Red Hat Security Advisory: RHTAS 1.4.2 - Red Hat Trusted Artifact Signer Release
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API
🎯 Affected products5
- Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/createtree-rhel9@sha256:677a8596784f322ee36ab7b788a65f0f1db163fcd6b7a93f756eb4450324b539_s390x as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/createtree-rhel9@sha256:b1c742d404b5a28dd067f7d77696c2b21d998e257243f054fa167b34e476f72d_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/createtree-rhel9@sha256:b93cd8eda401b3de28cdcb75b46b61ff485590775b6b1a56479db869fa033b03_ppc64le as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/createtree-rhel9@sha256:bfe49c2bd976ea7182c4e2d9db2c487be221363ac8ebad02fd3b0eb48a7b313c_arm64 as a component of Red Hat Trusted Artifact Signer 1.4
✅ Remediation
Red Hat Trusted Artifact Signer simplifies cryptographic signing and verifying of software artifacts such as container images, binaries and source code changes. It is a self-managed on-premise deployment of the Sigstore project available at https://sigstore.dev Platform Engineers, Software Developers and Security Professionals may use RHTAS to ensure the integrity, transparency and assurance of their organization's software supply chain. For details on using the operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4/html-single/release_notes/index
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:37267
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4/html-single/release_notes/index
- externalhttps://access.redhat.com/security/cve/CVE-2026-42151
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_37267.json