Red Hat Security Advisory: Red Hat OpenShift GitOps v1.18.4 security update
🔗 CVE IDs covered (8)
📋 Description
CVE-2025-12816 — node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-66031 — node-forge: node-forge ASN.1 Unbounded Recursion CVE-2025-66418 — urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion CVE-2025-66471 — urllib3: urllib3 Streaming API improperly handles highly compressed data CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-21441 — urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
🎯 Affected products42
- Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:2353be1ea01a24c35fd63d6f033046680a815e4a1100360782b71149e48d93af_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:95fbb3c2082487b2a40bd0e9992761845cca988c262b03180bfdddeab31de919_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:abe87d778ec9473a971ad712dc464d349489cd94563c899bb24697204c506f6e_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:b8912d1100c5a5e1ca872156bc521e0aad5db03df936a1f4aa8bc7b9a7762027_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:7ea7d9fc96b14f18a1fc8c79f691a43e801c55973cec92aa08c0473ac291a957_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:88aae2bc6fc9ed73e505b2bae797be5cf8b5792abf426ce08167c6792843c9b8_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:88d93d43277ea7c1b2e1b4d8d900acb74bf40c3817ba199efa37606ed724031f_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:e2f02e7115c916450ea8b906da6b575e75de8072ea032f02c05b685585aaf399_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:3d23d71c607b1243a62fb8ac2444b392e52ede2886bb1e990e48ef62bcacd5f5_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:686bdf2af69f6942481b06fc1d4deb1c839252ea3f3fdf6c4308999b5ebbf9b0_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:80a5160b09aa9c8a3cc10f68ed4a97f55ba3836c9c221a95ccf437a938afe8c0_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:fd5e9bdef07d72529f93405ba19bc9bfc3b9fd5d53cdea0a7967b2c7fde3c347_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:2f64e4d6f4ee6184d5288c0c9d4ab781c2c0c185a92bacc7ffbe24e26308d226_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:7151311f01cc0d1270b59853fe69802bede2ad2c3ff0134bd92ba7fb194eabde_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:73c3db4c9fce967ac0a2004b74e4734068117a8dd597383b6def6f04c29a94d2_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:9100f8cbe10726ca76b8c624569b48c0175b882cb31e647ccd0bf5a52d57db50_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:2d36a79c3dc4ad8ae93f6c98463e7e044b24e4bd273c06f38bd026bd76abe9b5_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:52b46a27b25468652f2767a3f4fb6d84afb3023a771ed01ab7f168a576c5fe89_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:7167dca18a526637f60ebfd5901245bcc298646e41dce407bad58bceef700eb6_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:9036c60a2f2f8d24a9ffe7ded0686b9c35ee1315821616c99c588a1dfb31ebef_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:67049777e7c82a5e07124c2b00508a2d343146db3126ee013faa9fbc7ea47458_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:82977f08615644a6c6ee758f2ed8a25cc7e567f2786bedb2398d48e66104ad19_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:9da34d6dbf86101b9938e16b29d194b3757969a47465a094762f9e6c50b9e732_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:e82fdd38c9dbcb0c27245cd903e40622f0b3fd617c6e94959da16638d0e6c4aa_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:243a6b615a77bad0f3d3b79aa3aad5a8fca9bb464597f4931dd8bfa325dbc770_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:2fbf107528457256fd962e601c848da512e2fd5421db3b1ec477238d75c7bb43_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:c3482bc8d470b0a50e4fa5c50654516087044843c419b547a3101c45c12809c6_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:ebd8e40ab8fb89f9ab4410f1c6bedfb836c576d386e549ba4c58829b9d23d89e_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/gitops-operator-bundle@sha256:6fc4720fce99dc2d20d5d30e153c01754937dd7aca0a6697e0ecb16c16cab2ac_amd64 as a component of Red Hat OpenShift GitOps 1.18
- +12 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:3874
- externalhttps://access.redhat.com/security/cve/CVE-2025-12816
- externalhttps://access.redhat.com/security/cve/CVE-2025-13465
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-66031
- externalhttps://access.redhat.com/security/cve/CVE-2025-66418
- externalhttps://access.redhat.com/security/cve/CVE-2025-66471
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/CVE-2026-21441
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_gitops/1.18/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3874.json