Red Hat Security Advisory: Red Hat OpenShift GitOps v1.21.4 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
🎯 Affected products42
- Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:4c59626880586824b3d90231ac09ffb5a85897f405a575e0b102c28597a59f57_arm64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:74b2f0104ce1214d4447cbe9ede3dafadbd68ed7065b45f303329320ac7b759a_amd64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:bc8925bf15e08de75529f035e323758f92226f15fa0773a341c3c780a2627e41_ppc64le as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:c40ad7dd9d066ad66b176df22cddfd402beaca3755e60cfc1425d93af0b7d9a6_s390x as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:3789bbdd43fab8849dfacd3d8939537a266c1f2ea6860a7a306c06bb0e906d14_arm64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:6fd3a3ede21e5fdc0c97efac84ea3ec9afa6bd4fac110e2b2104b2ecb688ad4e_amd64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:df1c7c67545a60ed6055f18f445f68d33bf0b3f9aa94a6d1a2403b9a2ee5866e_s390x as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:eb5ccbb531eafd37aeb42e13d6e1917264588171f4d12d49569bc8cba5b3dacf_ppc64le as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:0ba721897bc5a4e076b02d5693bea29eca9a2be60b44dbdf932c5bc473df6052_s390x as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:aa2cda6c28226806411d8ebd93e775c6e665ad1040b53cd0839fb5b4ef9f87ea_arm64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:e791933d511b5ed4c8138d0628732bb5d33898b847dc37013accf92246e9cbe6_ppc64le as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:f7da4ffbe6916f550eeabc69756aa716053c7458f01c5dc62719a091240e13e3_amd64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:342cc001fc9cb52f3d47a4b6a6a284d9820d9c4bed09338bd477f8da77df78e1_arm64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:8c338d9d4216f05e127a841edc44f39480a739db0d4f5412c146a2aaec341c36_s390x as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:d4efa37d5ee4ab3c61c079f8be32f1477a34cedc2ace6c01777ec89b0652d53d_amd64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:e48d3564eae6200891ebf19528521ff88ace15b74ad615010add7ecb38c41113_ppc64le as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:569c756cd88e5e6bc460b98694f2103d65fe7d8219abf0cba3f1c8d2abc9476b_amd64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:954bc32992ba8c2c6e0323e8069f0805c148df3b2bbe333d11bed2d232c28e93_arm64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:a828c5ca4c962ea86e39a33441d9b8a8045b12b2ec4c368fc94f66551222d2e6_ppc64le as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:f81370e7f14e88273a7b8cf678f06838f9524bcf5309521b908edadad0e43957_s390x as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:63a4b1ddc6a45e23627d6a78bad142ac47d425edd815da9bde72e6f4af4a0ec0_amd64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:8f5bf98900dc97d0f39f8a6426124ed5db27a0b82bef62a0708f2a8345b65e37_arm64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:aa4bf40eda4bd37046ca33b3d8b0a421790d6227a46d0f876f6e0815ec07642a_ppc64le as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:f0a24f5678bca16a58147b854d8748fdc767d8c66dd9d5db0f26a8181661804b_s390x as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:478bb23dd35bd224edfb313f6997db808bad75aca2de48d58b082e5d2b3604ab_arm64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:6347e35e2242361d51e10d1fac42915b1ba71300de2c49c2b74cf84f8fee80a6_amd64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:dcee8a0d5ece080e04714af98f2fd6ecfb245abd6ef47ead9bbb49095a25f591_ppc64le as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:e2d71c14897b8291580c4d37c080d66a8064a0666d737ea7028715f11b493069_s390x as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/gitops-operator-bundle@sha256:695edcad731d569be85ec95461f7466a5d2c1201a80c30bacba90ebf2d5b777b_amd64 as a component of Red Hat OpenShift GitOps 1.21
- +12 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:63142
- externalhttps://access.redhat.com/security/cve/CVE-2026-44740
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_gitops/1.21/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_63142.json