Red Hat Security Advisory: RHTAS 1.3.2 - Tech Preview Release Of the Model Validation Operator
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate
🎯 Affected products3
- Red Hat Trusted Artifact Signer 1.3
- registry.redhat.io/rhtas/model-validation-operator-bundle@sha256:8471c015335f643ecd982a5afd1d54d257d05941e7411a2f3df08d8dd0a0e7e5_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
- registry.redhat.io/rhtas/model-validation-rhel9-operator@sha256:6567a87975df684dd6bf5ad25d27d1b1c406e00eafd5a23ba442fa791194a4e2_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
✅ Remediation
The Model Validation Operator is a Go-based Kubernetes operator for OpenShift that validates AI/ML models and their signatures at pod runtime. It verifies signatures on model and container artifacts before workloads are allowed to run. Platform Engineers, ML practitioners, and Security teams use it to ensure only trusted, compliant models execute on OCP clusters, in both connected and disconnected environments. For details on using the RHTAS Model Validation Operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/index Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:4276
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/index
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_4276.json