RHSA-2026:41036HighCVSS 8.8

Red Hat Security Advisory: Red Hat OpenShift Builds 1.8.1

Published
July 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (13)

📋 Description

CVE-2026-10840 — openshift-pipelines-operator-rh: openshift-pipelines-operator: tekton-scheduler-rolebinding grants system:authenticated write access to Kueue and cert-manager resources CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVE-2026-39833 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation

🎯 Affected products38

  • Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:0ac4f867b4fbd7035b9b7a6158c134c091946383f3d739aeec71ff15f286f5dd_s390x as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:4196be761279241d472c4f73e3c098afdbe711b334613c368119d44baf92eabc_ppc64le as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:d18eb2063450f25e7c1bb015372fac90003bb3a6749ce544bfc96cfdb0c28951_arm64 as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:d8e57c472bdf507de76bf7e88dc9895ae32de6394895bee12a34ffb08232f49a_amd64 as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:0595dce81dede2bb7f823fb1e7f3de98865414af8fb30ea3a45a0a5f7a3b8657_s390x as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:2a1c0932f3bc30280e21353541bd7a8ab6a983c8f3dac2774c6e8ba1eb9b14c4_ppc64le as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:c8aece0e34203e38305245f99232ffe74034b6684a1927b04b7dfcdecc6322ee_arm64 as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:db72c0a0a440464697b1fb1b75ecf1bf0cf51f6b8a6e1ebc48fd5aebe1f14b18_amd64 as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:526883a7ec90c8748a49de98e0026e4a21a877b125de75c1548109892d97bd6c_amd64 as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:aad222ffe48442a2da11b6111e7fd60f0296f430f6fb6d6ce46e33c5184fb1da_arm64 as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:caba28465f7078e4fab08585ad77b6aa52cf87c1d9af26d2f62a719b499cb9e6_s390x as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:f9e95dafe5f90bbb4195cf494444bdeba555d1a54ac7392a3dcadf2084e28be0_ppc64le as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:167a23fbe223e5e588ec7f30e5a7a6748c913f4d1b65218305280c3de0b00864_amd64 as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:343751add5a7fc7c0f0a6911b8238337f163e46c4f312c6c60e56295cb08bf96_s390x as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:ce5a93d17bec20669e0b050a89cb11f6f9d3296ae734426b275cfb4b7d0be68f_arm64 as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:f5462fd3e487225983f131e565e6978c6a5ad6ef3474e367405afa0de584254f_ppc64le as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-operator-bundle@sha256:fae5ad88d9ac7f97a1b207fd441c24a5fd7d7f6b818bb1fedf0ba0c8bb247e5f_amd64 as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:045a83220498c646c908c63e4e813327be2c8fe9761db10461926ed6e1b0c027_arm64 as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:a99c51463eb5cadbd636f570aa39b7a0be8a94b34eb722057e31f6d140c5c4ff_amd64 as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:b66220032a25e314676dee1a2fd60fde5591372e3ee383702a0c9d4bba91454d_ppc64le as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:d08845514b0108036745ad5471c60671edd447459d830fae558b3c1dee55453c_s390x as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:3cc88f81ea9859f134b760284e87703769b619735fec3e0a64d40a851fecab2b_s390x as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:5ce61d2230d475a35ff7ff75950440da4da5c791f00abb01c003cac3bab108c8_amd64 as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:5fe39506407bae7aae2c2347a9ebeb7113406337a21c3034b1979cb9987f80d9_ppc64le as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:862bf4412106f7caab91c35f1984dce3e6cffb8d3ac78880b42c0ae88328112f_arm64 as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:43e78562af5bfa860073dce43964bfa7610ac6829e68c5806653caca4a59a3c3_ppc64le as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:d4d0dd2ed1b83a6e0824c94338b57542b605ae9c501d46589655371e94e7ae0b_arm64 as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:d54ccefd000d02c26e6e45fdecd46e3f0b052979fcbbd86824fd1df432992bb2_amd64 as a component of Red Hat OpenShift Builds 1.8.1
  • registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:e1b45bf2ee851c2262a0a3e8a23eb8f53f2be0c06a576bfaff48f9877e7278d5_s390x as a component of Red Hat OpenShift Builds 1.8.1
  • +8 more not shown

✅ Remediation

It is recommended that existing users of Red Hat OpenShift Builds 1.8.0 upgrade to 1.8.1 Workaround: If the Tekton Scheduler feature is not in use, administrators can mitigate this by patching the ClusterRoleBinding to reference a specific ServiceAccount instead of system:authenticated: oc patch clusterrolebinding tekton-scheduler-rolebinding --type=merge -p '{"subjects": [{"kind": "ServiceAccount", "name": "openshift-pipelines-operator", "namespace": "openshift-operators"}]}' IMPORTANT: The OpenShift Pipelines operator's reconciliation loop may revert this manual patch. Verify that the operator does not reconcile this binding back to system:authenticated after applying the mitigation. If it does, scale down the operator deployment or configure the operator to skip reconciliation of this object. Alternatively, the ClusterRoleBinding can be deleted if the Tekton Scheduler is not enabled. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: Update affected Go applications to use golang.org/x/crypto version 0.52.0 or later, which rejects unsupported ConfirmBeforeUse keys instead of silently ignoring the constraint. As a workaround, do not add keys with ConfirmBeforeUse to the in-memory keyring from golang.org/x/crypto/ssh/agent, or use an SSH agent implementation that correctly enforces confirm-before-use.

🔗 References (17)