RHSA-2026:20943HighCVSS 9.1

Red Hat Security Advisory: Red Hat OpenShift GitOps v1.19.4 security update

Published
May 26, 2026
Last Modified
August 25, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33487 — github.com/russellhaering/goxmldsig: goxmlsig: Integrity bypass due to incorrect XML Digital Signature validation via loop variable capture issue CVE-2026-42880 — argoproj/argo-cd: Argo CD: Information disclosure of Kubernetes Secret data via Server-Side Apply dry-run mechanism

🎯 Affected products46

  • Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:093d586a268c1129068c4c92ce4e23de78bf72944a392beaa46bd2364ca0336b_arm64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:12cfb7c85072330ccc14faa278f2dcc4ce87972fa46432ba00c609c3656e092d_s390x as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:4770392a4f37b9e8b6f8d8a37748243fbf4f63eabc4125b0e31f55f927b4598f_ppc64le as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:b6773a29fc3d9504143f9aed3438781e04b4262a4ac46d1926f2ce76c87ad0c9_amd64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:474bf4e9a76c93e3983695ce125a7836d5bd0bde611bbb48b8b5b8be721b15de_s390x as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:7078ad00e7f3573c36de3bd2b970d77e9d4445f810d4d65f2fb19286f4e9d89f_arm64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:e9feb44bbe30da9b742c50d01de7768b1e452384fa11a65c689ee7d128fa56da_amd64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:f9ee62dc4533db9cde78c7595efc92cb708d31263dad4c7572af141ceb0a385e_ppc64le as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:084929fa28329d1382a0667a61e83e349f55369d80f71ef2f6af8a88dcda19d1_ppc64le as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:0c72e0769629dafa087f03221987ba896604d4e136fbf9a28666b9c55c8d987c_arm64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:63cbd262105c2b5a0173f842a879fc5a036e52578bd48af9bc470eb48a660595_amd64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:aacb1fd3d0cd707059b4f94730c1f8cdc84ba8442e52299480d87eaa0350dfeb_s390x as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:021a2b93438ab7a0cdb1ee15ce32c38cccb556802203b7f79604b21fde0dfe38_ppc64le as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:0c81eedce2f08c304fea9aa8662fed9f845ac13638bca8f5a9b1684819dc207e_s390x as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:4c0a72935660b5f38b9c981432195892853e798e0c07e637bd9e3bcf90e12987_amd64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:c769040e7b362ea4918e077b1481b1059fbf5d762b8e2444631d3e08d391434a_arm64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:5919feb409837ec88c5197df633639a697c5ec6138cd2620f1f452ef5a3bd365_s390x as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:66c18c542c66eb54f38c8c22ca7ee83b14dfaf4c89525a4958cece1c608d9997_arm64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:990bcf2561d70247f42cfac2d9ed81bad938f113a79e4c254c07a6b25a3f4074_amd64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:9e1f91b60724585e27ec0ddc860eb359d22f4a4c13369b453a4aec4c7e05f319_ppc64le as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:1b7901e494b7274e5fe66969d535e7e8e104b0a1d922830264b63cd011aee636_s390x as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:2d7b4f9c6cc56113f6fbf280906ad12800cd6000c6176b8da23749477d51e5f6_amd64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:37b2555153f4260511bb69e79c877661edf4f54a91c235255d0fa7620e114256_arm64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:ef149f4672aa43d14957cdc42c5bdea2e3a42ae00b28b5b12dcd4939f7efcd40_ppc64le as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:781e28a4fd1e3e49d0964a7cc23f35419ef82a8b58681fed0b52c959a796abe9_s390x as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:867432aa79ea7b612d90e6a6a2e3a16cb14f9d4a0ad22f2358f2809cb717e8a9_amd64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:c3a631bdb8c4805a7a82cf3a81b010a2dd4fb837e9cddf3bad0720c6307c2996_ppc64le as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:de5acfcacf2d7ddc3a32c3eb8ca542d52bbe59b2fcd06b88b0e1a2508d539635_arm64 as a component of Red Hat OpenShift GitOps 1.19
  • registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:12c586d1f3bfb82db15f63f066fa1aa1745939fce43d6f811210f46b098550fa_amd64 as a component of Red Hat OpenShift GitOps 1.19
  • +16 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (9)