RHSA-2026:55898HighCVSS 7.5

Red Hat Security Advisory: Red Hat Web Terminal Operator 1.12.1 release.

Published
August 18, 2026
Last Modified
August 23, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages CVE-2026-39836 — net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows

🎯 Affected products5

  • Red Hat Web Terminal 1.12
  • registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:2fbac1ddd75833f997cb864dd28fd639446ba243cdaf2dbe8df39f6e0e960c95_amd64 as a component of Red Hat Web Terminal 1.12
  • registry.redhat.io/web-terminal/web-terminal-operator-bundle@sha256:2d3c389629fc5883bd71a9ce74846995d846cba41cc5407d930f993fd88226c9_amd64 as a component of Red Hat Web Terminal 1.12
  • registry.redhat.io/web-terminal/web-terminal-rhel9-operator@sha256:db4ae6558120c65d6669fb8865c4b6631f4555ca65a6914cc365b2addd07aa16_amd64 as a component of Red Hat Web Terminal 1.12
  • registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:a5c68396c51ea804a4d47a4ed7840be3783882544aa6544fd4ec61f0666c1a55_amd64 as a component of Red Hat Web Terminal 1.12

✅ Remediation

To start using the Web Terminal Operator, install the Web Terminal Operator from OpenShift OperatorHub on OpenShift Container Platform 4.17 or higher. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (7)