Red Hat Security Advisory: Red Hat OpenShift GitOps v1.20.8 security update
🔗 CVE IDs covered (8)
📋 Description
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-50162 — oras-go: oras-go: File store write outside working directory via symlink traversal CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56854 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
🎯 Affected products42
- Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:9219504aef129b62971960248aeab972ed8df13073b8437b11ea09f08caecbe1_s390x as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:a36c50caa37b406916dd278376eb1d35229c087beb3b82dfd511dfb41076164d_amd64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:ab47286abdc45bf45b8bfec0ecd4b3d63c9bee9fbd43d48fc5d3cb43876b00de_ppc64le as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:f2e8cad4de081b8cb9db1031378c42279afc9dcba555287964595b54542c01c2_arm64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:1f04d0d51f761b5c4e7cfd6796b7dfcec2b4ff6c43fc0a9b48e29ac126ab3641_arm64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:27868736f490d2ae04a0690c8abd271316084f86e605474be90801442abee29f_amd64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:af6ce25027d048b087fba568c85a0ba17a5635b272e2215aeac8f14c1ecda802_s390x as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:d89b4a85b4afe0ea7b759221c32c1ff0867ce7f61cf0e2ef0e05cbdc8809aad7_ppc64le as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:03697a7435a7ecb988faad6663771633b765f64320254fc0c32abb9ede750846_amd64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:5c95e70e6f3bb483966700e65211583a7d99fb308efc2f0355458eb03886cfdc_ppc64le as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:80d3d37a8f99f7af6d78aa20a41e495c078ca4e7d228c3d84eb288ade41e67ab_arm64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:d84e36da2b2c116ffbbaa3bc79f04f7c324745b048d0fe212a6c4f9daed7dc1b_s390x as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:aac2b234e8b0c1d698984068f08e127f65ad563c57e263096fe5b0fcee85c757_ppc64le as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:d7751e168acc34788363659361bc257b0fe34cc33ebc691278747a899f6f2985_arm64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:dc8e1cab87a08c403f7bd7b4b306652e4accb5c9f5706ccb626a1d942f16c874_s390x as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:ff0c3c179be1eae5dd8af3f0b273339655642deb53d91f78e29533c34311a334_amd64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:29b6164d34787ee1b4881d16d6efadbca82cd4909eb8f53126d405fffa4a2bd1_amd64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:5580f88c8f896f9a94bada7d2053eb4216be0f8b060d08eacdbb0ab49e859a07_arm64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:5e2815998b123ef256df13c8256e9a68eb174ad31d12728a3366f73212030f6d_s390x as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:7cc9d10b10bcbd007e01cf0473ad12843adff1a47abe36ac32fdac367d4e7a14_ppc64le as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:2f5fb5efc32c0744df6f8ba94cfdae028412609efb9ceb0e13d84fac95705d7f_arm64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:6f3f275f729b1c39dce4d8d4fe5b1e95d7c0cdab1f51282f5cbe890c3c909452_s390x as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:7ec5d4c543bbb0f42aae03437eb3d27779ce90cb9e5c58180e4b21634486f9bf_amd64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:b9174bc56ec02e7a71f9807e56d85c887fad782b153f17daf37f10851f4833bb_ppc64le as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:18473fe92565afb2c13427a1119e3333f885e12188bb13ae7ca52e922033b6f6_arm64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:33dbb17bfa2436b09fe2a974fb5d84ac751a8d15939ccb8bd1ebe744a9be5e0a_amd64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:563769cf60c122fa4eaadcb2649d51abf803b3448c5ba6153b8818c866c8c0e0_s390x as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:b63d4916eb9f4ff2b0381c8a82e8c44ffc0050724747f152fa7560b0925f2b47_ppc64le as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/gitops-operator-bundle@sha256:5b68b3c0bae4429238f723910f48ead084ccf40b41158676c3a8874ae65b35ca_amd64 as a component of Red Hat OpenShift GitOps 1.20
- +12 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:77273
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-50162
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56854
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_gitops/1.20/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_77273.json