Red Hat Security Advisory: Red Hat Web Terminal Operator 1.15.2 release.
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
🎯 Affected products5
- Red Hat Web Terminal 1.15
- registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:65f8aba0d6534f741dec91dea85ebfab31a1ea99883d0f0bffad3ae4a49ac12e_amd64 as a component of Red Hat Web Terminal 1.15
- registry.redhat.io/web-terminal/web-terminal-operator-bundle@sha256:cb445623e6426d97cd9c40710a1798d2a55df15aa1ede29ce5afd38e9591e077_amd64 as a component of Red Hat Web Terminal 1.15
- registry.redhat.io/web-terminal/web-terminal-rhel9-operator@sha256:84e322cc84b73862139e07c049a0ad6be04e63c118318dea53f68c5f078b94ca_amd64 as a component of Red Hat Web Terminal 1.15
- registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:8e5f14416926b36c1533a13197c9c1a5908e4bfb8b8d457253b6b7f5c60d9935_amd64 as a component of Red Hat Web Terminal 1.15
✅ Remediation
To start using the Web Terminal Operator, install the Web Terminal Operator from OpenShift OperatorHub on OpenShift Container Platform 4.20 or higher. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2026:70393
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://redhat.atlassian.net/browse/WTO-521
- externalhttps://redhat.atlassian.net/browse/WTO-528
- externalhttps://redhat.atlassian.net/browse/WTO-535
- externalhttps://redhat.atlassian.net/browse/WTO-542
- externalhttps://redhat.atlassian.net/browse/WTO-550
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_70393.json