Red Hat Security Advisory: OpenShift File Integrity Operator bug fix and enhancement update
🔗 CVE IDs covered (6)
📋 Description
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-32282 — golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering
🎯 Affected products5
- Compliance Operator 1
- registry.redhat.io/compliance/openshift-file-integrity-operator-bundle@sha256:c38526d3744cb4f6b2487656c617a8bf40dd996d6e8ad903aa75a69050e290c8_amd64 as a component of Compliance Operator 1
- registry.redhat.io/compliance/openshift-file-integrity-rhel8-operator@sha256:25da62811e1ea81c6a39469173d9e2be2393f825dae053b77b137a2eca2e2b76_s390x as a component of Compliance Operator 1
- registry.redhat.io/compliance/openshift-file-integrity-rhel8-operator@sha256:ad5f1c38a11e4164c26775e62d67b9361d798c93d0441f7f5f51605b2d140135_amd64 as a component of Compliance Operator 1
- registry.redhat.io/compliance/openshift-file-integrity-rhel8-operator@sha256:ceae8d1964727c09992eb9d353f7014bfb151f143b1ab04798d3d061f8a84e9f_ppc64le as a component of Compliance Operator 1
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.openshift.com/container-platform/latest/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:54288
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-32281
- externalhttps://access.redhat.com/security/cve/CVE-2026-32282
- externalhttps://access.redhat.com/security/cve/CVE-2026-42151
- externalhttps://access.redhat.com/security/cve/CVE-2026-42154
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54288.json