RHSA-2026:17462HighCVSS 7.5

Red Hat Security Advisory: zero trust workload identity manager for Red Hat OpenShift 1.0.1

Published
May 14, 2026
Last Modified
August 2, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-21441 — urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)

🎯 Affected products5

  • Zero Trust Workload Identity Manager 1.0
  • registry.redhat.io/zero-trust-workload-identity-manager/spiffe-spire-server-rhel9@sha256:1adc34cd1e87024bab6850b2cda63743f42c57ae7c3ae483574760294b1a91a9_amd64 as a component of Zero Trust Workload Identity Manager 1.0
  • registry.redhat.io/zero-trust-workload-identity-manager/spiffe-spire-server-rhel9@sha256:6e6fd51cafc3f1bf85b49f9e4158a75f830be7c1ac125b3cafb668b2a3fb1ca1_arm64 as a component of Zero Trust Workload Identity Manager 1.0
  • registry.redhat.io/zero-trust-workload-identity-manager/spiffe-spire-server-rhel9@sha256:7614014330d5f6fdcdb035f3a24812e4db8131a4f3d908cc1afa369eae2908bd_ppc64le as a component of Zero Trust Workload Identity Manager 1.0
  • registry.redhat.io/zero-trust-workload-identity-manager/spiffe-spire-server-rhel9@sha256:9e544d9078dcd142a6f88833619af8c2691b92b4249358f01af884416b06644f_s390x as a component of Zero Trust Workload Identity Manager 1.0

✅ Remediation

Before installing the operator, make sure all previously released errata relevant to your system have been applied. The steps to apply the upgraded images will differ depending on the installation plan approval policy that will be used while installing thezero trust workload identity manager for Red Hat OpenShift. - If the approval policy is set to `Automatic`, then the Operator will be upgraded automatically when there is a new version of the Operator. No further action is required to upgrade. This is the default setting. - If you changed the approval policy to `Manual`, then you must manually approve the upgrade to the Operator.

🔗 References (5)