Red Hat Security Advisory: Red Hat OpenShift API for Data Protection
🔗 CVE IDs covered (19)
📋 Description
CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-42306 — github.com/docker/docker: github.com/moby/moby: Moby container framework: Host file overwrite via race condition in docker cp mount setup CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin CVE-2026-53492 — github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration. CVE-2026-71235 — github.com/absmach/magistrala: Magistrala IoT Platform: Arbitrary Code Execution via Unrestricted Script Execution
🎯 Affected products46
- OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-cli-binaries-rhel9@sha256:05054881739aac3d6f7fadd2d0df6dbe0971022e86654df8d271dbf524ddd2a1_ppc64le as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-cli-binaries-rhel9@sha256:49d9060816e80f92a26704ecf09b099100a6769fb12fe8d162b296f684d5db5f_arm64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-cli-binaries-rhel9@sha256:611ec141ca5f61fc4fe6c7f74a6aca2013f89efd26f58663759285baae8cbcec_amd64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-cli-binaries-rhel9@sha256:6a21843a583d7d69ed69a5bfd02f6150ff954c90acbc1509df9cd26b9a765ff2_s390x as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:07c945f427187424cb7f343c03bc624c81446e0f61cd25caea5240ca3f74fb38_ppc64le as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:46422f786cef9ed4efe40b13af7ba568adadac903481c5f0a4a77e22cea5b74f_amd64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:e2a3c9a554fc977444bb97b2a8a33ff402b1f3ddc295d82536578c4df9eb765e_s390x as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:f603ccb3f67965797a32ab2953fb8294a7eff079d2e5dccfa38c0b4e9d3223ab_arm64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:05ac094d4e312e3ee6881ce987b4100ca2856655ff5d56fa0e0fde7bbf1ac4ea_amd64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:44b5c718cbb1e5bf0117c2576dc8c9f7d0102bd0f4c3ffe8ee0250ca651e2644_s390x as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:5c71577846878600dfce7d003068a180d3af495e89769e6685e4daf930140ea9_arm64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:b2129d4689a33a4d8a4a26973c2e6f18658bce7c1e9efb83e63fd29ec47f71a1_ppc64le as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-operator-bundle@sha256:785fe18302f9bde71d6bcbd603773991822ecc0f6a7cd30e8b933dd8fdc025c1_amd64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:0a9a1e3b737b7f01d813bb11df2aa6c6973370a1033f7c634b28857bab7f52e0_s390x as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:27f3a6fb5c6e631821ca0876d70f14e251585db68d3b660242841c529552d46a_arm64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:6261764c79f56e1f178a8b3cbb771527073d9f76e7fc38d279f90b881183cb3c_ppc64le as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:6509279b3873753948d3f9ea275829d4fb15ba6db6d527d6f8502ef747f0e51b_amd64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:1876085b7a73583343ec55ab681bda68dc919d8434b54c077132fbbcbcc952d6_ppc64le as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:9b85835c5ace2401fdbe205a8847ae7f3bd50839a98d682e9ba67d18818b855e_amd64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:bd8025908869417f6374f38f92c8b460e9d0b076a94dd5c2d20a89af2ce38bf8_s390x as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:cb49f13e711da4c2945e7656229e8f1ac92731d24cf140728ddc3bc6f06af96f_arm64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:61c0ac14cd59c749a2ab1254074b710739b7e1f42fcdd2dd3b92b9930f930f44_arm64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:82883c7618903e7ba7b9408f5e80dda19c9bdfb8f13c14b8fe94d50723da707b_s390x as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:a8b0e3a2ee5876a6047f28737c4e6bbb1397d5d9362e999f797cd57f91d3a285_amd64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:bdc1a6559fcd666677e06ee25f42d8e4817f283d35f0260aa0d237755b39d56f_ppc64le as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-legacy-aws-rhel9@sha256:07ed682cae82efe7757024a1e16a5fa46054b460e7efa8bf2ec2a39684b464e9_arm64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-legacy-aws-rhel9@sha256:9561bd529d4fad2d4fff6956432f05054b1ad8a51a7539b1e4a0fb6f18eb1328_ppc64le as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-legacy-aws-rhel9@sha256:9f816497517150c96dcf16acb6b8337d3b52d293d5e69bb3f7eeae2c7a98a8da_amd64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-legacy-aws-rhel9@sha256:d9dba07974d38a7e51d89ef64c729c00b830d065989697aed336c1562e40e8df_s390x as a component of OpenShift API for Data Protection 1.4
- +16 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path.
🔗 References (23)
- selfhttps://access.redhat.com/errata/RHSA-2026:59467
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-33811
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-42306
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/cve/CVE-2026-42508
- externalhttps://access.redhat.com/security/cve/CVE-2026-44740
- externalhttps://access.redhat.com/security/cve/CVE-2026-46595
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-53488
- externalhttps://access.redhat.com/security/cve/CVE-2026-53492
- externalhttps://access.redhat.com/security/cve/CVE-2026-71235
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/backup_and_restore/oadp-application-backup-and-restore
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_59467.json