RHSA-2026:55903HighCVSS 7.5

Red Hat Security Advisory: Red Hat Web Terminal Operator 1.14.0 release.

Published
August 18, 2026
Last Modified
August 23, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages CVE-2026-39836 — net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows

🎯 Affected products5

  • Red Hat Web Terminal 1.14
  • registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:df20e285fc92d28cc6ea46fdd40c7ad51f4ed4a8f3b6379e9685db448a2dd2bb_amd64 as a component of Red Hat Web Terminal 1.14
  • registry.redhat.io/web-terminal/web-terminal-operator-bundle@sha256:4738078b0ac638ac346b5363e4653901d967f213c3e2ed787d3ced2fd81408c9_amd64 as a component of Red Hat Web Terminal 1.14
  • registry.redhat.io/web-terminal/web-terminal-rhel9-operator@sha256:852f110540d3e7d7ac7c5134d41f4a85268a7e0e880952da9a79900d605133f0_amd64 as a component of Red Hat Web Terminal 1.14
  • registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:5ad495a8457b56d64d931f7dc135783d33def1cc76363e03c9e1d0f3f9b5627d_amd64 as a component of Red Hat Web Terminal 1.14

✅ Remediation

To start using the Web Terminal Operator, install the Web Terminal Operator from OpenShift OperatorHub on OpenShift Container Platform 4.19 or higher. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (7)