RHSA-2026:63141HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift GitOps v1.20.7 security update

Published
September 3, 2026
Last Modified
September 3, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header

🎯 Affected products42

  • Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:38cdbf64b8daa06edd8b2a0c3b37b025a9c84903ca273ed9b9d6812a437c2850_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:588d6a9d770a4837d80a858cbcf259621044193d94093915174661bac67c76f2_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:d3c29ca88ac664d86db0e8ee978034d1e972d1035d4970f3e82e4de7c114ff9b_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:fdb951e3fea4ab3bfecead3bf4eb51cb8855f0b57f417e476167eb52be0ad34c_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:1988aea17921397e70a34cbc328603fecb58f164857799602f720d5b3c95ee2a_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:d536d8a47f2ed03502b883c47e7bd5ef15cd428148707e50af3ffcc26ced70f0_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:f05bef3e906d7a17871eb6381cb2e12748d56cfb42e93514c76be4ca6e5fad89_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:f739e41efecb0ab489490276341ae2a2a90793fe120be66f4b2be7c44d875843_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:8bf2187e9c0f15f8aae94e96a73fcad54e92502ba6ab3657393b9ee7fca5228e_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:bc4e4d6425eadd569b0695e1ffb9e69644f736339b4cfe46d018db9dde0f0dcd_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:c220b4af4c808100d17070cf3798dd4795b0b14d7b46d5f13f266651eed36813_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:ddabe81568743878f631ec1aee9d2828533fbe0a13395847cb3b47d3f68753bd_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:02209861d396216a44fbfce93306bd6a4f227c881c782f9c4c799578f9a365ac_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:3e4559e3103a5f1675459c7e6daa5b69a18206d9be2011f803306704d639c41b_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:fcb439056e4812e3b400635b44cde81c59fb54d78ed92377a8aee1b058a552e0_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:ffc3b6f7b770ce40f32c5ef8895ed1f37ba68d56cc24cd9cd24aa41a7f83fb7f_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:046a1d865e3cf4d1867f4bf1443249830a6d7141a1189fc5e87d483f02481bb2_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:68627bb67acb939429c0f0e806bb4aa4cd8fe72c467e1b7c10022b62b4ab4670_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:dc39a9fde468701e0303f26f54c6cc76b922dd038e39db5a3761d20fd36cb803_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:ea527e4330e042cc07a3eefd04c976bcf00d5518ac4fe6ff11fb7920319936b3_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:863e3c5cb738d6b8a3c11656ff26f25a52bca98ae28b1b68d76f393923bc46fe_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:9fec423e3fe6b1608c7011d657eaa6d3c67c2fd92ca7d9034e886e6d44ce9928_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:ceabf9f79afe653e71e279f974cfd02390411344cf37a87a0e600ac62ab0fc79_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:f6f4775938de366bd4143c00b92d43121a36ce3c997729ebe7ac963eda2eb185_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:4c9e00ebb92f6a5749f83cfd3b9a33aba16e717a3f33ff0da6cf5ef0cb42f4c1_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:b31b21638ca0f47dba01fa624c30143fa9e341534ced47d4fb33fdb4ec7ceb92_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:c38f980401b47ba560659962fc5a4629947987fbae1cb9ca02d8af2f7e15ed1d_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:ee2976bc10447aa2560b57c0e43a40590725ce25793ae2794ca14aaf79607652_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/gitops-operator-bundle@sha256:8d6bde9550ba17422972bf7c7f244e3504b9ec112d6aa664b2d123a8dc2fed13_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • +12 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package.

🔗 References (5)