Red Hat Security Advisory: Red Hat OpenShift Workload Availability Operator v0.13.1 security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing
🎯 Affected products6
- Red Hat OpenShift Workload Availability 0.13
- registry.redhat.io/workload-availability/self-node-remediation-operator-bundle@sha256:b6ff2ce15359c7ccda7f9fdfa5500d7f01ce240ae9701de5625c31899872ca99_amd64 as a component of Red Hat OpenShift Workload Availability 0.13
- registry.redhat.io/workload-availability/self-node-remediation-rhel9-operator@sha256:07593c5d721545ec74310851bdeb5eb050336273a1164fc452fbc526edd4f5b0_amd64 as a component of Red Hat OpenShift Workload Availability 0.13
- registry.redhat.io/workload-availability/self-node-remediation-rhel9-operator@sha256:117992cdf46fc18f6d50b2fde0d8bdf6b711642242c3c37cca6f548e88f3805d_s390x as a component of Red Hat OpenShift Workload Availability 0.13
- registry.redhat.io/workload-availability/self-node-remediation-rhel9-operator@sha256:705512633725cde8afe513597b30acee051db00bf510475b70cf9f312a2a85e7_arm64 as a component of Red Hat OpenShift Workload Availability 0.13
- registry.redhat.io/workload-availability/self-node-remediation-rhel9-operator@sha256:87b7964f08cad9e9e475a2f095c85d08894bcc4fc20203924bcaa933385b34cf_ppc64le as a component of Red Hat OpenShift Workload Availability 0.13
✅ Remediation
For more information on the RHWA 4.22-0 release, see https://docs.redhat.com/en/documentation/workload_availability_for_red_hat_openshift/4.22-0 Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:54284
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-33811
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54284.json