RHSA-2026:55902HighCVSS 7.5
Red Hat Security Advisory: Red Hat Web Terminal Operator 1.13.0 release.
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages CVE-2026-39836 — net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows
🎯 Affected products5
- Red Hat Web Terminal 1.13
- registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:b69058544e1a8592ef16ccff88ee9ed573c4a5e47cd888806649a742490f6091_amd64 as a component of Red Hat Web Terminal 1.13
- registry.redhat.io/web-terminal/web-terminal-operator-bundle@sha256:7d6d7e84afe53fc61d4445cfb9cfd3f1b2b4a9976f2e3cff338e830112f37ae1_amd64 as a component of Red Hat Web Terminal 1.13
- registry.redhat.io/web-terminal/web-terminal-rhel9-operator@sha256:fcac84e1114d5994328e808edad7ddcf9229b007121fff6062032e1d382053fa_amd64 as a component of Red Hat Web Terminal 1.13
- registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:6fc2767a1608c3bee67a3dbfe9c2a206c56bed3c0a1a98cab4df35d784c455e6_amd64 as a component of Red Hat Web Terminal 1.13
✅ Remediation
To start using the Web Terminal Operator, install the Web Terminal Operator from OpenShift OperatorHub on OpenShift Container Platform 4.18 or higher. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:55902
- externalhttps://access.redhat.com/security/cve/CVE-2026-32283
- externalhttps://access.redhat.com/security/cve/CVE-2026-39836
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://redhat.atlassian.net/browse/WTO-440
- externalhttps://redhat.atlassian.net/browse/WTO-506
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_55902.json