RHSA-2026:3723HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift Pipelines Release 1.15.4

Published
March 4, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2025-66506 — github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token

🎯 Affected products14

  • Red Hat OpenShift Pipelines 1.15
  • registry.redhat.io/openshift-pipelines/pipelines-operator-bundle@sha256:29e53c58884174c78c5b86c8f63024f4643c9b5f90e476eddd5fd4725855a0d4_amd64 as a component of Red Hat OpenShift Pipelines 1.15
  • registry.redhat.io/openshift-pipelines/pipelines-operator-proxy-rhel8@sha256:682728a8ecb86109fbcc407e7ac4114d7993ed9acc11bb49f7761197a4965ad9_s390x as a component of Red Hat OpenShift Pipelines 1.15
  • registry.redhat.io/openshift-pipelines/pipelines-operator-proxy-rhel8@sha256:74dd0d15fdcf95ac1eedea4dafc45598dda258fec28831acc95f2d2784804a04_ppc64le as a component of Red Hat OpenShift Pipelines 1.15
  • registry.redhat.io/openshift-pipelines/pipelines-operator-proxy-rhel8@sha256:9d33602222295d4ecab52e990e0af7ae5f84e094721c2afaea1ddca904a91ae2_arm64 as a component of Red Hat OpenShift Pipelines 1.15
  • registry.redhat.io/openshift-pipelines/pipelines-operator-proxy-rhel8@sha256:a914252e2e10112e151571221a7f6b9db43d4584b8b906a960df4d6f358dcfb9_amd64 as a component of Red Hat OpenShift Pipelines 1.15
  • registry.redhat.io/openshift-pipelines/pipelines-operator-webhook-rhel8@sha256:644385b4abc586388b938baec6207d4406e0ff906aded74871644120143170a5_arm64 as a component of Red Hat OpenShift Pipelines 1.15
  • registry.redhat.io/openshift-pipelines/pipelines-operator-webhook-rhel8@sha256:83f7ba7cdf1b25ac5b9c91cd3aa76c1d7136a3d34d826f19a4fe4813a9c062d1_ppc64le as a component of Red Hat OpenShift Pipelines 1.15
  • registry.redhat.io/openshift-pipelines/pipelines-operator-webhook-rhel8@sha256:bbf204c5370405e55ef38b687bcb207806043c5e87b6735cad76e0dd202213db_amd64 as a component of Red Hat OpenShift Pipelines 1.15
  • registry.redhat.io/openshift-pipelines/pipelines-operator-webhook-rhel8@sha256:c9fe952471a5033cb77237850bcbcbb7690e9b4bafaa9a10d5a3b40bc4a49791_s390x as a component of Red Hat OpenShift Pipelines 1.15
  • registry.redhat.io/openshift-pipelines/pipelines-rhel8-operator@sha256:19a36e841519488d5895b999f84bffd8200c16b026f769ac72919296c65cc136_arm64 as a component of Red Hat OpenShift Pipelines 1.15
  • registry.redhat.io/openshift-pipelines/pipelines-rhel8-operator@sha256:2aa9f0a7afddf5e2ad7c642eb72a874c4d7e5a092828753da19e657fb6db69cb_s390x as a component of Red Hat OpenShift Pipelines 1.15
  • registry.redhat.io/openshift-pipelines/pipelines-rhel8-operator@sha256:61301a05842875ebaafe19ed7c426b22b014e4ea9ba0a5ff3c12e1b8fb03d97d_ppc64le as a component of Red Hat OpenShift Pipelines 1.15
  • registry.redhat.io/openshift-pipelines/pipelines-rhel8-operator@sha256:f128ce3188364bdf50142e1211e976dbb0bac67f541bad87a5577e81ef30e41b_amd64 as a component of Red Hat OpenShift Pipelines 1.15

✅ Remediation

Red Hat OpenShift Pipelines is a cloud-native, continuous integration and continuous delivery (CI/CD) solution based on Kubernetes resources. It uses Tekton building blocks to automate deployments across multiple platforms by abstracting away the underlying implementation details. Tekton introduces a number of standard custom resource definitions (CRDs) for defining CI/CD pipelines that are portable across Kubernetes distributions.

🔗 References (5)