RHSA-2026:5459HighCVSS 7.5

Red Hat Security Advisory: RHTAS 1.3.3 - Red Hat Trusted Artifact Signer Release

Published
March 23, 2026
Last Modified
August 22, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2025-66471 — urllib3: urllib3 Streaming API improperly handles highly compressed data CVE-2026-3336 — aws-lc: aws-lc: Certificate validation bypass via improper handling of PKCS7 objects CVE-2026-3338 — aws-lc: AWS-LC: Signature bypass due to improper validation in PKCS7_verify() CVE-2026-21441 — urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) CVE-2026-31812 — quinn-proto: quinn-proto: Denial of Service via crafted QUIC Initial packet

🎯 Affected products3

  • Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/tuffer-rhel9@sha256:f30c3610c1c840ea8edb99c2679edb09768c45012979da1389605c6a54204292_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/tuftool-rhel9@sha256:cc2676a9d70599503faf8ca413e7bbc29cd523782a3d1e81bfc8f9e6323b4a28_amd64 as a component of Red Hat Trusted Artifact Signer 1.3

✅ Remediation

Red Hat Trusted Artifact Signer simplifies cryptographic signing and verifying of software artifacts such as container images, binaries and source code changes. It is a self-managed on-premise deployment of the Sigstore project available at https://sigstore.dev Platform Engineers, Software Developers and Security Professionals may use RHTAS to ensure the integrity, transparency and assurance of their organization's software supply chain. For details on using the operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/index Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (10)