Red Hat Security Advisory: Red Hat Web Terminal Operator 1.13.0 release.
🔗 CVE IDs covered (6)
📋 Description
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-27137 — crypto/x509: Incorrect enforcement of email constraints in crypto/x509 CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
🎯 Affected products5
- Red Hat Web Terminal 1.13
- registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:33aedbb88539c99ebf0a85e99a1f0b7e681f69a9ee281e88c5ff214e54d85d8a_amd64 as a component of Red Hat Web Terminal 1.13
- registry.redhat.io/web-terminal/web-terminal-operator-bundle@sha256:54ef39794ebdb90596e4666bb89e23a4fad8fe8cdc79eb825f1c57af5af9951b_amd64 as a component of Red Hat Web Terminal 1.13
- registry.redhat.io/web-terminal/web-terminal-rhel9-operator@sha256:c9e040ffac9873b07f37d29b8c83cbebf5f380d94c46be86ad63798afe8ba363_amd64 as a component of Red Hat Web Terminal 1.13
- registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:790b2a87d81149568d58618db96e7804068b2bc112ff9313e0a06e95ac9841de_amd64 as a component of Red Hat Web Terminal 1.13
✅ Remediation
To start using the Web Terminal Operator, install the Web Terminal Operator from OpenShift OperatorHub on OpenShift Container Platform 4.18 or higher. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2026:8338
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/CVE-2026-25679
- externalhttps://access.redhat.com/security/cve/CVE-2026-27137
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://redhat.atlassian.net/browse/WTO-366
- externalhttps://redhat.atlassian.net/browse/WTO-371
- externalhttps://redhat.atlassian.net/browse/WTO-375
- externalhttps://redhat.atlassian.net/browse/WTO-381
- externalhttps://redhat.atlassian.net/browse/WTO-386
- externalhttps://redhat.atlassian.net/browse/WTO-391
- externalhttps://redhat.atlassian.net/browse/WTO-396
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_8338.json