Red Hat Security Advisory: Red Hat Web Terminal Operator 1.17.1 release.
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
🎯 Affected products5
- Red Hat Web Terminal 1.17
- registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:49879511a7c78484f9e722dbc1d90504f8d23ef297639383d9526e85e4f8ff98_amd64 as a component of Red Hat Web Terminal 1.17
- registry.redhat.io/web-terminal/web-terminal-operator-bundle@sha256:b435089281a2b60f9dc91619ea022e6e4f3b3484f875e969522c531446b358ce_amd64 as a component of Red Hat Web Terminal 1.17
- registry.redhat.io/web-terminal/web-terminal-rhel9-operator@sha256:0a24903fb0e03762a3d701d6713c0dae12c249d7392bfd815312c8835c4dab1c_amd64 as a component of Red Hat Web Terminal 1.17
- registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:f985f3d5a9940b3cf5e231d35973d5295013242d0220756241ed5c2be0744537_amd64 as a component of Red Hat Web Terminal 1.17
✅ Remediation
To start using the Web Terminal Operator, install the Web Terminal Operator from OpenShift OperatorHub on OpenShift Container Platform 4.22 or higher. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2026:70394
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://redhat.atlassian.net/browse/WTO-523
- externalhttps://redhat.atlassian.net/browse/WTO-530
- externalhttps://redhat.atlassian.net/browse/WTO-537
- externalhttps://redhat.atlassian.net/browse/WTO-544
- externalhttps://redhat.atlassian.net/browse/WTO-551
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_70394.json