Red Hat Security Advisory: Red Hat Edge Manager Version 1.1.3 Security Update
🔗 CVE IDs covered (29)
📋 Description
CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2025-69873 — ajv: ReDoS via $data reference CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-4926 — path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-32141 — flatted: flatted: Unbounded recursion DoS in parse() revive phase CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-32282 — golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33810 — crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-33816 — github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
🎯 Affected products29
- Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-alert-exporter-rhel9@sha256:beaacb4be3f6b8f814ea6581b92c34b56676ec49adc0428ed757731c14a56eae_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-alert-exporter-rhel9@sha256:e05ac211c00d4def3c8b4fbea4c4a191a1ea1e42dbc82c15dc17c07404be895c_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-alertmanager-proxy-rhel9@sha256:2729e3aa249d0b09a893d372ad150d09b955cd97b770b71b233592a04f63499f_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-alertmanager-proxy-rhel9@sha256:e5e79c8f41b374f816570a6203b13438fbcc5862c8bf6fbb3eb0aeb414dfe342_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-api-rhel9@sha256:1ef321ebc3a9b1b00e6ec9e8739a90a8a9ce5090a62080091cdd84f8fb09c5e2_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-api-rhel9@sha256:41646b37ef607efd7109f0450d45aaab7b238a496ec2c00668ab17a417b85c54_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-cli-artifacts-rhel9@sha256:b1985eaa9816fa7cc50aaf86ea722c56a8886554423a78c0623dc4ee04b16185_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-cli-artifacts-rhel9@sha256:d8986490f548237eb1e2790eb49c7eab29e2de21aeb4834e55fb6525b048c8dc_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-db-setup-rhel9@sha256:5b68fdcbf91efbec4932fe4dfed16d55fe37dd39d426712a8549c089fea5027c_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-db-setup-rhel9@sha256:b98b7b2c190bcae4b576676a610e0dd1d802c9a4f8be4a71560f4c34dbb056cf_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-imagebuilder-api-rhel9@sha256:0041833131abcec4fb42c2ee11929cb8aeecee37b3d03245f898c7c0d0a7b5fe_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-imagebuilder-api-rhel9@sha256:9f55a517fadcb7d5082f9d6f4a906c20d4981c09231d3081ca1295dc5d0bfd2f_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-imagebuilder-worker-rhel9@sha256:39ce652bf1a16685cd85818131281235e8fa2da311f7fcf0aad06d06a28979d5_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-imagebuilder-worker-rhel9@sha256:afba0e403ca2873a477c68adbd3866147904a34f1d6bb94741091b0d269e4bf2_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-pam-issuer-rhel9@sha256:7ca9965aabd79b15a3df9cddcab95e2cd3dc8e8eb78b2dba82b1f750e8f32398_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-pam-issuer-rhel9@sha256:baefe61c9054e19cd1f84485ed5482cdbb529e3a90b34afab75f74a2efc00fb2_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-periodic-rhel9@sha256:918510077d32a453641cd84fe9332e8db287bdf4ed5a7a7fbdf69518f75a7811_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-periodic-rhel9@sha256:dc8ef7e38b65248b2452037abfd03a108ea82439421d7caee528607f2aaf54f5_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-telemetry-gateway-rhel9@sha256:849e8aade0c291f2e33e227c983071e5899c38326af4b06c55693de77939e87e_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-telemetry-gateway-rhel9@sha256:fcdaa73650ca2159743281854f85a365fc0a69eec3120a4f7b2eb7d2b04a1578_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-ui-ocp-rhel9@sha256:734eff9f2aca059dc262e6a477dd42509364a7f3187e0e083fabb7335decbaf5_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-ui-ocp-rhel9@sha256:bd0faf7b42dea2a06be2dcd48a199ff8486988c874d0dbda202de0ef94980b31_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-ui-rhel9@sha256:7eda4f8ce4002ded99b7dc4574fbc77e90904b859c32262e0e5e4075de12c105_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-ui-rhel9@sha256:f40c17c9dfd12d87e20eccaed3a2a39a32ab867955b21b956cdcfcf6c87717a7_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-userinfo-proxy-rhel9@sha256:0485733482f41a980933afa20c7eac1189c7f41ca553887020ed635d8f3af3f1_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-userinfo-proxy-rhel9@sha256:7181bf99791f472d0558bf1a06a35e29e6ec1bea2af11ada37307c31c9867c85_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-worker-rhel9@sha256:05c23067536a9d5b2969355df88a5b107d518778c6614f6f24417ba7c096bc20_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-worker-rhel9@sha256:92baae35191a113fc41bee45d38559db1061b408e5718e17a45875f661461105_amd64 as a component of Red Hat Edge Manager 1.1
✅ Remediation
See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: To mitigate this issue, disable the $data feature if your application does not require it. If $data must be used, implement strict validation of the input fields that are referenced by the pattern keyword to ensure they contain only expected and safe characters. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, limit the use of multiple sequential optional groups in route patterns within applications that use `path-to-regexp`. Additionally, avoid directly passing user-controlled input as route patterns to prevent the generation of maliciously crafted regular expressions. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect.
🔗 References (34)
- selfhttps://access.redhat.com/errata/RHSA-2026:40118
- externalhttps://access.redhat.com/security/cve/CVE-2025-13465
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/CVE-2025-69873
- externalhttps://access.redhat.com/security/cve/CVE-2026-13676
- externalhttps://access.redhat.com/security/cve/CVE-2026-22029
- externalhttps://access.redhat.com/security/cve/CVE-2026-25679
- externalhttps://access.redhat.com/security/cve/CVE-2026-29063
- externalhttps://access.redhat.com/security/cve/CVE-2026-32141
- externalhttps://access.redhat.com/security/cve/CVE-2026-32280
- externalhttps://access.redhat.com/security/cve/CVE-2026-32281
- externalhttps://access.redhat.com/security/cve/CVE-2026-32282
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-33810
- externalhttps://access.redhat.com/security/cve/CVE-2026-33811
- externalhttps://access.redhat.com/security/cve/CVE-2026-33816
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39832
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-42151
- externalhttps://access.redhat.com/security/cve/CVE-2026-42154
- externalhttps://access.redhat.com/security/cve/CVE-2026-42508
- externalhttps://access.redhat.com/security/cve/CVE-2026-46595
- externalhttps://access.redhat.com/security/cve/CVE-2026-4800
- externalhttps://access.redhat.com/security/cve/CVE-2026-4926
- externalhttps://access.redhat.com/security/cve/CVE-2026-6322
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.15/html-single/edge_manager/index#edge-mgr-intro
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/managing_device_fleets_with_the_red_hat_edge_manager/assembly-edge-manager-intro
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_40118.json