RHSA-2026:55901HighCVSS 7.5
Red Hat Security Advisory: Red Hat Web Terminal Operator 1.11.1 release.
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages CVE-2026-39836 — net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows
🎯 Affected products5
- Red Hat Web Terminal 1.11
- registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:e4c3cde853eb0f6116ca1d892778ef1e4337b7be740839e6fa530cb5ea3b2380_amd64 as a component of Red Hat Web Terminal 1.11
- registry.redhat.io/web-terminal/web-terminal-operator-bundle@sha256:220f35a9902489841951c5670a1ba5d77699d497881161344946740c8cb20533_amd64 as a component of Red Hat Web Terminal 1.11
- registry.redhat.io/web-terminal/web-terminal-rhel9-operator@sha256:62369b6dc976767a9de9cb80b3aba9f1d8c9fb3028350c8c07e1311d85bf70e7_amd64 as a component of Red Hat Web Terminal 1.11
- registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:b0e5de3998a4a97d24a5304d919ca18249b87533219551c7b1816b283e4d1a65_amd64 as a component of Red Hat Web Terminal 1.11
✅ Remediation
To start using the Web Terminal Operator, install the Web Terminal Operator from OpenShift OperatorHub on OpenShift Container Platform 4.16 or higher. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:55901
- externalhttps://access.redhat.com/security/cve/CVE-2026-32283
- externalhttps://access.redhat.com/security/cve/CVE-2026-39836
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://redhat.atlassian.net/browse/WTO-442
- externalhttps://redhat.atlassian.net/browse/WTO-504
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_55901.json