RHSA-2026:50910HighCVSS 8.1

Red Hat Security Advisory: RHTAS 1.4.3 - Tech Preview Release Of the Go based Model Transparency CLI

Published
August 5, 2026
Last Modified
August 13, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs

🎯 Affected products5

  • Red Hat Trusted Artifact Signer 1.4
  • registry.redhat.io/rhtas/model-transparency-cli-rhel9@sha256:09bc4e06c612f0d6e11874a2255d22f945b2ac064aceca12bb4afd44e27a075f_ppc64le as a component of Red Hat Trusted Artifact Signer 1.4
  • registry.redhat.io/rhtas/model-transparency-cli-rhel9@sha256:223d49545c116bce2a9622c9c50be27a123c493581c9e324c1966c6b615dbea7_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
  • registry.redhat.io/rhtas/model-transparency-cli-rhel9@sha256:5369aaa0b050bf80c17eb43dba4e3fb1004e31205db8735f10ae9c3761a3af91_s390x as a component of Red Hat Trusted Artifact Signer 1.4
  • registry.redhat.io/rhtas/model-transparency-cli-rhel9@sha256:bf0daf4e60fab5ced2764dc37c5c14291984a7f1f7c8b9605791b22be19d3be1_arm64 as a component of Red Hat Trusted Artifact Signer 1.4

✅ Remediation

The Model Transparency CLI Image is a containerized command-line tool for signing and verifying AI/ML workloads against a private Red Hat Trusted Artifact Signer (RHTAS) instance. It lets teams create signatures and attestations for model artifacts and validate them at build or deploy time using enterprise trust material (e.g., Fulcio/Rekor). For details on using the Model Transparency CLI image, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (6)