Red Hat Security Advisory: Red Hat OpenShift GitOps v1.19.6 security update
🔗 CVE IDs covered (11)
📋 Description
CVE-2026-15416 — argo-cd: Argo CD unauthenticated remote code execution in repo-server via GenerateManifest gRPC endpoint CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-39836 — net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
🎯 Affected products46
- Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:2d046fc4a4abd29189af3a8d01eeb9ba38261fa30cb5adfdeac54f5fa5cb5305_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:c678a84165a60596f4aba9aee51f6437e6465e0af47e7562b06b0d8f5a1bf8a9_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:d222a8cb9c2f33c7741d1b9695acd558a24a15c3a80adb1d54605c910237ceda_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:f6167de02c0403131881e30296edb45e6aa711a414da2de623c3bf6d9c731e6d_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:330ead58ecce72175ce2c34f207e80755783a0534cb2a8e94bd15ee5cf92511d_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:5947a59783b905502b66af07befb19ab6fab4be99714dbedd7149e97096db4e0_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:7e964c76f80bcccf684e9623f5b4d97413f4b590a905c4e5253a784b22af50ac_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:b6a0c02b0c2578ba9013ce3fa39e8f24bca8a23fca5dead02492c53bdee6f3de_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:5ad703c24f73e3da315399f8e5fd563c5b618a22db136859cf23aa44a000dac3_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:765743affc37903b9bae5f5fac16fe020e1308945cb888ab8e72bff909bd6705_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:7ad9db84580d10f4d360f5e638e881a1313da9a4a451196c8ba0dcb3286fd76b_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:7fd4f18969029ebd021e29589b1a540cab6f27ab0db0149bae64a81312799566_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:20e60ecb2be26acaa621f12bb375f57ce26287773d9861f72c2c634927712f39_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:af9890aa8a5d4d983740b3417c6968bb81532223a87b1502a6b272378b68b942_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:e9ad4a36bf18dfffefcc27dce89334cf0cc306f4eb0a6c53c3d5bc3c6393d7ea_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:ec656dfd54812c4ed207d20b25fdade5ea420940ebc23c42c32a76be12d4b301_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:388eb549053f8d18a1ea3487ad0c3ff9058f1e47e6f54cdaadee26806b9b3b78_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:3b1b3795a7a9a69902021c9b759394f6beeeb9c38eef8330469d501e4b9cae42_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:ca23d643694d9e47a1108f8ad0cee0eebb086f2e4bbbd513882bfc48919c1895_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:f222617d567faca6eb1419f4e83fdac19fc243aec1781ae32a692ac09440fb55_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:575d88f67f65fcf1f50162b6e61665b2135d745206b8e13f4865f666feaa8262_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:6686d4a4703ad5d2fb2b5868817f556b72b26025f3e6ec96a8882a38e350ff89_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:a579d5894ccf8eb5e5fde8886d4147bac2a76497a5cba413d1a2edc7611d1150_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:b48e180aa536afb9bbde682789067039407ac3bd90e05652f19fe8471837f86b_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:007fcc54a14a82969d44e7a8cae7f4ed43242de5969dba6f09d5e099da874dc8_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:10ec7bba4c958ed31fb82a4fbbf7fa92bc375655b2548b3d660ff793a7b0a9f4_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:3b58275492956e95561564c4e7ab86138bb5745176a09e0ba36aca324108112e_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:4d0f91e941a2c80fd77dd420582b6dd1fdce7f8a0cb2f04e6fb86166cc5db92c_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:327e2bff158f9f1b12f4310652f8617359632a577f1e0b723979fa899638ed36_amd64 as a component of Red Hat OpenShift GitOps 1.19
- +16 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Limit network access to the Argo CD repo-server gRPC endpoint to trusted internal components using Kubernetes NetworkPolicy or equivalent network access controls. Do not expose the repo-server outside the cluster or to untrusted networks. Restrict access to the associated Redis service and update to a fixed version once one becomes available. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2026:52857
- externalhttps://access.redhat.com/security/cve/CVE-2026-15416
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-39832
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-39836
- externalhttps://access.redhat.com/security/cve/CVE-2026-42508
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_gitops/1.19/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_52857.json