Red Hat Security Advisory: external secrets operator for Red Hat OpenShift 1.0.1
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption
🎯 Affected products5
- external secrets operator for Red Hat OpenShift 1.0
- registry.redhat.io/external-secrets-operator/external-secrets-rhel9@sha256:0566fa6851afd673fcb65620362b3964cbc3883aaa3961e45a7b8374c829744f_arm64 as a component of external secrets operator for Red Hat OpenShift 1.0
- registry.redhat.io/external-secrets-operator/external-secrets-rhel9@sha256:266e0868a8529a5b0c83b0d2c9214553c3a4a0bf75eb260cda237043fc95debc_ppc64le as a component of external secrets operator for Red Hat OpenShift 1.0
- registry.redhat.io/external-secrets-operator/external-secrets-rhel9@sha256:2e2121930e077c11013417a142e92fce676931361d65c37f74e89b89ef58ad51_amd64 as a component of external secrets operator for Red Hat OpenShift 1.0
- registry.redhat.io/external-secrets-operator/external-secrets-rhel9@sha256:4304057ab39f82e3d005a62ccde7842fcff844451ad9cb862096a75c4126fae0_s390x as a component of external secrets operator for Red Hat OpenShift 1.0
✅ Remediation
Before installing the operator, make sure all previously released errata relevant to your system have been applied. The steps to apply the upgraded images will differ depending on the installation plan approval policy that will be used while installing the external secrets operator for Red Hat OpenShift. - If the approval policy is set to `Automatic`, then the Operator will be upgraded automatically when there is a new version of the Operator. No further action is required to upgrade. This is the default setting. - If you changed the approval policy to `Manual`, then you must manually approve the upgrade to the Operator. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:40924
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/security_and_compliance/external-secrets-operator-for-red-hat-openshift
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_40924.json