Red Hat Security Advisory: Red Hat OpenShift GitOps v1.18.6 security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33487 — github.com/russellhaering/goxmldsig: goxmlsig: Integrity bypass due to incorrect XML Digital Signature validation via loop variable capture issue CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object
🎯 Affected products42
- Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:11d3830c3d9691d77aa1413af45a1bce1aca931b000e7f5da75172fb76c4145b_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:6fc8c53df3e32e265886d662c4acb4afc5ea290e31d1435d7ec1e0e2678daca5_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:a4e3a3345862f1dbefe620bce99794e01fca58e650f3291ec4519a953398e726_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:cd70a3fa917e91985111bfe950282be66e89ba08d32bb32186126e8df1f56acd_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:4cc779a08ad6832c88e680e2e82a931459aea07691d2db7246e12dc66bb9fe2f_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:4d138120e590ac5c5d007f07abae74c68d06e0b137cb60de44644c1ad351bc61_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:55bc37227d5b0ec3626ab92ccf9d6d594ad4233d7b11fc0bfead2b7f1ae3f825_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:bd95b790234bf8524db5c024b2e5f6f2457b4f3c72b1476fc73a5a2f64077dd6_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:12a6fb97bd7ebe6f9c04e04a5fc302343b7bf6fcd95e365efad7861fbe502d3b_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:2d8b62a8209079daeaeab25881089c160f1585658fd954619ba2ca2fa7185ecd_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:ad940c4fd6e141a04fb58da780443d2c24945759de6380b6328ef1fa2e8e1f57_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:bd139d8c24c811320221406edbb7a66618e174ca538c3784a73feb60a0558a0a_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:1101419bfdba559e9bb01a4cd28517393e6ff4a01a73fd46e6328ea6846e7fb5_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:355472dfe72924d5e1e1dc24553a2fd7f3f79d4751f3df52ee04fa903658e4d2_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:d06ac49a21994874eb28b8c6a0f5acb4d09999d723dd887436210d047e80153d_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:dcead116f99d5c00012dd9207156048142ee24bc70862f36a7bcf894e5ae1ee9_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:68019fbee61af5ef1368e3e496e462d2f9dbe5a96fa817f9326ec14d907fb0c6_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:8ee41b5ede1963eead37122685b2201a61859e6ef416098dc9a8d584d0be3e62_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:bb58c6d2b73a99a564f7ef9c142ee39a6405cddead621cc9ac70cf424f1a79a6_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:ec84b7694e343de23afb17e7e12445babb38be2c353456f5924ffe2909161432_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:0ad1db16a7868c92ff6fe5e0a019ccbb24b96de1b382564ae2470cd907498b12_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:4ba81a63701fcb3a5f726035aa27b044a960456cfa6f8bb84078e1f6af0bcf00_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:5d6d5f2382315719bb2e02124d58226ac86d3639c061c2b4107ea079a0787966_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:6a7901155bd171509d8d1181784cb51574468e728232b7565a9b724a43e31390_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:45982222d809b7e77adf13a750f5e5dca63aa0240d76b7d496f1e2676f71c87f_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:567aaa242d33749676a4da80d41b6e3b98b0d589307b59c975b803e87dfef2f2_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:7ba98db93e1874366433a09d4c63c302ea645431b7666d31c6664acd79cf60b6_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:b567fe32d1e685fbad4625ed93b2592821590117d4722cb7a398005be87a4654_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/gitops-operator-bundle@sha256:cf81d0157a9065d04ab880096a613e0400c4bcda36f01eeb94879389cec30159_amd64 as a component of Red Hat OpenShift GitOps 1.18
- +12 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:20946
- externalhttps://access.redhat.com/security/cve/CVE-2026-32281
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-33487
- externalhttps://access.redhat.com/security/cve/CVE-2026-34986
- externalhttps://access.redhat.com/security/cve/CVE-2026-4800
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_gitops/1.18/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_20946.json