Red Hat Security Advisory: Red Hat OpenShift GitOps v1.17.5 security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2025-12816 — node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-66418 — urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion CVE-2025-66471 — urllib3: urllib3 Streaming API improperly handles highly compressed data CVE-2026-21441 — urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
🎯 Affected products42
- Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:0a66843c2b966114a3438d4f11d2bc6cafe46ae4e3e941baf01bc0301aff7fd7_s390x as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:227a8e4f996b077ad1a284c5e14855e37423e99c62175f6862d13e8201c588e5_amd64 as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:a8a6e1c81223128f24b66619cf373666957067605f3df9d85ecf3319da7e68ae_arm64 as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:dd441993e9b173999be85c6f69718e3f7b433caad5e6c65c0d359fd259c91b77_ppc64le as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:321c3940495fdca2243f65ba5e197c1a6d91c3d615e3fedbe7227d14664b5398_arm64 as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:6ecd87f063a5ec9cf3281f008fcb80d12d77e291459440464a35ed10d12a3bdc_ppc64le as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:75ae465e708b6cdc35ead810e63e06e31748f0c2ed5bf594354923ddd0917c2f_s390x as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:857f0a30e261a68dd35a92a661259f7a1bbbf0d806b3fd294bb4bdbaed34a2a2_amd64 as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:01d3bc986dfab006ffae245d3afc81215d7f1ffe314625f3f7ec1334e4336a2e_s390x as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:674ff46ec584be22c7388fc25a7534dbb9aa3c8b14b5401bd76fab8480ebd609_ppc64le as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:88f63890290927cca47e1e1aaee21a95a5f462af46ab4400a0f6e430e1f5623b_amd64 as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:ae59e94554327b660b9d7ae36c21dae91d53e1511c042f64aaa79bd92cc4db4b_arm64 as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:0d754ffcfee2da93c085f92a973adb47e2cc65f44be8a1b162983a52a213fb13_s390x as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:5654b69c24a1bb03e5fd6a60635c18d8def47a259169ad5680d125b429e41678_ppc64le as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:9a17ad8e4efa4ce78562d503bc360f7b661f0d75dd8e0fd454909f49f099fa58_amd64 as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:d73dc505b53a564bb1f4c6f3bbd8ae645ea3184aa10d9193594de5c77f985c74_arm64 as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:52a017f6e2408179a323dc5e6ff043861d49c757be5a0d0dd7af4d6941629508_arm64 as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:8fa4b854c88f6d1ebabccbb847dd11d9bee66275b5091f6bcd9b0eb860e52444_amd64 as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:c8bb51aadf678fdb8ff83135be94b84df53d4551915ba7af44fb3ed5cfe4a075_ppc64le as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:d0c3317fb4530c48734a993ea4cf4ad958de50e2e9bdc1cbfec84abe2e143fb7_s390x as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:382872d09838547bd7b9416f5c800afb28c290e3a14109285da3ca2ff94a22af_ppc64le as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:51878bf4ea05a68c73ebd99664ef4b3c718fc8ec53cf98bcac589b4267af7764_amd64 as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:7a587b41a50879e4ac1b7ce35efaa2e6b05227a08da041ea0b21b889c07d8b6a_s390x as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:da70d77c71e755144cc5ed0224b78c78b4a6676db998040bce16becfd731a11a_arm64 as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:162f9d7ff3c4e5e06e73a6c8cd24dbd9afaacacbf6d57d83988a4e27754f0754_amd64 as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:76134796ff5c05eb6fdd9e6520b4d32ae054822a9fc94584f48ce87c2e3ec6c3_ppc64le as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:d4738ad5467d0bf0e851d239ed97c81fe23929b2f6c24f9dac5af6231b16d4f1_arm64 as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:dc8b2b43eb5f9c10be39bfc326068bc5680844bdcc9970c6cebfe952f3f42e58_s390x as a component of Red Hat OpenShift GitOps 1.17
- registry.redhat.io/openshift-gitops-1/gitops-operator-bundle@sha256:28f4abb103e42261349702992b66571b260509fd25546bfe6e0a2dc6b916822f_amd64 as a component of Red Hat OpenShift GitOps 1.17
- +12 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:3869
- externalhttps://access.redhat.com/security/cve/CVE-2025-12816
- externalhttps://access.redhat.com/security/cve/CVE-2025-13465
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-66418
- externalhttps://access.redhat.com/security/cve/CVE-2025-66471
- externalhttps://access.redhat.com/security/cve/CVE-2026-21441
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_gitops/1.17/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3869.json