RHSA-2026:37272HighCVSS 8.8

Red Hat Security Advisory: RHTAS 1.4.2 - Red Hat Trusted Artifact Signer Release

Published
July 9, 2026
Last Modified
August 26, 2026

🔗 CVE IDs covered (16)

📋 Description

CVE-2025-71319 — image-size: image-size: Denial of Service due to infinite loop when processing specially crafted images. CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42570 — devalue: devalue: Excessive memory consumption via deserialization of sparse arrays CVE-2026-44573 — next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n CVE-2026-44574 — Next.js: Next.js: Authorization bypass via crafted query parameters CVE-2026-44575 — next.js: Next.js: Unauthorized access to protected content via middleware bypass CVE-2026-44577 — Next.js: Next.js: Denial of Service via Image Optimization API CVE-2026-44578 — Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests CVE-2026-44579 — next.js: Next.js: Denial of Service via crafted POST requests to server actions CVE-2026-45109 — next.js: Next.js: Information disclosure via security fix bypass in middleware with Turbopack CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray CVE-2026-48779 — ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments

🎯 Affected products11

  • Red Hat Trusted Artifact Signer 1.4
  • registry.redhat.io/rhtas/certificate-transparency-rhel9@sha256:428e9da9c20b26a5ba88ec84f1be212ce0474f81c2fd56ac062e3948eb23070d_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
  • registry.redhat.io/rhtas/fulcio-rhel9@sha256:9ba4d183d46315edb1a059e55267f30ab66069324cfc3a1a205fdabe45641e71_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
  • registry.redhat.io/rhtas/rekor-backfill-redis-rhel9@sha256:c34be5197926b29fc858ca4295773feb24d7a812691d4c88a70f3be3bbe49ff9_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
  • registry.redhat.io/rhtas/rekor-search-ui-rhel9@sha256:c0dfe2abf8d55740eefbaa647de617d1f796390111fae05919bf77897763977b_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
  • registry.redhat.io/rhtas/rekor-server-rhel9@sha256:938ca7e6d7fa3862825a86f142be9c6a7b5da1f7dfc6393bff5f77e24613bf67_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
  • registry.redhat.io/rhtas/timestamp-authority-rhel9@sha256:5c3552503bc698f229f835e3686462b75a3af15575edfa1081880fc945f2d8cf_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
  • registry.redhat.io/rhtas/trillian-database-rhel9@sha256:b5736b9f843573e1820b25da162b537b5f324d437c78a79c54f5258fa2204521_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
  • registry.redhat.io/rhtas/trillian-logserver-rhel9@sha256:6cac09fcce3938f4e08e0dc5960ca5159bd4c36d238e1e49037c977c62dde85d_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
  • registry.redhat.io/rhtas/trillian-logsigner-rhel9@sha256:613398e5394371bac97d05c04d97b163c5048a8095ff8ff8bc510a24e46092d6_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
  • registry.redhat.io/rhtas/trillian-redis-rhel9@sha256:fd4c05777a37475158316b694d4319c0a8ea0e39838306ee73523ec37fd3f3fa_amd64 as a component of Red Hat Trusted Artifact Signer 1.4

✅ Remediation

Red Hat Trusted Artifact Signer simplifies cryptographic signing and verifying of software artifacts such as container images, binaries and source code changes. It is a self-managed on-premise deployment of the Sigstore project available at https://sigstore.dev Platform Engineers, Software Developers and Security Professionals may use RHTAS to ensure the integrity, transparency and assurance of their organization's software supply chain. For details on using the operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4/html-single/release_notes/index Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (21)