Red Hat Security Advisory: Red Hat Web Terminal Operator 1.15.0 release.
🔗 CVE IDs covered (5)
📋 Description
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-27137 — crypto/x509: Incorrect enforcement of email constraints in crypto/x509
🎯 Affected products5
- Red Hat Web Terminal 1.15
- registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:1a4e4ddfdd6f353c67172dec6b6d5e3c07d3f67410d537066e2b0321b044698a_amd64 as a component of Red Hat Web Terminal 1.15
- registry.redhat.io/web-terminal/web-terminal-operator-bundle@sha256:69bbe9115e6a686bf3efba029c4d27fe87a003745536db3a80abe7466398206d_amd64 as a component of Red Hat Web Terminal 1.15
- registry.redhat.io/web-terminal/web-terminal-rhel9-operator@sha256:a531c9a89a0ddf261241c353de8866f6609b535e3dbaf05bf3ff410234398d7b_amd64 as a component of Red Hat Web Terminal 1.15
- registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:4c3d303dca13ac5383927d0c428b9418a6009e2b8ee686b1f246c94b783e02b0_amd64 as a component of Red Hat Web Terminal 1.15
✅ Remediation
To start using the Web Terminal Operator, install the Web Terminal Operator from OpenShift OperatorHub on OpenShift Container Platform 4.20 or higher. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2026:8167
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/CVE-2026-25679
- externalhttps://access.redhat.com/security/cve/CVE-2026-27137
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://redhat.atlassian.net/browse/WTO-368
- externalhttps://redhat.atlassian.net/browse/WTO-373
- externalhttps://redhat.atlassian.net/browse/WTO-377
- externalhttps://redhat.atlassian.net/browse/WTO-383
- externalhttps://redhat.atlassian.net/browse/WTO-390
- externalhttps://redhat.atlassian.net/browse/WTO-393
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_8167.json