Red Hat Security Advisory: RHTAS 1.3.2 - Red Hat Trusted Artifact Signer Release
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2026-27606 — rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability
🎯 Affected products3
- Red Hat Trusted Artifact Signer 1.3
- registry.redhat.io/rhtas/rhtas-console-rhel9@sha256:7f9dcc3503ef31563733eb925c6c15ce0d945069f1369692456c49361c60a399_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
- registry.redhat.io/rhtas/rhtas-console-ui-rhel9@sha256:d23bf73126fb5c18ff24369bb05c7adb03e9f3fefdbb49795b8aeb3d7c223cdb_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
✅ Remediation
Red Hat Trusted Artifact Signer simplifies cryptographic signing and verifying of software artifacts such as container images, binaries and source code changes. It is a self-managed on-premise deployment of the Sigstore project available at https://sigstore.dev Platform Engineers, Software Developers and Security Professionals may use RHTAS to ensure the integrity, transparency and assurance of their organization's software supply chain. For details on using the operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/index Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate the risk of arbitrary file writes and remote code execution, ensure that build processes utilizing the Rollup module bundler are executed within a strictly controlled and isolated environment, such as a container with minimal privileges. Restrict the file system permissions of the user or service account running Rollup to only the directories absolutely necessary for its operation. Additionally, rigorously validate all inputs, including CLI arguments, manual chunk aliases, and third-party plugins, to prevent the introduction of malicious path traversal sequences.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:5649
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/index
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2026-27606
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_5649.json