RHSA-2026:63139HighCVSS 7.5
Red Hat Security Advisory: Red Hat OpenShift GitOps v1.19.7 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header
🎯 Affected products46
- Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:16375c745ab1a94c9421a956a85ddb4f7965ec3d3a10889a18ae7279c4d2ffb4_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:3343941b20322363cc197972dcc21382b37d634d082bba6c4556e149f0439932_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:a4bfca07484f4296b329baaa37a9fcfa77c1b1e20ee2ff08a1847219073f715f_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:eb4ccd97dd3d2b8db6b17ad24d58e8ad3d6a6a9e04a298f01335d5ae8c2eab8b_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:39e3e78093e3a5685f0366538be764ddf71f14d41519c748e66d4cb0b5490c00_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:57c6d1dee910c0532afb0a8ab99cf7e177f5e0c734c632b6505bce2730f7926c_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:60131608cd7ce95fa274dd6c52470f236964de3e1bf105e0c957cff023a87f0a_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:639d5bb7af81d78e2a4432deea64a8e4c47560269d3fb20ec57ee6a14257379a_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:13845bfd78f44cb81f80718913f2885bef0ce0acc08b79b8d7d9f9d371ed439d_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:7015085befd66e3f03927b37d63107b88e3db01319759fb5fa0dd74427df1285_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:cab30343a7cb2d32c26df5a826aadfe504623ae79505e5dd867c9099b6a02c3c_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:cfa1de08a64b1db1062f1eae6c4855e9519aa41b95a6791d4d0ddec0a717f1bf_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:3d42c9f73bc5781e8dc930c2cdc7953ecf620ff6f7bc2ba120996c3511a31e67_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:8cb2395d0d5b6f430b880727517bedf4b5c8471f56941a1b4128fc1334151d89_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:ad1f873a9c2b927dae9fc9e3b7b4248ea44348bd369c65da9e100623173175dc_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:b00bcd0f9d74457799a946a3299fae11923ef8053c56ebcd4b704d7b91294a6f_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:20e0ff54213a4c91cb8d96e5fb09225a17a16de18badcafdd8669c03c1a88606_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:8b27c725931eb0cd9f0af22a8d71ad627dc9efbf8c3c2b640389286385bbdb52_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:b02520ce147855c753bc0d8a8c329313f59e0a52dba8c3816f9b215236a7fd8c_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:ffb08b649d0bf2fcd3cf3096b5d0ab6e577da4ff619f3d48e7d7ec6ffa482c23_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:39e3dcd1afc1ee3a24b60d10cb9aa11abc3926681d8cedc99dba0410ef6d7657_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:51fa8195acf54f8f71cc8fc4da6d7b25b5fe88deef28b45ae2c703fc29e104fc_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:54aefdef3a1b89f20782ce0395a832b40a75b5e566a0f0220ce0c1c7cd40dde0_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:9e6825260086271d6b579f1b7f3b5f8d042ada52d750546a1121fe812f644ce6_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:279591871701fcfac9406a950f2026b8433cc6ae8c0c7c87e723a5a9ebf66646_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:9255616092c986b5229f0441b50b0eaa9070afbab24280e9305d923cd73a1922_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:9da2bf2ad1e5bc601ae6e1cd3b8487e7f43f3459aee9f6225d9d0ab83ba38500_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:cb9b6584c552f058d10ff07d8d4d267e90660fcabfede412f65619092a5dbe38_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:b275e3b06b08a07d9433903162fe949a7ecfdd5e73dc67e3a2ce2f20520bc20e_s390x as a component of Red Hat OpenShift GitOps 1.19
- +16 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:63139
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_gitops/1.19/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_63139.json