Red Hat Security Advisory: external secrets operator for Red Hat OpenShift 1.2.1
🔗 CVE IDs covered (8)
📋 Description
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-71556 — github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution
🎯 Affected products5
- external secrets operator for Red Hat OpenShift 1.2
- registry.redhat.io/external-secrets-operator/external-secrets-rhel9@sha256:28f303432f34c0c60815efb140f2d3d26d1f0e9cd1dcb8246ec9f12944d98629_ppc64le as a component of external secrets operator for Red Hat OpenShift 1.2
- registry.redhat.io/external-secrets-operator/external-secrets-rhel9@sha256:6603672dc04b2fbbb3e043e9180da5d83e690865cceb9680ba07c417f4385788_amd64 as a component of external secrets operator for Red Hat OpenShift 1.2
- registry.redhat.io/external-secrets-operator/external-secrets-rhel9@sha256:6d3ac3ccefd4ac8c2f25e543718d3dcc8597a64e8a479c1300440abe47388cc4_s390x as a component of external secrets operator for Red Hat OpenShift 1.2
- registry.redhat.io/external-secrets-operator/external-secrets-rhel9@sha256:f369f5758ae02eb3bc79cdfc9067f56301e295e329dca2d24a71703582c0295a_arm64 as a component of external secrets operator for Red Hat OpenShift 1.2
✅ Remediation
Before installing the operator, make sure all previously released errata relevant to your system have been applied. The steps to apply the upgraded images will differ depending on the installation plan approval policy that will be used while installing the external secrets operator for Red Hat OpenShift. - If the approval policy is set to `Automatic`, then the Operator will be upgraded automatically when there is a new version of the Operator. No further action is required to upgrade. This is the default setting. - If you changed the approval policy to `Manual`, then you must manually approve the upgrade to the Operator. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later).
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:66363
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-71556
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/security_and_compliance/external-secrets-operator-for-red-hat-openshift
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_66363.json