RHSA-2026:5463HighCVSS 7.5

Red Hat Security Advisory: RHTAS 1.3.3 - Red Hat Trusted Artifact Signer Release

Published
March 23, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url

🎯 Affected products3

  • Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/rhtas-operator-bundle@sha256:32e72247b14ffbf95f4a25e0950d30d61e227d15145ca5a4a410d15c26bf454c_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/rhtas-rhel9-operator@sha256:46e034f706fdcd5f84f35a1250a064495f5f68c90fef13be9c01936904b07ed6_amd64 as a component of Red Hat Trusted Artifact Signer 1.3

✅ Remediation

Red Hat Trusted Artifact Signer simplifies cryptographic signing and verifying of software artifacts such as container images, binaries and source code changes. It is a self-managed on-premise deployment of the Sigstore project available at https://sigstore.dev Platform Engineers, Software Developers and Security Professionals may use RHTAS to ensure the integrity, transparency and assurance of their organization's software supply chain. For details on using the operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/index Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

🔗 References (6)