RHSA-2026:70828HighCVSS 7.5

Red Hat Security Advisory: RHTAS 1.3.8 - Red Hat Trusted Artifact Signer Release

Published
September 23, 2026
Last Modified
October 1, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-56854 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions CVE-2026-71556 — github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution CVE-2026-73500 — etcd: etcd: Denial of Service via unbounded TLS handshake goroutines

🎯 Affected products6

  • Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/cosign-rhel9@sha256:a219166aed42f7720e27c23deb504a8753a29b3757257e4db3884c30eae331b8_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/fetch-tsa-certs-rhel9@sha256:ad230399915e0508b55053897dc0ad344dfb4ab0901310ba361893bfbf28ff08_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/gitsign-rhel9@sha256:951ec7a6b7a38d2c890e08173500b7a5b43f79b0ad80e1f7ec55b6519ebf6dc7_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/rekor-cli-rhel9@sha256:c22cdb38572e225ed0a2f619fb1878af438881498eb46ef8ab64090e740e3d1c_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/updatetree-rhel9@sha256:e926c1e1ce6b7f2314880590f57c4e046c705537e8a8b8d5804a492df25fb76f_amd64 as a component of Red Hat Trusted Artifact Signer 1.3

✅ Remediation

Red Hat Trusted Artifact Signer simplifies cryptographic signing and verifying of software artifacts such as container images, binaries and source code changes. It is a self-managed on-premise deployment of the Sigstore project available at https://sigstore.dev Platform Engineers, Software Developers and Security Professionals may use RHTAS to ensure the integrity, transparency and assurance of their organization's software supply chain. For details on using the operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/index Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later). Workaround: Restrict network access to the etcd TLS listener to only trusted clients and networks. Configure firewall rules to limit inbound connections to the etcd client port (default 2379) and peer port (default 2380) to authorized hosts. This reduces the attack surface by preventing untrusted network attackers from reaching the vulnerable service.

🔗 References (9)