Red Hat Security Advisory: Red Hat OpenShift GitOps v1.20.6 security update
🔗 CVE IDs covered (9)
📋 Description
CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
🎯 Affected products42
- Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:00ab3f1c310b9d271fcd443b55ac584b16eed918110248ca93ea70f31f920dd3_s390x as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:5dc131c6cfa2c3b51b413dca51f29c78a0a50ec5f4a60bad0dcaca7285f03e72_arm64 as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:8460e8fd3aa1782cea6f7dafffdc0ce905e35b5d2031f800fc1421e9058a8b81_ppc64le as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:e13198a63c267ab7e4447218a5b071a4d64d7828e3c19825642b690fdd924a12_amd64 as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:14a01615cea9153eae529bfee5f0d62d8f0df78e222217bc3c0e885512001f18_ppc64le as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:559599a66ad79ac5cd0f45fcc36535cc5a44e294dc7f19a389ac1a85842c15f3_s390x as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:5dd26d91dea4e8f12914d649854544e93ced87ef9d31aa85d837cbc7dde71fd3_arm64 as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:e28b5f43144ec00d70c9783df0746137528ed5c31119cc3d0efe79e7d610caf4_amd64 as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:1a0fa9305c51cc018e30db541f7d9eae8a7149f9ad1fe54de3f1fa13b5a31c07_amd64 as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:44ea2bef7f926cfc75c8e97de4b75208f04aea7b2ef50d1f553e5f28790d8235_ppc64le as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:880eb37b3450547fd3f83ab720f04f420c1927c0ec9cb988d567a92929d854d9_arm64 as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:fc68588a2cf7c68f11f5381530c9046ee96ed7ff40f0458110df21882b7e3666_s390x as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:37c88231b75ed84457dbef520c16586e2bd250062956cb03b75e9c7d574445ab_ppc64le as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:539f9f95ebc0f32b3645548fd94abb087dad391fe5182a715b21c85e2231ccf5_arm64 as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:e0757f600f0572473524382a3b581bd454d740228f36a88aba81dd8fbe46021c_s390x as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:f3a697acdc090650bc9cd5bbb85314bced2a9f3ab8d463839406a28c8713a4f0_amd64 as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:5e5c98b183a483d24356930e6ed8561f6c1731e9cb495021c1be080554cfdd54_arm64 as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:70aad197929ddb3d4b7f0ac3ce450652b8b3f23a5633115b855b83f6994a433c_s390x as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:857c25929f02dcdb5efdfca6a44270aa59279ee00fc0d1e844ffcaed9494e5ff_amd64 as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:f538166c509e824680dae0beae52f3fb2952da9ced6e57a365f49f7f4ca1ee0e_ppc64le as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:120b87848c99a28d4bc3bcc2bdae93f591928d916c211d606fc1c9e1dc19f18f_arm64 as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:244f8fbe5ec80a4a250091ffbcdb1bf306af18fdea6244e8f6f49f0a44e80264_s390x as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:31aa77b980ca80dd04d20688808feb2e5eb5d21f4c128004dc721a9ddaacb73a_amd64 as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:42b3a7e88b81bce3445885d6005305728495a67ae9f01ce3ce83094706f61d67_ppc64le as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:3acfbdb97f1e3d88363393f95e1a4cc20741267d16c33010b0dc598321d0531e_s390x as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:6deca0a6dc84212f857860f578609615be187789a807d75c14adcaf29a9477bc_ppc64le as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:8a1dd18f2ff4b02cc9510e3585b6fc01744f55ede6842a8467b9f3dbe8f3bcba_amd64 as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:e0232cf48a552cc2f58cbb0539c0cd2c97410238f1a89b947bf5157d32d69b15_arm64 as a component of Red Hat OpenShift GitOps 1.2
- registry.redhat.io/openshift-gitops-1/gitops-operator-bundle@sha256:0aea43abfd0702c07cf70541bc46fe742b0742c9f43641134e2163eaca8f4b5c_amd64 as a component of Red Hat OpenShift GitOps 1.2
- +12 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2026:52910
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-39832
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-42508
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_gitops/1.20/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_52910.json