Red Hat Security Advisory: Red Hat OpenShift API for Data Protection
🔗 CVE IDs covered (33)
📋 Description
CVE-2026-15792 — github.com/moby/buildkit: BuildKit: Denial of Service via malicious client request CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39833 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin CVE-2026-53492 — github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration. CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-71235 — github.com/absmach/magistrala: Magistrala IoT Platform: Arbitrary Code Execution via Unrestricted Script Execution CVE-2026-75593 — github.com/moby/buildkit: BuildKit: File escape vulnerability allows unauthorized file modification
🎯 Affected products50
- OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-cli-binaries-rhel9@sha256:86b2b917fa9e60362acef43cd2710e17ab3fce4f1a1264f2457dd0a549a19e3d_arm64 as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-cli-binaries-rhel9@sha256:bfe2b3f1eb23812e5ea190aa5e308b14050c4b92636bbdc510e5dcd0664e8c8c_ppc64le as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-cli-binaries-rhel9@sha256:c9086940a41eb912f5e6f1527d787421744a3d3e0f6958616f183e7b8e6109cb_s390x as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-cli-binaries-rhel9@sha256:e495d40f9da17b8566c49e7121cfbb4fd4b79408afc1fc04cfea3e56378b9ea7_amd64 as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-hypershift-velero-plugin-rhel9@sha256:1aea1f487b7caf2f6c102afc7a80edda1738d05f5c41f7d66a6e91ca7b92c6dc_arm64 as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-hypershift-velero-plugin-rhel9@sha256:adc739841238fe4054bcfebbd4fef833684fa7d703fc10f1ab8791796a1e0baa_ppc64le as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-hypershift-velero-plugin-rhel9@sha256:b7105a4da85893ae5b2869e475d2ee17a54ba06c316d8f24143b8fbf67c3b87f_amd64 as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-hypershift-velero-plugin-rhel9@sha256:f3354f5ebb22d2efb209da7935f6245b06f354cc0a246beae07067dfd568aa80_s390x as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:0e36cf8d11f557fda21e66dfb596a27126d78864671f852b567ba9657fc5f3c0_s390x as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:678abccd66e9574a8b3bb333bf93b6179a3b95ab2ef465008907453eeecfee32_arm64 as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:87b1ae0dc54b6ce5f1db04d82afe47b4fc9a895df5d453ca1579ae7142f82dfa_ppc64le as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:9308951a40603e841f93e1126e3ff1dee92c0102ea19aeb3f594605861c66b8d_amd64 as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:1c737c4d68f7d2f053aa52e28cd5a4af40d8eeb766f1d70d751ae996b537cab9_amd64 as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:2f89f2bb91f00dfaa6e58acc1d11f4ebd45f2133ed35483ab492a48c448ff601_ppc64le as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:3e2dcd67840ee18ac548ab98b7381fecad0f2a465dd0c53bb935632941057c0e_arm64 as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:c2b67773686988ba3e1e22caf8aec477347bb0702fb530d9db208d1641a0ceb9_s390x as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-non-admin-rhel9@sha256:5f87e37756b9a95f45de74f134b02039cff9895eaabcfeb42df7e323ceb9288f_arm64 as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-non-admin-rhel9@sha256:6a8540ca8247f8b7591dad5ce5921b5a5b23a8817d7824c1024b86bca0cf7d37_amd64 as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-non-admin-rhel9@sha256:919db373731de8c371a5197596ebaeef9a4d3a65bf408d848a093a0d00e7993c_s390x as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-non-admin-rhel9@sha256:ba70e9b3bc7188abe19a05b1c1efa1859350611b304c2ddc47dd93698d237662_ppc64le as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-operator-bundle@sha256:e4e8d5f4cf6688139ba9c08cb3136709e8ea9fe65eec0d03bf6bfcbbbf945c6a_amd64 as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:05235069feda59356693d1d675facc7d34b85939af18350c4d084f51bdbe2baf_ppc64le as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:d93edb3b783b1b127c04ac237552e6b79a88dd5c012d54eb38c8224998732883_s390x as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:f1347b6330634758cb9d4e65902c2ca9f8eb65501c33e033476426913016e0e7_arm64 as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:f84b4e1d660345626314a8e0ba8f09d1afdc2756bc43fccc68f1abea4a6301ab_amd64 as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:3f09757662e388a65d09d04163c9c80b7a73203b4dd1cfa8c4cd9537b2f3bf38_amd64 as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:50b8257a3f52942841b152f8e6941ecb24dc0f294942b7627a2e2892ea83bb19_s390x as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:6b17d2f232968adbbc84fe3fb3f325b0dc9b7e46f9ecd3a66962f496c50a5358_ppc64le as a component of OpenShift API for Data Protection 1.5
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:d926cc6f5045abd71a35afaa9249ab63bcc4eea5f4f9845121c7502b8e0a375e_arm64 as a component of OpenShift API for Data Protection 1.5
- +20 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. Workaround: Avoid building container images using BuildKit frontends from untrusted sources. A BuildKit frontend is typically specified using a "# syntax" directive at the top of a Dockerfile, or with the "--frontend" option to the "buildctl build" command. Only use frontend images that come from a trusted source. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: Update affected Go applications to use golang.org/x/crypto version 0.52.0 or later, which rejects unsupported ConfirmBeforeUse keys instead of silently ignoring the constraint. As a workaround, do not add keys with ConfirmBeforeUse to the in-memory keyring from golang.org/x/crypto/ssh/agent, or use an SSH agent implementation that correctly enforces confirm-before-use. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path. Workaround: Restrict access to the BuildKit control API to only trusted users and services. Implement robust authentication and authorization policies for all clients interacting with the BuildKit daemon to prevent unauthorized access and potential file system escapes.
🔗 References (37)
- selfhttps://access.redhat.com/errata/RHSA-2026:66022
- externalhttps://access.redhat.com/security/cve/CVE-2026-15792
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-32283
- externalhttps://access.redhat.com/security/cve/CVE-2026-33811
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-39833
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-42508
- externalhttps://access.redhat.com/security/cve/CVE-2026-44740
- externalhttps://access.redhat.com/security/cve/CVE-2026-46595
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-53488
- externalhttps://access.redhat.com/security/cve/CVE-2026-53492
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-71235
- externalhttps://access.redhat.com/security/cve/CVE-2026-75593
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/backup_and_restore/oadp-application-backup-and-restore
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_66022.json