RHSA-2026:50874HighCVSS 7.5

Red Hat Security Advisory: RHTAS 1.4.3 - Red Hat Trusted Artifact Signer Release

Published
August 5, 2026
Last Modified
August 6, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API

🎯 Affected products5

  • Red Hat Trusted Artifact Signer 1.4
  • registry.redhat.io/rhtas/createtree-rhel9@sha256:4425002ad8b0a88bf0b276798b489fd2eb27937bfd1fee8cb30faa5e7436e4bc_ppc64le as a component of Red Hat Trusted Artifact Signer 1.4
  • registry.redhat.io/rhtas/createtree-rhel9@sha256:67ffc065718d8937fd5763b712f89f2c720e3b6936852e8360e395bfea49c28a_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
  • registry.redhat.io/rhtas/createtree-rhel9@sha256:da3b159bde293bb7f19ec0a29405e58c4cd708abadddd017487ebe919979830c_arm64 as a component of Red Hat Trusted Artifact Signer 1.4
  • registry.redhat.io/rhtas/createtree-rhel9@sha256:f159e250d6d60eb672f9ce0ad46fc97e35bd0e9bc7e24530ff1efc64979e80f9_s390x as a component of Red Hat Trusted Artifact Signer 1.4

✅ Remediation

Red Hat Trusted Artifact Signer simplifies cryptographic signing and verifying of software artifacts such as container images, binaries and source code changes. It is a self-managed on-premise deployment of the Sigstore project available at https://sigstore.dev Platform Engineers, Software Developers and Security Professionals may use RHTAS to ensure the integrity, transparency and assurance of their organization's software supply chain. For details on using the operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4/html-single/release_notes/index

🔗 References (6)