RHSA-2026:40970HighCVSS 7.5

Red Hat Security Advisory: RHTAS 1.3.6 - Red Hat Trusted Artifact Signer Release

Published
July 16, 2026
Last Modified
September 1, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint

🎯 Affected products2

  • Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/createtree-rhel9@sha256:8d6b3161f936e040379053b779750239fb7e3df70b4aca8108e47bb93214a5ca_amd64 as a component of Red Hat Trusted Artifact Signer 1.3

✅ Remediation

Red Hat Trusted Artifact Signer simplifies cryptographic signing and verifying of software artifacts such as container images, binaries and source code changes. It is a self-managed on-premise deployment of the Sigstore project available at https://sigstore.dev Platform Engineers, Software Developers and Security Professionals may use RHTAS to ensure the integrity, transparency and assurance of their organization's software supply chain. For details on using the operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/index Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect.

🔗 References (7)