Red Hat Security Advisory: RHTAS 1.4 - GA Release of Model Transparency 1.0.3
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens CVE-2026-59886 — pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values
🎯 Affected products3
- Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/model-transparency-rhel9@sha256:997111359afd34ae4f5e27ac9e883182e0438f7ddcfc4f829d05b79ac5c468ab_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/model-transparency-rhel9@sha256:e0f2fe8d94dbe653218403f633691887fdbd7b651f15c74a3ec909bae2c309e6_arm64 as a component of Red Hat Trusted Artifact Signer 1.4
✅ Remediation
The Model Transparency CLI Image is a containerized command-line tool for signing and verifying AI/ML workloads against a private Red Hat Trusted Artifact Signer (RHTAS) instance. It lets teams create signatures and attestations for model artifacts and validate them at build or deploy time using enterprise trust material (e.g., Fulcio/Rekor). For details on using the Model Transparency CLI image, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4/html-single/release_notes/index Workaround: When processing untrusted ASN.1 data with pyasn1, avoid calling prettyPrint(), str(), float(), int(), or performing comparisons or arithmetic on decoded Real (ASN.1 REAL type) objects. Instead, inspect the raw (mantissa, base, exponent) tuple directly. Where logging decoded ASN.1 structures is necessary, filter out or sanitize Real-typed values before conversion.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:50904
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4/html-single/release_notes/index
- externalhttps://access.redhat.com/security/cve/CVE-2026-48526
- externalhttps://access.redhat.com/security/cve/CVE-2026-59886
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_50904.json