Red Hat Security Advisory: RHTAS 1.3.6 - Red Hat Trusted Artifact Signer Release
🔗 CVE IDs covered (9)
📋 Description
CVE-2026-42211 — react-router: React Router: Remote Code Execution via prototype pollution in Framework Mode CVE-2026-42342 — react-router: @remix-run/server-runtime: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpoint CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name CVE-2026-55603 — http-proxy-middleware: http-proxy-middleware: Data integrity compromise via CR/LF injection
🎯 Affected products3
- Red Hat Trusted Artifact Signer 1.3
- registry.redhat.io/rhtas/rhtas-console-rhel9@sha256:7a33c13a4fe493b4638f342a14d7dab93152141895771e543f3e028773bfa10f_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
- registry.redhat.io/rhtas/rhtas-console-ui-rhel9@sha256:eea5c4b6830a8fd26acfc5e0c01c01cb7dd6519f27cef4ac4874546c1dbb03bd_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
✅ Remediation
Red Hat Trusted Artifact Signer simplifies cryptographic signing and verifying of software artifacts such as container images, binaries and source code changes. It is a self-managed on-premise deployment of the Sigstore project available at https://sigstore.dev Platform Engineers, Software Developers and Security Professionals may use RHTAS to ensure the integrity, transparency and assurance of their organization's software supply chain. For details on using the operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/index Workaround: To mitigate this vulnerability, ensure that applications using React Router are not configured in Framework Mode. Instead, utilize Declarative Mode (`<BrowserRouter>`) or Data Mode (`createBrowserRouter/<RouterProvider>`), as these modes are not susceptible to this flaw. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Upgrade to a patched version to fully mitigate the issues (ref: https://github.com/remix-run/react-router/security/advisories/GHSA-8x6r-g9mw-2r78). Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Restrict network access to affected proxy services. Do not pass untrusted user input into proxy target or header configuration. Upgrade http-proxy-middleware to 3.0.7 or 4.1.1 (or later) once updated packages are available for the affected components.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2026:42085
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/index
- externalhttps://access.redhat.com/security/cve/CVE-2026-42211
- externalhttps://access.redhat.com/security/cve/CVE-2026-42342
- externalhttps://access.redhat.com/security/cve/CVE-2026-44486
- externalhttps://access.redhat.com/security/cve/CVE-2026-44487
- externalhttps://access.redhat.com/security/cve/CVE-2026-44488
- externalhttps://access.redhat.com/security/cve/CVE-2026-44492
- externalhttps://access.redhat.com/security/cve/CVE-2026-44494
- externalhttps://access.redhat.com/security/cve/CVE-2026-44496
- externalhttps://access.redhat.com/security/cve/CVE-2026-55603
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_42085.json