RHSA-2026:17463HighCVSS 7.5

Red Hat Security Advisory: zero trust workload identity manager for Red Hat OpenShift 1.0.1

Published
May 14, 2026
Last Modified
September 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2026-21441 — urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)

🎯 Affected products5

  • Zero Trust Workload Identity Manager 1.0
  • registry.redhat.io/zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-rhel9@sha256:5ddd2b7dcb4f2ace06627cb7d3e7d1bd59b5ca81a1ef3f01839f7f7d048a92dd_arm64 as a component of Zero Trust Workload Identity Manager 1.0
  • registry.redhat.io/zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-rhel9@sha256:91a8cf930546c3614d031eaf216e7ff06ad3c69e69298dc0b673674da9fd22aa_s390x as a component of Zero Trust Workload Identity Manager 1.0
  • registry.redhat.io/zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-rhel9@sha256:c90ed9e428a4e5f8cc85e88de0ef1e80834700a0354f796d13154e50cd95a2fe_amd64 as a component of Zero Trust Workload Identity Manager 1.0
  • registry.redhat.io/zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-rhel9@sha256:df017fb22687410a658c968262e8f54a5effafb496319a0067f74b9ee9c0349b_ppc64le as a component of Zero Trust Workload Identity Manager 1.0

✅ Remediation

Before installing the operator, make sure all previously released errata relevant to your system have been applied. The steps to apply the upgraded images will differ depending on the installation plan approval policy that will be used while installing thezero trust workload identity manager for Red Hat OpenShift. - If the approval policy is set to `Automatic`, then the Operator will be upgraded automatically when there is a new version of the Operator. No further action is required to upgrade. This is the default setting. - If you changed the approval policy to `Manual`, then you must manually approve the upgrade to the Operator. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

🔗 References (6)