RHSA-2026:70829HighCVSS 7.5

Red Hat Security Advisory: RHTAS 1.3.8 - Red Hat Trusted Artifact Signer Release

Published
September 23, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray CVE-2026-48779 — ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments CVE-2026-56854 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow CVE-2026-73088 — browserslist: Browserslist: Prototype pollution leading to denial of service CVE-2026-73089 — browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results CVE-2026-73500 — etcd: etcd: Denial of Service via unbounded TLS handshake goroutines CVE-2026-73646 — postcss: PostCSS: Information disclosure via path traversal in source map auto-loading

🎯 Affected products11

  • Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/certificate-transparency-rhel9@sha256:3cd47987002faa665cd262011d3074b16fd31fdbc30168e6c03b3b0041196f37_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/fulcio-rhel9@sha256:c588a704915623f231507206b51432a4ebb13d12740ae503860bce6ebb19cfa3_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/rekor-backfill-redis-rhel9@sha256:33dfd44c85f4699fd4e6976128846c7bc28114c3e0c01ff9c99aa2ece0daba50_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/rekor-search-ui-rhel9@sha256:7933b00020529ecbdfa107a238939773c9aa003cfa12e2236a2d397dc22acc52_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/rekor-server-rhel9@sha256:0c037fba9d943c6a54bdec1cd96114ec4a55c0f3d67c15e3a6df387b85f024f9_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/timestamp-authority-rhel9@sha256:694ac391493b38e6332997d5bea5081f42e108665deb7d94da985222cb57ebae_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/trillian-database-rhel9@sha256:d6bce7c3d1ef3e6b65afc44f6cdf7c86ec4924325a4584c914b6d1a102ce2a7a_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/trillian-logserver-rhel9@sha256:fcf18899f2e831f2d0d418f2ca571f3f39c784d6d1a1694c85d8480dcc7d3ee1_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/trillian-logsigner-rhel9@sha256:814d7fe782bb18a0a3efa8bb79810ec0ac8c8925038b25125c7cc587f2a4fa14_amd64 as a component of Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/trillian-redis-rhel9@sha256:eebfd2e7e0472bcc123aa9f41c17ff6fc531e1d76af8fb78c3c385d457a38e8a_amd64 as a component of Red Hat Trusted Artifact Signer 1.3

✅ Remediation

Red Hat Trusted Artifact Signer simplifies cryptographic signing and verifying of software artifacts such as container images, binaries and source code changes. It is a self-managed on-premise deployment of the Sigstore project available at https://sigstore.dev Platform Engineers, Software Developers and Security Professionals may use RHTAS to ensure the integrity, transparency and assurance of their organization's software supply chain. For details on using the operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/index Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: To reduce exposure, ensure that the `browserslist` tool processes only trusted `browserslist-stats.json`, `opts.stats`, and CLI `--stats` data. Avoid using the tool with untrusted input sources in development or build environments. If `browserslist` is integrated into automated pipelines, validate all input data originates from trusted sources. Workaround: Restrict network access to the etcd TLS listener to only trusted clients and networks. Configure firewall rules to limit inbound connections to the etcd client port (default 2379) and peer port (default 2380) to authorized hosts. This reduces the attack surface by preventing untrusted network attackers from reaching the vulnerable service.

🔗 References (15)