Red Hat Security Advisory: Red Hat OpenShift Builds 1.8.2
🔗 CVE IDs covered (10)
📋 Description
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56854 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-71556 — github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution
🎯 Affected products38
- Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:0b79371fc4b8aa5c102721f4eab4844b387a8588a1a9251b97399c02c8cd6913_amd64 as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:47ca1b9c64d67fdb1349e1e0441073b92bf96c8360d7fbb582e0ab895614bd9d_ppc64le as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:b868303e6b11ec72513f040a7283b683b71a8dd21b4cd755bee5b525ad0f73aa_s390x as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:daac50379d3b9ade972316b1c5beaf88b7854b0406f992eda34e61e25621d477_arm64 as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:3184a6c724648b2cf0f16633843893dc14a701322d3cd07da9bca1d44db4bea8_s390x as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:69476b98ad47fd46ee9e8e4dcb675cfdfd690741d4a300f56212eb69f38e04ed_ppc64le as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:cc47b40aa9fff307345e43aa8feab3b784399f8e0c6ef524a24aa48cb610786f_arm64 as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:dd8b319ca717f4e6ef937eda90224ca49ae719c1542b5ea4d6ecc3e962691699_amd64 as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:332ae7ff62506e996d43c2025ccd97cfd248894e8e6820d048f0dbe846049b53_arm64 as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:39ef60f276f42488c3dd4ab82ce77b05dcbcad6a7f762ac334fd9a817c73a6d2_s390x as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:9a99e5b253cbe27a0cb224146384d1eb2389e12105e2dce6d47a247ba1d96e1d_ppc64le as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:deea4876a35572800aaa040d9d8a1a561e83db1308a3e06919a18b705a4b5230_amd64 as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:56c6d824f7882e3919e0f64cb588e29a6e2e2e362960093aa78e4340963409c2_arm64 as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:b4ad4464947343e70d2797cffcde5a24750418e0a1246db4d3a27e527e9247e5_ppc64le as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:c98e45ded58bc8b76be0bb00067618430680674711a2bcd85c928da03930e2c2_s390x as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:fa1b6cf4773e0b89379e6197b8de7bce62f645a1f8cb0363415b15e9d11b97b6_amd64 as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-operator-bundle@sha256:f10ea49c62ae90ab5e50603805525d56dd05a2756f1f3ef7047b10e848334c33_amd64 as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:b570f9d820c67fc3e288f22447bce4c267b3079661004a5cb07589aad6168c1f_ppc64le as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:dadcc914df9cacb66d49c1997d949de8dac40b0e7262226f0331091556f7cdc9_amd64 as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:ead23921e08bd601433da316d909d32488ff52bb50a0e4edcf446573c5b4edfe_arm64 as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:eb7ec783d4d417b5bf5f401c12bc0fe12ca1888c87c966dd590432c4415e0a03_s390x as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:3e6c8363bcf9c7ac870fb122bee0ab51ab6534fa6ec73a72679e472108fd3baf_amd64 as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:49c9189a03b7c65c28ba6786584a5c8e71e32c94363bfff4752d6f775443e304_s390x as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:87af96ae285b0973f1b11557a72a15b948ea27cef60c7b6f75a94cf7539f9cc7_arm64 as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:f0482177e9624d86644c846ac496b03960f05ab0893e78276bf9a20ba2c8ce78_ppc64le as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:47437484b971236485be70004fb0b11e6f6b16b3de7558dde72e453566c5ccfd_arm64 as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:52e1c0911dcbcb415ec30aba209b5cdf8571e04633b7a7d17852c2d2549f0915_amd64 as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:66fd4518b5143efc1240c33a42379d661fcd836ef770fdfa99691a91ca89ecbb_s390x as a component of Red Hat OpenShift Builds 1.8.1
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:d4efe63ca37bb0cf590cab527050b17aeb3799e250a0857ff6ef17f1ba72ea62_ppc64le as a component of Red Hat OpenShift Builds 1.8.1
- +8 more not shown
✅ Remediation
It is recommended that existing users of Red Hat OpenShift Builds 1.8.z upgrade to 1.8.2 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later).
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2026:69928
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56854
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-71556
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_69928.json