Red Hat Security Advisory: Red Hat Web Terminal Operator 1.16.2 release.
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
🎯 Affected products5
- Red Hat Web Terminal 1.16
- registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:515e07fa7137917ed01cce67ebee3bfb0de08edac67f04a9232ca6f327e2e453_amd64 as a component of Red Hat Web Terminal 1.16
- registry.redhat.io/web-terminal/web-terminal-operator-bundle@sha256:e8b2f94a11b4724d90b7a50568b51dfef44a6751eb93b49ba9f8851cf9ad17bb_amd64 as a component of Red Hat Web Terminal 1.16
- registry.redhat.io/web-terminal/web-terminal-rhel9-operator@sha256:3f3443c4d29148c336b9ebc899bbfbac6dcab40ce64e7e3add06875895c95435_amd64 as a component of Red Hat Web Terminal 1.16
- registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:b7280b90f53e01998eb7fedd12ce220cfafd911e4bd7b53d7b78799ae4072c40_amd64 as a component of Red Hat Web Terminal 1.16
✅ Remediation
To start using the Web Terminal Operator, install the Web Terminal Operator from OpenShift OperatorHub on OpenShift Container Platform 4.21 or higher. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2026:70395
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://redhat.atlassian.net/browse/WTO-522
- externalhttps://redhat.atlassian.net/browse/WTO-529
- externalhttps://redhat.atlassian.net/browse/WTO-536
- externalhttps://redhat.atlassian.net/browse/WTO-543
- externalhttps://redhat.atlassian.net/browse/WTO-549
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_70395.json