RHSA-2026:55900HighCVSS 7.5
Red Hat Security Advisory: Red Hat Web Terminal Operator 1.15.1 release.
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages CVE-2026-39836 — net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows
🎯 Affected products5
- Red Hat Web Terminal 1.15
- registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:2aa62ae1ab1557e538d9281fdab3ab9ae442c30066365e08681f70ecd07a7473_amd64 as a component of Red Hat Web Terminal 1.15
- registry.redhat.io/web-terminal/web-terminal-operator-bundle@sha256:bd3b4080ae43f2c74cac83031964822865d7863eb649e3b685feffe0a3d07adb_amd64 as a component of Red Hat Web Terminal 1.15
- registry.redhat.io/web-terminal/web-terminal-rhel9-operator@sha256:a0ee9d8fff411020f0d084d523a89a8b5252046050ce1445ff903a882b0e1e2f_amd64 as a component of Red Hat Web Terminal 1.15
- registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:a42283f96c6b1a77ab397e524dd40ae14bdad8abb07c958e2a7a7d6d708def13_amd64 as a component of Red Hat Web Terminal 1.15
✅ Remediation
To start using the Web Terminal Operator, install the Web Terminal Operator from OpenShift OperatorHub on OpenShift Container Platform 4.20 or higher. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:55900
- externalhttps://access.redhat.com/security/cve/CVE-2026-32283
- externalhttps://access.redhat.com/security/cve/CVE-2026-39836
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://redhat.atlassian.net/browse/WTO-437
- externalhttps://redhat.atlassian.net/browse/WTO-508
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_55900.json