Red Hat Security Advisory: Red Hat OpenShift GitOps v1.21.5 security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-50162 — oras-go: oras-go: File store write outside working directory via symlink traversal CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56854 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions
🎯 Affected products42
- Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:032920dfca6f029af5cae69f462449eec3a1d4119be7466607294b5828a79f1f_arm64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:406593b925ee30ec43661ea90368f705689de6234b1b422a1c819dac3c0daff5_amd64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:47724fa440a51c8cd9c82fbd205e1c1e4854764298e02281f528b21ad6879a5d_s390x as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:de9c1622fbd7cc50ad66bfd32390f597a46034b9104fd78704864fda25ee0fbd_ppc64le as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:19512146836efa84057b9e50b9d7900695172c0d5864d1e3bdcdfae4281cb899_arm64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:2a615abf1722e91dec261408f02c125006e7328f552aec5d2e597d47a46e9849_ppc64le as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:56da59bec26f5db84d12f3b58dd6b14d1b675782d1004f503e93c85ff01bba8d_s390x as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:a5b2c663350de430f0c970347a5676aafdb43c778695e3e98b093f3455c03a93_amd64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:0f73995b3f3ca9ba851492d938f4ff885a35b5c89b2360ef9c73c74bf568452b_amd64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:4b236f6514c994331160be3251e19142313e3af3cf74172bedaf1c9a1164f42b_s390x as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:6cd5ad5b7adddd7982c35de161ffbf5b37d33cdecc4336cc8ea9159730a0557f_arm64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:a4be367f0b80db8ced20c8ebba2589c72ddfade14c1d695b163c980f9d67531d_ppc64le as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:2d125f10085f0f5528e4ec501e3382ed4970d4549178815b13a2c1d0b6e566ab_ppc64le as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:5868c23f6100c6dfb6480b7d5dcba931e2e921bf2a68d56c5154a905a6378e54_arm64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:abae959302bc998a06d414ab6de56a695779d965ffe5456d79d3f3017325ac8e_s390x as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:b973526c361b32580e0b4fb9670ed602ee13b34b8474115d35e6aa3155212d9d_amd64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:49cb6fac7a1ee4c44053822a447b2c57abf5a0e195076e2f1208af1eff26166c_amd64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:f32c3010f66d945f41d7289e79022f47bcadb4b81429a4f401ce2bc6ac64f6cb_s390x as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:f53638b4470adcd01a4d023e82aa05a719deafed146c7a169b606e089307f231_ppc64le as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:ffa4d96e59265f09ebb23f4fb3d607ffb58abd5a12ec9220c5728a7b59ef81c5_arm64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:1340e125539783821a958146cd51a9675b633d6e9e8c2fab335eb0a39d3722ec_arm64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:147b67179b88ec8c63aa3d3cc10e11a9ce6a0c940c4bf3911519ffb56d7b8909_amd64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:669576fd9f27835fdac8f2fd891a6d2a5fc9a77b725636d376aeff091d11bb0c_s390x as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:69082f001997c1e78caf3bab6a141c1caf5d01d08a6a118c2959af124469f420_ppc64le as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:3fe442406e293cd2f732344fd82d1402c7a7743e8ac898f9703c319375d8c9bc_s390x as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:92a8a5337c2a3efbe0dc84c76bb85d7bee8feed33c0b3f5366a3e715a47448a7_amd64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:c74882ec2776b9c3e979f76fd5fff08fa88efd7c7f8e618717005829444d1a4d_ppc64le as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:cf1e7307d5fc72f28a4e976a467a4ffbc68e8d69874dca7fc7a3161933013ff6_arm64 as a component of Red Hat OpenShift GitOps 1.21
- registry.redhat.io/openshift-gitops-1/gitops-operator-bundle@sha256:1e65eafa4600cfcf853d07f17596bf725693cdd8b6ef3ccd952936b134026158_amd64 as a component of Red Hat OpenShift GitOps 1.21
- +12 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:77269
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-50162
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56854
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_gitops/1.21/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_77269.json