Red Hat Security Advisory: RHTAS 1.3.6 - Red Hat Trusted Artifact Signer Release
🔗 CVE IDs covered (15)
📋 Description
CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-44573 — next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n CVE-2026-44574 — Next.js: Next.js: Authorization bypass via crafted query parameters CVE-2026-44575 — next.js: Next.js: Unauthorized access to protected content via middleware bypass CVE-2026-44577 — Next.js: Next.js: Denial of Service via Image Optimization API CVE-2026-44578 — Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests CVE-2026-44579 — next.js: Next.js: Denial of Service via crafted POST requests to server actions CVE-2026-45109 — next.js: Next.js: Information disclosure via security fix bypass in middleware with Turbopack CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
🎯 Affected products11
- Red Hat Trusted Artifact Signer 1.3
- registry.redhat.io/rhtas/certificate-transparency-rhel9@sha256:b713256acad58c623920da912e3442803a4c6d2f7354d532ff3f772740fe86ab_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
- registry.redhat.io/rhtas/fulcio-rhel9@sha256:ddeaf6343db4caaa9e33c6acac0ac2025b807780570bcbfaa412d0bf89b8cb9b_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
- registry.redhat.io/rhtas/rekor-backfill-redis-rhel9@sha256:28a5270a23b171cdaaca9adf3d6fc24db410a01fc1acdbd87b666e61215f5b3c_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
- registry.redhat.io/rhtas/rekor-search-ui-rhel9@sha256:8ee5d92df659073a13d9aa71e3e5fedac97e0c555a865ebf3697591ea6a38c59_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
- registry.redhat.io/rhtas/rekor-server-rhel9@sha256:03a020d623cc6115237fee9579500f7b047789857df04bdc7c6c14cb37e6de7b_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
- registry.redhat.io/rhtas/timestamp-authority-rhel9@sha256:cc908b30beddb8c8857888ab0a7b2c84990749b7bfd326ccbd06606ae93427d2_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
- registry.redhat.io/rhtas/trillian-database-rhel9@sha256:cbb7c79ec6053cea1269941dd40d55efb8f6437039d6cbd6a9b4ef55b6393278_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
- registry.redhat.io/rhtas/trillian-logserver-rhel9@sha256:716df3ddc8bbf4a5c25dae7dbbd1bebba91508df2bb4cc2cc1979c5e5d97923e_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
- registry.redhat.io/rhtas/trillian-logsigner-rhel9@sha256:a480b790358eaf214628d5e9d94b9a05614b76540e35ccca33cff3319c7ae6a0_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
- registry.redhat.io/rhtas/trillian-redis-rhel9@sha256:e4d9e12f8a0af0fa79ef79d0f3b938a7b1d0049baaf305168fb70a8a9922694e_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
✅ Remediation
Red Hat Trusted Artifact Signer simplifies cryptographic signing and verifying of software artifacts such as container images, binaries and source code changes. It is a self-managed on-premise deployment of the Sigstore project available at https://sigstore.dev Platform Engineers, Software Developers and Security Professionals may use RHTAS to ensure the integrity, transparency and assurance of their organization's software supply chain. For details on using the operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/index Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2026:40974
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/index
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-42151
- externalhttps://access.redhat.com/security/cve/CVE-2026-42154
- externalhttps://access.redhat.com/security/cve/CVE-2026-44573
- externalhttps://access.redhat.com/security/cve/CVE-2026-44574
- externalhttps://access.redhat.com/security/cve/CVE-2026-44575
- externalhttps://access.redhat.com/security/cve/CVE-2026-44577
- externalhttps://access.redhat.com/security/cve/CVE-2026-44578
- externalhttps://access.redhat.com/security/cve/CVE-2026-44579
- externalhttps://access.redhat.com/security/cve/CVE-2026-45109
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_40974.json