry.redhat.io/zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9@sha256:b325cd07a17b927b01b90c554586a6df21487d6630eb62c4dcb3e25e332e478e_s390x as a component of Zero Trust Workload Identity Manager 1.0
- registry.redhat.io/zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9@sha256:b96e8ef2d4e0697ddf666df6d7d0c54ecb18e708139ee408fadf9324d96bfa49_ppc64le as a component of Zero Trust Workload Identity Manager 1.0
✅ Remediation
Before installing the operator, make sure all previously released errata relevant to your system have been applied. The steps to apply the upgraded images will differ depending on the installation plan approval policy that will be used while installing thezero trust workload identity manager for Red Hat OpenShift. - If the approval policy is set to `Automatic`, then the Operator will be upgraded automatically when there is a new version of the Operator. No further action is required to upgrade. This is the default setting. - If you changed the approval policy to `Manual`, then you must manually approve the upgrade to the Operator.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:17461
- externalhttps://access.redhat.com/security/cve/CVE-2026-21441
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/security_and_compliance/zero-trust-workload-identity-manager
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_17461.json